Skip to main content

Framework setup (compliance programs)

Frameworks in the left sidebar is where you set up one compliance program for the whole workspace. You choose which organizational standards apply, then track controls, risks, and progress.

The page title is Organizational frameworks.


What you pick here vs on an AI use case​

These are two different lists.

WhereWhat you attach
Frameworks (this page)ISO 27001, ISO 42001, NIST AI RMF, ISO 9001, GDPR Compliance Framework, SOC 2 Type II, and CCPA Compliance Framework
AI use cases (create, edit, or Settings on a use case)EU AI Act, NYC Local Law 144, and HIPAA Security Rule

You cannot add the EU AI Act, NYC Local Law 144, or HIPAA on this page. Attach those on the AI use case. That unlocks Frameworks/regulations on the use case, and for the EU AI Act also FRIA, CE marking, and Monitoring.


Where to find it​

  • Left sidebar → Frameworks (with Dashboard and Tasks).
  • From the Dashboard, click Compliance posture.

One program per workspace​

Each workspace has one organizational framework program. If you already have one, you cannot create a second — edit the existing program, or an Admin can delete it and start again.

If your plan has reached its framework limit, Create framework asks you to upgrade instead of opening the form.


If you have no program yet​

You see No framework project yet.

  • Admin and Editor can click Create framework.
  • Reviewer and Auditor cannot create a program — ask an Admin.

The empty-state copy lists ISO 27001, ISO 42001, NIST AI RMF, ISO 9001, GDPR, SOC 2, and CCPA.


Create or edit a program​

Create framework opens a form. Fill in:

FieldPurpose
Framework titleName of the program (for example “AI Governance Program”).
OwnerWho owns the program (required).
Start dateWhen the program started.
GeographyRegion (Global, EU, US, and so on).
StatusHigh-level status (Not started, In progress, and so on).
GoalWhat you are trying to achieve (required).
TeamOptional extra members.
Applicable regulationsAt least one of ISO 27001, ISO 42001, NIST AI RMF, ISO 9001, GDPR Compliance Framework, SOC 2 Type II, CCPA Compliance Framework.

Saving creates the program and loads the controls for every regulation you selected. Large catalogues can take a little while.

To edit later: Manage framework → Edit framework, or Settings → Edit. The same form opens with current values. Save changes updates this program — it does not create another one. If you remove a regulation in that form, it is unlinked the same way as Remove in Settings.


After you have a program​

The header shows Organizational frameworks. Admin and Editor see Manage framework:

  • Edit framework — update title, team, regulations, and other details.
  • Delete framework — Admin only. This permanently removes the program and related data.

On the left, switch between:

TabWhat it is
DashboardProgress, assignment coverage, and status charts
Framework risksRisks for this program, plus an optional heat map
Linked modelsModels tied to this program
Controls & RequirementsThe control work for each regulation
SettingsRead-only summary plus add/remove regulations

Dashboard tab​

Three cards:

  1. Framework progress — per regulation, completed vs total clauses (and annexes if that regulation has them). If nothing is linked: No regulations linked yet.
  2. Assignment status — how many items have an owner assigned (this is not the same as “implemented”).
  3. Status breakdown — donut per regulation: Not started, In progress, Awaiting review, Implemented. Hover a slice for count and percentage.

Framework risks tab​

Active risks for this program (not the organisation-wide Risk register).

  • Filter by risk level, or show All.
  • Risk matrix / Hide matrix toggles a likelihood × severity grid.
  • The table shows title, owner, severity, mitigation, risk level, target date, and (for Admin/Editor) edit and delete.

Empty state: No risks found.


Linked models tab​

Models connected to this program. Open model registry → takes you to Model registry.

To link a model: in the model form, use Used in framework programs, or attach the model to an AI use case that uses this program.


Controls & Requirements tab​

Pick a regulation at the top (one pill per linked standard). Search by code or title.

How each regulation looks​

RegulationWhat you see
ISO 27001, ISO 42001, ISO 9001Clauses and, when they exist, Annexes. Expand a group, then open a row for full detail. ISO 9001 has no annex tab.
NIST AI RMFGovern, Map, Measure, and Manage — not ISO-style clauses. Open a subcategory to document it.
GDPR Compliance FrameworkChapters and articles — not ISO clauses.
SOC 2 Type IITrust service categories (CC1, CC2, and so on) and the controls inside each one. Open a control to answer its question and attach evidence.
CCPA Compliance FrameworkCategories (Consumer Rights, Business Obligations, Security Requirements) and the requirements inside each one. Open a requirement to document it; the listed questions are prompts, not separate rows.

Admin and Editor can change status from the list (look for Saving…, then a Control saved message) or open a row for the full panel. Reviewer and Auditor can view only.

Statuses you can choose: Not started, Draft, In progress, Awaiting review, Awaiting approval, Implemented, Needs rework.

When you open a control​

SectionPurpose
DetailsDescription, key questions, implementation notes, status, owner / reviewer / approver, due date, auditor feedback
EvidenceFiles for this control — upload or pick from the evidence library (PDF, images, Office, text, CSV; max 20 MB)
Cross mappingsLink risks from your risk lists (not the same as the Framework risks tab)
NotesExtra notes, separate from the implementation description

Most fields save when you change them or when you leave the box. Use Save if you prefer one explicit save.

Pick a regulation
│
▼
Search (optional)
│
▼
Open a requirement
│
▼
Details · Evidence · Cross mappings · Notes

Settings tab​

Project details (read-only): title, status, owner, start date, geography, goal, team, and regulation chips. Edit opens the same form as create.

Framework management: add or remove regulations. Adding one loads its controls and questions.

  • Add to program / Remove (shows Updating… while it runs).
  • The list is the same organizational catalogue: ISO 27001, ISO 42001, NIST AI RMF, ISO 9001, GDPR Compliance Framework, SOC 2 Type II, CCPA Compliance Framework. EU AI Act, NYC Local Law 144, and HIPAA are not listed here.

Who can do what​

See Workspace roles & permissions for the four roles.

  • Admin or Editor: create, edit, add/remove regulations, update controls, manage framework risks.
  • Delete framework: Admin only.
  • Reviewer and Auditor: view only.