Frameworks inform the work; they do not replace judgment
Intelligence724 uses public frameworks and standards as operating references. They help organize governance, lifecycle risk, evaluation, security, and evidence. They are not presented as automatic legal requirements, universal checklists, or certifications.
Primary reference stack
| Reference | How it is used |
|---|---|
| NIST AI Risk Management Framework | Govern, Map, Measure, and Manage as a flexible risk and accountability spine. |
| NIST Generative AI Profile | Generative-system risks, pre-deployment testing, incident disclosure, provenance, monitoring, and stop planning. |
| ISO/IEC 42001 | Management-system structure for policy, roles, lifecycle controls, performance evaluation, corrective action, and improvement. |
| ISO/IEC 23894 and ISO 31000 | AI-specific and enterprise risk-management principles. |
| OWASP GenAI and agentic guidance | Application-level threat patterns such as prompt injection, disclosure, unsafe output handling, supply-chain risk, and excessive agency. |
| Info724 DMAIC heritage | Define, Measure, Analyze, Improve, and Control as the process-improvement backbone. |
Claim boundaries
- NIST alignment is not NIST certification.
- ISO readiness or alignment is not accredited ISO certification.
- Security testing cannot prove a system is universally secure.
- Governance controls do not replace legal analysis.
- A passed pilot does not guarantee permanent performance after model, data, process, or vendor change.
- Every framework is tailored to the system context, consequence, and client risk tolerance.