Framework crosswalk
Which framework items each test category produces evidence toward. This is the mapping printed in section 4 of every report, in every tier.
Allymet provides technical testing evidence that supports selected controls. Allymet does not certify, accredit, or attest to compliance with any framework, standard, or regulation. Certification under ISO 42001 or any other standard requires an accredited audit of the management system by a qualified auditor.
Crosswalk table
| Test category | ISO/IEC 42001 Annex A | OWASP LLM Top 10 (2025) | NIST AI RMF 1.0 | EU AI Act | OWASP Agentic (2026) | MITRE ATLAS |
|---|---|---|---|---|---|---|
| Jailbreak Resistance | A.6.2.4 | LLM01 | MAP, MANAGE | Art. 55(1)(a) | ASI01 | AML.T0054, AML.T0043 |
| Prompt Injection Defense | A.6.2.4 | LLM01 | MAP, MANAGE | Art. 55(1)(a) | ASI01 | AML.T0051, AML.T0043 |
| Multi-Turn Attack Resistance | A.6.2.4 | LLM01 | MAP | ASI01 | AML.T0051, AML.T0054 | |
| System Prompt Protection | A.6.2.4 | LLM02, LLM07 | MAP | Art. 50(1) | AML.T0056, AML.T0057 | |
| Supply Chain Security | A.6.2.4 | LLM03 | MANAGE | ASI04 | AML.T0010 | |
| Output Sanitization | A.6.2.4 | LLM05 | MANAGE | ASI05 | ||
| Inter-Agent Security | ||||||
| PII/PHI Protection | A.5.4 | LLM02 | MANAGE | Art. 53(1)(a) | AML.T0057 | |
| RAG Data Security | A.7.4 | LLM04, LLM08 | ASI06 | |||
| Copyright Protection | Art. 53(1)(c) | |||||
| Factual Accuracy | A.7.4 | LLM09 | MEASURE | Art. 53(1)(a) | ||
| Bias and Fairness | A.7.4, A.5.4 | MEASURE | ||||
| Harmful Content Prevention | A.9.4 | MANAGE | Art. 55(1)(a) | AML.T0048 | ||
| Human Override Respect | A.9.4 | LLM06 | GOVERN (informational) | Art. 50(1) | ||
| Tool Use Safety | ||||||
| Cascading Failure Resilience | ||||||
| Cost and Resource Protection | A.6.2.6 | LLM10 | GOVERN (informational) |
A blank cell means the category does not produce evidence for that framework. Inter-Agent Security, Tool Use Safety, and Cascading Failure Resilience require a tool-calling sandbox or a multi-agent architecture and are reported as N/A in a single-agent API assessment. Framework items that cannot be observed through API probing (for example EU AI Act Art. 50(2), OWASP ASI02, ASI03, ASI07 to ASI10, ATLAS AML.T0061) appear in the report as N/A with the reason stated.
Notes by framework
- ISO/IEC 42001:2023
- A management system standard. Test results provide evidence toward clauses 6.1.2, 6.1.3, 8.2, 8.3 and a risk-based subset of Annex A: A.6.2.4, A.7.4, A.5.4, A.9.4, A.6.2.6 (5 of 38). Annex A selection is set by the organization's Statement of Applicability, so this is a partial mapping. No per-clause pass rate is reported; clauses are process requirements.
- OWASP LLM Top 10 (2025)
- The most directly testable framework for a deployed LLM. All ten controls are probed. Deployment-environment controls (logging, monitoring, sandboxing) need separate review.
- NIST AI RMF 1.0
- MAP, MEASURE, and MANAGE are assessed. GOVERN is organizational and is shown as informational context only; it is excluded from status tallies and from the coverage count.
- EU AI Act (Regulation 2024/1689)
- Mapped at article level: Art. 50(1) transparency obligations, Art. 53(1)(a) and (c) GPAI technical documentation and copyright policy, Art. 55(1)(a) adversarial testing for systemic-risk GPAI. Art. 50(2) marking of synthetic content is N/A under API probing. Articles 53 and 55 place obligations on providers of general-purpose models; for a deployer building on a third-party model, the mapping indicates evidence relevant to the model layer, not obligations owed by the deployer. This is not a conformity assessment.
- OWASP Top 10 for Agentic Applications (2026)
- ASI01, ASI04, ASI05, ASI06 are observable through API probing. ASI02, ASI03, ASI07, ASI08, ASI10 require a tool sandbox or multi-agent architecture. ASI09 is a property of approval workflows and is not observable through the API.
- MITRE ATLAS
- Seven techniques probed: AML.T0051 (parent level, both direct and indirect sub-techniques exercised), T0054, T0056, T0057, T0043, T0048, T0010. T0061 is not isolated by the current probe set. Model theft, training poisoning, and evasion techniques require model-level access.
- CSA AI-CAIQ and SIG 2026
- Not mapped in the current report version. Premium engagements include a manual crosswalk to the buyer's own questionnaire, which covers these where the buyer uses them.
How to read a mapped result
A control marked Evidenced means its contributing categories passed under probing at sufficient sample size. It does not establish that the control is implemented across every execution path, and it does not mean the control is met. Not Evidenced means the observed pass rate was below threshold; the failing issue classes are listed in the findings section. N/A and Insufficient Sample mean no conclusion was drawn, and a control may still be implemented through mechanisms that API probing cannot observe.
See the methodology for the status vocabulary and the report page for the framework section as it appears on the page.