Framework overlap

Does NIST AI Risk Management Framework (AI RMF 1.0) cover GLI-33?

You hold NIST AI Risk Management Framework (AI RMF 1.0) and have been told to do GLI-33. Here is how much overlaps, control by control.

25% of GLI-33 you already have

NIST AI Risk Management Framework (AI RMF 1.0) already covers about 25% of GLI-33, leaving 9 of 12 controls as genuinely new work.

Already covered 1 Likely covered 2 New work 9

What is genuinely new work

Nothing in NIST AI Risk Management Framework (AI RMF 1.0) reaches these. This is the list to scope.

GLI33-Audit-Logging-InfoSec-ChangeControl
GLI-33 Audit, Significant Event Logging, Information Security, Change Control, Resilience
GLI33-CertificationLifecycle-OngoingAudit
GLI-33 Certification Lifecycle, Annual Audit, Re-Testing on Change
GLI33-Crosswalk-PCI-NIST-ISO-StateStandards
GLI-33 Crosswalk to PCI DSS, NIST CSF, ISO 27001, State Technical Standards
GLI33-Geolocation-Mobile-Internet-Wagering
GLI-33 Geolocation Verification, Mobile and Internet Wagering Security, Session Management
GLI33-Implementation-Roadmap-Roles-Tooling
GLI-33 Implementation Roadmap, Organizational Roles, Tooling and Metrics
GLI33-ResponsibleGaming-Integrity-AntiFraud
GLI-33 Responsible Gaming, Self-Exclusion, Integrity Monitoring, Anti-Fraud and Collusion Detection
GLI33-Scope-GLI-CertModel
GLI-33 Scope, Gaming Laboratories International Certification Model, GLI-19/21/27 Coordination
GLI33-StateRegulator-Adoption-Multistate
GLI-33 State Regulator Adoption, Multi-State Mobile, International Adoption
GLI33-Status-2024-2025-Pipeline-Brazil-AI
GLI-33 2024-2025 Update Pipeline, Brazil Market Entry, AI Anti-Fraud, Cryptocurrency
Show the 3 you already have
GLI33-EventWagering-System-Architecture
GLI-33 Event Wagering System Architecture, Wager Engine, Odds Engine and Risk Management
GLI33-PAM-KYC-AML-Payments
GLI-33 Player Account Management, KYC, AML, Payment Processing and Account Lifecycle
GLI33-Sports-Integrity-DataProviders-Compliance
GLI-33 Sports Event Data Integrity, Provider Certification and Regulatory Reporting

How this is calculated

Already covered means a mapping runs from a control in NIST AI Risk Management Framework (AI RMF 1.0) to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition