The AboveBoard Standard · Version 1.0 · September 2026

A standard you can read in twenty minutes. Published in full, because a rubric you can't see isn't one.

Five domains. Forty controls. Four maturity levels per control, scored 0–3 and scaled to 20 points per domain. Mapped to the NIST AI Risk Management Framework 1.0 and cross-walked to ISO/IEC 42001:2023. Designed for firms that use AI, in the language those firms actually speak.

Design principles

What the Standard is, and isn't.

  • Practices, not outcomes. We verify that governance practices exist and are evidenced. We do not test AI systems and we never certify that an AI output is correct.
  • Proportionate. A 15-person CPA firm and a 900-person law firm answer the same forty questions; the evidence expected scales with size and risk.
  • Evidence-based. Every control names the evidence that proves it. Self-assessment produces a provisional score; only reviewed evidence produces a verified one.
  • Framework-anchored. Every control maps to a NIST AI RMF 1.0 function and sub-category and to an ISO/IEC 42001 clause or Annex A control, so work done here transfers.
  • Plain English. If a managing partner can't explain a control to a client in one sentence, we rewrote it.
  • Versioned. The Standard is reviewed at least annually. Changes are published with a change log; firms are scored against the version in force when their review begins.

Scoring

Per control0–3
Per domain (8 controls)0–24 raw, scaled to 0–20
Total0–100
Leading90–100
Advanced75–89
Verified60–74
Not yet verified<60 (private)

Gating controls. Regardless of total score, a firm cannot be listed at any level with a 0 on G1 (written AI policy), D3 (vendor terms reviewed) or O1 (human review of client-facing output). These are the three controls every regulator, insurer and client questionnaire asks about first.

Framework mapping

How the five domains line up with NIST AI RMF and ISO/IEC 42001

AboveBoard domainNIST AI RMF 1.0ISO/IEC 42001:2023Regulatory hooks (US, Sept 2026)
1. Governance & AccountabilityGOVERN 1–6 (policies, accountability, risk culture, inventory); MAP 1Clauses 4–6 (context, leadership, planning); Annex A.2 (policies), A.3 (internal organization), A.6 (AI system lifecycle)Texas TRAIGA affirmative defense for NIST AI RMF alignment; NAIC AI Model Bulletin (written AI program); SEC exam priorities (supervision)
2. Data Security & PrivacyMAP 2, 4; MEASURE 2.6–2.10; MANAGE 3Annex A.7 (data for AI systems), A.4 (resources), A.10 (third-party relationships)CCPA ADMT regs; California CRD ADS records rule; HIPAA (healthcare); GLBA (financial); state privacy laws
3. Operational ControlsMEASURE 1–4; MANAGE 1–4 (human oversight, incident response, third-party risk)Clause 8 (operation), 10 (improvement); Annex A.6.2, A.8 (information for interested parties), A.9 (use of AI systems), A.10ABA Formal Opinion 512 (competence, supervision); court standing orders on AI; NAIC bulletin (third-party oversight)
4. Workforce Capability & TrainingGOVERN 2.2, 4.1; MAP 1.2Clause 7.2–7.3 (competence, awareness); Annex A.4.6 (human resources)EU AI Act Art. 4 literacy (deployers with EU exposure); state bar CLE ethics rules; NAIC bulletin (training)
5. Transparency & Client TrustGOVERN 5, 6; MAP 5; MANAGE 4.2–4.3Clause 7.4 (communication); Annex A.8 (transparency, information for interested parties), A.9.3 (objectives for responsible use)FTC Act §5 and 2026 policy statements on AI claims; SEC AI-washing enforcement; ABA 512 (client disclosure); Illinois HB 3773 / Connecticut SB 5 (notice)

Full control-level crosswalk (40 rows) is delivered with every report. Neither NIST nor ISO endorses AboveBoardAI; mappings are AboveBoard's own analysis.

The rubric

All forty controls, all four levels.

Rendered from the same question bank the assessment uses, so this page is never out of date.

Optional · scored separately

The Stewardship Endorsement

Eight additional controls on how deliberately a firm chooses, uses and accounts for AI with its environmental footprint in mind. Scored 0–20 on its own scale and shown beside the AboveBoard Score. It never moves the 0 to 100 number. Firms that reach 12/20, with vendor selection (E1) above zero, earn the Stewardship seal on their badge and registry entry.

Every control is something a firm that uses AI can evidence itself: vendor selection criteria, right-sizing guidance, waste-reduction practices, hardware decisions, usage measurement, disclosure, energy and cloud choices, and a named owner. We do not score vendors' data centers, and we do not accept a vendor's sustainability page as evidence of the firm's own practice.

Framework anchors: ISO/IEC 42001 Annex C (environmental impact as an AI objective) · NIST AI RMF 1.0 MAP 5 and the "safe, sustainable" trustworthiness characteristics. Reviewed with the audit for $1,500/yr; included at Established tier and above.

AboveBoard Stewardship seal

Stewardship controls E1–E8 20 points · separate scale

Evidence requested, by domain

Twenty-five requests (thirty with the Stewardship Endorsement). You upload what you have; anything you mark "don't have yet" becomes a remediation item and we send a template. Reviewers sample rather than read every page, and may ask for more where the sample raises questions.

Governance

AI policy · AI inventory/register · accountability evidence · leadership oversight minutes · risk assessment examples

Data & Privacy

Data classification guidance · approved-tools list · vendor terms/DPAs · access-control evidence · retention settings

Operations

Human review procedure · QA log · incident plan (AI section) · incident/near-miss log · vendor monitoring & change log

Workforce

Training completion report · curriculum/role matrix · acceptable-use acknowledgments · leadership training record · credentials

Transparency

Engagement clause · public AI statement · claims review procedure · questionnaire answer bank · complaints & communications guidance

Stewardship (optional)

Vendor sustainability evidence · right-sizing and waste-reduction guidance · usage export and footprint estimate · disclosure · energy, cloud and hardware documentation

Version history

v1.0, September 2026. Initial release. The pre-release draft's "Environmental Performance" domain becomes the optional Stewardship Endorsement (E1–E8), scored on its own 0–20 scale so the core 0–100 score stays focused on the controls regulators, insurers and clients ask about; Transparency & Client Trust takes its place among the five scored domains.