Skip to content
Appendices

Appendix A. Standards mapping

This appendix is the crosswalk auditors and compliance reviewers reach for first. Each BAGF section maps to the closest equivalent control in ISO/IEC 42001:2023, function or category in the NIST AI Risk Management Framework 1.0, article of the EU AI Act (Regulation (EU) 2024/1689), entry of the OWASP Top 10 for LLM Applications, and article of Vietnam’s Decree 13/2023/NĐ-CP. Where a column has no direct correspondence we use a dash. That means no specific clause maps cleanly, not that the topic is unaddressed by the standard.

BAGF §Bizzi controlISO/IEC 42001NIST AI RMFEU AI ActOWASP LLMDecree 13/2023
I.1Business alignmentA.5.2GOVERN-1.1Art. 9..
I.2Governance model (hub-and-spoke)A.6.1GOVERN-1.2...
I.3Governance oversightA.5.1, A.6.1GOVERN-2Art. 17..
I.4Guiding valuesA.5.2GOVERN-3...
I.5StrategyA.5.2GOVERN-1, GOVERN-4...
I.6Roles and responsibilities (RACI)A.6GOVERN-1, GOVERN-2...
I.7Policies, standards, proceduresA.5.2, A.6.2GOVERN-1...
I.8AI risk management. six-stepA.8MAP, MEASURE, MANAGEArt. 9..
I.9Continuous monitoringA.8.3MEASURE-3Art. 15..
I.10Internal audit and red-teamA.9, A.10MANAGE-4...
I.11Incident managementA.8.4MANAGE-4..Art. 23
I.12KPIs and monitoringA.8.3MEASURE-2, MEASURE-3...
I.13ReportingA.8.3, A.9GOVERN-4, MEASURE-4...
BAGF §Bizzi controlISO/IEC 42001NIST AI RMFEU AI ActOWASP LLMDecree 13/2023
II.1Regulatory landscapeA.5.4GOVERN-1.6Art. 6, 9.entire decree
II.2Legal considerations assessmentA.5.4GOVERN-1.6Art. 9.Art. 22
II.3Data protection (Decree 13 PII redaction)A.7.2MAP-2Art. 10LLM06Art. 4–19
II.4Data residencyA.7.4MAP-2..Art. 24, 25
II.5Liability and risk distributionA.6.3GOVERN-2Art. 14.Art. 19
II.6Vendor risk and zero data retentionA.7.4GOVERN-6.LLM05, LLM10.
II.7Intellectual property and output ownershipA.7.5....
II.8DPIA / ROPAA.6.2GOVERN-1.6..Art. 21, 22
II.9Legal safeguardsA.6.3GOVERN-6..Art. 23
II.10Ongoing auditsA.9MANAGE-4..Art. 21, 22
II.11Emerging trendsA.10.2GOVERN-1.6Art. 6..

Pillar III: Ethics, transparency, and explainability

Section titled “Pillar III: Ethics, transparency, and explainability”
BAGF §Bizzi controlISO/IEC 42001NIST AI RMFEU AI ActOWASP LLMDecree 13/2023
III.1AccountabilityA.6.2GOVERN-2.1Art. 13..
III.2Fairness and bias auditA.7.3MAP-1, MEASURE-2.11Art. 10..
III.3Human-centricity (HITL / HOTL)A.6.2MAP-3.4Art. 14LLM09Art. 19
III.4Inclusivity (WCAG)A.7.3MAP-1Art. 14..
III.5Cultural norms (Vietnam context)A.7.3MAP-1.6...
III.6Transparency in development (model and data cards)A.6.2, A.7.1GOVERN-1.4Art. 11..
III.7Transparency in operations (confidence)A.7.1MEASURE-3Art. 13, 50..
III.8Transparency in serving (explanation API)A.6.2GOVERN-4Art. 13..
III.9Trade-offsA.7.3MAP-1.2Art. 13..
III.10Grounded reasoningA.7.3, A.8.2MEASURE-2Art. 13..
III.11Traceability and audit trailA.6.2, A.8.4MEASURE-3, MANAGE-4Art. 12..
III.12Right to explanationA.6.2GOVERN-4Art. 86.Art. 14, 19

