ISO 42001
EditorialInternational standard for AI management systems.
ISO 42001:2023
Standards library
Six external standards AECO Compliance monitors and cites. Not a certification body — the frameworks are the authoritative source, and every citation carries a public verification link.
Methodology v3.4
The 6 frameworks
Live citation counts against the methodology’s citation library. Each card links to the framework’s own public source — nothing on this page substitutes for reading the standard itself.
International standard for AI management systems.
ISO 42001:2023
US framework for managing AI risk across the lifecycle.
NIST AI RMF 1.0
EU regulation classifying and governing AI systems by risk.
EU AI Act (Regulation 2024/1689)
US DoD cybersecurity maturity certification for defense contractors.
CMMC 2.0
International standard for BIM and information management in construction.
ISO 19650-2:2018, ISO 19650-5:2020
IBM's published principles for trustworthy and transparent AI.
IBM Principles for Trust and Transparency
Auto — the framework’s canonical page is fetched on a cadence and hash-diffed; any change enters the editorial review queue. Editorial — the framework’s source page blocks programmatic clients (Cloudflare or federal WAF), so a curator verifies on schedule instead.
How we monitor
Three frameworks (NIST AI RMF, EU AI Act, IBM AI Principles) publish their canonical text at URLs a program can fetch. We poll each on a scheduled cadence, hash the normalized content, and compare it against the last known hash. When the hash changes, an alert enters the review queue with a count of methodology citations that framework grounds.
Three frameworks (ISO 42001, ISO 19650, CMMC 2.0) publish through channels that block programmatic clients — iso.org and the DoD CIO site return 403 to any automated fetch. Rather than build fragile bypass scraping, we schedule a manual verification cadence: a curator reviews the source page and confirms the current edition is unchanged, or files a change note.
Both channels route through the same editorial gate. A detected or reported change never auto-updates methodology citations — it queues a review for a human curator. If the change matters, methodology version bumps and citations update in the next release; if it doesn’t, the alert resolves with a “no-change” note.
How the citations are used
The ACS methodology grounds specific decisions to specific citations. When a rubric question depends on ISO 42001 section 6.2.4, the methodology stores a reference to ISO_42001.6.2.4 — the native citation identifier — so an auditor can trace every methodology decision back to the framework text it reads from.
Each citation row carries a public source URL, an applicability tag set (which topics / disciplines / firm sizes / use cases it applies to), a priority score (1-10, hand-curated), and the framework edition it was sourced against. Reports generated by AECO Shield emit these citations in canonical form, so a downstream reader can verify each claim against the framework directly.
What this does NOT claim
Every tool in the registry is scored against the methodology that grounds to these six frameworks. Scores are versioned; citations are traceable.
See how tools score against these →