Machine-readable maps from APRF pillars and checks to peer frameworks. Use them for gap analysis and evidence reuse.
Not certification
Crosswalks are informative alignment only. They do not constitute NIST, ISO/IEC, OWASP, AICPA, or other endorsement—and passing APRF does not imply SOC 2, ISO 42001, or similar certification.
NIST AI Risk Management Framework
1.0 (2023)Peer sourceInformative alignment only. Does not constitute certification, accreditation, or official endorsement.
GOVERNGovernsupports
organizational-governance, compliance, model-governance, human-approvalORG-M1, ORG-M2, ORG-M3, CMP-M1, HUM-M1
MAPMapsupports
model-governance, data-governance, context-engineering, explainabilityMOD-M1, DG-M1, CTX-M1, EXP-M1
MEASUREMeasuresupports
evaluation, observability, performance-slo, safety-responsible-aiEVL-M1, EVL-M2, OBS-M1, PERF-M1, SAF-M2
MANAGEManagesupports
incident-readiness, change-management, reliability-continuity, tool-safety, agent-governanceINC-M1, INC-M2, CHG-M1, REL-M1, TOL-M1, AGN-M2
SafeSafealigns with
safety-responsible-ai, evaluation, human-approvalSAF-M1, SAF-M2, SAF-M3, HUM-M3
Secure & ResilientSecure and Resilientaligns with
ai-security, authentication, authorization, secrets, tool-safety, supply-chain, infrastructure, reliability-continuity
ExplainableExplainable and Interpretablealigns with
explainability, observabilityEXP-M1, EXP-M2, OBS-M2
Privacy-EnhancedPrivacy-Enhancedaligns with
data-privacy, memory-management, context-engineeringPRI-M1, PRI-M3, MEM-M1
FairFair — Harmful Bias Managedpartial
safety-responsible-ai, evaluation, data-governanceSAF-M3, EVL-M2, DG-M2
APRF covers fairness eval gates; organizational bias programs may need extra controls.
AccountableAccountable and Transparentsupports
organizational-governance, human-approval, explainability, change-managementORG-M2, HUM-M1, EXP-M3, CHG-M3
ISO/IEC 42001
2023 (clause-level conceptual)Peer sourceInformative alignment only. Does not constitute certification, accreditation, or official endorsement. Not a substitute for a certified AI management system.
§4Context of the organizationaligns with
organizational-governance, compliance, data-governanceORG-M1, CMP-M1, DG-M1
§5Leadershipsupports
organizational-governance, human-approvalORG-M2, HUM-M1
§6Planningpartial
organizational-governance, safety-responsible-ai, evaluation, cost-optimizationORG-M3, SAF-M1, EVL-M1, COST-M1
Risk/objectives planning spans org process plus safety and eval gates.
§7Supportpartial
platform-engineering, secrets, infrastructureDX-M1, SEC2-M1, INF-M1
Competence/awareness are org processes; APRF emphasizes platform & secrets support.
§8Operationsupports
prompt-engineering, model-governance, change-management, tool-safety, agent-governance, data-privacy
§9Performance evaluationsupports
evaluation, observability, performance-slo, complianceEVL-M1, EVL-M2, OBS-M1, PERF-M1, CMP-M2
§10Improvementaligns with
incident-readiness, organizational-governance, change-managementINC-M2, ORG-M3, CHG-M1
Annex AAI system controls (selected themes)partial
ai-security, safety-responsible-ai, data-privacy, data-governance, model-governance, human-approval, supply-chain
Annex A themes → APRF security, safety, data, model, human oversight, supply chain.
OWASP Top 10 for Large Language Model Applications
2025Peer sourceInformative alignment only. Does not constitute certification, accreditation, or official endorsement.
LLM01Prompt Injectionsupports
ai-security, prompt-engineering, tool-safetySEC-M1, SEC-M3, PRM-M1, TOL-M1
LLM02Sensitive Information Disclosuresupports
data-privacy, context-engineering, secrets, memory-managementPRI-M1, PRI-M3, SEC2-M1, MEM-M1
LLM03Supply Chainsupports
supply-chain, model-governance, infrastructureSCI-M1, SCI-M2, MOD-M1
LLM04Data and Model Poisoningsupports
data-governance, memory-management, model-governance, evaluationDG-M2, MEM-M2, MOD-M2, EVL-M1
LLM05Improper Output Handlingsupports
ai-security, tool-safety, safety-responsible-aiSEC-M3, TOL-M2, SAF-M1
LLM06Excessive Agencysupports
tool-safety, agent-governance, human-approval, authorizationTOL-M1, TOL-M2, TOL-M3, AGN-M2, HUM-M1, AUTHZ-M1
LLM07System Prompt Leakagealigns with
prompt-engineering, ai-security, secretsPRM-M2, SEC-M1, SEC2-M2
LLM08Vector and Embedding Weaknessessupports
memory-management, context-engineering, data-governanceMEM-M1, MEM-M3, CTX-M2, DG-M3
LLM09Misinformationaligns with
safety-responsible-ai, evaluation, explainabilitySAF-M2, EVL-M2, EXP-M1
LLM10Unbounded Consumptionsupports
cost-optimization, reliability-continuity, performance-sloCOST-M1, COST-M3, REL-M1, PERF-M1
Denial-of-wallet and resource exhaustion — spend ceilings + timeouts.
