Frameworks
AI-specific overlays on a technical record.
Test once, map many. These pages describe how OptimaTrust uses framework language. They are not certified audits and not a substitute for legal advice.
ISO 42001
AI management system
The international management-system standard for AI. OptimaTrust overlays ISO 42001 onto tests, evidence, and use-case gates.
ISO 23894
AI risk management guidance
Risk-management guidance for AI. OptimaTrust stores explainable risk factors per asset and use case.
NIST AI RMF
AI Risk Management Framework
Govern, Map, Measure, Manage — applied to the AI estate OptimaTrust actually holds.
EU AI Act
European Union AI Act
Use-case classification, obligations, and evidence packs for systems that may fall under the Act.
OWASP LLM
OWASP Top 10 for LLM applications
Prompt injection, sensitive-data disclosure, supply chain, and related LLM risks as runnable tests.
OWASP Agentic
OWASP agentic AI risks
Excessive agency, tool misuse, memory poisoning, and related agent threats.
MITRE ATLAS
Adversarial threat landscape for AI systems
Attack-surface context from inventory, tests, and relationship edges.
SOC 2 AI overlay
SOC 2-aligned AI overlay
AI-specific evidence themes that can sit beside a SOC 2 program — not a SOC 2 audit product.
Trusted AI. Assured future.
See OptimaTrust test the systems you actually run.
Bring an agent API, a model endpoint, or a shadow-AI list. We will show registry, labs, score deductions, and evidence — not a GRC slide deck.
