Framework setup (compliance programs)
Frameworks in the left sidebar is where you set up one compliance program for the whole workspace. You choose which organizational standards apply, then track controls, risks, and progress.
The page title is Organizational frameworks.
What you pick here vs on an AI use case
These are two different lists.
| Where | What you attach |
|---|---|
| Frameworks (this page) | ISO 27001, ISO 42001, NIST AI RMF, ISO 9001, GDPR Compliance Framework, SOC 2 Type II, and CCPA Compliance Framework |
| AI use cases (create, edit, or Settings on a use case) | EU AI Act, NYC Local Law 144, and HIPAA Security Rule |
You cannot add the EU AI Act, NYC Local Law 144, or HIPAA on this page. Attach those on the AI use case. That unlocks Frameworks/regulations on the use case, and for the EU AI Act also FRIA, CE marking, and Monitoring.
Where to find it
- Left sidebar → Frameworks (with Dashboard and Tasks).
- From the Dashboard, click Compliance posture.
One program per workspace
Each workspace has one organizational framework program. If you already have one, you cannot create a second — edit the existing program, or an Admin can delete it and start again.
If your plan has reached its framework limit, Create framework asks you to upgrade instead of opening the form.
If you have no program yet
You see No framework project yet.
- Admin and Editor can click Create framework.
- Reviewer and Auditor cannot create a program — ask an Admin.
The empty-state copy lists ISO 27001, ISO 42001, NIST AI RMF, ISO 9001, GDPR, SOC 2, and CCPA.
Create or edit a program
Create framework opens a form. Fill in:
| Field | Purpose |
|---|---|
| Framework title | Name of the program (for example “AI Governance Program”). |
| Owner | Who owns the program (required). |
| Start date | When the program started. |
| Geography | Region (Global, EU, US, and so on). |
| Status | High-level status (Not started, In progress, and so on). |
| Goal | What you are trying to achieve (required). |
| Team | Optional extra members. |
| Applicable regulations | At least one of ISO 27001, ISO 42001, NIST AI RMF, ISO 9001, GDPR Compliance Framework, SOC 2 Type II, CCPA Compliance Framework. |
Saving creates the program and loads the controls for every regulation you selected. Large catalogues can take a little while.
To edit later: Manage framework → Edit framework, or Settings → Edit. The same form opens with current values. Save changes updates this program — it does not create another one. If you remove a regulation in that form, it is unlinked the same way as Remove in Settings.
After you have a program
The header shows Organizational frameworks. Admin and Editor see Manage framework:
- Edit framework — update title, team, regulations, and other details.
- Delete framework — Admin only. This permanently removes the program and related data.
On the left, switch between:
| Tab | What it is |
|---|---|
| Dashboard | Progress, assignment coverage, and status charts |
| Framework risks | Risks for this program, plus an optional heat map |
| Linked models | Models tied to this program |
| Controls & Requirements | The control work for each regulation |
| Settings | Read-only summary plus add/remove regulations |
Dashboard tab
Three cards:
- Framework progress — per regulation, completed vs total clauses (and annexes if that regulation has them). If nothing is linked: No regulations linked yet.
- Assignment status — how many items have an owner assigned (this is not the same as “implemented”).
- Status breakdown — donut per regulation: Not started, In progress, Awaiting review, Implemented. Hover a slice for count and percentage.
Framework risks tab
Active risks for this program (not the organisation-wide Risk register).
- Filter by risk level, or show All.
- Risk matrix / Hide matrix toggles a likelihood × severity grid.
- The table shows title, owner, severity, mitigation, risk level, target date, and (for Admin/Editor) edit and delete.
Empty state: No risks found.
Linked models tab
Models connected to this program. Open model registry → takes you to Model registry.
To link a model: in the model form, use Used in framework programs, or attach the model to an AI use case that uses this program.
Controls & Requirements tab
Pick a regulation at the top (one pill per linked standard). Search by code or title.
How each regulation looks
| Regulation | What you see |
|---|---|
| ISO 27001, ISO 42001, ISO 9001 | Clauses and, when they exist, Annexes. Expand a group, then open a row for full detail. ISO 9001 has no annex tab. |
| NIST AI RMF | Govern, Map, Measure, and Manage — not ISO-style clauses. Open a subcategory to document it. |
| GDPR Compliance Framework | Chapters and articles — not ISO clauses. |
| SOC 2 Type II | Trust service categories (CC1, CC2, and so on) and the controls inside each one. Open a control to answer its question and attach evidence. |
| CCPA Compliance Framework | Categories (Consumer Rights, Business Obligations, Security Requirements) and the requirements inside each one. Open a requirement to document it; the listed questions are prompts, not separate rows. |
Admin and Editor can change status from the list (look for Saving…, then a Control saved message) or open a row for the full panel. Reviewer and Auditor can view only.
Statuses you can choose: Not started, Draft, In progress, Awaiting review, Awaiting approval, Implemented, Needs rework.
When you open a control
| Section | Purpose |
|---|---|
| Details | Description, key questions, implementation notes, status, owner / reviewer / approver, due date, auditor feedback |
| Evidence | Files for this control — upload or pick from the evidence library (PDF, images, Office, text, CSV; max 20 MB) |
| Cross mappings | Link risks from your risk lists (not the same as the Framework risks tab) |
| Notes | Extra notes, separate from the implementation description |
Most fields save when you change them or when you leave the box. Use Save if you prefer one explicit save.
Pick a regulation
│
▼
Search (optional)
│
▼
Open a requirement
│
▼
Details · Evidence · Cross mappings · Notes
Settings tab
Project details (read-only): title, status, owner, start date, geography, goal, team, and regulation chips. Edit opens the same form as create.
Framework management: add or remove regulations. Adding one loads its controls and questions.
- Add to program / Remove (shows Updating… while it runs).
- The list is the same organizational catalogue: ISO 27001, ISO 42001, NIST AI RMF, ISO 9001, GDPR Compliance Framework, SOC 2 Type II, CCPA Compliance Framework. EU AI Act, NYC Local Law 144, and HIPAA are not listed here.
Who can do what
See Workspace roles & permissions for the four roles.
- Admin or Editor: create, edit, add/remove regulations, update controls, manage framework risks.
- Delete framework: Admin only.
- Reviewer and Auditor: view only.
Related help
- Workspace roles & permissions
- Tasks
- Evidence & documents
- Risk register
- Model registry
- AI use cases — attach EU AI Act / NYC Local Law 144 here
- Dashboard
- Governance Flow