ISO 42001
EditorialInternational standard for AI management systems.
ISO 42001:2023
First international certifiable AI management standard (published Dec 2023).
Standards library
The external standards this work monitors and cites. Not a certification body — the frameworks are the authoritative source, and every citation carries a public verification link.
Standards reviewed quarterly · last reviewed September 2026
The frameworks
Live citation counts against the methodology’s citation library. Each card links to the framework’s own public source — nothing on this page substitutes for reading the standard itself.
International standard for AI management systems.
ISO 42001:2023
First international certifiable AI management standard (published Dec 2023).
US framework for managing AI risk across the lifecycle.
NIST AI RMF 1.0
Active — 1.0 (Jan 2023) + Generative AI Profile (Jul 2024). RMF 1.0 under revision per the White House AI Action Plan (Jul 2025).
EU regulation classifying and governing AI systems by risk.
EU AI Act (Regulation 2024/1689)
General application from Aug 2, 2026; high-risk (Annex III) deferred to Dec 2, 2027 (Digital Omnibus, Reg. (EU) 2026/1744). Penalties up to €35M / 7% turnover (prohibited practices); €15M / 3% (high-risk & transparency).
US DoD cybersecurity maturity certification for defense contractors.
CMMC 2.0
Phase 1 live since Nov 2025. Phase 2 (Level 2 third-party certification) suspended Jul 2026 pending DoD review.
International standard for BIM and information management in construction.
ISO 19650-2:2018, ISO 19650-5:2020
Parts 1–3 in revision (DIS stage, 2026); publication targeted late 2026, 2027 as fallback. Current parts: 1:2018, 2:2018, 3:2020, 4:2022, 5:2020, 6:2025.
IBM's published principles for trustworthy and transparent AI.
IBM Principles for Trust and Transparency
Principles for Trust and Transparency — published governance principles.
US state law governing algorithmic decision-making systems.
—
SB 24-205 was delayed, then repealed and replaced by SB 26-189 (effective Jan 1, 2027) before taking effect; the new ADMT disclosure regime drops the NIST AI RMF / ISO 42001 affirmative defense. Effective date subject to pending litigation.
US bar-association guidance on generative AI in professional practice.
—
ABA Formal Opinion 512 (Jul 29, 2024) — guidance on generative AI in legal professional practice.
Auto — the framework’s canonical page is fetched on a cadence and hash-diffed; any change enters the editorial review queue. Editorial — the framework’s source page blocks programmatic clients (Cloudflare or federal WAF), so a curator verifies on schedule instead.
How we monitor
Three frameworks (NIST AI RMF, EU AI Act, IBM AI Principles) publish their canonical text at URLs a program can fetch. We poll each on a scheduled cadence, hash the normalized content, and compare it against the last known hash. When the hash changes, an alert enters the review queue with a count of methodology citations that framework grounds.
Three frameworks (ISO 42001, ISO 19650, CMMC 2.0) publish through channels that block programmatic clients — iso.org and the DoD CIO site return 403 to any automated fetch. Rather than build fragile bypass scraping, we schedule a manual verification cadence: a curator reviews the source page and confirms the current edition is unchanged, or files a change note.
Both channels route through the same editorial gate. A detected or reported change never auto-updates methodology citations — it queues a review for a human curator. If the change matters, methodology version bumps and citations update in the next release; if it doesn’t, the alert resolves with a “no-change” note.
How the citations are used
The methodology grounds specific decisions to specific citations. When a rubric question depends on ISO 42001 section 6.2.4, the methodology stores a reference to ISO_42001.6.2.4 — the native citation identifier — so an auditor can trace every methodology decision back to the framework text it reads from.
Each citation row carries a public source URL, an applicability tag set (which topics / disciplines / firm sizes / use cases it applies to), a priority score (1-10, hand-curated), and the framework edition it was sourced against. Published work emits these citations in canonical form, so a downstream reader can verify each claim against the framework directly.
What this does NOT claim
These frameworks set the language a carrier, a board or a client will use. The research works through what they actually require of a licensed professional using AI — and what they leave open.