Implement once, comply many
UACAF, the Unified AI Compliance and Assurance Framework, is one set of 110 AI controls that answers a hard question: how do you know your AI is compliant?
Created by Dr. Abe Okomanyi, Second Key Security.
The problem
Ask five people in your organization how you know your AI is compliant, and you will probably get five answers.
Compliance points to the AI policy. Legal points to its EU AI Act analysis. Privacy mentions the impact assessment. Security talks about red teaming. Product says the vendor has a SOC 2 report. Each answer is partly right, and none is complete.
The obligations arrive from every direction at once, each in its own vocabulary:
- Horizontal AI laws: the EU AI Act, Colorado and Texas.
- Privacy regulators: for example, California's automated decision-making rules.
- Sector supervisors: model risk, fair lending and employment.
- Public-sector mandates: the OMB memoranda.
- Voluntary standards: NIST and ISO.
- Security communities: CSA and OWASP.
Teams run duplicate assessments, gaps open between functions, and nobody has a single, evidence-backed answer for the board, a regulator or a customer.
What it is
One harmonized set of 110 AI controls, organized into 18 domains.
Each control is mapped to NIST AI RMF and its GenAI Profile, ISO/IEC 42001, the EU AI Act as amended by the 2026 Digital Omnibus, the CSA AI Controls Matrix, and the OWASP Top 10 lists for LLM and agentic applications. It also maps to US federal, state and sector requirements.
Because every control maps to several of them, one piece of evidence can satisfy several obligations. Each control also names its owner, the evidence that proves it works, and how to test it.
A framework document
The governance model, roles, the risk-tiering method, lifecycle gates, the full control catalog, playbooks, sector and public-sector overlays, an assurance program and a roadmap.
A working control matrix
A filterable catalog, a risk-tiering calculator, an assessment tracker that works out which controls apply to each system, a dashboard, a regulatory timeline and a vendor due-diligence questionnaire.
Use, develop, embed
Every control is tagged to the ways an organization works with AI.
Use
You adopt AI built by others: assistants, copilots and AI features inside the tools you already run.
Develop
You build, train, fine-tune or configure AI yourself, including RAG applications and agents.
Embed
You deliver AI to customers inside your own products and services.
A company that only uses vendor AI sees a much smaller set of controls than one that ships AI features to customers.
Rigor scales with risk
Low-risk uses are not weighed down with high-risk requirements.
Baseline
Applies to every AI system: ownership, inventory, acceptable use, security basics, disclosure and monitoring.
Enhanced
Adds deeper assessment, documentation, testing and oversight for elevated-risk systems.
High
Applies only where AI makes or shapes consequential decisions about people, such as credit, employment, housing, insurance or healthcare.
Agentic AI is a domain of its own
Agents plan, use tools, hold memory and act with delegated authority, so a model error can become a real action.
UACAF gives agents their own domain of controls:
- Limits on what each agent may do and touch
- Human approval for consequential actions
- An identity and credentials for each agent
- Governance of tools and MCP servers
- Memory integrity and sandboxing
- A kill switch
Laws are overlays
The core stays stable while the law keeps changing.
UACAF anchors its controls to durable standards and treats each law as an overlay on top. When a deadline moves, the controls stay the same. Only the timeline and what applies to you change.
Where to start
- Stand up cross-functional AI governance with real decision rights.
- Build an AI inventory that includes AI features inside your SaaS tools and shadow AI.
- Tier every system and screen out prohibited uses.
- Close the transparency duties already in force: tell people when they are talking to AI, and mark synthetic content.
- Put AI clauses in vendor contracts, starting with no training on your data.
- Get high-risk systems ready for 2027: California ADMT and Colorado in January, EU Annex III in December.
See where you stand
The AI Governance Check scores your answers against UACAF in about 3 minutes, in your browser. The full framework is free on request, with the form below.
Request the full framework
All 110 controls, the crosswalks and the assessment workbook. We email it to you within one business day.
or email hello@secondkeysecurity.com
Thanks, we'll email you the full framework within one business day.
Created by Dr. Abe Okomanyi, Second Key Security. Not legal advice.