Purpose
Map regulatory and contractual obligations to concrete AI controls and produce auditable evidence—while recognizing compliance alone does not prove production readiness.
Mandatory checks
Gate controls. Each check is pass/fail via artifact + pass condition. Expected from the annotated capability level when the system meets the minimum criticality tier.
Every production AI system shall have applicable legal/regulatory/contractual obligations identified in a register with a named owner, or an explicit “none in scope” attestation with owner and review date within 12 months.
- Artifact
- Inventory of production AI system IDs in scope + Obligations register mapping each system to obligations (or none-in-scope) with owner and review date
- Pass condition
- Every production AI system ID has ≥1 mapped obligation entry or an explicit “none in scope” attestation with owner and review date ≤12 months (register evidence measuredAt ≤90 days). If no production AI systems exist, score NOT_APPLICABLE.
Why this control exists
Threat mapEnsure the legal and regulatory obligations that apply to production AI are identified and owned.
Threats mitigated
RepudiationInsider MisuseProtects
Audit TrailUsersSafetyMITRE: no technique mapped — this control addresses governance or assurance rather than a specific adversary technique.
Obligations that have not been identified cannot be evidenced, tested, or assigned. This is a governance precondition with no adversary technique mapping.
Informative threat context — mappings reduce exposure and do not guarantee mitigation; not certification.
Every in-scope obligation shall map to at least one evidence artifact ID (APRF Check or internal control ID) in a control→evidence matrix reviewed within 12 months, with zero orphan obligations lacking an evidence pointer.
- Artifact
- Control→evidence matrix linking in-scope obligations to APRF Checks or internal control/evidence IDs + Matrix review date (≤12 months) and confirmation of zero orphan obligation rows
- Pass condition
- 100% of in-scope obligations map to ≥1 evidence artifact ID; matrix review date ≤12 months; 0 orphan obligations without an evidence pointer (matrix evidence measuredAt ≤90 days). If no obligations are in scope (all none-in-scope), score NOT_APPLICABLE.
Why this control exists
Threat mapTie each in-scope AI obligation to the concrete evidence artifact that demonstrates it.
Threats mitigated
RepudiationProtects
Audit TrailMITRE: no technique mapped — this control addresses governance or assurance rather than a specific adversary technique.
Mapping obligations to artifacts is what makes a compliance claim verifiable rather than asserted. It is a documentation control with no adversary technique mapping.
Informative threat context — mappings reduce exposure and do not guarantee mitigation; not certification.
Critical AI control-plane changes shall be written to an audit log retained at least as long as policy requires (for example ≥365 days); a synthetic change shall appear in the log within ≤5 minutes and remain queryable after a retention smoke check.
- Artifact
- Audit log retention config for critical AI control-plane change events (policy minimum documented) + Synthetic control-plane change test showing ≤5 minute appearance and queryability after retention smoke check
- Pass condition
- Retention is configured ≥ policy minimum (e.g. ≥365 days); a synthetic control-plane change appears in the audit log within ≤5 minutes and remains queryable after a retention smoke check (config/smoke evidence measuredAt ≤90 days). If no critical AI control plane is in scope (model/prompt/tool promotion, policy, kill-switch, or equivalent), score NOT_APPLICABLE.
Why this control exists
Threat mapPreserve an immutable record of AI control-plane changes for detection and investigation.
Threats mitigated
RepudiationInsider MisusePrivilege EscalationProtects
Audit TrailLogsInfrastructureMITRE: ATLAS AML.T0081 · ATLAS AML.T0107 · ATT&CK T1070 · ATT&CK T1685
Retained, tamper-resistant control-plane logs stop an attacker from erasing evidence of model, prompt, or agent configuration changes. They are the primary detective source for unauthorized control-plane activity and the reason defence-evasion attempts remain visible.
Informative threat context — mappings reduce exposure and do not guarantee mitigation; not certification.
Evidence required
- Obligations register for the AI product
- Evidence packs per critical control
- Audit log retention configuration
Recommended checks
Strengthen posture beyond the gate. Same measurable structure; non-blocking unless elevated by organizational policy.
Documented AI/compliance controls for production systems shall be tested on the published schedule within the last cycle (≤90 days default); every open exception shall name an owner, expiry, and compensating control.
- Artifact
- Control-testing schedule + latest test results pack for in-scope AI/compliance controls + Exceptions register with owner, expiry, and compensating control for every open exception
- Pass condition
- Documented controls due in the last cycle were tested on schedule (cycle age ≤90 days default); every open exception has owner, expiry, and compensating control (testing/exceptions evidence measuredAt ≤90 days). If none are in scope, score NOT_APPLICABLE.
Why this control exists
Threat mapTest controls on a cadence and record the exceptions that testing reveals.
