Compliance frameworks

Adding frameworks

Add any of the 25 built-in frameworks to your organization or a use case, and work through their requirements.

Overview

VerifyWise comes with 25 compliance frameworks: EU AI Act, ISO 42001, ISO 27001 and NIST AI RMF, plus 21 more bundled frameworks covering privacy, security, sector rules and AI ethics. Every framework is available to every organization. There is nothing to enable or install; you add the ones you need.

Each framework is one of two types, and the type decides where you add it:

  • Organization-level: Applies to the organization as a whole. You add it on the Frameworks page.
  • Use case-level: Applies to one AI system. You add it to a use case from its Frameworks/regulations tab.

Organization-level frameworks

Framework
ISO 42001
ISO 27001
NIST AI RMF
SOC 2 Type II Framework
GDPR Compliance Framework
CCPA Compliance Framework
DORA Compliance Framework
CIS Controls v8
Data Governance Framework
NIST Cybersecurity Framework
UAE Personal Data Protection Law
Saudi Arabia Personal Data Protection Law
Qatar Personal Data Privacy Law
Bahrain Personal Data Protection Law
Quebec Law 25 Compliance Framework

Use case-level frameworks

Framework
EU AI Act
PCI-DSS Lite Framework
HIPAA Security Rule Framework
ALTAI - Assessment List for Trustworthy AI
FTC AI Guidelines
NYC Local Law 144 - Automated Employment Decision Tools
AI Ethics & Governance Framework
OECD AI Principles
Texas Responsible AI Governance Act Framework
Colorado Artificial Intelligence Act Framework

Adding a framework to your organization

  1. Click Frameworks in the sidebar.
  2. Click Manage frameworks and choose Add/remove frameworks.
  3. In the AI Frameworks dialog, click Add on each framework you want. Added frameworks show an Added badge.
  4. Click Done.

The dialog only lists organization-level frameworks. Your frameworks then appear on the Requirements and Controls tab; use the switcher at the top of the tab to move between them. The page also has Dashboard, Framework risks, Linked models and Settings tabs.

First time on the Frameworks page
If your organization has no organization-level project yet, the page says "No Organizational Project Found". Open the Create new framework form, choose frameworks under Applicable regulations (optional) if you like, and click Create framework. After that, Manage frameworks is available.
Use Manage frameworks, not the Settings tab
The Settings tab on the Frameworks page only offers ISO 27001, ISO 42001 and NIST AI RMF. To add any of the other organization-level frameworks, use Manage frameworks > Add/remove frameworks.

Adding a framework to a use case

  1. Click Use cases in the sidebar and open the use case.
  2. Open the Frameworks/regulations tab.
  3. Click Manage frameworks/regulations. If the use case has no frameworks yet ("No frameworks installed"), click Add Framework instead.
  4. In the AI Frameworks dialog, click Add on each framework you want, then click Done.

The dialog only lists use case-level frameworks. You can also pick frameworks when you create a use case, in the Applicable regulations (optional) field.

Rules to know

  • No duplicates: A framework can only be added once to the same organization or use case.
  • Type must match: Organization-level frameworks go on the Frameworks page, use case-level frameworks go on use cases. You can't mix them.
  • Pending approval: While a use case has a pending approval request, you can't add or remove its frameworks. VerifyWise shows "This use case has a pending approval request…" until the approval process is complete.
  • Starting point: Adding a framework creates all of its requirements with the status "Not started".

Removing a framework

Open the same AI Frameworks dialog and click Remove on the framework. Confirm in the Confirm framework removal dialog by clicking Remove.

Removing deletes your work on that framework
Removing a framework deletes all of its implementation data for that organization or use case: statuses, assignments, due dates, and links to evidence and risks. Adding it again starts from "Not started".

Working on a requirement

In any of the 21 bundled frameworks, click a requirement to open its drawer. The drawer has four tabs:

  • Details: Read what the requirement asks for, and set the Status, Owner, Reviewer, Approver and Due date.
  • Evidence: Add proof with Upload new files, or reuse files already in VerifyWise with Attach existing files.
  • Cross mappings: Link the risks this requirement addresses with Add/remove risks.
  • Notes: Leave notes for your team.

Click Save to keep your changes. The available statuses are Not started, Draft, In progress, Awaiting review, Awaiting approval, Implemented, Audited and Needs rework.

Reports

Generated reports currently cover EU AI Act, ISO 42001, ISO 27001 and NIST AI RMF. The 21 bundled frameworks are not included in reports yet.

Who can do what

ActionRequired role
View frameworks and requirementsAdmin, Editor, Auditor
Add or remove frameworksAdmin, Editor
Update requirementsAdmin, Editor

Frameworks that aren't listed

You can't create your own framework in VerifyWise yet. If you need a framework that isn't listed, contact the VerifyWise team.
PreviousCompliance overview
NextEU AI Act compliance
Adding frameworks - Compliance frameworks - VerifyWise User Guide