CoSAI · OASIS Open Project · V1.0
Make responsibility clear before you scale AI.
CoSAI SRF maps every obligation and control to an accountable owner.
It complements the regulations and standards you already follow (NIST AI RMF, ISO/IEC 42001, the EU AI Act) by answering the one question they leave open: who is accountable. The SRF assigns exactly one accountable party to every activity, across every layer of your AI stack and every operating model you deploy. When a system acts, delegates, or uses tools, that assignment still names one persona. Autonomy level (L0 to L5) and override tier (T1 to T5) describe how independently it may act and how it can be stopped. They do not move the owner.
-
Deploying AI
Know what your vendor owes you before an incident, across a multi-vendor stack.
Map accountability -
Building AI
Turn your accountability boundary into contract language and commitments customers can verify.
See obligations -
Governing AI
Name an owner for every control. Find accountability gaps before they become incidents.
Start assessment
However you enter, you finish in the same place: a signed Accountability Decision Record that names one accountable party per layer for your deployment, captures the residual gaps, and carries a sign-off.
Create a Decision RecordSRF Stress Test
Describe your AI deployment.
Get an accountability analysis.
The SRF Stress Test takes a plain-language description of your AI scenario (the model, platform, deployment model, and use case) and returns a layered accountability breakdown, gap analysis, and risk flags in seconds. Powered by GPT-4o mini.
Try the SRF Stress Test →How the SRF complements what you already use
Other frameworks define what. SRF assigns accountability.
The SRF sits alongside your existing frameworks and assigns one accountable party per activity. NIST AI RMF defines what governance outcomes to achieve. ISO/IEC 42001 defines how to manage AI within your organization. EU AI Act defines which regulatory obligations apply by risk tier. None assigns who holds accountability when an incident crosses vendor boundaries.
-
NIST AI RMF → CoSAI SRF
What to achieve → Who achieves itNIST AI RMF defines the governance outcomes to achieve: Govern, Map, Measure, Manage. SRF adds which party in a multi-vendor deployment is accountable for each outcome.
-
EU AI Act → CoSAI SRF
Which obligations apply → Who at which layerThe EU AI Act defines which regulatory obligations apply by risk tier. SRF maps those obligations to specific layers and operating models: the implementation detail the regulation intentionally leaves to practitioners.
-
ISO 42001 → CoSAI SRF
How to manage AI → Who manages which partISO/IEC 42001 defines how to manage AI within a single organization's boundary. SRF provides the multi-party accountability model that 42001's Clause 5 and 6 require but leave undefined for cloud AI deployments.
Five layers. One accountable party each.
Governance requirements cascade from L1 downward. Each layer has exactly one accountable party, shifting with your operating model.
Accountability shifts by operating model. In AI-SaaS, the provider owns L3–L5. In IaaS, you own everything. See the full operating model matrix → How this applies across the AI security lifecycle →
Interactive tools
Browser-based. No account. Nothing leaves your device.
Nine assessment tools built on the framework. State saves in your browser and exports as JSON or PDF.
-
Accountability Decision Record
Name one accountable party per layer for a specific deployment, flag residual gaps, and export a signed one-page record.
-
SRF Stress Test
Describe any AI deployment scenario and get a layered accountability analysis, gap flags, and risk summary.
-
Layer Integration Matrix
Who owns what across all four operating models and five layers.
-
Controls Assessment (AICM)
243 CSA AICM controls mapped to SRF layers, with MITRE ATLAS technique crosswalk.
-
AI Security Controls
Layer-by-layer security controls with OWASP LLM Top 10 and ATLAS adversarial threat mapping.
-
AI Regulation Discovery
Filter regulations and standards by industry, geography, and SRF layer. Export a custom reference set.
-
AI Policy Pyramid
Map governance documents to the SRF layer hierarchy and identify gaps in policy coverage.
-
Official System Prompts
Canonical SRF system instructions for LLMs and AI assistants.
-
SRF Schema Viewer
Browse layers, operating models, and accountability assignments as structured data.
For LLMs & agents
Built to be read by machines, not just people.
The whole framework is published as plain text, JSON, and a concept graph with stable IDs. Point an agent at any of these to ground it in the SRF.
-
Site index for LLMs
A concise, linked map of the framework, verticals, tools, and data. The place to start an agent.
-
Whole site, one file
Full site content as a single text file for retrieval and bulk ingestion.
-
Machine-readable data
Every control schema, layer, persona, and responsibility matrix as static JSON.
-
Knowledge graph
Concept nodes and typed edges for layers, personas, operating models, controls, and mapped standards.
-
SRF Schema Viewer
Browse layers, operating models, and accountability assignments as structured data.
-
Retrieval validation
Simulate RAG ingestion against the knowledge pack. Returns matched chunks, concept hits, and a confidence score.
-
GRC matrix export
The accountability matrix as an OSCAL 1.1.2 catalog and a flat CSV for GRC and spreadsheet tools.