Skip to content
Ayliea

STANDARDS CROSSWALK

How Ayliea's assessment maps to established AI security frameworks

Ayliea assesses AI systems against recognized frameworks and maps findings back to them — NIST AI RMF, ISO/IEC 42001, the HIPAA Security Rule, OWASP LLM Top 10, and MITRE ATLAS. Ayliea is not a certification body; a mapping documents a relationship, it does not confer certification, compliance, or endorsement.

NIST AI RMFISO/IEC 42001HIPAA Security RuleOWASP LLM Top 10MITRE ATLAS

What the crosswalk does

Every engagement organizes evidence, findings, and scoring against Ayliea's ten AI-specific control domains — governance, AI asset inventory, data protection, access control, supply-chain risk, output validation, incident response, monitoring, training, and model security.

Those findings are then crosswalked to established external frameworks so they can be discussed in language your security team, auditors, and vendors already recognize. A crosswalk means Ayliea has documented a relationship between an assessment finding and a framework concept — it does not mean the framework owner has reviewed, approved, or endorsed Ayliea, and it does not turn an Ayliea assessment into a certification against that framework.

ANCHOR FRAMEWORKS

Five frameworks findings are mapped to

NIST AI RMF 1.0

National Institute of Standards and Technology

A voluntary framework organized around four functions — Govern, Map, Measure, Manage — for identifying and managing risk across the AI system lifecycle.

Assessment findings are organized against the Govern / Map / Measure / Manage functions. NIST does not review, approve, or endorse Ayliea or its assessments.

ISO/IEC 42001:2023

International Organization for Standardization

The international standard for an AI management system (AIMS) — policy, roles, risk treatment, and continual improvement for organizations that develop or use AI.

We assess against ISO/IEC 42001 concepts to structure findings. This mapping is not a certification; ISO/IEC 42001 certification requires an audit by an accredited certification body, which Ayliea is not.

HIPAA Security Rule

U.S. Department of Health & Human Services

Administrative, physical, and technical safeguards required for electronic protected health information (ePHI) handled by covered entities and business associates.

Where an AI system touches ePHI, findings are mapped to applicable safeguard categories. This is not a certification and not a legal opinion — HIPAA compliance determinations require qualified legal counsel.

OWASP LLM Top 10

OWASP Foundation

The most critical security risks specific to large language model applications — prompt injection, excessive agency, supply-chain vulnerabilities, and more.

Findings involving LLM-based tools are aligned to the relevant OWASP LLM Top 10 risk category so terminology stays consistent with the broader application-security community.

MITRE ATLAS

MITRE Corporation

A knowledge base of adversary tactics and techniques against AI systems, structured the same way as MITRE ATT&CK.

Applicable threats identified during an assessment are mapped to ATLAS techniques to describe attacker behavior in a vendor-neutral, widely recognized vocabulary.

STRUCTURE

Ten AI-specific control domains

This is the internal structure Ayliea uses to organize evidence before it is crosswalked to the frameworks above.

AC-1

AI Governance & Policy

Organizational policies, roles, and accountability structures for AI adoption and oversight.

AC-2

AI Asset Management

Discovery, inventory, and classification of all AI tools and services in use across the organization.

AC-3

Data Protection in AI

Controls for data flowing to, from, and within AI systems — including DLP, classification, and retention.

AC-4

Access Control for AI

Authentication, authorization, and least-privilege access to AI tools and the data they process.

AC-5

AI Supply Chain Security

Vendor risk assessment, third-party AI service evaluation, and supply chain integrity verification.

AC-6

AI Output Validation

Controls ensuring AI-generated outputs are reviewed, accurate, and appropriate before use in decisions.

AC-7

AI Incident Response

Procedures for detecting, responding to, and recovering from AI-related security incidents.

AC-8

AI Monitoring & Logging

Visibility into AI system usage, data flows, anomalies, and audit trail maintenance.

AC-9

AI Training & Awareness

Employee education on safe AI usage, acceptable use policies, and organizational AI guidelines.

AC-10

Model Security

Protection of AI models from adversarial attacks, prompt injection, data poisoning, and model theft.

WHY IT MATTERS

Mapping is the proof point, not the product

The crosswalk exists to make the assessment's reasoning inspectable. The deliverable remains the assessor-led engagement and the signed evidence package.

Traceable

Every finding can be traced back to the control domain it was evaluated under and, where applicable, the framework references it was crosswalked to.

Vendor-neutral vocabulary

Mapping to widely recognized frameworks means findings can be discussed in terms your security team, auditors, and vendors already use.

Not a substitute for certification

A crosswalk documents a relationship between an assessment finding and a framework concept. It is not a certification, attestation, or endorsement by the framework owner.

Reviewable

The engagement report documents the underlying evidence for every mapped finding, so a reviewer can evaluate the basis for the mapping independently.

Need the assessment, not just the crosswalk?

A named assessor applies this structure to your environment and delivers the documented findings, framework mappings, and signed assessment package.