Guides · APRF practice notes
Governance Guides
Name owners, accept residual risk explicitly, and map APRF evidence to SOC 2 and ISO. These guides support APRF Organizational Governance and Compliance.
Ownership, risk acceptance, and audit mapping — APRF Governance & Compliance.
For SOC 2 control checklists and posture patterns, see Cybersecurity guides.
AI Production Readiness Framework
Related APRF controls
- AI Production Readiness
AI production readiness is the engineering question of whether a specific AI application can safely operate in production—security, evaluation, operability, cost, and governance—not whether a demo worked.
- AI Readiness
AI readiness describes whether people, processes, and systems are prepared to use AI responsibly. It is broader than AI production readiness, which asks whether a specific AI application can safely operate in production.
- AI System Ownership, RACI, and Risk Acceptance
Ungoverned AI is everyone-and-nobody's problem. APRF Organizational Governance requires a named owner, RACI for control gates, and explicit risk acceptance when you ship with residual gaps.
- Mapping APRF Evidence to SOC 2 and ISO for AI
Do not rebuild AI controls from scratch for every audit. APRF Compliance expects a crosswalk: gate evidence that maps to SOC 2 Trust Services and ISO control objectives—with AI-specific artifacts included.
Next: Organizational Governance
Open the related pillar specification for mandatory checks, artifacts, and pass conditions. Self-attest is optional.