TrackerHelp

Frameworks & controls

A framework is a named group of controls. A control is a labelled obligation with one or more requirements that must be satisfied.

How the pieces fit together

Tracker organises compliance work into five nested concepts. A framework holds controls; a control holds requirements; each requirement collects evidence, gaps, and tasks against it.

Framework
e.g. ISO 42001
Control
e.g. A.5.1
Requirement
status, owner, due
Evidence
proof
Gaps
open issues
Tasks
work

You spend most of your time on the right-hand side — adding evidence, logging gaps, and closing tasks. The framework + control scaffolding is set up once at import.

Framework library

The library ships with curated subsets of popular AI-governance frameworks. Import creates the framework, all its controls, and every requirement for you — so you can start updating status on day one rather than transcribing the regulation.

  • EU AI Act — Articles 9–17, 26, 50 (high-risk and transparency obligations).
  • ISO/IEC 42001:2023 — management system clauses 4–10 plus key Annex A controls.
  • NIST AI RMF 1.0 — Govern / Map / Measure / Manage.
  • OWASP LLM Top 10 — the ten most critical LLM application vulnerabilities with mitigations.
  • Cyber Essentials — the five technical control themes from the NCSC self-assessment scheme.
  • Cyber Essentials Plus — the same five themes plus the Plus assessment activities (external scan, authenticated workstation scan, email and web payload tests).
  • AI Governance Starter — an opinionated baseline if you're not yet tied to a specific regulation.

The library is a jumpstart, not a conformance tool — treat it as opinionated scaffolding. Edit any control or requirement after import.

Building your own

Click New framework, then add controls one by one. Each control has a free-form reference label (think A.5.1, AI-1.1, or just SEC-1), a title, and an optional description. Requirements live under controls.