Flagship Platform · Powered by GGF
Most consultants sell you one certification at a time. We built a single framework — the Gnaan Governance Framework (GGF) — that sits above ISO/IEC 42001, the EU AI Act, NIST AI RMF, SOC 2, ISO/IEC 27001 and CMMI, and AuditSense is the platform that operates it: one evidence base, characterised once, mapped everywhere it's required.
The Premise
Treat every standard as its own project and you collect the same evidence five times, under five different names, on five different timelines. Buy a compliance-automation tracker instead and you get a completeness bar with nothing behind it. Neither survives contact with an actual auditor. GGF exists to fix the first problem. AuditSense exists to enforce the second.
The Framework
GGF is Gnaan AI's own unified governance framework — nine domains covering accountability and mandate, AI and data system inventory, training data, model risk, runtime enforcement, provider-held security and assurance. It sits above ISO/IEC 42001, the EU AI Act, NIST AI RMF, SOC 2, ISO/IEC 27001 and CMMI, so a single assessment produces evidence positioned for every one of them at once. This is what AuditSense actually is: the platform GGF runs on. Nothing in this section is a claim about any single standard — it's the layer above all of them.
GGF issues no certificate, no rating and no score. It issues an attestation of evidence: a statement that governance evidence has been examined and mapped to the requirements of the frameworks in scope.
What It Does
AuditSense runs GGF's evidence model directly — the same vocabulary our assessors use, not a paraphrase of it. Every control lands in one of five states, backed by evidence a third party can inspect without reassembling it.
Every control in AuditSense lands in exactly one status — the same five GGF defines for a human assessor.
Framework Coverage
Every GGF domain is mapped to the frameworks below with a stated coverage type — Full, Partial or Contributes. A requirement is only ever reported as covered where every mapping to it is Full and every contributing control is Evidenced.
Framework
What GGF Maps
Deliverable
Accountability, inventory, risk & impact assessment, and assurance domains mapped clause by clause against Annex A controls.
Certification Readiness Annex + evidence pack, structured for Stage 1 & 2 with the certification body.
Risk-tiering, human oversight, transparency and logging domains mapped to the Act's requirements, with procedural items outside GGF's reach listed as framework deltas.
Certification Readiness Annex naming exactly what's covered — and what the organisation must still address itself.
Accountability, inventory and assurance domains mapped directly onto the four RMF functions.
Readiness Annex usable standalone or alongside an ISO 42001 engagement.
Provider-held security and runtime-enforcement domains shared with SOC 2 trust criteria and ISO 27001 Annex A, via the compensating-route model for controls a provider holds.
Shared evidence base — nothing re-collected for a second audit.
Where AI governance and process-maturity controls overlap, GGF's assurance and accountability domains feed directly into CMMI's PIIDs evidence model.
Complementary evidence for a parallel or sequenced CMMI appraisal.
The Journey
GGF defines the sequence; AuditSense runs it. Each class has its own purpose, depth and independence requirement — and any class can be taken on its own.
Why AuditSense
No other consultancy runs a single proprietary framework above ISO 42001, EU AI Act, NIST AI RMF, SOC 2, ISO 27001 and CMMI. GGF is why one evidence base satisfies all of them.
A second assessor working from the same evidence reaches the same characterisation. Where that isn't true, the rule is underspecified and gets fixed — not left to judgement.
An assessor who implemented a control is blocked from attesting it — a platform rule in AuditSense, led by PECB-certified ISO/IEC 42001 Senior Lead Auditors.
Field Notes
Book a complimentary 45-minute AI Governance Readiness Assessment with our Senior Lead Auditor team.