
Compliance
Forge provides evidence mapping and posture assessment. It does not provide
certification, legal advice, or a regulatory attestation.
Assessments
Forge evaluates framework items from current:- Findings and inventory entities.
- Runtime and source coverage.
- Policies and policy hits.
- Governance evaluations and resolved workflows.
- Manual evidence.
- Time-bound risk acceptances.
pass, partial, fail, unknown, or accepted. Evidence links
state whether a record satisfies, evidences, violates, or resolves the item.
Unknown remains distinct from pass when Forge lacks an evidence path.
Framework summaries show readiness, evidence coverage, open risk pressure, and
the number of items that still need evidence. Refreshing creates or reuses a
versioned snapshot based on the framework catalog and current input set.
Snapshots can be exported as JSON, CSV, or PDF.
Frameworks
Forge includes:- NIST AI RMF.
- EU AI Act.
- ISO/IEC 42001.
- OWASP LLM Top 10, Agentic Top 10, and AI Vulnerability Scoring System.
- MITRE ATLAS.
- Cisco AI Security Framework.
- AIUC-1.
- IBM AI Risk Atlas.
- CSA AI Controls Matrix.
- SOC 2 Trust Services Criteria.
- GDPR and CCPA/CPRA.
- HIPAA Security Rule.
- PCI DSS.
Manual evidence
Manual evidence attaches an external artifact or platform record to one framework item. It records an evidence type, trust label, title, locator, justification, creator, and optional expiration. Revoking it removes the record from future active assessments without rewriting previous snapshots.Risk acceptance
A risk acceptance records a justification, owner, expiration, and optional scope to a specific platform resource. An active acceptance changes the applicable assessment status toaccepted; it does not convert the underlying
evidence into a pass. Acceptances can be revoked before expiration.
Related pages
Inventory
Review the AI assets, identities, configurations, and risks used as
evidence.
Policies
Understand the controls and policy decisions mapped into assessments.
Privacy
Configure evidence and security-record retention.
Audit Log
Review the administrative history behind governance evidence.