A documented relationship exists between a Clause5afe criterion or evidence requirement and an external requirement, control, principle, or obligation.
Framework Coverage
Coverage should be explainable, not just countable.
Clause5afe's framework layer is designed to show how certification criteria relate to external laws, standards, and governance frameworks while keeping the certification claim precise about scope, evidence, and authority.
Coverage vocabulary
Four words that should mean four different things.
The finished public methodology will use controlled definitions so a buyer can distinguish a crosswalk from an actual in-scope evidence assessment.
The Clause5afe criterion materially corresponds to an external objective or control, without claiming that the external body has approved or certified Clause5afe.
Evidence relevant to the mapped requirement is actually examined within the defined certification scope for the system under review.
The public or client-facing scope identifies what is included, what is outside scope, and the limitations on any framework-related claim.
Beyond headline counts
A framework number is not a coverage methodology.
Runtime indicators may support some technical obligations while governance, documentation, organizational, rights, lifecycle, and management-system requirements demand different evidence. A credible coverage claim has to identify which is which.
- Is the framework merely referenced, or have individual requirements been mapped?
- Which requirements are actually applicable to the system and deployment being certified?
- Which requirements can be evidenced technically, and which depend on governance or organizational records?
- Was evidence examined, or is the relationship only a theoretical crosswalk?
- What version and effective date of the external framework was used?
- What does the resulting certification claim explicitly not mean?
Current reference layer
Regulation, risk management, management systems, privacy, and ethics.
The current approved internal certification model explicitly references the EU AI Act, NIST AI RMF, ISO/IEC 42001, GDPR, and UNESCO through the Clause 5 Framework. Published crosswalks include approved mapping detail and version information without exposing confidential methodology.
EU AI Act
System classification, risk obligations, governance, technical documentation, oversight, monitoring, and other applicable regulatory requirements depend on the actual use and legal context.
NIST AI RMF
A structured reference for AI risk governance, mapping, measurement, and management that can inform evidence expectations without functioning as a statutory certification regime.
ISO/IEC 42001
An AI management-system reference that can inform governance evidence. Clause5afe certification is not represented as ISO/IEC 42001 certification.
GDPR
Privacy, lawful processing, rights, accountability, data governance, and related evidence may be relevant when personal data is processed within the certified system context.
UNESCO AI Ethics
Human-rights, fairness, transparency, accountability, oversight, and societal-impact principles can inform the broader governance evidence considered through Clause 5.
System-specific application
The same framework can create different evidence questions for different systems.
Applicability depends on what the system does, who uses it, who is affected, the jurisdiction, deployment context, risk classification, architecture, and the organizational controls surrounding it. Framework mapping informs scope; it does not replace scope.
Version control
Framework coverage changes when the external source changes.
Production framework pages are intended to carry source identity, version or date, verification date, Clause5afe review owner, and a review trigger so time-sensitive regulatory information does not become stale marketing copy.
Certification scope
Start with the system, then determine the applicable evidence.
Clause5afe does not sell a framework checklist or legal opinion. Certification scoping identifies the system, deployment, risk, and applicable evidence boundary for the engagement.