// compliance crosswalk

One evidence trail.
Every AI framework.

ISO 42001. NIST AI RMF. EU AI Act. OWASP LLM Top 10. One AI use case — the coding agents your developers run — reaches all of them at once. The frameworks ask you to manage AI risk and prove you did. MoorAI produces that proof a different way: content-free, on the device. Below, each shipped MoorAI control crosswalked to the clause, function, article and risk it actually supports — evidence without egress.

01 · See what applies
Discover the agents
Shadow-AI discovery and a live AIBOM show which agents, models and MCP servers are actually running — the real scope of your AI use.
02 · Find the overlap
One control, many clauses
A single on-device control — review before the call runs — sits in the overlap of all four frameworks. Do it once; satisfy many.
03 · Prove it
Evidence without egress
Signed, content-free decisions and Event-Flow lineage are the audit evidence — produced on the device, with no prompt ever leaving it.
ISO 42001 NIST AI RMF EU AI Act MoorAI content-free evidence

Three frameworks, one AI use case — and the OWASP LLM Top 10 as the security lens over all of it. One content-free, on-device evidence trail sits in the overlap.

The crosswalk

Each row is a control MoorAI ships. Each column is the clause, function, article or risk it supports — the reference an auditor or governance lead can point to. This is a mapping to help assemble evidence, not a certification.

MoorAI control MoorAIships it ISO/IEC 42001AI management system NIST AI RMFGovern · Map · Measure · Manage EU AI ActArticles OWASP LLM Top 102025 risks
On-device gateway — review prompts & tool-calls before they run Clause 8 · Operation / risk treatment MANAGE · risk response at the action Art 14 human oversight · Art 9 risk mgmt LLM01 Prompt Injection · LLM05 Output Handling
MCP server allow-list + per-tool argument rules Clause 8 · Annex A system security MANAGE / GOVERN · controls Art 14 oversight · Art 15 cybersecurity LLM06 Excessive Agency
Model-endpoint allow-list Clause 8 · treatment control MAP / MANAGE · boundaries Art 15 robustness & cybersecurity LLM03 Supply Chain · LLM10 Unbounded Use
Cryptographically signed, tamper-evident decisions Clause 9 monitoring · Annex A records GOVERN / MEASURE · documentation Art 12 record-keeping · Art 26 deployer logs
Content-free data lineage / Event Flow Annex A data governance MAP / MEASURE · traceability Art 10 data governance · Art 12 logs LLM02 Sensitive Info Disclosure
AIBOM — live agent / model / MCP inventory Clause 5.4 lifecycle inventory MAP · context & inventory Art 11 · technical documentation (Annex IV) LLM03 Supply Chain
Shadow-AI agent + app / browser discovery Clause 4 / 5.4 · scope of the AIMS MAP · establish context Art 4 AI literacy · Art 26 deployer awareness LLM03 Supply Chain
Rules-file poisoning detection (CLAUDE.md / .cursorrules) Clause 8 · Annex A integrity MEASURE / MANAGE · treat risk Art 15 accuracy & robustness LLM04 Data/Model Poisoning · LLM07 System-Prompt Leakage
Lethal-trifecta / cross-server toxic-flow detection Clause 8 · risk treatment MEASURE · measure & track risk Art 9 risk mgmt · Art 15 LLM01 Prompt Injection · LLM06 Excessive Agency
Per-agent assurance score Clause 9 · monitoring & measurement MEASURE · risk tracking Art 9 risk mgmt · Art 72 post-market monitoring
JIT elevation + entitlement envelope Clause 8 · Annex A access control MANAGE · risk response Art 14 human oversight LLM06 Excessive Agency
Natural-language policy authoring (device-side) Clause 5.2 policy · Clause 6 planning GOVERN · policies & procedures Art 9 risk-management system
Break-glass / offline fail-closed Clause 8 · operational control MANAGE · incident & continuity Art 15 robustness / resilience LLM10 Unbounded Consumption
Content-free by construction — only category · risk · hash leave Annex A · data governance / minimization GOVERN / MEASURE · privacy Art 10 data governance (GDPR-aligned) LLM02 Sensitive Info Disclosure

Informational, not a certification. This page maps MoorAI's shipped controls to the referenced frameworks to help teams assemble evidence; it is not a certification, legal advice, or a conformity assessment. Clause, function and article references are indicative — verify them against each framework's current text. ISO/IEC 42001 certification is issued by accredited bodies against a full audit of your AI Management System. marks a control outside a given framework's scope.

Go deeper on any framework

The crosswalk is the map; these are the detailed walk-throughs.

glick.run — AGPL-3.0