Public Reference

Regulatory frameworks AltiriOS aligns with.

A reference catalog of the external regulatory frameworks and standards that shape AI governance work for our clients. Each entry links to the issuing body's primary source — no proprietary claims or internal track-record metrics.

Six frameworks. One reference page.

Each card lists the canonical name, the issuing body's primary source URL, the publication date of the cited source, and a one-sentence description drawn from that source.

NIST AI Risk Management Framework 1.0

Published 2023-01-26 · National Institute of Standards and Technology www.nist.gov/itl/ai-risk-management-framework →

A voluntary framework providing a structured approach for managing risks across the AI lifecycle, organized around Govern, Map, Measure, and Manage functions.

ISO/IEC 42001:2023

Published 2023-12-18 · International Organization for Standardization www.iso.org/standard/81230.html →

The first internationally recognized management system standard for AI, defining requirements for an AI Management System (AIMS) that is certifiable by accredited auditors.

Regulation (EU) 2024/1689 — EU AI Act

Published 2024-07-12 · Official Journal of the European Union eur-lex.europa.eu/eli/reg/2024/1689/oj →

A European Union regulation establishing a risk-based horizontal framework governing the development, placing on the market, and use of artificial intelligence systems in the Union.

Executive Order 14110

Published 2023-10-30 · The White House / Federal Register www.federalregister.gov/d/2023-24283 →

United States presidential directive titled "Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence," directing federal agencies to establish standards and oversight for AI.

HIPAA / HITECH

HIPAA: 1996-08-21 · HITECH: 2009-02-17 · U.S. Department of Health and Human Services www.hhs.gov/hipaa/index.html →

HIPAA sets United States standards for the protection of individually identifiable health information (PHI); HITECH supplements HIPAA with breach notification and enforcement requirements.

Cybersecurity Maturity Model Certification (CMMC) 2.0

Updated 2024-10-15 · U.S. Department of Defense dodcio.defense.gov/CMMC/ →

A Department of Defense program requiring contractors and subcontractors handling Controlled Unclassified Information to achieve a specified level of cybersecurity maturity through independent assessment.