The IACAIP Shielded Framework®
A version-controlled framework for cybersecurity, AI governance, AI safety, privacy and risk management. Assessments reference an exact framework version, so historical assessments remain reproducible.
Version controlled
Frameworks, domains, controls, questions, weights and critical controls are all versioned. New versions do not alter historical assessments.
Domain based
Ten initial domains spanning governance, risk, cybersecurity, privacy, identity, resilience, supply chain, AI safety and governance, and monitoring.
Critical controls
Critical controls cannot be hidden by a high overall score. Certification eligibility depends on more than a number.
Framework domains
Administrators can create future framework versions with different domains.
Maturity scale
Numeric scores are stored separately from display labels. Certification results are never calculated from display text.
0
Not Implemented
1
Initial
2
Developing
3
Defined
4
Managed
5
Optimised
Unified framework alignment
External frameworks are alignment and mapping references only.
| IACAIP Domain | External Reference |
|---|---|
| AI Governance | NIST AI RMF, ISO/IEC 42001 |
| Cybersecurity | NIST CSF 2.0, ISO/IEC 27001 |
| Secure AI | UK AI Cyber Security Code of Practice, UK NCSC Guidance |
| Risk Management | ISO/IEC 27001, NIST AI RMF |
| AI Regulation | Relevant EU AI Act provisions and applicable national laws |
| Privacy | GDPR, UK GDPR and applicable privacy laws |
| Organisational Assurance | IACAIP Shielded Framework |
| Professional Assessment | IACAIP assessment methodology |
| Credential Verification | IACAIP Shielded Registry |
IACAIP does not represent the Shielded Framework® as being issued by, owned by, or certified by NIST, ISO, the UK Government, the EU or any other external organisation unless formally authorised.
