Your auditors are converging on two documents: ISO/IEC 42001, the AI management system standard, and the NIST AI Risk Management Framework. Ripcord was not built to pass audits; it was built to gate actions. It turns out those are the same controls. This page maps them.
ISO/IEC 42001 follows the standard ISO management-system structure, Clauses 4 through 10. The NIST AI RMF organizes work into four functions: GOVERN, MAP, MEASURE, MANAGE. Every Ripcord control below produces its evidence automatically, as ledger rows, because enforcement and record are the same act.
| RIPCORD CONTROL | ISO/IEC 42001 | NIST AI RMF | THE EVIDENCE IT PRODUCES | EVIDENCE REF · FINDINGS |
|---|---|---|---|---|
| Risk scorecard every action scored by expected loss before it runs | Clause 6 · Planning Clause 8 · Operation | MAP · MANAGE | A per-action risk assessment, applied in production, with the scoring inputs recorded. Risk treatment that runs 24/7 instead of living in a register. | |
| Human approval routing consequential actions wait for a named owner | Clause 5 · Leadership Clause 8 · Operation | GOVERN | Documented roles and accountabilities per corridor, plus proof of human oversight on every high-risk action: who, what, when. | |
| Rules become scorecard signals written policy compiles into enforcement | Clause 7 · Support Clause 8 · Operation | GOVERN | The policy document and its enforcement are one artifact. No gap between what the policy says and what the system does. | |
| Hash-chained audit ledger append-only record of every verdict | Clause 9 · Performance evaluation | MEASURE | Continuous monitoring with tamper-evident records. Internal audit becomes a query, not a quarter. | |
| Conduct grades, A to D drift, escalation, velocity, off-hours, egress | Clause 9 · Performance evaluation Clause 10 · Improvement | MEASURE · MANAGE | Periodic evaluation of AI system behavior against mandate, with classified deviations and remediation tracked to closure. | |
| Reversal engine holds, snapshots, staged execution, rollback | Clause 8 · Operation Clause 10 · Improvement | MANAGE | Incident response with receipts: what was caught, what was undone, and the snapshot that made the undo possible. | |
| Incident dossier export one click from the Near-Miss Report | Clause 10 · Improvement | MANAGE | Nonconformity and corrective-action records formatted for a postmortem, a board, a regulator or an insurer. | |
| Tokenization, egress scorecard, residency routing the model sees tokens, never customers | Clause 8 · Operation | GOVERN · MANAGE | Data minimization enforced at the gateway, egress gated like dollars, and routing by data class. The lineage ledger answers records-of-processing and subject-access requests (GDPR Articles 30 and 15) in one query. |
Every incident dossier exported from the Near-Miss Report references this mapping, so the evidence annex travels with the incident record.