Back to home

Standards library

The frameworks your carrier, your board, and your client will ask about.

The external standards this work monitors and cites. Not a certification body — the frameworks are the authoritative source, and every citation carries a public verification link.

Standards reviewed quarterly · last reviewed September 2026

The frameworks

Cited, monitored, editorially reviewed.

Live citation counts against the methodology’s citation library. Each card links to the framework’s own public source — nothing on this page substitutes for reading the standard itself.

ISO 42001

Editorial

International standard for AI management systems.

ISO 42001:2023

First international certifiable AI management standard (published Dec 2023).

15citations in the methodology
Verify at the source →

NIST AI RMF

Auto

US framework for managing AI risk across the lifecycle.

NIST AI RMF 1.0

Active — 1.0 (Jan 2023) + Generative AI Profile (Jul 2024). RMF 1.0 under revision per the White House AI Action Plan (Jul 2025).

19citations in the methodology
Verify at the source →

EU AI Act

Auto

EU regulation classifying and governing AI systems by risk.

EU AI Act (Regulation 2024/1689)

General application from Aug 2, 2026; high-risk (Annex III) deferred to Dec 2, 2027 (Digital Omnibus, Reg. (EU) 2026/1744). Penalties up to €35M / 7% turnover (prohibited practices); €15M / 3% (high-risk & transparency).

9citations in the methodology
Verify at the source →

CMMC 2.0

Editorial

US DoD cybersecurity maturity certification for defense contractors.

CMMC 2.0

Phase 1 live since Nov 2025. Phase 2 (Level 2 third-party certification) suspended Jul 2026 pending DoD review.

8citations in the methodology
Verify at the source →

ISO 19650

Editorial

International standard for BIM and information management in construction.

ISO 19650-2:2018, ISO 19650-5:2020

Parts 1–3 in revision (DIS stage, 2026); publication targeted late 2026, 2027 as fallback. Current parts: 1:2018, 2:2018, 3:2020, 4:2022, 5:2020, 6:2025.

7citations in the methodology
Verify at the source →

IBM AI Principles

Auto

IBM's published principles for trustworthy and transparent AI.

IBM Principles for Trust and Transparency

Principles for Trust and Transparency — published governance principles.

6citations in the methodology
Verify at the source →

Colorado AI Act

Editorial

US state law governing algorithmic decision-making systems.

—

SB 24-205 was delayed, then repealed and replaced by SB 26-189 (effective Jan 1, 2027) before taking effect; the new ADMT disclosure regime drops the NIST AI RMF / ISO 42001 affirmative defense. Effective date subject to pending litigation.

ABA Opinion 512

Editorial

US bar-association guidance on generative AI in professional practice.

—

ABA Formal Opinion 512 (Jul 29, 2024) — guidance on generative AI in legal professional practice.

Auto — the framework’s canonical page is fetched on a cadence and hash-diffed; any change enters the editorial review queue. Editorial — the framework’s source page blocks programmatic clients (Cloudflare or federal WAF), so a curator verifies on schedule instead.

How we monitor

Two channels, one editorial gate.

Three frameworks (NIST AI RMF, EU AI Act, IBM AI Principles) publish their canonical text at URLs a program can fetch. We poll each on a scheduled cadence, hash the normalized content, and compare it against the last known hash. When the hash changes, an alert enters the review queue with a count of methodology citations that framework grounds.

Three frameworks (ISO 42001, ISO 19650, CMMC 2.0) publish through channels that block programmatic clients — iso.org and the DoD CIO site return 403 to any automated fetch. Rather than build fragile bypass scraping, we schedule a manual verification cadence: a curator reviews the source page and confirms the current edition is unchanged, or files a change note.

Both channels route through the same editorial gate. A detected or reported change never auto-updates methodology citations — it queues a review for a human curator. If the change matters, methodology version bumps and citations update in the next release; if it doesn’t, the alert resolves with a “no-change” note.

How the citations are used

A citation library, not a re-authoring.

The methodology grounds specific decisions to specific citations. When a rubric question depends on ISO 42001 section 6.2.4, the methodology stores a reference to ISO_42001.6.2.4 — the native citation identifier — so an auditor can trace every methodology decision back to the framework text it reads from.

Each citation row carries a public source URL, an applicability tag set (which topics / disciplines / firm sizes / use cases it applies to), a priority score (1-10, hand-curated), and the framework edition it was sourced against. Published work emits these citations in canonical form, so a downstream reader can verify each claim against the framework directly.

What this does NOT claim

We cite and monitor. We are not a certification body.

  • AECO.digital does not certify tools, firms, or deliverables to ISO 42001, NIST AI RMF, or any other framework listed here. The methodology cites and monitors these standards; it does not confer compliance with them. Certification requires third-party accreditation infrastructure that AECO.digital does not operate.
  • Citing a framework is not conferring compliance with it. The methodology reads these standards and grounds its own reasoning to them; nothing it produces implies ISO, NIST, or any third-party accreditation of a firm, a tool, or a deliverable.
  • AECO.digital is not a partner, licensee, or affiliate of ISO, NIST, the European Commission, the U.S. Department of Defense, or IBM. The frameworks are cited under standard-reference conventions; every citation carries a link to the framework’s own public source for independent verification.
  • Anything published here cites framework text and shows which reasoning grounds to which citation. That is evidence of the methodology having been applied — it is not a certificate of framework compliance, and it does not substitute for reading the standard itself.

What this means for stamped work.

These frameworks set the language a carrier, a board or a client will use. The research works through what they actually require of a licensed professional using AI — and what they leave open.