Threats mitigated
RepudiationConfiguration DriftProtects
Audit TrailSafetyMITRE: no technique mapped — this control addresses governance or assurance rather than a specific adversary technique.
Controls decay silently between audits, and untested controls are indistinguishable from absent ones. Periodic testing with recorded exceptions keeps posture claims honest; no adversary technique maps.
Informative threat context — mappings reduce exposure and do not guarantee mitigation; not certification.
Customer-facing trust/security documentation for production AI systems shall cover identity, safety/eval, data handling, and incident contact at minimum; include an explicit APRF pillar or Core Profile mapping table; and show a last-updated date within 12 months.
- Artifact
- Customer-facing trust/security doc with published URL and last-updated date + Explicit APRF pillar or Core Profile mapping table covering identity, safety/eval, data handling, and incident contact
- Pass condition
- Public trust doc covers identity, safety/eval, data handling, and incident contact; pillar/Core mapping table is explicit; last-updated ≤12 months (trust-doc evidence measuredAt ≤90 days). If no customer-facing production AI surface, score NOT_APPLICABLE.
Why this control exists
Threat mapGive customers an accurate, published account of the AI controls in place.
Threats mitigated
RepudiationProtects
UsersAudit TrailMITRE: no technique mapped — this control addresses governance or assurance rather than a specific adversary technique.
Published control documentation gives customers a factual basis for their own risk decisions and creates an accountable public statement of posture. It is a transparency control with no adversary technique mapping.
Informative threat context — mappings reduce exposure and do not guarantee mitigation; not certification.
Every AI system that claims or attains APRF capability maturity Level 5 (Optimizing—typically Regulated / highest-discipline production) shall be covered by an independent assessment or internal-audit report ≤12 months old that samples APRF gates and lists sampled Check IDs, findings, and remediation owners. Level 5 is capability maturity, not criticality tier (tiers are 0–3).
- Artifact
- Independent assessment or internal-audit report sampling capability Level-5 AI systems against APRF gates + Coverage proof that every capability Level-5 system ID was in scope, with findings and remediation owners
- Pass condition
- Last assessment age ≤12 months; covers every system that claims or attains capability Level 5; lists sampled Check IDs, findings, and remediation owners (assessment evidence measuredAt ≤90 days). If no systems claim or attain capability Level 5, score NOT_APPLICABLE.
Why this control exists
Threat mapObtain independent verification of control effectiveness for the highest-capability systems.
Threats mitigated
RepudiationInsider MisuseProtects
Audit TrailSafetyMITRE: no technique mapped — this control addresses governance or assurance rather than a specific adversary technique.
Self-assessment tends to overstate maturity, particularly for the systems with the most at stake. Independent assessment corrects that bias; no adversary technique maps.
Informative threat context — mappings reduce exposure and do not guarantee mitigation; not certification.
More detailPhilosophy, failures, practices, validations, examples, crosswalks, and evolution
Engineering philosophy
Compliance is necessary evidence, not sufficient engineering. APRF treats compliance as a pillar that packages proof of other pillars for auditors and customers.
Why it matters
Enterprises cannot buy or deploy AI systems that cannot demonstrate control evidence. Conversely, checkbox compliance without engineering depth still fails in production.
Common failures
- Claiming 'we are compliant' without control-to-evidence mapping
- Policies that do not match runtime behavior
- No audit trail for model and prompt changes
- Ignoring sector-specific AI obligations until late
Severity & risk
- Severity
- high
- Impact if violated
- Risk level
- medium
- Typical residual risk (impact × likelihood)
Engineering best practices
- Derive technical tickets from obligations; avoid orphan policies
- Reuse APRF pillar evidence for multiple frameworks where mappings exist
- Keep compliance language accurate: readiness ≠ certification
- Version compliance artifacts with product releases
Automatic validations
- Continuous control monitoring where automatable
- Alerts on audit log pipeline failure
- CI attaching evidence artifacts to releases
Manual validations
- Internal audit sampling
- Legal review of external AI claims
Examples
- A SOC 2 narrative points to APRF eval gates and access reviews as evidence
- Change tickets for prompt releases satisfy audit sampling requests
References
Crosswalks
GOVERN Govern
NIST AI Risk Management Framework · supports
§4 Context of the organization
ISO/IEC 42001 · aligns-with
§9 Performance evaluation
ISO/IEC 42001 · supports
L6 Security & Compliance
CSA MAESTRO (Multi-Agentic Threat Model) · supports
CC1 Control Environment
SOC 2 Trust Services Criteria · evidence-for
P-series Privacy (selected)
SOC 2 Trust Services Criteria · partial
Future evolution
Common control catalogs mapping APRF pillars to regional AI regulations.