Public Framework Document · v1.0

RAISE Framework

Risk-Adaptive AI Security & Enforcement

A 14-domain maturity model for governing AI systems across their full lifecycle — from discovery through decommissioning — weighted for your industry and regulatory profile.

14
Governance Domains
76
Control Objectives
5
Maturity Levels
7+
Regulatory Mappings
4
Governance Pillars
VISIBILITY RISK & CONTROLS OPERATIONS SECURITY RAISE Framework
4 Governance Pillars
Visibility
Domains 01, 05
Knowing what AI systems you operate, where they run, what data they touch, and whether you can see their activity. The foundation everything else depends on.
Risk & Controls
Domains 02, 03, 07
Classifying AI systems by risk, applying proportionate controls, and ensuring regulatory compliance. Determines which governance requirements apply to each system.
Operations
Domains 06, 08, 10, 11
Running AI governance operationally: onboarding new systems through an intake gate, monitoring performance and drift, responding to incidents, and generating audit evidence.
Security
Domains 04, 09, 12, 13, 14
Defending AI systems from adversarial attack, insider threat, supply chain compromise, and agentic privilege abuse. Security-forward and built for the adversarial AI threat landscape.
5-Level Maturity Model
1
Initial
Ad hoc, no
formal process
Cannot demonstrate control existence to auditors
2
Developing
Aware, some activity,
inconsistent
Can demonstrate awareness, not consistent execution
3
Defined
Documented, repeatable,
assigned ownership
Can demonstrate design and some operating effectiveness
4
Managed
Measured, monitored,
evidence-based
Can demonstrate operating effectiveness with evidence samples
5
Optimized
Continuous improvement,
proactive, integrated
Continuous audit-readiness; regulatory examination is a scheduled event, not a crisis
14 Governance Domains
#DomainPillarControls
01
AI Asset DiscoveryVisibility01.1–01.5
02
Risk ClassificationRisk & Controls02.1–02.5
03
Controls & EnforcementRisk & Controls03.1–03.6
04
RAG & Vector SecuritySecurity04.1–04.5
05
Telemetry & VisibilityVisibility05.1–05.6
06
Rapid RemediationOperations06.1–06.6
07
Regulatory ComplianceRisk & Controls07.1–07.5
08
Audit EvidenceOperations08.1–08.6
09
Insider Threat ControlsSecurity09.1–09.5
10
AI Onboarding & IntakeOperations10.1–10.5
11
Drift & Performance MonitoringOperations11.1–11.5
12
Red Teaming & Adversarial TestingSecurity12.1–12.5
13
Shift-Left AI SecuritySecurity13.1–13.6
14
Agentic AI GovernanceSecurity14.1–14.5
Regulatory Crosswalk
RegulationPrimary DomainsKey Obligations & Deadlines
EU AI Act
02, 03, 06, 07, 08,
10, 11, 12, 13, 14
High-risk classification (Art. 6), conformity assessment (Art. 9), serious incident reporting 72h (Art. 73). High-risk obligations: Aug 2026.
OCC / FFIEC
06, 08, 10, 11 Model risk management (SR 11-7 / OCC 2011-12), ongoing monitoring, 36-hour notification rule.
GDPR
01, 04, 07, 09, 14 DPIA (Art. 35), automated decision rights (Art. 22), breach notification 72h (Art. 33).
HIPAA
04, 09, 11 Technical safeguards (§164.312), workforce security (§164.308), AI models processing PHI.
NIST AI RMF
01, 02, 03, 05, 08,
12, 13
GOVERN, MAP, MEASURE, MANAGE across the AI lifecycle.
ISO 42001
02, 03, 07, 08, 10, 11 AI management system: policy, risk treatment, operational controls, monitoring, management review.
CO SB205 /
NYC LL144
02, 07, 11 Algorithmic discrimination protections. NYC LL144 bias audits (effective Feb 2026).
Free RAISE Maturity Assessment
  • 70+ questions across all 14 domains
  • Industry-weighted scoring
  • Peer benchmarks included
  • Regulatory exposure analysis
  • Prioritized remediation roadmap
  • Downloadable PDF report