Pillar IV: Data, AIOps, and infrastructure

Section titled “Pillar IV: Data, AIOps, and infrastructure”
BAGF §Bizzi controlISO/IEC 42001NIST AI RMFEU AI ActOWASP LLMDecree 13/2023
IV.1Data systems architectureA.7.2, A.7.4MAP-2...
IV.2Data classificationA.7.2MAP-2.3..Art. 7
IV.3Data handling (encryption, retention, DSAR)A.7.2MAP-2..Art. 7–14
IV.4Data qualityA.7.2, A.7.3MAP-2, MEASURE-2.6Art. 10LLM03.
IV.5ADLC overviewA.8MEASURE-2, MANAGE-2Art. 9, 17..
IV.6ADLC stage 1. designA.8.1, A.6.2MAP-2.3Art. 11..
IV.7ADLC stage 2. evaluation (LLM-as-judge)A.8.2, A.9MEASURE-2.5Art. 15..
IV.8ADLC stage 3. testing (A/B and shadow)A.8.1, A.8.2MEASURE-2, MEASURE-4Art. 17..
IV.9ADLC stage 4. deployment (AI gateway)A.8.1, A.8.4MANAGE-2.4Art. 15LLM05.
IV.10ADLC stage 5. monitoring (drift)A.8.3, A.10MEASURE-3, MANAGE-2.4Art. 15..
IV.11Multi-agent architectureA.8MAP-3, MEASURE-2Art. 9, 15LLM08.
IV.12Model Context Protocol (MCP)A.7.4, A.8.1MAP-3.4, MEASURE-2.7.LLM06, LLM07, LLM08.
IV.13Agentic state managementA.8.1, A.8.4MEASURE-2.7, MANAGE-2.LLM04, LLM08.
IV.14Agentic observabilityA.6.2, A.8.3MEASURE-3, MEASURE-4Art. 12..
BAGF §Bizzi controlISO/IEC 42001NIST AI RMFEU AI ActOWASP LLMDecree 13/2023
V.1Threat modelA.7.1MAP-1, MEASURE-1Art. 9LLM01–10.
V.2OWASP LLM mappingA.7.4MAP, MEASURE.LLM01–10.
V.3Prompt injectionA.8.4MEASURE-2.7, MANAGE-2.4Art. 15LLM01.
V.4Training data poisoningA.7.2, A.8.1MAP-2.2, MEASURE-2.10Art. 10LLM03.
V.5Data catalog and lineageA.7.2MAP-2.2, MEASURE-2.LLM03, LLM05.
V.6Model management securityA.8.1, A.7.4..LLM05, LLM10.
V.7Sensitive information disclosureA.7.2..LLM06Art. 4, 7
V.8Output handlingA.8.2..LLM02.
V.9Agent RBACA.6.2, A.8.1MAP-3.4, MANAGE-2.LLM07, LLM08.
V.10Rate limiting / denial of walletA.8.4..LLM04.
V.11Kill-switchA.8.4MANAGE-4.LLM04.
V.12Incident responseA.8.4MANAGE-3, MANAGE-4..Art. 23
V.13Platform security (ISMS)A.7. A.8GOVERN, MANAGE...
  • A dash marks the absence of a direct mapping. The topic might still be addressed by the standard at a higher level of abstraction. No specific article or control corresponds.
  • ISO/IEC 42001 references follow the 2023 edition.
  • EU AI Act references follow Regulation (EU) 2024/1689.
  • NIST AI RMF references follow version 1.0 (January 2023).
  • OWASP Top 10 for LLM Applications references follow the current edition (updated annually).
  • Decree 13/2023 references follow Decree 13/2023/NĐ-CP, in force from 1 July 2023.