Standards
The framework stack we deliver against.
We do not invent frameworks. We deliver against the standards your regulators, auditors, and board already recognise. Below is the stack used in every Inline Code engagement, and the optional layers we add for clients with offshore exposure.
Layer
AI risk taxonomy
Standard
NIST AI RMF 1.0 and Generative AI Profile (NIST AI 600-1)
Purpose
Organising backbone for all assessments and reports. Function-based structure: govern, map, measure, manage.
Jurisdiction
United States, internationally adopted
Layer
Management system
Standard
ISO/IEC 42001:2023
Purpose
Structure for ongoing AI management system implementation. The certifiable management standard for AI.
Jurisdiction
International (ISO)
Layer
Privacy
Standard
Australian Privacy Principles, Privacy Act 1988
Purpose
Data handling for AI inputs and outputs. APP 6, 8, and 11 are the heart of AI data governance.
Jurisdiction
Australia (OAIC)
Layer
Prudential, information security
Standard
APRA CPS 234
Purpose
Information security obligations for regulated financial entities. Mandatory.
Jurisdiction
Australia (APRA-regulated)
Layer
Prudential, operational risk
Standard
APRA CPS 230
Purpose
Operational risk management, including material service providers. AI tooling falls in scope.
Jurisdiction
Australia (APRA-regulated)
Layer
Application threat coverage
Standard
OWASP Top 10 for LLM Applications
Purpose
Technical control selection at the application layer. Prompt injection, sensitive disclosure, supply chain.
Jurisdiction
International (OWASP)
Layer
Adversarial threat modelling
Standard
MITRE ATLAS
Purpose
Attacker tactics and techniques targeting AI systems. The MITRE ATT&CK equivalent for ML.
Jurisdiction
International (MITRE)
Layer
Foundational endpoint and identity
Standard
ASD Essential Eight
Purpose
Baseline controls where AI deployment touches identity, endpoint, or admin tooling.
Jurisdiction
Australia (ASD)
Optional layers
Add-on frameworks for offshore exposure.
For clients with users, employees, or operations outside Australia, additional regimes are layered on top of the core stack.
Risk classification
EU AI Act
Risk classification of AI systems. Applies to organisations with EU-resident users or operations.
Consumer protection
Colorado AI Act
Consequential decision systems. Applies to organisations with Colorado-resident users.
Employment AI
NYC Local Law 144
Automated employment decision tools. Applies to organisations with New York City employees.
Service control attestation
SOC 2 Type II
Service organisation controls for AI providers and AI-enabled SaaS. Increasingly expected by enterprise buyers.
Where formal legal review is required (for example contracts, regulator correspondence, statutory interpretation), we flag this and continue producing the technical artifact in parallel. We do not provide legal advice.
AI Security
How the AI Security services map to the stack.
Testing an AI system is only useful if the findings arrive in a language your existing risk process already speaks. Each service classifies its output against published frameworks for that reason.
OWASP Top 10 for LLM Applications, OWASP Top 10 for Agentic Applications, MITRE ATLAS, CVSS v3.1
Findings are classified against OWASP and mapped to ATLAS techniques, so AI findings sit alongside your ATT&CK-based reporting rather than in a separate document nobody reconciles.
NIST AI RMF, ISO/IEC 42001, Australian Privacy Principles
Control objectives are written from the RMF measure and manage functions before configuration begins, so the deployment produces its own evidence.
CISA and ASD ACSC agentic AI guidance, ASD Essential Eight, NIST CSF 2.0
Containment controls map to Essential Eight mitigations and CSF functions, so agent security is reported through the maturity model you already use.
APRA CPS 234, ASD Essential Eight, NIST CSF 2.0
In development. The intent is reporting that maps to CPS 234 obligations and Essential Eight maturity levels, described in the section below.
APRA
The AI letter, in five lines.
APRA wrote to industry on artificial intelligence on 30 April 2026. It is short, and it changed what regulated entities are expected to show.
- 01 AI is not a separate governance regime. AI-enabled IT services are managed under CPS 230 and CPS 234.
- 02 Boards are expected to hold enough AI literacy to set direction and provide effective challenge.
- 03 Vendor concentration among a small number of dominant AI providers is named as a risk to manage.
- 04 Change management built for static systems does not fit systems whose behaviour moves.
- 05 The expectation is continuous monitoring across the AI lifecycle, not point-in-time assessment.
Roadmap
How Digital CISO Agent reporting is intended to map.
The Digital CISO Agent is in development. This is the reporting model we are designing towards, published early so design partners can tell us where it is wrong.
| Reporting area | Intended mapping | Note |
|---|---|---|
| Control drift detection | CPS 234 paragraph 27, regular testing of control effectiveness | Continuous checks rather than an annual test cycle. |
| Configuration baseline monitoring | Essential Eight maturity levels one to three | Evidence collected on a schedule, scored against the level you are targeting. |
| Incident and exposure surfacing | CPS 234 paragraph 35, notification obligations | Material issues surfaced with the timeline needed to meet notification windows. |
| Monthly governance reporting | CPS 510 board oversight, CPS 230 operational risk reporting | Drafted from evidence, reviewed and signed by the accountable human. |
Nothing in this table is shipping. It describes intent, and a named human reviews and signs any reporting before it reaches a board or a regulator.
Get started
Bring AI risk under board oversight in two weeks.
A thirty-minute discovery call costs nothing. We confirm fit, scope, and timing, then issue a fixed-fee statement of work within two business days.