6% of ISO 26262:2018 you already have
NIST AI Risk Management Framework (AI RMF 1.0) already covers about 6% of ISO 26262:2018, leaving
65 of 69 controls as genuinely new work.
Already covered 2
Likely covered 2
New work 65
What is genuinely new work
Nothing in NIST AI Risk Management Framework (AI RMF 1.0) reaches these. This is the list to scope.
ISO-26262-2-5Overall safety management
ISO-26262-2-6Safety management during the concept and product development
ISO-26262-2-7Safety management after release for production
ISO-26262-2-8Safety culture
ISO-26262-2-9Confirmation measures
ISO-26262-3-6Initiation of the safety lifecycle
ISO-26262-3-8Functional safety concept
ISO-26262-4-10Functional safety assessment
ISO-26262-4-5Initiation of product development at the system level
ISO-26262-4-6Specification of the technical safety requirements
ISO-26262-4-7System design
ISO-26262-4-8Item integration and testing
ISO-26262-4-9Safety validation
ISO-26262-5-10Hardware integration and verification
ISO-26262-5-5Initiation of product development at the hardware level
ISO-26262-5-6Specification of hardware safety requirements
ISO-26262-5-7Hardware design
ISO-26262-5-8Evaluation of the hardware architectural metrics
ISO-26262-5-9Evaluation of safety goal violations due to random hardware failures
ISO-26262-6-10Software integration and testing
ISO-26262-6-11Verification of software safety requirements
ISO-26262-6-5Initiation of product development at the software level
ISO-26262-6-6Specification of software safety requirements
ISO-26262-6-7Software architectural design
ISO-26262-6-8Software unit design and implementation
ISO-26262-6-9Software unit testing
ISO-26262-7-6Operation, service (maintenance and repair)
ISO-26262-7-7Decommissioning
ISO-26262-8-10Documentation
ISO-26262-8-11Confidence in the use of software tools
ISO-26262-8-12Qualification of software components
ISO-26262-8-13Qualification of hardware components
ISO-26262-8-14Proven in use argument
ISO-26262-8-5Interfaces within distributed developments
ISO-26262-8-6Specification and management of safety requirements
ISO-26262-8-9Verification
ISO-26262-9-5Requirements decomposition with respect to ASIL tailoring
ISO-26262-9-6Criteria for coexistence of elements
ISO-26262-9-7Analysis of dependent failures
ISO-26262-9-8Safety analyses
ISO26262-2.5Safety Management Overall
ISO26262-2.6Project Dependent Safety Management
ISO26262-3.5Item Definition
ISO26262-3.6Hazard Analysis and Risk Assessment
ISO26262-3.7Functional Safety Concept
ISO26262-4.6Technical Safety Concept
ISO26262-4.7System and Item Integration and Testing
ISO26262-4.8Safety Validation
ISO26262-5.6Hardware Safety Requirements
ISO26262-5.7Hardware Design
ISO26262-5.8Evaluation of Hardware Architectural Metrics
ISO26262-5.9Evaluation of Safety Goal Violations Due to Random Hardware Failures
ISO26262-6.10Software Integration and Verification
ISO26262-6.6Software Safety Requirements
ISO26262-6.7Software Architectural Design
ISO26262-6.8Software Unit Design and Implementation
ISO26262-6.9Software Unit Verification
ISO26262-7.6Operation, Service, and Decommissioning
ISO26262-8.11Confidence in the Use of Software Tools
ISO26262-8.12Qualification of Software Components
ISO26262-8.6Specification and Management of Safety Requirements
ISO26262-9.5Requirements Decomposition with Respect to ASIL Tailoring
ISO26262-9.7Safety Analyses
Show the 4 you already have
ISO-26262-3-5Item definition
ISO-26262-3-7Hazard analysis and risk assessment (HARA)
ISO-26262-8-7Configuration management
ISO-26262-8-8Change management
How this is calculated
Already covered means a mapping runs from a control in NIST AI Risk Management Framework (AI RMF 1.0) to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition