VeritomeHelp Centre
/
Browse documentation
Using Veritome

Frameworks: switch a standard on, and see what it asks

The Configure screen for the regimes your organisation is run against: the five toggles, the Programme cards, the Coverage matrix, every requirement row, and the regulatory-change register.

Updated Veritome documentation

Frameworks (under Configure) is where you decide which regimes your organisation is run against, and where each one shows what it is scoped to and how much of one another they already answer. Toggling a framework changes what the requirement resolver returns — no screen changes shape.

The screen is absent from the rail while the frameworks-crosswalk switch is off: the cross-mapping of ISO/IEC 42001, ISO/IEC 27001 and NIST AI RMF lands by 13 October. Until then the EU AI Act and GDPR run per system as they always have, and the regulatory updates reach the Dashboard directly.

Five tabs

TabWhat it shows
FrameworksThe five toggles — EU AI Act and GDPR always on; ISO/IEC 42001, ISO/IEC 27001 and NIST AI RMF switched on per organisation — with a profile card per framework: requirements, covered by a verified control, controls needed, and how many requirements another enabled framework also answers.
ProgrammeOne card per enabled standard: its phase strip, steps evidenced, the next step, and the target date. See Programmes: a standard as a path, not a list.
CoverageThe requirement-by-requirement matrix for a framework — each clause with the step assigned to it, reading Workflow assigned rather than "covered" — and its CSV.
RequirementsEvery requirement row of the enabled frameworks, with search and a framework filter. A framework contributes rows only once it is enabled.
ChangesThe regulatory-change register and the tracked EU feeds. See Regulatory watch: track changes, decide, and leave a trail.

Three counts sit above the tabs — Requirements in scope, Distinct duties (counted once across frameworks) and Shared (requirements another framework also answers).

Enabling a standard

Switch a framework on and it becomes a programme: ordered steps in gated phases, each producing a record, generated when the subscription flips to enabled. Each standard is bought as a programme — ISO/IEC 42001 is included in the Manage plan from 13 October 2026 — and the plan gate says so at the toggle. Aria's knowledge sources follow the same toggles, so a standard you enable is one Aria can cite.

Each framework has its own page. The ISO/IEC 42001 page carries the management-system workspace — the Annex A control catalogue, the QMS profile, the Statement of Applicability and the reviews (see Quality Management (QMS): ISO/IEC 42001 controls and Art. 17). The NIST AI RMF programme produces a profile document; the ISO/IEC 27001 programme shares several records with ISO/IEC 42001, so a context, roles or risk record written once counts in both.

What the frameworks are not

None of them is a certificate. ISO/IEC 42001 is not a legal shield and NIST AI RMF has no certification; the EU AI Act and GDPR are the binding law, and the standards are ways of organising the work that evidences it. The plain-language reads under Frameworks explained say what each one gives you, and what it does not.