NIST AI RMF · ISO 42001 · ISO 23894 · EU AI Act

Answer a control once.
Satisfy four frameworks.

Stratify collapses NIST AI RMF, ISO/IEC 42001, ISO/IEC 23894 and the EU AI Act into one set of 62 plain-English controls. Answer them once and watch 179 framework clauses turn green at the same time — with the evidence attached and the audit trail already written.

No credit card. Every framework unlocked during the trial.

One control set
62 controls
UC-38
Technical documentation pack
“Technical documentation is maintained and kept current, sufficient to demonstrate compliance and enable third-party assessment.”
SATISFIES
  • NIST AI RMF4 functions · 72 subcategories72
  • ISO/IEC 42001AIMS clauses + 38 Annex A controls51
  • ISO/IEC 23894Principles · framework · process29
  • EU AI ActObligations across the risk tiers27
367 clause mappings ship with the product — every one carries a coverage rating of full, partial or supporting, so nothing claims more than it delivers.
62
unified controls
179
framework clauses mapped
100%
clause coverage
4
frameworks, one answer
The crosswalk

Stop answering the same question four times

Most teams run parallel compliance tracks: a NIST workbook, an ISO Statement of Applicability, an AI Act readiness sheet, and a folder of evidence duplicated across all three. The work is the same. The documentation is not.

Stratify inverts it. You maintain one control set. Every clause that control contributes to updates the moment you answer — and the crosswalk view shows exactly which clauses are met, partially met, or still open in each framework.

  • Coverage is rated honestly — full, partial, or supporting
  • Clause status derives from your answers, not from a checkbox you tick twice
  • Mark a control not applicable and the justification travels with it
UC-09
Complete AI system inventory
FrameworkClauseCoverage
NIST AI RMFGOVERN 1.6full
ISO/IEC 42001A.4.2full
ISO/IEC 42001A.4.5partial
ISO/IEC 238946.3.2partial
EU AI ActArticle 6partial
One answer. Five clauses. Four frameworks.

AI governance became mandatory before it became affordable

The deadline is already here

EU AI Act prohibitions and the AI literacy duty have applied since February 2025. GPAI obligations landed in August 2025. The high-risk regime follows in August 2026. This is law with extraterritorial reach — it binds any provider placing a system on the EU market.

Your GRC tool doesn't cover it

Traditional GRC platforms model controls, not models. They have no concept of an AI system inventory, autonomy level, drift, an Annex III use case, or a fundamental rights impact assessment.

The specialists price you out

Credo AI, Holistic AI, OneTrust and IBM OpenPages start between $30,000 and $200,000 a year. That is a rational price for a Fortune 500 program and an impossible one for a 40-person company that just got an AI questionnaire from its largest customer.

What you get on day one

AI system inventory

Register every model, API, agent and embedded feature — including the shadow AI in your SaaS stack. Each system gets an owner, a lifecycle stage, and a risk profile.

Explainable risk scoring

A 0–100 composite across autonomy, data sensitivity, consequence, oversight gap, scale, regulatory exposure and supply chain. Every point traces to a named driver — no black-box score you can't defend.

EU AI Act tier classification

Screens each system against Article 5 prohibited practices and Annex III high-risk use cases, then returns the tier and the specific article-by-article obligations that follow.

ISO 23894 risk methodology

The framework almost no platform operationalizes: identification, analysis, evaluation, treatment planning, residual risk acceptance, monitoring and reporting — as a real process, not a checkbox.

Deduplicated evidence repository

Upload the model card once and attach it to the eleven controls it proves. SHA-256 recorded at ingest, expiry tracked, so stale evidence surfaces before an auditor finds it.

Hash-chained audit trail

Every action is appended with a hash covering the previous entry. Edit or delete a row and verification fails — which is what makes the trail tamper-evident rather than merely promised.

One-click audit packet

Control set, clause coverage per framework, evidence index with digests, risk register and the verified audit trail — as a single document you hand to an auditor, a customer, or the board.

Sector overlays

Healthcare, finance and defense packs layer sector-specific controls — clinical validation, model risk management, adverse action reasoning, CUI boundaries — on top of the core set.

Powered by Claude

You have already done more of this than you think

Upload the policies, SOPs, model cards, vendor questionnaires and security documents you already wrote. Claude reads them against all 62 controls and tells you which ones they evidence — with a verbatim quote from your own document as the citation.

A three-week consulting engagement becomes a three-minute upload. And nothing is applied automatically: every finding is a proposal your compliance officer accepts or rejects, and the decision is recorded in the audit trail.

information-security-policy.pdfAnalyzed
UC-27satisfied · 92%
Data governance for AI

All data used in automated processing must be classified and approved by the Data Governance Committee prior to use.

UC-35partial · 64%
Security and adversarial resilience

Annual penetration testing is performed against all production applications.

Findings shown are illustrative. Real output cites your document verbatim.

Priced for the companies the incumbents skipped

Every plan starts with a 14-day trial with all four frameworks unlocked and no card required. Annual billing saves two months.

Starter

For the team that just got asked for an AI policy

$499/month
$4,990 billed annually
  • NIST AI RMF + EU AI Act
  • 5 AI systems, 3 seats
  • Unified control set and evidence repository
  • Risk scoring and EU AI Act tier classification
  • 5 Claude policy analyses / month
Start with Starter

Growth

Most chosen

For the team that has to prove it to a customer or an auditor

$1,500/month
$15,000 billed annually
  • All four frameworks fully crosswalked
  • 25 AI systems, 15 seats
  • One-click audit packet export
  • 50 Claude policy analyses / month
  • Immutable, hash-chained audit trail
Start with Growth

Scale

For the team running AI governance as a program

$3,500/month
$35,000 billed annually
  • Unlimited AI systems and seats
  • Sector overlays: healthcare, finance, defense
  • SSO / SAML
  • 250 Claude policy analyses / month
  • API access and priority support
Talk to us

For comparison: comparable AI governance platforms are priced from $30,000 to $200,000 per year.

Find out where you actually stand

Register your AI systems, upload the documents you already have, and get a gap report across all four frameworks. Most teams have their first readiness picture inside an hour.