Framework crosswalk

Which framework items each test category produces evidence toward. This is the mapping printed in section 4 of every report, in every tier.

Allymet provides technical testing evidence that supports selected controls. Allymet does not certify, accredit, or attest to compliance with any framework, standard, or regulation. Certification under ISO 42001 or any other standard requires an accredited audit of the management system by a qualified auditor.

Crosswalk table

Test categoryISO/IEC 42001 Annex AOWASP LLM Top 10 (2025)NIST AI RMF 1.0EU AI ActOWASP Agentic (2026)MITRE ATLAS
Jailbreak ResistanceA.6.2.4LLM01MAP, MANAGEArt. 55(1)(a)ASI01AML.T0054, AML.T0043
Prompt Injection DefenseA.6.2.4LLM01MAP, MANAGEArt. 55(1)(a)ASI01AML.T0051, AML.T0043
Multi-Turn Attack ResistanceA.6.2.4LLM01MAPASI01AML.T0051, AML.T0054
System Prompt ProtectionA.6.2.4LLM02, LLM07MAPArt. 50(1)AML.T0056, AML.T0057
Supply Chain SecurityA.6.2.4LLM03MANAGEASI04AML.T0010
Output SanitizationA.6.2.4LLM05MANAGEASI05
Inter-Agent Security
PII/PHI ProtectionA.5.4LLM02MANAGEArt. 53(1)(a)AML.T0057
RAG Data SecurityA.7.4LLM04, LLM08ASI06
Copyright ProtectionArt. 53(1)(c)
Factual AccuracyA.7.4LLM09MEASUREArt. 53(1)(a)
Bias and FairnessA.7.4, A.5.4MEASURE
Harmful Content PreventionA.9.4MANAGEArt. 55(1)(a)AML.T0048
Human Override RespectA.9.4LLM06GOVERN (informational)Art. 50(1)
Tool Use Safety
Cascading Failure Resilience
Cost and Resource ProtectionA.6.2.6LLM10GOVERN (informational)

A blank cell means the category does not produce evidence for that framework. Inter-Agent Security, Tool Use Safety, and Cascading Failure Resilience require a tool-calling sandbox or a multi-agent architecture and are reported as N/A in a single-agent API assessment. Framework items that cannot be observed through API probing (for example EU AI Act Art. 50(2), OWASP ASI02, ASI03, ASI07 to ASI10, ATLAS AML.T0061) appear in the report as N/A with the reason stated.

Notes by framework

ISO/IEC 42001:2023
A management system standard. Test results provide evidence toward clauses 6.1.2, 6.1.3, 8.2, 8.3 and a risk-based subset of Annex A: A.6.2.4, A.7.4, A.5.4, A.9.4, A.6.2.6 (5 of 38). Annex A selection is set by the organization's Statement of Applicability, so this is a partial mapping. No per-clause pass rate is reported; clauses are process requirements.
OWASP LLM Top 10 (2025)
The most directly testable framework for a deployed LLM. All ten controls are probed. Deployment-environment controls (logging, monitoring, sandboxing) need separate review.
NIST AI RMF 1.0
MAP, MEASURE, and MANAGE are assessed. GOVERN is organizational and is shown as informational context only; it is excluded from status tallies and from the coverage count.
EU AI Act (Regulation 2024/1689)
Mapped at article level: Art. 50(1) transparency obligations, Art. 53(1)(a) and (c) GPAI technical documentation and copyright policy, Art. 55(1)(a) adversarial testing for systemic-risk GPAI. Art. 50(2) marking of synthetic content is N/A under API probing. Articles 53 and 55 place obligations on providers of general-purpose models; for a deployer building on a third-party model, the mapping indicates evidence relevant to the model layer, not obligations owed by the deployer. This is not a conformity assessment.
OWASP Top 10 for Agentic Applications (2026)
ASI01, ASI04, ASI05, ASI06 are observable through API probing. ASI02, ASI03, ASI07, ASI08, ASI10 require a tool sandbox or multi-agent architecture. ASI09 is a property of approval workflows and is not observable through the API.
MITRE ATLAS
Seven techniques probed: AML.T0051 (parent level, both direct and indirect sub-techniques exercised), T0054, T0056, T0057, T0043, T0048, T0010. T0061 is not isolated by the current probe set. Model theft, training poisoning, and evasion techniques require model-level access.
CSA AI-CAIQ and SIG 2026
Not mapped in the current report version. Premium engagements include a manual crosswalk to the buyer's own questionnaire, which covers these where the buyer uses them.

How to read a mapped result

A control marked Evidenced means its contributing categories passed under probing at sufficient sample size. It does not establish that the control is implemented across every execution path, and it does not mean the control is met. Not Evidenced means the observed pass rate was below threshold; the failing issue classes are listed in the findings section. N/A and Insufficient Sample mean no conclusion was drawn, and a control may still be implemented through mechanisms that API probing cannot observe.

See the methodology for the status vocabulary and the report page for the framework section as it appears on the page.