Methodology 1.0.0-rc.2 · Public calibration candidate · Not production active

The Alpha Standard · Crosswalks

Frameworks define what matters.

Alpha determines whether the enterprise can govern it.

The Alpha Standard maps material AI governance obligations, practices, and threats into a governed evidence and rating system. It makes performance comparable without claiming certification, compliance, or framework equivalence.

Rated subject
Enterprise governance system
Analytical hierarchy
6 pillars · 24 subcategories · 48 requirements
Rating family
Alpha AI Governance Rating

The judgment layer

From public framework to comparable opinion.

A crosswalk is useful only when it preserves applicability, evidence, and judgment. Select a source to inspect the path Alpha exposes.

External source

DIRECT

Article 14 · Human oversight

High-risk AI systems require effective human oversight appropriate to their risk, autonomy, and context of use.

Status
In force · consolidated 2026-07-27
Source type
Binding regulation
Inspect official source

Alpha requirement

PRIMARY HOME

Intervention, override & shutdown

Material AI and agents must have tested, authorized intervention paths that preserve containment, attribution, and safe restart.

Pillar
Monitoring & Improvement
Cadence
Quarterly and event-driven

Evidence and test

OPERATING EVIDENCE

Trace an intervention exercise

Inspect authority, shutdown, credential revocation, downstream containment, state integrity, and authorized restart.

Public visibility
Low
Score anchor
0 Absent → 4 Assured

Alpha judgment

HUMAN APPROVED

Rating symbol, outlook, and rationale

The calculated result may be constrained by a critical-pillar ceiling. Missing applicable evidence produces NR, never an inferred pass.

Output
AAA-D or NR
History
Immutable observation

Crosswalk mappings indicate relevance and possible applicability. They do not constitute legal advice, certification, safe harbor, compliance, or framework equivalence. Source records reviewed 2026-08-04.

What Alpha assesses

One governance question. Six scored pillars.

Each pillar contains four equal-weight subcategories and eight requirements. A strong average cannot erase a severe failure in a critical pillar.

PillarBoard questionWeight
01Leadership & Accountability

Who is responsible for AI, and can the board hold them accountable?

20%
02Safety, Security & Resilience

Can AI operate safely and withstand attack, failure, and disruption?

22%
03Data, Privacy & Transparency

Is data protected, and are AI uses, decisions, and claims clear?

15%
04People & Rights

Are people treated fairly, protected from harm, and able to challenge decisions?

14%
05Compliance & Third Parties

Are legal duties, vendors, models, and external dependencies governed?

15%
06Monitoring & Improvement

Can the enterprise detect problems, intervene, correct them, and learn?

14%

Framework library

Mapped by obligation, practice, and threat.

The library is organized by source family and status. Every public record carries a source, review date, and applicability boundary.

8 reviewed sources

EU

EU AI Act

Role- and risk-based legal obligations mapped to entity-specific applicability.

In force · consolidated 2026-07-27
Source
US

NIST AI RMF

Govern, Map, Measure, and Manage outcomes traced to Alpha requirements and tests.

AI RMF 1.0 under revision
Source
ISO

ISO/IEC 42001

AI management-system clauses mapped to evidence of authority and operating effectiveness.

Published · 2023
Source
OECD

OECD AI Principles

Trustworthy-AI principles connected to accountability, rights, transparency, and resilience.

Updated · 2024
ATLAS

MITRE ATLAS

AI adversary tactics, techniques, and mitigations linked to controls and test evidence.

Maintained
Source
OWASP

LLM and agentic security guidance

Application and agentic weaknesses mapped to safety, ecosystem, and intervention controls.

Maintained · 2026 materials reviewed
SOC

SOC 2

Assurance evidence may support Alpha requirements but does not establish AI governance alone.

Supporting evidence
27001

ISO/IEC 27001

Information-security evidence is evaluated within scope, freshness, and relevance limits.

Published · 2022; amended 2024

Source library last reviewed .

One rating, two evidence bases

Same standard. Different evidence perimeter.

Public and verified observations use the same analytical structure but remain separate. Private evidence cannot enter, alter, or be inferred from a public rating.

Public Information

Attributable public evidence

Filings, policies, regulator records, incidents, litigation, standards activity, and attributable reporting available by the cutoff date.

Normal maximum
A
AA only with accepted disclosed independent assurance. Never AAA.

Verified Assessment

Evidence verified by Alpha

Board records, inventories, tests, change logs, vendor registers, incidents, and corrective actions within a signed assessment perimeter.

Available scale
AAA-D
Subject to applicable evidence, review, constraints, and approval.

Boundary of opinion

What the Alpha Standard does not replace.

An Alpha Governance Rating is an independent governance opinion. It is not a legal conclusion, product certificate, audit opinion, or substitute for accountable decision-making.

  1. 01Legal advice or an entity-specific compliance determination
  2. 02EU conformity assessment or notified-body certification
  3. 03ISO certification, SOC 2, or a financial-statement audit
  4. 04Product safety testing, red teaming, or penetration testing
  5. 05Regulator, court, auditor, insurer, management, or board judgment

Alpha Ratings

Examine the judgment system.

Review the methodology, evidence boundaries, and framework mappings with Alpha.