Five domains. Forty controls. Four maturity levels per control, scored 0–3 and scaled to 20 points per domain. Mapped to the NIST AI Risk Management Framework 1.0 and cross-walked to ISO/IEC 42001:2023. Designed for firms that use AI, in the language those firms actually speak.
| Per control | 0–3 |
| Per domain (8 controls) | 0–24 raw, scaled to 0–20 |
| Total | 0–100 |
| Leading | 90–100 |
| Advanced | 75–89 |
| Verified | 60–74 |
| Not yet verified | <60 (private) |
Gating controls. Regardless of total score, a firm cannot be listed at any level with a 0 on G1 (written AI policy), D3 (vendor terms reviewed) or O1 (human review of client-facing output). These are the three controls every regulator, insurer and client questionnaire asks about first.
| AboveBoard domain | NIST AI RMF 1.0 | ISO/IEC 42001:2023 | Regulatory hooks (US, Sept 2026) |
|---|---|---|---|
| 1. Governance & Accountability | GOVERN 1–6 (policies, accountability, risk culture, inventory); MAP 1 | Clauses 4–6 (context, leadership, planning); Annex A.2 (policies), A.3 (internal organization), A.6 (AI system lifecycle) | Texas TRAIGA affirmative defense for NIST AI RMF alignment; NAIC AI Model Bulletin (written AI program); SEC exam priorities (supervision) |
| 2. Data Security & Privacy | MAP 2, 4; MEASURE 2.6–2.10; MANAGE 3 | Annex A.7 (data for AI systems), A.4 (resources), A.10 (third-party relationships) | CCPA ADMT regs; California CRD ADS records rule; HIPAA (healthcare); GLBA (financial); state privacy laws |
| 3. Operational Controls | MEASURE 1–4; MANAGE 1–4 (human oversight, incident response, third-party risk) | Clause 8 (operation), 10 (improvement); Annex A.6.2, A.8 (information for interested parties), A.9 (use of AI systems), A.10 | ABA Formal Opinion 512 (competence, supervision); court standing orders on AI; NAIC bulletin (third-party oversight) |
| 4. Workforce Capability & Training | GOVERN 2.2, 4.1; MAP 1.2 | Clause 7.2–7.3 (competence, awareness); Annex A.4.6 (human resources) | EU AI Act Art. 4 literacy (deployers with EU exposure); state bar CLE ethics rules; NAIC bulletin (training) |
| 5. Transparency & Client Trust | GOVERN 5, 6; MAP 5; MANAGE 4.2–4.3 | Clause 7.4 (communication); Annex A.8 (transparency, information for interested parties), A.9.3 (objectives for responsible use) | FTC Act §5 and 2026 policy statements on AI claims; SEC AI-washing enforcement; ABA 512 (client disclosure); Illinois HB 3773 / Connecticut SB 5 (notice) |
Full control-level crosswalk (40 rows) is delivered with every report. Neither NIST nor ISO endorses AboveBoardAI; mappings are AboveBoard's own analysis.
Rendered from the same question bank the assessment uses, so this page is never out of date.
Eight additional controls on how deliberately a firm chooses, uses and accounts for AI with its environmental footprint in mind. Scored 0–20 on its own scale and shown beside the AboveBoard Score. It never moves the 0 to 100 number. Firms that reach 12/20, with vendor selection (E1) above zero, earn the Stewardship seal on their badge and registry entry.
Every control is something a firm that uses AI can evidence itself: vendor selection criteria, right-sizing guidance, waste-reduction practices, hardware decisions, usage measurement, disclosure, energy and cloud choices, and a named owner. We do not score vendors' data centers, and we do not accept a vendor's sustainability page as evidence of the firm's own practice.
Framework anchors: ISO/IEC 42001 Annex C (environmental impact as an AI objective) · NIST AI RMF 1.0 MAP 5 and the "safe, sustainable" trustworthiness characteristics. Reviewed with the audit for $1,500/yr; included at Established tier and above.
Twenty-five requests (thirty with the Stewardship Endorsement). You upload what you have; anything you mark "don't have yet" becomes a remediation item and we send a template. Reviewers sample rather than read every page, and may ask for more where the sample raises questions.
AI policy · AI inventory/register · accountability evidence · leadership oversight minutes · risk assessment examples
Data classification guidance · approved-tools list · vendor terms/DPAs · access-control evidence · retention settings
Human review procedure · QA log · incident plan (AI section) · incident/near-miss log · vendor monitoring & change log
Training completion report · curriculum/role matrix · acceptable-use acknowledgments · leadership training record · credentials
Engagement clause · public AI statement · claims review procedure · questionnaire answer bank · complaints & communications guidance
Vendor sustainability evidence · right-sizing and waste-reduction guidance · usage export and footprint estimate · disclosure · energy, cloud and hardware documentation
v1.0, September 2026. Initial release. The pre-release draft's "Environmental Performance" domain becomes the optional Stewardship Endorsement (E1–E8), scored on its own 0–20 scale so the core 0–100 score stays focused on the controls regulators, insurers and clients ask about; Transparency & Client Trust takes its place among the five scored domains.