Standards & Frameworks
Infrarails evaluations map to 50+ regulatory and industry frameworks, so the evidence your platform already produces is the evidence your next audit actually asks for.
What we map to
A representative sample of the framework families Infrarails maps evaluations against — not an exhaustive list.
EU AI Act
EuropeRisk-tiered obligations for AI systems placed on the EU market, including technical documentation and post-market monitoring requirements for high-risk systems.
NIST AI Risk Management Framework
United StatesA voluntary process framework — Govern, Map, Measure, Manage — for organizational AI risk management.
ISO/IEC 42001
InternationalA certifiable AI management system standard. Certification is granted by an accredited external body, not by any tooling vendor.
SOC 2
United StatesTrust Services Criteria for security, availability, and confidentiality controls.
HIPAA
United StatesHealthcare data handling requirements — PHI protection, minimum necessary standard, administrative safeguards.
OWASP LLM Top 10
InternationalCommunity-maintained catalog of the most critical security risks specific to LLM applications.
GDPR
EuropeData protection and privacy requirements, including data processing agreements, right to erasure, and data portability.
MIT AI Risk Repository
ResearchAn independently-maintained, living meta-review taxonomy of AI risks. Infrarails' own risk taxonomy (GAiTSF) is cross-walked against it at the domain and subdomain level — see our Research page for the methodology.
How the mapping works
Every framework mapping ties a specific regulatory article, function, or clause to the control or evaluator category that produces evidence for it. This produces the technical documentation an audit expects — it does not itself constitute certification. Certification is granted by an accredited external body after an organizational audit, not by any tooling vendor, including us.
Where Infrarails' own risk taxonomy is checked against an external reference — like the MIT AI Risk Repository — that crosswalk is run at the domain and subdomain level and re-run against each new revision of the external source, so the comparison doesn't go stale the moment either side stops updating. See our Research page for the full methodology.
See how Infrarails maps to your framework
Talk to us about the specific frameworks your organization is audited against.