Tel: +44 203 916 6309128 City Road, London, United Kingdom EC1V 2NXRegistration No: 16843978
Proprietary framework

The IACAIP Shielded Framework®

A version-controlled framework for cybersecurity, AI governance, AI safety, privacy and risk management. Assessments reference an exact framework version, so historical assessments remain reproducible.

Version controlled

Frameworks, domains, controls, questions, weights and critical controls are all versioned. New versions do not alter historical assessments.

Domain based

Ten initial domains spanning governance, risk, cybersecurity, privacy, identity, resilience, supply chain, AI safety and governance, and monitoring.

Critical controls

Critical controls cannot be hidden by a high overall score. Certification eligibility depends on more than a number.

Framework domains

Administrators can create future framework versions with different domains.

GOVGovernance & Leadership
RSKRisk Management
CYBCybersecurity
DATData Protection & Privacy
IAMIdentity & Access Management
RESResilience & Incident Management
SUPSupply Chain & Third-Party Risk
AISAI Safety
AIGAI Governance
MONMonitoring & Continuous Improvement

Maturity scale

Numeric scores are stored separately from display labels. Certification results are never calculated from display text.

0

Not Implemented

1

Initial

2

Developing

3

Defined

4

Managed

5

Optimised

Unified framework alignment

External frameworks are alignment and mapping references only.

IACAIP DomainExternal Reference
AI GovernanceNIST AI RMF, ISO/IEC 42001
CybersecurityNIST CSF 2.0, ISO/IEC 27001
Secure AIUK AI Cyber Security Code of Practice, UK NCSC Guidance
Risk ManagementISO/IEC 27001, NIST AI RMF
AI RegulationRelevant EU AI Act provisions and applicable national laws
PrivacyGDPR, UK GDPR and applicable privacy laws
Organisational AssuranceIACAIP Shielded Framework
Professional AssessmentIACAIP assessment methodology
Credential VerificationIACAIP Shielded Registry

IACAIP does not represent the Shielded Framework® as being issued by, owned by, or certified by NIST, ISO, the UK Government, the EU or any other external organisation unless formally authorised.