CODITECT AI Risk Management Framework
Enterprise-grade AI governance framework aligned with NIST AI RMF 2.0, EU AI Act, and ISO/IEC 42001.
Overview
This framework provides comprehensive policies, standards, and operational guidance for responsible AI development, deployment, and management.
Framework at a Glance
| Attribute | Details |
|---|---|
| Version | 2.1 (Enhanced) |
| Documents | 25 integrated artifacts |
| Compliance Coverage | NIST AI RMF 2.0, EU AI Act, ISO/IEC 42001 |
| Target Audiences | SMB and Enterprise organizations |
| Status | Production-ready |
Document Portfolio
Core Governance Documents (01-10)
| # | Document | Purpose |
|---|---|---|
| 01 | AI Governance Operating Model | Governance structure, bodies, lifecycle |
| 02 | AI Risk Governance Charter | Authority, mandate, decision rights |
| 03 | AI Risk Classification Matrix | 4-tier risk scoring system |
| 04 | AI Intake Registration Form | AI system registration |
| 05 | Enterprise AI Policy Standard | Rules, prohibitions, standards |
| 06 | AI System Card Template | Technical documentation |
| 07 | Algorithmic Impact Assessment | Deep risk assessment (FRIA) |
| 08 | Implementation Plan 30-60-90 | Phased rollout roadmap |
| 09 | GenAI Governance Addendum | LLM and agentic AI controls |
| 10 | Executive Summary | Leadership overview |
Extended Compliance Documents (11-25)
| # | Document | Purpose |
|---|---|---|
| 11 | Gap Analysis 2025 Compliance | Compliance verification |
| 12 | CODITECT Impact Analysis | Platform application |
| 13 | AI-BOM Template | AI Bill of Materials |
| 14 | GPAI Compliance Framework | EU AI Act GPAI requirements |
| 15 | Third-Party AI Risk Management | Vendor/supply chain |
| 16 | Continuous Monitoring Standard | Operational monitoring |
| 17 | SMB Quick-Start Guide | Simplified implementation |
| 18 | ISO 42001 Alignment Matrix | Certification mapping |
| 19 | Board Presentation Outline | Executive presentation |
| 20 | Training Program Curriculum | Staff training |
| 21 | Vendor Contract Clause Library | Contract templates |
| 22 | Healthcare FDA Industry Appendix | Healthcare/FDA specifics |
| 23 | Audit Evidence Checklist | Audit preparation |
| 24 | Worked Examples & Sample Templates | Filled-out template examples |
| 25 | Finance Industry Appendix | Banking/insurance/securities |
Regulatory Compliance
EU AI Act Timeline Readiness
| Deadline | Requirement | Framework Coverage | Status |
|---|---|---|---|
| Feb 2, 2025 | Prohibited AI practices | Policy 3.1 | Ready |
| Aug 2, 2025 | GPAI transparency | Doc 14 | Ready |
| Aug 2, 2025 | AI literacy requirements | Doc 08 3.2 | Ready |
| Aug 2, 2026 | High-risk AI conformity | Full framework | Ready |
| Aug 2, 2027 | Legacy system compliance | Transition guidance | Ready |
Standards Alignment
| Standard | Coverage |
|---|---|
| NIST AI RMF 2.0 | 98% (GOVERN, MAP, MEASURE, MANAGE) |
| EU AI Act | 98% |
| ISO/IEC 42001 | 95% (36/38 Annex A controls) |
| OWASP LLM Top 10 | 95% |
| SPDX 3.0 AI Profile | 95% |
Quick Start
For SMBs
Start with 17-smb-quick-start-guide.md for a streamlined implementation path.
For Enterprises
Begin with 10-executive-summary.md and follow the 08-implementation-plan-30-60-90.md.
For Healthcare Organizations
Review 22-healthcare-fda-industry-appendix.md for FDA-specific requirements.
For Financial Services
Review 25-finance-industry-appendix.md for SR 11-7, fair lending, and securities requirements.
Looking for Examples?
Start with 24-worked-examples-sample-templates.md for complete filled-out examples across risk tiers.
Getting Started
# Clone with CODITECT ecosystem
git clone https://github.com/coditect-ai/coditect-ai-risk-management-framework.git
cd coditect-ai-risk-management-framework
# Review executive summary
cat docs/framework/10-executive-summary.md
Integration with CODITECT
This framework integrates with the CODITECT AI development platform:
- Automated Compliance Checks: Framework rules enforced via CODITECT hooks
- AI System Cards: Auto-generated from code analysis
- Risk Classification: Automated based on system characteristics
- Audit Trail: Full traceability via CODITECT context management
License
Copyright (c) 2026 AZ1.AI INC. All rights reserved.
Repository: coditect-ai-risk-management-framework Parent Organization: coditect-ai Owner: AZ1.AI INC | Lead: Hal Casteel