Framework Overview

Strategic AI Alignment Framework.

AltiriOS's umbrella methodology that operationalizes AI governance across regulated-industry engagements. Each phase of the framework is grounded in the Govern, Map, Measure, and Manage functions of NIST AI RMF 1.0 (primary source) and aligned to Executive Order 14110 (primary source) and Regulation (EU) 2024/1689 (primary source), commonly referred to as the EU AI Act.

Three primary sources. One consolidated methodology.

Each phase of the Strategic AI Alignment Framework maps to one or more of the three anchor authorities below. For the broader six-framework catalog (ISO/IEC 42001, HIPAA / HITECH, CMMC 2.0, and the three authorities below), see the public reference at altirios.com/frameworks.html.

NIST AI Risk Management Framework 1.0

Published 2023-01-26 · National Institute of Standards and Technology www.nist.gov/itl/ai-risk-management-framework →

A voluntary framework providing a structured approach for managing risks across the AI lifecycle, organized around the Govern, Map, Measure, and Manage functions.

Executive Order 14110

Published 2023-10-30 · The White House / Federal Register www.federalregister.gov/d/2023-24283 →

United States presidential directive titled "Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence," directing federal agencies to establish standards and oversight for AI.

Regulation (EU) 2024/1689 — EU AI Act

Published 2024-07-12 · Official Journal of the European Union eur-lex.europa.eu/eli/reg/2024/1689/oj →

A European Union regulation establishing a risk-based horizontal framework governing the development, placing on the market, and use of artificial intelligence systems in the Union.

Four phases. Mapped to the NIST AI RMF functions.

The SAA Framework organizes every engagement into four sequential phases. Each phase corresponds to one or more of the Govern, Map, Measure, and Manage functions of NIST AI RMF 1.0. NIST AI RMF 1.0 primary source → www.nist.gov/itl/ai-risk-management-framework.

Phase 1 — Assess & Inventory

Mapped to NIST AI RMF 1.0: Map. Source: www.nist.gov/itl/ai-risk-management-framework →

Catalog every AI system in production or pre-production, classify use cases by risk tier, and document data sources, model lineage, and intended downstream use. Deliverables: an AI inventory register, a data lineage register, and a regulatory applicability matrix.

Phase 2 — Govern & Align

Mapped to NIST AI RMF 1.0: Govern. Source: www.nist.gov/itl/ai-risk-management-framework →

Establish the policies, decision rights, escalation paths, and control owners for AI risk. Deliverables: an AI governance charter, a model risk committee charter, role-level accountability mapping, and a policy library aligned to Regulation (EU) 2024/1689 (EU AI Act →) and Executive Order 14110 (EO 14110 →).

Phase 3 — Measure & Operate

Mapped to NIST AI RMF 1.0: Measure. Source: www.nist.gov/itl/ai-risk-management-framework →

Implement the control set: model evaluation, bias and drift monitoring, evidence collection, logging, and incident response. Deliverables: an evaluation pipeline, an evidence register tied to controls, an incident playbook, and integration with existing GRC tooling.

Phase 4 — Audit & Improve

Mapped to NIST AI RMF 1.0: Manage. Source: www.nist.gov/itl/ai-risk-management-framework →

Run pre-assessment walkthroughs, prepare external-audit evidence packages, and feed assessment findings back into the governance loop. Deliverables: an external-audit evidence package, an exceptions register, and a quarterly program-of-record review.

The framework in practice. Two regulated-industry credentials tracks.

The SAA Framework is the methodology — these are the two client-facing engagements that operationalize it for regulated industries. Each link below opens the service overview page.

CMMC Advisory

For defense suppliers handling Controlled Unclassified Information (CUI) — gap assessments, SSP authorship, control implementation, POA&M scoping, and C3PAO coordination. Anchors the SAA Framework's Phase 4 (Audit & Improve) into the CMMC Level 2 assessment cycle.

altirios.com/services/cmmc-advisory.html →

Altiri Governed Knowledge Layer (AGKL)

A client-owned, audit-ready compliance evidence system built on the Open Knowledge Format (OKF). Anchors Phases 2 (Govern & Align) and 3 (Measure & Operate) into a deployable, queryable knowledge layer with cited AI answers. Not a GRC platform, not a managed service — a knowledge layer you own.

altirios.com/services/agkl.html →

Common Questions

Reference answers anchored to NIST AI RMF 1.0, Executive Order 14110, and Regulation (EU) 2024/1689.

What is NIST AI RMF 1.0?

The NIST AI Risk Management Framework (AI RMF 1.0) is a voluntary framework published by the National Institute of Standards and Technology offering a structured approach to managing risks across the AI lifecycle, organized around the Govern, Map, Measure, and Manage functions.

What is Executive Order 14110?

Executive Order 14110 is a United States presidential directive titled 'Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence,' directing federal agencies to establish standards and practices for the safe and trustworthy development and use of AI.

What is the EU AI Act?

Regulation (EU) 2024/1689, commonly referred to as the EU AI Act, is a European Union regulation establishing a risk-based horizontal framework for the development, placing on the market, and use of artificial intelligence systems in the Union.

What does the Framework include?

Four operational phases — Assess & Inventory, Govern & Align, Measure & Operate, and Audit & Improve — each mapped to one or more of the Govern, Map, Measure, and Manage functions of NIST AI RMF 1.0 and traceable into the requirements of Executive Order 14110 and Regulation (EU) 2024/1689.

How does the Framework connect to specific industries?

The Framework is the umbrella methodology that operationalizes the eight client-facing offerings in AltiriOS — CMMC Advisory and AGKL for defense suppliers, HIPAA/HITECH readiness for healthcare, and AI risk and compliance tracks for financial services and other regulated verticals.

Want a focused conversation about the Framework?
Tell us how your organization handles AI governance today and we'll route the right AltiriOS specialist to follow up — no script, just a structured intake.
Start a Consultation →