AltiriOS's umbrella methodology that operationalizes AI governance across regulated-industry engagements. Each phase of the framework is grounded in the Govern, Map, Measure, and Manage functions of NIST AI RMF 1.0 (primary source) and aligned to Executive Order 14110 (primary source) and Regulation (EU) 2024/1689 (primary source), commonly referred to as the EU AI Act.
Each phase of the Strategic AI Alignment Framework maps to one or more of the three anchor authorities below. For the broader six-framework catalog (ISO/IEC 42001, HIPAA / HITECH, CMMC 2.0, and the three authorities below), see the public reference at altirios.com/frameworks.html.
A voluntary framework providing a structured approach for managing risks across the AI lifecycle, organized around the Govern, Map, Measure, and Manage functions.
United States presidential directive titled "Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence," directing federal agencies to establish standards and oversight for AI.
A European Union regulation establishing a risk-based horizontal framework governing the development, placing on the market, and use of artificial intelligence systems in the Union.
The SAA Framework organizes every engagement into four sequential phases. Each phase corresponds to one or more of the Govern, Map, Measure, and Manage functions of NIST AI RMF 1.0. NIST AI RMF 1.0 primary source → www.nist.gov/itl/ai-risk-management-framework.
Catalog every AI system in production or pre-production, classify use cases by risk tier, and document data sources, model lineage, and intended downstream use. Deliverables: an AI inventory register, a data lineage register, and a regulatory applicability matrix.
Establish the policies, decision rights, escalation paths, and control owners for AI risk. Deliverables: an AI governance charter, a model risk committee charter, role-level accountability mapping, and a policy library aligned to Regulation (EU) 2024/1689 (EU AI Act →) and Executive Order 14110 (EO 14110 →).
Implement the control set: model evaluation, bias and drift monitoring, evidence collection, logging, and incident response. Deliverables: an evaluation pipeline, an evidence register tied to controls, an incident playbook, and integration with existing GRC tooling.
Run pre-assessment walkthroughs, prepare external-audit evidence packages, and feed assessment findings back into the governance loop. Deliverables: an external-audit evidence package, an exceptions register, and a quarterly program-of-record review.
The SAA Framework is the methodology — these are the two client-facing engagements that operationalize it for regulated industries. Each link below opens the service overview page.
For defense suppliers handling Controlled Unclassified Information (CUI) — gap assessments, SSP authorship, control implementation, POA&M scoping, and C3PAO coordination. Anchors the SAA Framework's Phase 4 (Audit & Improve) into the CMMC Level 2 assessment cycle.
altirios.com/services/cmmc-advisory.html →A client-owned, audit-ready compliance evidence system built on the Open Knowledge Format (OKF). Anchors Phases 2 (Govern & Align) and 3 (Measure & Operate) into a deployable, queryable knowledge layer with cited AI answers. Not a GRC platform, not a managed service — a knowledge layer you own.
altirios.com/services/agkl.html →Reference answers anchored to NIST AI RMF 1.0, Executive Order 14110, and Regulation (EU) 2024/1689.
The NIST AI Risk Management Framework (AI RMF 1.0) is a voluntary framework published by the National Institute of Standards and Technology offering a structured approach to managing risks across the AI lifecycle, organized around the Govern, Map, Measure, and Manage functions.
Executive Order 14110 is a United States presidential directive titled 'Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence,' directing federal agencies to establish standards and practices for the safe and trustworthy development and use of AI.
Regulation (EU) 2024/1689, commonly referred to as the EU AI Act, is a European Union regulation establishing a risk-based horizontal framework for the development, placing on the market, and use of artificial intelligence systems in the Union.
Four operational phases — Assess & Inventory, Govern & Align, Measure & Operate, and Audit & Improve — each mapped to one or more of the Govern, Map, Measure, and Manage functions of NIST AI RMF 1.0 and traceable into the requirements of Executive Order 14110 and Regulation (EU) 2024/1689.
The Framework is the umbrella methodology that operationalizes the eight client-facing offerings in AltiriOS — CMMC Advisory and AGKL for defense suppliers, HIPAA/HITECH readiness for healthcare, and AI risk and compliance tracks for financial services and other regulated verticals.