Flagship Platform · Powered by GGF

AuditSense: The Platform Behind the Gnaan Governance Framework

Most consultants sell you one certification at a time. We built a single framework — the Gnaan Governance Framework (GGF) — that sits above ISO/IEC 42001, the EU AI Act, NIST AI RMF, SOC 2, ISO/IEC 27001 and CMMI, and AuditSense is the platform that operates it: one evidence base, characterised once, mapped everywhere it's required.

The Premise

A framework problem needs a framework, not a checklist

Treat every standard as its own project and you collect the same evidence five times, under five different names, on five different timelines. Buy a compliance-automation tracker instead and you get a completeness bar with nothing behind it. Neither survives contact with an actual auditor. GGF exists to fix the first problem. AuditSense exists to enforce the second.

01
One evidence item, six frameworks
GGF's controls are mapped to ISO/IEC 42001, the EU AI Act, NIST AI RMF, SOC 2, ISO/IEC 27001 and CMMI. Collect it once under GGF; it's already positioned for every framework it touches.
02
The strictest requirement wins
Where frameworks disagree on what a control needs, GGF sets the evidence bar at the most demanding of them. That's what makes one evidence base portable across all of them.
03
AuditSense is where it runs
AuditSense enforces GGF's evidence rules continuously, so the record is current by construction — not reconstructed the week before an audit.

The Framework

The Gnaan Governance Framework (GGF)

GGF is Gnaan AI's own unified governance framework — nine domains covering accountability and mandate, AI and data system inventory, training data, model risk, runtime enforcement, provider-held security and assurance. It sits above ISO/IEC 42001, the EU AI Act, NIST AI RMF, SOC 2, ISO/IEC 27001 and CMMI, so a single assessment produces evidence positioned for every one of them at once. This is what AuditSense actually is: the platform GGF runs on. Nothing in this section is a claim about any single standard — it's the layer above all of them.

The principles that make it defensible

  • Evidence over assertion. No control is recorded as satisfied on the strength of a statement. The organisation's account of its governance is the starting point for examination, not its conclusion.
  • Strictest consumer. Where frameworks in scope differ on what a control requires, the most demanding requirement sets the bar for all of them — the property that makes one evidence base portable.
  • Operation, not only design. A policy proves a control was designed. Only evidence drawn across a period proves it operated. GGF distinguishes the two throughout.
  • Facts, not grades. Every output records facts about evidence. Nothing issued to a third party scores, grades or ranks the organisation.
  • Independence. The individual who implemented a control may not attest it — enforced in AuditSense, not left to judgement.

Attestation, not certification

GGF issues no certificate, no rating and no score. It issues an attestation of evidence: a statement that governance evidence has been examined and mapped to the requirements of the frameworks in scope.

  • What GGF never claims: that you will obtain any certification, that a certifying body will accept the evidence, or that you conform to any external standard.
  • What GGF does claim: the evidence exists, meets a stated sufficiency bar, and is mapped to identified requirements — a narrower, more defensible statement than most vendors make.
  • Acceptance for certification, audit or regulatory purposes always remains a matter for the body concerned. That boundary is written into the attestation itself.

What It Does

Evidence, characterised the same rigorous way, every time

AuditSense runs GGF's evidence model directly — the same vocabulary our assessors use, not a paraphrase of it. Every control lands in one of five states, backed by evidence a third party can inspect without reassembling it.

Evidence & capabilities

  • Living AI & data system inventory — every model, dataset, vendor and shadow-AI instance, classified by operator role, risk tier and system class, in one register that never goes stale.
  • Three evidence types, weighted correctly — direct artefacts (the control's own output), indirect artefacts (by-products implying it operated) and affirmation. No direct artefact, no evidenced status — no exceptions.
  • Cross-framework control mapping — every GGF domain maps to ISO/IEC 42001, the EU AI Act, NIST AI RMF, SOC 2, ISO/IEC 27001 and CMMI, so nothing is collected twice.
  • Sampling & currency enforced, not assumed — minimum sample sizes by population, evidence expiry by validity period, all disclosed rather than hidden in a footnote.
  • Nonconformity & remediation tracking — every gap statement has an owner, a due date and a closure trail a certification body can follow.