SOC 2 Trust Services Criteria
2017 (with 2022 revisions) — evidence reusePeer sourceInformative alignment only. Does not constitute certification, accreditation, or official endorsement. Passing APRF does not imply SOC 2 compliance.
CC1Control Environmentevidence for
organizational-governance, complianceORG-M1, ORG-M2, CMP-M1
CC3Risk Assessmentevidence for
organizational-governance, safety-responsible-ai, evaluationORG-M3, SAF-M1, EVL-M1
CC5Control Activitiesevidence for
tool-safety, human-approval, platform-engineeringTOL-M1, HUM-M1, DX-M2
CC6Logical and Physical Accessevidence for
authentication, authorization, secrets, infrastructureAUTHN-M1, AUTHN-M2, AUTHZ-M1, SEC2-M1, INF-M1
CC7System Operationsevidence for
observability, incident-readiness, reliability-continuityOBS-M1, OBS-M2, INC-M1, INC-M2, REL-M2
CC8Change Managementevidence for
change-management, model-governance, prompt-engineeringDEP-M1, CHG-M1, CHG-M3, MOD-M1, PRM-M1
CC9Risk Mitigationevidence for
supply-chain, ai-security, reliability-continuitySCI-M2, SEC-M1, REL-M1
A1Availabilityevidence for
reliability-continuity, performance-slo, infrastructureREL-M1, REL-M2, PERF-M1, INF-M2
C1Confidentialityevidence for
data-privacy, secrets, memory-managementPRI-M1, PRI-M3, SEC2-M1, MEM-M1
PI1Processing Integrityevidence for
evaluation, observability, change-managementEVL-M1, EVL-M2, OBS-M1, CHG-M3
P-seriesPrivacy (selected)partial
data-privacy, data-governance, compliancePRI-M1, PRI-M2, DG-M1, CMP-M3
Privacy TSC is broader than APRF privacy checks; use as AI evidence pack only.
AWS Well-Architected Framework
WA Framework pillars + Generative AI Lens (conceptual)Peer sourceInformative alignment only. Does not constitute certification, accreditation, or official endorsement. Not an AWS Well-Architected Lens review or AWS certification.
Operational ExcellenceOperational Excellencealigns with
observability, incident-readiness, change-management, platform-engineering, organizational-governanceOBS-M1, INC-M1, CHG-M1, ORG-M2
SecuritySecurityaligns with
authentication, authorization, secrets, ai-security, tool-safety, infrastructure, supply-chainAUTHN-M1, AUTHZ-M1, SEC2-M1, SEC-M1, TOL-M1, INF-M1, SCI-M2
ReliabilityReliabilityaligns with
reliability-continuity, performance-slo, incident-readinessREL-M1, REL-M2, PERF-M1, INC-M2
Performance EfficiencyPerformance Efficiencypartial
performance-slo, observability, context-engineeringPERF-M1, OBS-M2
Cost OptimizationCost Optimizationsupports
cost-optimizationCOST-M1, COST-M3
SustainabilitySustainabilitypartial
cost-optimization, model-governanceCOST-M1, MOD-M1
APRF does not define sustainability metrics; cost/routing and model selection are nearest proxies.
Generative AI LensGenerative AI Lens (themes)aligns with
safety-responsible-ai, evaluation, agent-governance, human-approval, prompt-engineering, model-governance, data-privacySAF-M1, EVL-M1, AGN-M2, HUM-M1, PRM-M1, MOD-M1, PRI-M1
SLSA (Supply-chain Levels for Software Artifacts)
v1.0 — conceptual levels / provenancePeer sourceInformative alignment only. Does not constitute certification, accreditation, or official endorsement. APRF alignment does not confer a SLSA level attestation.
Level 1Build process documentedpartial
supply-chain, change-management, model-governanceSCI-M2, DEP-M1, MOD-M1
Level 2Hosted build + signed provenancealigns with
supply-chain, infrastructure, change-managementSCI-M2, SCI-R1, INF-M1, CHG-M1
Level 3Hardened buildspartial
supply-chain, infrastructure, platform-engineeringSCI-M4, SCI-R1, INF-M1, DX-M2
APRF SCI-M4 / hardened admission approximate L3 themes; not a full SLSA L3 claim.
ProvenanceArtifact provenancesupports
supply-chain, model-governanceSCI-M2, SCI-R2, MOD-M1
Verify-on-deployVerification before usesupports
supply-chain, infrastructure, change-managementSCI-R1, INF-M1, CHG-M3