Standards we reference, and where they stand
These standards shape how the platform is designed and what our reviews track. They are marked referenced until mapped control by control in the registry.
| Standard | Scope | Status in Cogna8 |
|---|---|---|
| ISO/IEC 42001 | AI management system, including AI system impact assessment | Referenced |
| EU AI Act | Risk tiers, transparency, deployer duties; high-risk obligations from 2 December 2027 and 2 August 2028 | Referenced |
| NIST AI RMF | Govern, map, measure and manage AI risk | Referenced |
| ISO/IEC 23894 | Guidance on AI risk management | Referenced |
| MAS AI risk management | Proposed expectations for financial institutions in Singapore | Referenced |
| IMDA agentic AI framework | Governance of agentic AI deployments in Singapore | Referenced |
| OWASP Top 10 for LLM applications | Security risks specific to LLM and agent systems | Referenced in security |
| MITRE ATLAS | Adversary tactics and techniques against AI systems | Referenced in security |
Let's connect
Tell us where your AI programme is today. We start with a short, scoped pilot on your own AI estate, and every enquiry is handled in confidence.