Framework Compliance

17 frameworks. 693 questions. One platform.

Auditors don't accept generic checklists. AIRA runs 1:1 auditor-grade assessments across every major AI and security framework, with cross-mapping, evidence linking, and exportable audit packages.

Coverage

Every framework your auditor actually asks about.

From AI-specific (NIST AI RMF, EU AI Act, ISO 42001) to traditional security (NIST CSF, SOC 2, CMMC) to privacy (GDPR, CCPA, GLBA, NYDFS).

NIST AI RMF

97 questions

AI risk management lifecycle

EU AI Act

34 questions

High-risk AI obligations

ISO 42001

28 questions

AI management system

OWASP LLM Top 10

22 questions

LLM-specific vulnerabilities

OWASP Agentic

18 questions

Agent threat model

NIST CSF 2.0

97 questions

Cybersecurity framework

SOC 2 TSC

43 questions

Trust services criteria

CMMC

110 questions

DoD contractor compliance

HITRUST CSF

49 questions

Healthcare-class controls

CIS Controls

153 questions

Implementation-grade controls

GLBA

23 questions

Financial privacy

GDPR

34 questions

EU privacy rights

NYDFS Part 500

23 questions

NY financial services

CCPA

18 questions

California consumer privacy

Colorado Privacy Act

16 questions

CO consumer privacy

SHIELD Act

14 questions

NY data security

FCRA

14 questions

Consumer reporting

How it works

Assessment to audit package, in days not months.

1. Inventory

Catalog AI systems, owners, data flows, business criticality.

2. Assess

Run framework wizards, auditor-grade questions, not vibe-checks.

3. Evidence

Attach evidence to controls, cross-mapped across frameworks automatically.

4. Export

Generate executive PDF, audit DOCX, or board PPTX on demand.

Run your first framework in a 30-minute demo.

Pick your toughest framework. We'll show AIRA running it end-to-end.