Five control statuses. No sixth for wishful thinking.

Every control in AuditSense lands in exactly one status — the same five GGF defines for a human assessor.

  • Evidenced — direct artefact present, sufficiency met, operation demonstrated where claimed.
  • Evidenced (compensating) — satisfied through a defined compensating route where a third party holds the control.
  • Partially evidenced — an artefact exists, but sufficiency, period or sample is incomplete; the deficiency is stated.
  • Not evidenced — no sufficient direct artefact. Recorded, not hidden.
  • Not applicable — excluded by scope, role, tier or class, with the justification on record.

Framework Coverage

One GGF evidence base. A Readiness Annex for each framework.

Every GGF domain is mapped to the frameworks below with a stated coverage type — Full, Partial or Contributes. A requirement is only ever reported as covered where every mapping to it is Full and every contributing control is Evidenced.

Framework

What GGF Maps

Deliverable

GGF → ISO 42001
AI Management System (AIMS)

Accountability, inventory, risk & impact assessment, and assurance domains mapped clause by clause against Annex A controls.

Certification Readiness Annex + evidence pack, structured for Stage 1 & 2 with the certification body.

GGF → EU AI Act
Risk classification & technical documentation

Risk-tiering, human oversight, transparency and logging domains mapped to the Act's requirements, with procedural items outside GGF's reach listed as framework deltas.

Certification Readiness Annex naming exactly what's covered — and what the organisation must still address itself.

GGF → NIST AI RMF
Govern, Map, Measure, Manage

Accountability, inventory and assurance domains mapped directly onto the four RMF functions.

Readiness Annex usable standalone or alongside an ISO 42001 engagement.

GGF → SOC 2 / ISO 27001
Security & runtime enforcement

Provider-held security and runtime-enforcement domains shared with SOC 2 trust criteria and ISO 27001 Annex A, via the compensating-route model for controls a provider holds.

Shared evidence base — nothing re-collected for a second audit.

GGF → CMMI
Process & organisational maturity

Where AI governance and process-maturity controls overlap, GGF's assurance and accountability domains feed directly into CMMI's PIIDs evidence model.

Complementary evidence for a parallel or sequenced CMMI appraisal.

The Journey

Three GGF engagement classes. Progress at your own pace.

GGF defines the sequence; AuditSense runs it. Each class has its own purpose, depth and independence requirement — and any class can be taken on its own.

1
Weeks 1–4 · Discovery
Identify Gaps & Set Direction
One assessor, sampled evidence. Output: a gap report and remediation roadmap — no attestation issued.
2
Weeks 5–10 · Readiness Review
Test Readiness Before the Real Thing
Full method, single pass. Output: provisional Certification Readiness Annexes — for the organisation's own use, marked provisional.
3
Weeks 11–22 · Attestation
Independent, Corroborated, Issued
Lead assessor plus at least one further assessor, full evidence corroborated over the review period. Output: Assessment Result, final Certification Readiness Annexes, evidence pack and the attestation statement.
4
Ongoing · Surveillance
Two-Year Validity, Annual Check
Every Partially Evidenced and higher-risk-tier control re-examined annually, so the evidence base never goes stale between attestations.

Why AuditSense

GGF is the differentiator. AuditSense is why it holds up.

One framework, not five projects

No other consultancy runs a single proprietary framework above ISO 42001, EU AI Act, NIST AI RMF, SOC 2, ISO 27001 and CMMI. GGF is why one evidence base satisfies all of them.

Reproducible, not a matter of opinion

A second assessor working from the same evidence reaches the same characterisation. Where that isn't true, the rule is underspecified and gets fixed — not left to judgement.

Independence enforced, not promised

An assessor who implemented a control is blocked from attesting it — a platform rule in AuditSense, led by PECB-certified ISO/IEC 42001 Senior Lead Auditors.

Field Notes

More on governing AI

See your evidence base before an auditor does.

Book a complimentary 45-minute AI Governance Readiness Assessment with our Senior Lead Auditor team.

contact@gnaan.ai +91 6282 552 995