Frameworks & controls
A framework is a named group of controls. A control is a labelled obligation with one or more requirements that must be satisfied.
How the pieces fit together
Tracker organises compliance work into five nested concepts. A framework holds controls; a control holds requirements; each requirement collects evidence, gaps, and tasks against it.
You spend most of your time on the right-hand side — adding evidence, logging gaps, and closing tasks. The framework + control scaffolding is set up once at import.
Framework library
The library ships with curated subsets of popular AI-governance frameworks. Import creates the framework, all its controls, and every requirement for you — so you can start updating status on day one rather than transcribing the regulation.
- EU AI Act — Articles 9–17, 26, 50 (high-risk and transparency obligations).
- ISO/IEC 42001:2023 — management system clauses 4–10 plus key Annex A controls.
- NIST AI RMF 1.0 — Govern / Map / Measure / Manage.
- OWASP LLM Top 10 — the ten most critical LLM application vulnerabilities with mitigations.
- Cyber Essentials — the five technical control themes from the NCSC self-assessment scheme.
- Cyber Essentials Plus — the same five themes plus the Plus assessment activities (external scan, authenticated workstation scan, email and web payload tests).
- AI Governance Starter — an opinionated baseline if you're not yet tied to a specific regulation.
The library is a jumpstart, not a conformance tool — treat it as opinionated scaffolding. Edit any control or requirement after import.
Building your own
Click New framework, then add controls one by one. Each control has a free-form reference label (think A.5.1, AI-1.1, or just SEC-1), a title, and an optional description. Requirements live under controls.