Map one governance control environment across multiple frameworks.
AIGR uses a unified evidence model so one verified control can contribute to several mapped requirement references without duplicating the underlying evidence.
NIST AI RMF
Govern, Map, Measure and Manage references can be associated with the same operational controls used by the assessment.
ISO/IEC 42001
Clause references can be stored for readiness mapping without redistributing copyrighted standard text.
ISO/IEC 23894
AI risk-management references support traceability between operational controls and enterprise risk practices.
EU AI Act
Applicable obligations can be mapped by jurisdiction, system role and risk context.
OECD AI Principles
Principle-level alignment provides an additional governance reference layer.
Framework mapping does not replace evidence verification.
Each mapped control still requires evidence appropriate to its scope. The four evidence tests remain relevance, currency, traceability and sufficiency.
Relevance
Directly supports the requirement.
Currency
Matches the system and period assessed.
Traceability
Has a verifiable owner, date and source.
Sufficiency
Shows the control operating in practice.
Sector frameworks use a common evidence architecture.
AIGR sector research examines how control objectives, evidence requirements and materiality thresholds vary across healthcare, finance, agentic AI, government and real estate while preserving a consistent evidence model.