Govern your AI before someone asks you to.

The EU AI Act, ISO 42001, NIST AI RMF and the OWASP LLM Top 10 — all included, all in one place.

AI governance stopped being theoretical

Two years ago, governing AI meant an internal policy nobody read. Now there is a regulation with penalties, a certifiable management system standard, a federal risk framework and a security top ten — and your customers have started asking which of them you follow.

The awkward part is that they do different jobs. The EU AI Act is law, and it classifies systems by risk. ISO 42001 is a management system you can certify against, like ISO 27001 but for AI. NIST AI RMF is a voluntary risk framework. The OWASP LLM Top 10 is about attacks against the systems themselves.

OpenGRC includes all four, at no extra cost, so you can run them together rather than picking one and hoping.

Four frameworks, one program

The same controls, counted once.

Inventory the AI you actually run

Inventory the AI you actually run

Most organisations cannot list their AI systems, which makes every one of these frameworks impossible to start. The application registry covers SaaS, desktop, server and appliance with required owner and vendor, so the inventory exists before you need it.

Risk assessment that fits AI systems

Risk assessment that fits AI systems

Both the AI Act and the NIST RMF are risk-classified rather than checklist-driven. Score inherent and residual risk, link each risk to the application and vendor it concerns, and record the treatment decision.

Certify against ISO 42001

Certify against ISO 42001

ISO 42001 is a management system standard, so it works the way ISO 27001 does: context, risk, controls, internal audit, management review. If you already run an ISMS in OpenGRC, the AIMS sits alongside it with shared evidence.

What each framework covers

FrameworkControls and scope
EU AI Act
European Union — law
347 — prohibited practices, high-risk system obligations, transparency, general-purpose AI
ISO 42001:2023
ISO/IEC — certifiable
67 — AI management system requirements and Annex A controls
NIST AI RMF 1.0
NIST — voluntary
72 — Govern (19), Map (18), Measure (22), Manage (13)
OWASP Top 10 for LLM Applications 2025
OWASP — security
10 — prompt injection, data leakage, supply chain and model risks
LLM AI Cybersecurity & Governance Checklist
OWASP
73 — practical governance checks for deploying LLMs
Google SAIF and AI Defense Matrix
Industry
Included — secure AI framework and adversarial control mapping

Import one or all of them. OpenGRC aggregates control coverage, so where the AI Act, ISO 42001 and the NIST RMF ask for the same thing — and they often do — you evidence it once.

AI governance questions

Which one should we start with?

If you sell into the EU, the AI Act is not optional, so start there. If customers are asking for assurance, ISO 42001 is the one you can certify against. If you want a structure without a compliance driver, the NIST AI RMF is the least burdensome entry point.

Does OpenGRC use AI itself?

Can we govern AI systems that are not ours?

Is ISO 42001 like ISO 27001?