Back to home

Standards library

The frameworks the ACS methodology cites.

Six external standards AECO Compliance monitors and cites. Not a certification body — the frameworks are the authoritative source, and every citation carries a public verification link.

Methodology v3.4

The 6 frameworks

Cited, monitored, editorially reviewed.

Live citation counts against the methodology’s citation library. Each card links to the framework’s own public source — nothing on this page substitutes for reading the standard itself.

ISO 42001

Editorial

International standard for AI management systems.

ISO 42001:2023

15citations in the methodology
Verify at the source →

NIST AI RMF

Auto

US framework for managing AI risk across the lifecycle.

NIST AI RMF 1.0

19citations in the methodology
Verify at the source →

EU AI Act

Auto

EU regulation classifying and governing AI systems by risk.

EU AI Act (Regulation 2024/1689)

9citations in the methodology
Verify at the source →

CMMC 2.0

Editorial

US DoD cybersecurity maturity certification for defense contractors.

CMMC 2.0

8citations in the methodology
Verify at the source →

ISO 19650

Editorial

International standard for BIM and information management in construction.

ISO 19650-2:2018, ISO 19650-5:2020

7citations in the methodology
Verify at the source →

IBM AI Principles

Auto

IBM's published principles for trustworthy and transparent AI.

IBM Principles for Trust and Transparency

6citations in the methodology
Verify at the source →

Auto — the framework’s canonical page is fetched on a cadence and hash-diffed; any change enters the editorial review queue. Editorial — the framework’s source page blocks programmatic clients (Cloudflare or federal WAF), so a curator verifies on schedule instead.

How we monitor

Two channels, one editorial gate.

Three frameworks (NIST AI RMF, EU AI Act, IBM AI Principles) publish their canonical text at URLs a program can fetch. We poll each on a scheduled cadence, hash the normalized content, and compare it against the last known hash. When the hash changes, an alert enters the review queue with a count of methodology citations that framework grounds.

Three frameworks (ISO 42001, ISO 19650, CMMC 2.0) publish through channels that block programmatic clients — iso.org and the DoD CIO site return 403 to any automated fetch. Rather than build fragile bypass scraping, we schedule a manual verification cadence: a curator reviews the source page and confirms the current edition is unchanged, or files a change note.

Both channels route through the same editorial gate. A detected or reported change never auto-updates methodology citations — it queues a review for a human curator. If the change matters, methodology version bumps and citations update in the next release; if it doesn’t, the alert resolves with a “no-change” note.

How the citations are used

A citation library, not a re-authoring.

The ACS methodology grounds specific decisions to specific citations. When a rubric question depends on ISO 42001 section 6.2.4, the methodology stores a reference to ISO_42001.6.2.4 — the native citation identifier — so an auditor can trace every methodology decision back to the framework text it reads from.

Each citation row carries a public source URL, an applicability tag set (which topics / disciplines / firm sizes / use cases it applies to), a priority score (1-10, hand-curated), and the framework edition it was sourced against. Reports generated by AECO Shield emit these citations in canonical form, so a downstream reader can verify each claim against the framework directly.

What this does NOT claim

We cite and monitor. We are not a certification body.

  • AECO does not certify tools to ISO 42001, NIST AI RMF, EU AI Act, CMMC 2.0, ISO 19650, or IBM AI Principles. Certification requires third-party accreditation infrastructure that AECO does not operate.
  • Stamp-Safe is a liability-classification derivation from the Q21b layer of the methodology. It is not a framework certification and does not imply ISO / NIST / any third-party accreditation.
  • AECO is not a partner, licensee, or affiliate of ISO, NIST, the European Commission, the U.S. Department of Defense, or IBM. The frameworks are cited under standard-reference conventions; every citation carries a link to the framework’s own public source for independent verification.
  • Reports emitted by AECO Shield cite framework text and show which methodology decisions ground to which citations. Reports are evidence of the methodology having been applied — they are not certificates of framework compliance.

See how tools score against these.

Every tool in the registry is scored against the methodology that grounds to these six frameworks. Scores are versioned; citations are traceable.

See how tools score against these →