Govern your AI before someone asks you to.
The EU AI Act, ISO 42001, NIST AI RMF and the OWASP LLM Top 10 — all included, all in one place.
AI governance stopped being theoretical
Two years ago, governing AI meant an internal policy nobody read. Now there is a regulation with penalties, a certifiable management system standard, a federal risk framework and a security top ten — and your customers have started asking which of them you follow.
The awkward part is that they do different jobs. The EU AI Act is law, and it classifies systems by risk. ISO 42001 is a management system you can certify against, like ISO 27001 but for AI. NIST AI RMF is a voluntary risk framework. The OWASP LLM Top 10 is about attacks against the systems themselves.
OpenGRC includes all four, at no extra cost, so you can run them together rather than picking one and hoping.
The same controls, counted once.
Inventory the AI you actually run
Most organisations cannot list their AI systems, which makes every one of these frameworks impossible to start. The application registry covers SaaS, desktop, server and appliance with required owner and vendor, so the inventory exists before you need it.
Risk assessment that fits AI systems
Both the AI Act and the NIST RMF are risk-classified rather than checklist-driven. Score inherent and residual risk, link each risk to the application and vendor it concerns, and record the treatment decision.
Certify against ISO 42001
ISO 42001 is a management system standard, so it works the way ISO 27001 does: context, risk, controls, internal audit, management review. If you already run an ISMS in OpenGRC, the AIMS sits alongside it with shared evidence.
What each framework covers
| Framework | Controls and scope |
|---|---|
| EU AI Act European Union — law | 347 — prohibited practices, high-risk system obligations, transparency, general-purpose AI |
| ISO 42001:2023 ISO/IEC — certifiable | 67 — AI management system requirements and Annex A controls |
| NIST AI RMF 1.0 NIST — voluntary | 72 — Govern (19), Map (18), Measure (22), Manage (13) |
| OWASP Top 10 for LLM Applications 2025 OWASP — security | 10 — prompt injection, data leakage, supply chain and model risks |
| LLM AI Cybersecurity & Governance Checklist OWASP | 73 — practical governance checks for deploying LLMs |
| Google SAIF and AI Defense Matrix Industry | Included — secure AI framework and adversarial control mapping |
Import one or all of them. OpenGRC aggregates control coverage, so where the AI Act, ISO 42001 and the NIST RMF ask for the same thing — and they often do — you evidence it once.
AI governance questions
Which one should we start with?
If you sell into the EU, the AI Act is not optional, so start there. If customers are asking for assurance, ISO 42001 is the one you can certify against. If you want a structure without a compliance driver, the NIST AI RMF is the least burdensome entry point.
™