Sourced comparison, not a ranking
Vendor Framework Alignment Matrix
Which vendors in Model Governance Index's reference set explicitly state, in their own published materials, that their methodology or platform is aligned to a specific named framework. A checkmark means the vendor itself makes that claim publicly, with a source cited on their profile - it is not this index's independent assessment of whether the alignment is complete or accurate, and it is not a ranking.
How to read this. A dash does not mean a vendor lacks that capability - it means our research did not find an explicit public statement of alignment for that framework as of the date on their profile. Many vendors likely support frameworks they simply haven't published a formal alignment statement for. Verify directly with any vendor before relying on this for a procurement decision.
| Vendor | NIST AI RMF | ISO 42001 | EU AI Act | IIA AI Auditing Framework | Three Lines Model |
|---|---|---|---|---|---|
| Holistic AI | ✓ | ✓ | ✓ | — | — |
| IBM watsonx.governance | — | — | ✓ | — | — |
| KPMG | ✓ | ✓ | ✓ | — | — |
| OneTrust | ✓ | ✓ | ✓ | — | — |
| Saidot | ✓ | ✓ | ✓ | — | — |
| Trustible | ✓ | ✓ | ✓ | — | — |
Source for each checkmark: see the "Sources" section on the linked vendor's own profile page.
Vendors without a found public alignment statement
These 14 vendors are real and referenced elsewhere on this site, but our research did not find an explicit, sourced public statement tying their methodology to one of the 5 named frameworks above. This is a research gap, not a claim about their actual capability.
Need help mapping your program to a specific framework? See the frameworks reference, or request AI governance consultants directly.
Browse frameworks →Request consultants