- Edition
- v.1.3
- Controls
- 98
- Frameworks
- 7
Mappings to adjacent frameworks.
HI-AAF was designed to be a sibling of existing assurance frameworks, not a replacement. Where a HI-AAF control evidences a requirement of NIST AI RMF, ISO/IEC 42001, OWASP LLM Top 10, SOC 2 Type II, the EU AI Act, MITRE ATLAS, or the Singapore Model AI Governance Framework, that linkage is documented here.
These mappings are directional: meeting a HI-AAF control evidences but does not by itself satisfy the corresponding external requirement. A customer pursuing certification under an external framework should use these mappings to identify evidence reuse — not to substitute one assurance for another.
Frameworks covered — primary
- NIST AI RMF
- NIST AI Risk Management Framework 1.0
- OWASP LLM Top 10
- OWASP Top 10 for Large Language Model Applications
Frameworks covered — regional & supplementary
The published v1.3 edition sets out cross-framework mapping at domain level and records that per-control mapping is maintained in the HI-AAF Assessor Manual (v1.3 §6). The figures above are the control-level references published on this page. Where a control carries no reference for a framework, the cell renders as an em dash: either the framework has no analogue at that level of granularity — the OWASP LLM Top 10 has ten items and does not reach most governance controls — or the reference has not yet been settled for public review. An em dash is never a claim that no relationship exists.
Notation
External framework references use the publishing body's native notation. NIST AI RMF uses FUNCTION CATEGORY.SUBCATEGORY; ISO/IEC 42001 uses clause numbers and Annex A control IDs; OWASP uses the LLM Top 10 short codes; SOC 2 uses AICPA Trust Services Criteria IDs; EU AI Act uses article and annex numbers; MITRE ATLAS uses tactic names; Singapore references use MAIGF dimension names, AI Verify principle names, and PDPA section numbers. An em dash (—) means no control-level reference is published for that framework at this edition; see Table C above.
Note on Singapore references: references to the Singapore Model AI Governance Framework, AI Verify principles, and the Singapore Personal Data Protection Act were introduced in v1.2 and carried forward to v1.3. They reflect the publisher's reading of those frameworks as of the date of this draft. Specific dimension names, principle labels, and statutory section references should be confirmed against current IMDA and AI Verify Foundation publications prior to citing this mapping in public materials.