Framework Coverage

Coverage should be explainable, not just countable.

Clause5afe's framework layer is designed to show how certification criteria relate to external laws, standards, and governance frameworks while keeping the certification claim precise about scope, evidence, and authority.

Coverage vocabulary

Four words that should mean four different things.

The finished public methodology will use controlled definitions so a buyer can distinguish a crosswalk from an actual in-scope evidence assessment.

Mapped

A documented relationship exists between a Clause5afe criterion or evidence requirement and an external requirement, control, principle, or obligation.

Aligned

The Clause5afe criterion materially corresponds to an external objective or control, without claiming that the external body has approved or certified Clause5afe.

Assessed

Evidence relevant to the mapped requirement is actually examined within the defined certification scope for the system under review.

Coverage-defined

The public or client-facing scope identifies what is included, what is outside scope, and the limitations on any framework-related claim.

Beyond headline counts

A framework number is not a coverage methodology.

Runtime indicators may support some technical obligations while governance, documentation, organizational, rights, lifecycle, and management-system requirements demand different evidence. A credible coverage claim has to identify which is which.

  • Is the framework merely referenced, or have individual requirements been mapped?
  • Which requirements are actually applicable to the system and deployment being certified?
  • Which requirements can be evidenced technically, and which depend on governance or organizational records?
  • Was evidence examined, or is the relationship only a theoretical crosswalk?
  • What version and effective date of the external framework was used?
  • What does the resulting certification claim explicitly not mean?

Current reference layer

Regulation, risk management, management systems, privacy, and ethics.

The current approved internal certification model explicitly references the EU AI Act, NIST AI RMF, ISO/IEC 42001, GDPR, and UNESCO through the Clause 5 Framework. Published crosswalks include approved mapping detail and version information without exposing confidential methodology.

Regulatory framework

EU AI Act

System classification, risk obligations, governance, technical documentation, oversight, monitoring, and other applicable regulatory requirements depend on the actual use and legal context.

Risk-management framework

NIST AI RMF

A structured reference for AI risk governance, mapping, measurement, and management that can inform evidence expectations without functioning as a statutory certification regime.

Management-system standard

ISO/IEC 42001

An AI management-system reference that can inform governance evidence. Clause5afe certification is not represented as ISO/IEC 42001 certification.

Data-protection law

GDPR

Privacy, lawful processing, rights, accountability, data governance, and related evidence may be relevant when personal data is processed within the certified system context.

Ethics framework

UNESCO AI Ethics

Human-rights, fairness, transparency, accountability, oversight, and societal-impact principles can inform the broader governance evidence considered through Clause 5.

System-specific application

The same framework can create different evidence questions for different systems.

Applicability depends on what the system does, who uses it, who is affected, the jurisdiction, deployment context, risk classification, architecture, and the organizational controls surrounding it. Framework mapping informs scope; it does not replace scope.

External requirement or controlClause5afe mapping and applicabilityIn-scope evidence assessmentCertification decision

Version control

Framework coverage changes when the external source changes.

Production framework pages are intended to carry source identity, version or date, verification date, Clause5afe review owner, and a review trigger so time-sensitive regulatory information does not become stale marketing copy.

Certification scope

Start with the system, then determine the applicable evidence.

Clause5afe does not sell a framework checklist or legal opinion. Certification scoping identifies the system, deployment, risk, and applicable evidence boundary for the engagement.

Discuss Your System