Skip to main content
ComplianceOps Book a consultation
Menu
Frameworks

The frameworks your buyers actually ask about.

Each one means something specific to a buyer, regulator, or board. Here is what each one is — and where each one matters.

01

SOC 2

AICPA · Trust Services Criteria

How we run it

What it is

The report most US enterprise buyers ask for. Demonstrates that you have controls over security, availability, processing integrity, confidentiality, and privacy.

Why it matters

Unblocks the procurement and vendor review process for almost every deal in the US mid-market and above.

02

ISO 27001

ISO/IEC · International standard

How we run it

What it is

The world's most recognized standard for an information security management system (ISMS). Certifiable by accredited bodies.

Why it matters

The default expectation in Europe and large swathes of APAC. Pairs well with SOC 2 for global deals.

03

ISO 42001

ISO/IEC · AI management system

How we run it

What it is

The first internationally recognized AI management system standard. Governs how AI is developed, deployed, and operated inside an organization.

Why it matters

Increasingly the answer enterprise buyers and regulators want when they ask "how do you govern your AI?"

04

NIST CSF 2.0

NIST · Cybersecurity Framework

How we run it

What it is

A flexible, outcome-based framework for maturing a cybersecurity program. The 2.0 update added Govern as a top-level function alongside Identify, Protect, Detect, Respond, Recover.

Why it matters

A common language for boards, customers, and insurers to ask about maturity — particularly across distributed and global organizations.

05

NIST AI RMF

NIST · AI Risk Management Framework

How we run it

What it is

A voluntary, US-anchored framework for managing risk across the AI lifecycle: Govern, Map, Measure, Manage.

Why it matters

The practical baseline most enterprise buyers and US regulators expect when asking about AI risk practices.

Not sure which framework fits your buyers?

We will map the frameworks your prospects, investors, and regulators actually expect — and the sequence to get there.

Book a consultation