{"frameworks":[{"framework":"eu-ai-act","controlCount":9,"scopeSource":"published","scopeIri":"https://markjspivey-xwisee.github.io/interego/ns/eu-ai-act#AuditScope","controls":[{"iri":"https://markjspivey-xwisee.github.io/interego/ns/eu-ai-act#RiskClassification","label":"AI system risk classification"},{"iri":"https://markjspivey-xwisee.github.io/interego/ns/eu-ai-act#RiskManagementRecord","label":"Risk management record (Article 9)"},{"iri":"https://markjspivey-xwisee.github.io/interego/ns/eu-ai-act#DataGovernanceAttestation","label":"Data governance attestation (Article 10)"},{"iri":"https://markjspivey-xwisee.github.io/interego/ns/eu-ai-act#LoggedAction","label":"Logged action (Article 12)"},{"iri":"https://markjspivey-xwisee.github.io/interego/ns/eu-ai-act#TransparencyDisclosure","label":"Transparency disclosure (Article 13)"},{"iri":"https://markjspivey-xwisee.github.io/interego/ns/eu-ai-act#HumanOversightCheckpoint","label":"Human oversight checkpoint (Article 14)"},{"iri":"https://markjspivey-xwisee.github.io/interego/ns/eu-ai-act#AccuracyAttestation","label":"Accuracy + robustness attestation (Article 15)"},{"iri":"https://markjspivey-xwisee.github.io/interego/ns/eu-ai-act#Article50Disclosure","label":"Article 50 disclosure"},{"iri":"https://markjspivey-xwisee.github.io/interego/ns/eu-ai-act#ConformityAssessment","label":"Conformity assessment record"}]},{"framework":"nist-rmf","controlCount":10,"scopeSource":"published","scopeIri":"https://markjspivey-xwisee.github.io/interego/ns/nist-rmf#AuditScope","controls":[{"iri":"https://markjspivey-xwisee.github.io/interego/ns/nist-rmf#Govern.1.1","label":"Govern 1.1 — policies for AI risk are documented"},{"iri":"https://markjspivey-xwisee.github.io/interego/ns/nist-rmf#Govern.1.4","label":"Govern 1.4 — policies are reviewed + updated"},{"iri":"https://markjspivey-xwisee.github.io/interego/ns/nist-rmf#Govern.2.1","label":"Govern 2.1 — accountability roles are defined"},{"iri":"https://markjspivey-xwisee.github.io/interego/ns/nist-rmf#Map.1.1","label":"Map 1.1 — context is established + understood"},{"iri":"https://markjspivey-xwisee.github.io/interego/ns/nist-rmf#Map.1.2","label":"Map 1.2 — interdisciplinary AI actors are identified"},{"iri":"https://markjspivey-xwisee.github.io/interego/ns/nist-rmf#Map.4.1","label":"Map 4.1 — likely benefits + impacts are characterized"},{"iri":"https://markjspivey-xwisee.github.io/interego/ns/nist-rmf#Measure.1.1","label":"Measure 1.1 — approaches + metrics for measuring AI risks are identified"},{"iri":"https://markjspivey-xwisee.github.io/interego/ns/nist-rmf#Measure.2.7","label":"Measure 2.7 — AI system security + resilience is evaluated"},{"iri":"https://markjspivey-xwisee.github.io/interego/ns/nist-rmf#Manage.1.2","label":"Manage 1.2 — treatment of documented AI risks is prioritized"},{"iri":"https://markjspivey-xwisee.github.io/interego/ns/nist-rmf#Manage.4.1","label":"Manage 4.1 — post-deployment AI system monitoring plans are implemented"}]},{"framework":"soc2","controlCount":25,"scopeSource":"published","scopeIri":"https://markjspivey-xwisee.github.io/interego/ns/soc2#AuditScope","controls":[{"iri":"https://markjspivey-xwisee.github.io/interego/ns/soc2#CC1.1","label":"CC1.1 — entity demonstrates commitment to integrity + ethical values"},{"iri":"https://markjspivey-xwisee.github.io/interego/ns/soc2#CC2.1","label":"CC2.1 — entity obtains/uses relevant + quality information"},{"iri":"https://markjspivey-xwisee.github.io/interego/ns/soc2#CC2.2","label":"CC2.2 — internal communication of objectives + responsibilities"},{"iri":"https://markjspivey-xwisee.github.io/interego/ns/soc2#CC3.1","label":"CC3.1 — entity specifies objectives sufficient to enable risk identification"},{"iri":"https://markjspivey-xwisee.github.io/interego/ns/soc2#CC3.2","label":"CC3.2 — entity identifies + analyzes risks to achieving its objectives"},{"iri":"https://markjspivey-xwisee.github.io/interego/ns/soc2#CC4.1","label":"CC4.1 — entity selects + develops control activities"},{"iri":"https://markjspivey-xwisee.github.io/interego/ns/soc2#CC4.2","label":"CC4.2 — entity evaluates + communicates internal control deficiencies in a timely manner"},{"iri":"https://markjspivey-xwisee.github.io/interego/ns/soc2#CC5.1","label":"CC5.1 — entity uses ongoing + separate monitoring"},{"iri":"https://markjspivey-xwisee.github.io/interego/ns/soc2#CC6.1","label":"CC6.1 — logical + physical access controls (security software, infrastructure, architectures)"},{"iri":"https://markjspivey-xwisee.github.io/interego/ns/soc2#CC6.2","label":"CC6.2 — registers + authorizes new internal/external users"},{"iri":"https://markjspivey-xwisee.github.io/interego/ns/soc2#CC6.3","label":"CC6.3 — modifies + revokes user access in alignment with role/responsibilities"},{"iri":"https://markjspivey-xwisee.github.io/interego/ns/soc2#CC6.7","label":"CC6.7 — restricts transmission, movement, removal of information"},{"iri":"https://markjspivey-xwisee.github.io/interego/ns/soc2#CC6.8","label":"CC6.8 — implements controls to prevent + detect unauthorized + malicious software"},{"iri":"https://markjspivey-xwisee.github.io/interego/ns/soc2#CC7.1","label":"CC7.1 — uses detection + monitoring to identify changes"},{"iri":"https://markjspivey-xwisee.github.io/interego/ns/soc2#CC7.2","label":"CC7.2 — monitors system components + operation for anomalies"},{"iri":"https://markjspivey-xwisee.github.io/interego/ns/soc2#CC7.3","label":"CC7.3 — evaluates security events to determine response"},{"iri":"https://markjspivey-xwisee.github.io/interego/ns/soc2#CC7.4","label":"CC7.4 — responds to identified security incidents"},{"iri":"https://markjspivey-xwisee.github.io/interego/ns/soc2#CC7.5","label":"CC7.5 — recovers from identified security incidents"},{"iri":"https://markjspivey-xwisee.github.io/interego/ns/soc2#CC8.1","label":"CC8.1 — authorizes, designs, develops, configures, documents, tests, approves changes"},{"iri":"https://markjspivey-xwisee.github.io/interego/ns/soc2#CC9.2","label":"CC9.2 — assesses + manages risks associated with vendors + business partners"},{"iri":"https://markjspivey-xwisee.github.io/interego/ns/soc2#C1.1","label":"C1.1 — identifies + maintains confidential information"},{"iri":"https://markjspivey-xwisee.github.io/interego/ns/soc2#C1.2","label":"C1.2 — disposes of confidential information per requirements"},{"iri":"https://markjspivey-xwisee.github.io/interego/ns/soc2#P1.1","label":"P1.1 — provides notice about its privacy practices"},{"iri":"https://markjspivey-xwisee.github.io/interego/ns/soc2#P3.1","label":"P3.1 — collects personal information for purposes identified in notice"},{"iri":"https://markjspivey-xwisee.github.io/interego/ns/soc2#P5.1","label":"P5.1 — grants identified subjects access to their personal information for review + update"}]}]}