CoSAI · OASIS Open Project · V1.0

Make responsibility clear before you scale AI.
CoSAI SRF maps every obligation and control to an accountable owner.

It complements the regulations and standards you already follow (NIST AI RMF, ISO/IEC 42001, the EU AI Act) by answering the one question they leave open: who is accountable. The SRF assigns exactly one accountable party to every activity, across every layer of your AI stack and every operating model you deploy. When a system acts, delegates, or uses tools, that assignment still names one persona. Autonomy level (L0 to L5) and override tier (T1 to T5) describe how independently it may act and how it can be stopped. They do not move the owner.

However you enter, you finish in the same place: a signed Accountability Decision Record that names one accountable party per layer for your deployment, captures the residual gaps, and carries a sign-off.

Create a Decision Record

SRF Stress Test

Describe your AI deployment.
Get an accountability analysis.

The SRF Stress Test takes a plain-language description of your AI scenario (the model, platform, deployment model, and use case) and returns a layered accountability breakdown, gap analysis, and risk flags in seconds. Powered by GPT-4o mini.

Try the SRF Stress Test →

Other frameworks define what. SRF assigns accountability.

The SRF sits alongside your existing frameworks and assigns one accountable party per activity. NIST AI RMF defines what governance outcomes to achieve. ISO/IEC 42001 defines how to manage AI within your organization. EU AI Act defines which regulatory obligations apply by risk tier. None assigns who holds accountability when an incident crosses vendor boundaries.

  • NIST AI RMF → CoSAI SRF

    What to achieve → Who achieves it

    NIST AI RMF defines the governance outcomes to achieve: Govern, Map, Measure, Manage. SRF adds which party in a multi-vendor deployment is accountable for each outcome.

  • EU AI Act → CoSAI SRF

    Which obligations apply → Who at which layer

    The EU AI Act defines which regulatory obligations apply by risk tier. SRF maps those obligations to specific layers and operating models: the implementation detail the regulation intentionally leaves to practitioners.

  • ISO 42001 → CoSAI SRF

    How to manage AI → Who manages which part

    ISO/IEC 42001 defines how to manage AI within a single organization's boundary. SRF provides the multi-party accountability model that 42001's Clause 5 and 6 require but leave undefined for cloud AI deployments.