Control Frameworks
Frameworks are the control libraries your assessments map onto. Backsplice ships built-in framework packs, and you can add your own custom frameworks.
The built-in packs today are NIST AI RMF 1.0 (the NIST AI Risk Management Framework) and NIST AI 600-1, the Generative AI Profile. Every question in the question bank belongs to a pack and maps to that pack's controls, so an assessment reports against the packs it covers. The Generative AI Profile's system questions are asked only of AI systems marked as using generative AI.
Every pack is included in Premium and Enterprise, and in the demo. There
is no limit on how many packs an assessment can cover. Custom frameworks are
included on both plans and in the demo too.
Built-in vs. custom
Built-in frameworks come pre-populated with their controls and are read-only: you can scope them into an assessment but not edit them. Custom frameworks are yours to build: create one with a name, description, source, and version, then add controls to it (each has a reference like AC-1, a title, an optional category, and a required flag). Mark a framework active to make it available for scoping; deactivate one you're not using.
How frameworks are used
Frameworks don't do anything on their own. You put them to work by scoping them into an assessment: pick the frameworks the assessment reports against when you create it. If you leave a pack out, the questions that belong only to it can be marked N/A with a recorded justification once you confirm the scope, and you can change that later. (See Assessments for scoping, and Cross-Framework Coverage for the AI that suggests where one answer satisfies controls in other frameworks.)
Who can do what
The Frameworks page (browsing the built-in libraries and managing your own: create, edit, add/remove controls, activate) is for org admins. Every member still sees the frameworks an assessment is scoped to, inside that assessment. A custom framework belongs to your organization and can be deleted by an admin.