23% of NIST AI Risk Management Framework (AI RMF 1.0) you already have
SA8000:2014 already covers about 23% of NIST AI Risk Management Framework (AI RMF 1.0), leaving
40 of 52 controls as genuinely new work.
Already covered 2
Likely covered 10
New work 40
What is genuinely new work
Nothing in SA8000:2014 reaches these. This is the list to scope.
AIRMF-GOV-02AI Risk Culture
AIRMF-GOV-03AI Compliance and Legal
AIRMF-GOV-04Third-Party AI Risk
AIRMF-GV-1.1Legal and regulatory requirements involving AI are understood, managed, and documented
AIRMF-GV-1.2Trustworthy AI characteristics are integrated into organisational policies, processes, and procedures
AIRMF-GV-2.1Roles and responsibilities related to AI risk management are documented and clear
AIRMF-GV-3.1Decision making related to mapping, measuring, and managing AI risks is informed by diverse perspectives
AIRMF-GV-4.1Organisational culture and incentives prioritise AI risk management
AIRMF-MAN-02AI Monitoring and Maintenance
AIRMF-MAP-01AI System Context
AIRMF-MEA-02Bias and Fairness Assessment
AIRMF-MEA-03AI Transparency and Explainability
AIRMF-MN-1.1AI risks are prioritised and resources are allocated to manage them
AIRMF-MN-2.1Mechanisms for tracking identified risks over time are in place
AIRMF-MN-3.1AI risks and benefits from third party resources are managed
AIRMF-MN-4.1AI risk management documentation and processes are improved continuously
AIRMF-MN-4.3Incidents and errors are communicated to relevant AI actors
AIRMF-MP-1.1Context of AI system use is established and understood
AIRMF-MP-2.1Categorisation of AI systems is performed
AIRMF-MP-3.1AI capabilities, targeted usage, goals, and expected benefits and costs are understood
AIRMF-MP-4.1Approaches and metrics for risk identification are established
AIRMF-MP-5.1Risks and benefits are characterised for components, including third party components
AIRMF-MS-1.1Appropriate methods and metrics for measuring AI risk are identified and applied
AIRMF-MS-2.1Test sets, evaluation criteria, and ongoing tracking are documented
AIRMF-MS-2.11Fairness and bias are evaluated and results documented
AIRMF-MS-2.8AI system explainability and interpretability are evaluated
AIRMF-MS-3.1Approaches and metrics for risk measurement are validated by stakeholders
NIST-AI600-GOV-1Legal and Regulatory Compliance
NIST-AI600-GOV-2Safety-First Culture
NIST-AI600-GOV-3Content Provenance Governance
NIST-AI600-GOV-4Pre-Deployment Testing Governance
NIST-AI600-GOV-5Incident Disclosure Governance
NIST-AI600-MAP-3Third-Party Risk Mapping
NIST-AI600-MEA-1Confabulation Testing
NIST-AI600-MEA-2Bias and Fairness Evaluation
NIST-AI600-MEA-3Privacy Leak Assessment
NIST-AI600-MEA-5Red-Teaming and Adversarial Testing
NIST-AI600-MGT-1Content Provenance Implementation
NIST-AI600-MGT-2Human Oversight Integration
NIST-AI600-MGT-5Decommissioning Procedures
Show the 12 you already have
AIRMF-MAN-03AI Incident Response
NIST-AI600-MGT-3Third-Party Dependency Management
AIRMF-GOV-01AI Risk Management Policies
AIRMF-MAN-01AI Risk Treatment
AIRMF-MAP-02AI Risk Identification
AIRMF-MAP-03AI Impact Assessment
AIRMF-MEA-01AI Performance Metrics
AIRMF-MS-2.7AI system security and resilience are evaluated
NIST-AI600-MAP-1GAI Risk Identification
NIST-AI600-MAP-2Stakeholder Impact Assessment
NIST-AI600-MEA-4Environmental Impact Measurement
NIST-AI600-MGT-4Incident Response for GAI
How this is calculated
Already covered means a mapping runs from a control in SA8000:2014 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition