5 AI Governance Frameworks
Built In. Not Bolted On.
Not On the Roadmap.
Every competitor either lacks AI governance entirely or has announced a future roadmap item. Aegis supports all five major AI risk frameworks in production today.
Production
🏛️
NIST AI RMF
AI Risk Management Framework 1.0 + Generative AI Profile (NIST AI 100-1)
The foundational US federal AI risk framework. Maps to the four core functions: Govern, Map, Measure, and Manage. Aegis tracks AI system inventory, risk assessments, and control evidence across all four functions with continuous posture monitoring.
- AI system inventory with risk classification
- Govern/Map/Measure/Manage function mapping
- GenAI Profile control coverage (NIST AI 100-1)
- Continuous risk posture monitoring
Production
📋
ISO 42001
Artificial Intelligence Management System — International Standard (2023)
The international standard for AI management systems, establishing requirements for responsible development, deployment, and use of AI. Aegis maps ISO 42001 controls alongside your existing ISO 27001 posture, enabling unified evidence collection and audit readiness.
- AI management system (AIMS) controls
- Unified evidence library with ISO 27001
- AI impact assessment workflow
- Supplier and third-party AI risk
Production
⚖️
EU AI Act
Regulation (EU) 2024/1689 — Risk-Based AI Regulatory Framework
The world's first comprehensive AI regulation. Aegis classifies your AI systems by risk tier (Unacceptable / High / Limited / Minimal), tracks conformity assessment obligations, and maintains the technical documentation required under Articles 11–17 for high-risk AI systems.
- AI system risk classification (4 tiers)
- High-risk system conformity tracking
- Technical documentation (Art. 11-17)
- Human oversight & transparency controls
Production
🔐
OWASP LLM Top 10
OWASP Top 10 for Large Language Model Applications (v1.1, 2025)
The definitive security reference for organizations deploying LLMs. Aegis maps your AI system controls to all 10 LLM risk categories — prompt injection, insecure output handling, training data poisoning, supply chain vulnerabilities, and six more — with continuous control monitoring.
- All 10 LLM risk categories mapped
- Prompt injection detection controls
- Supply chain & plugin security
- Sensitive information disclosure tracking
Production
🎯
MITRE ATLAS
Adversarial Threat Landscape for AI Systems — MITRE Knowledge Base
The adversarial ML threat matrix, built on the same structure as MITRE ATT&CK. Aegis maps AI-specific adversarial tactics — reconnaissance, resource development, model evasion, data poisoning — to your AI systems' detective and preventive controls.
- Adversarial ML tactic/technique mapping
- Model evasion & inversion controls
- Training data poisoning detection
- AI-specific threat intelligence feed
Key Differentiator
🏆
All 5. One Platform.
No other GRC platform does this today
We checked. As of Q1 2026, no existing GRC platform — not ServiceNow, Archer, Drata, or any other — has all five AI governance frameworks built in natively and in production. Most have zero. A few have announced roadmap items for one. Aegis ships them all, today, alongside your full traditional GRC posture.
Competitor Status
ServiceNow: 0 native (roadmap announced) · Drata: 0 · Archer: 0 · Aegis: 5 in production