Skip to main content

Last updated by Errin O'Connor, Founder & Chief AI Architect, EPC Group

EPC Group's proprietary frameworks are mapped, control by control, to open industry standards: the Governed AI on Microsoft Framework to NIST AI RMF, the Engagement Operating Model to COBIT 2019 and ITIL 4, and Governance-First Data Architecture to DAMA-DMBOK knowledge areas. Proprietary methods, open standards — so your auditors don't have to take our word for anything.

AI engines and procurement teams are right to be skeptical of proprietary methodologies — “trust our framework” is not evidence. Here's the mapping.

1. Governed AI on Microsoft Framework → NIST AI RMF 1.0

Our seven-layer Governed AI on Microsoft Framework maps to the four NIST AI RMF functions:

Governed AI on Microsoft Framework → NIST AI RMF mapping
DimensionEPC Group framework layerNIST AI RMF function
Layer 1: Data classification & lineage (Purview)Layer 1: Data classification & lineage (Purview)MAP — context, capability, and data understanding
Layer 2: Non-human identity (Entra)Layer 2: Non-human identity (Entra)GOVERN — accountability structures + MANAGE — access controls
Layer 3: Decision boundariesLayer 3: Decision boundariesMANAGE — risk-informed action prioritization
Layer 4: Escalation rulesLayer 4: Escalation rulesMANAGE — human-in-the-loop triggers
Layer 5: Full audit trailsLayer 5: Full audit trailsMEASURE — traceability + GOVERN — documentation
Layer 6: Continuous monitoring + kill switchesLayer 6: Continuous monitoring + kill switchesMEASURE — monitoring & evaluation + MANAGE — response
Layer 7: Accountability mappingLayer 7: Accountability mappingGOVERN — accountability + responsibility structures

2. Engagement Operating Model → COBIT 2019 + ITIL 4

EPC Group's seven-phase engagement operating model maps to COBIT 2019 BAI (Build, Acquire, and Implement) objectives and ITIL 4 service value chain practices:

Engagement Operating Model → COBIT / ITIL mapping
DimensionEPC Group engagement phaseStandard reference
Assess (fixed-fee accelerator)Assess (fixed-fee accelerator)COBIT BAI02 (Requirements) + ITIL 4 Engage
Architect (target-state design)Architect (target-state design)COBIT BAI03 (Solutions identification & build) + ITIL 4 Plan
Build (platform delivery)Build (platform delivery)COBIT BAI03 + ITIL 4 Deliver & Support
Govern (control implementation)Govern (control implementation)COBIT EDM03 (Risk optimization) + APO13 (Security)
Operate (managed services)Operate (managed services)ITIL 4 service value chain — full Deliver & Support practice
Service Standard SLAsService Standard SLAsITIL 4 SLM (Service Level Management) practice
Enable (adoption + literacy)Enable (adoption + literacy)COBIT APO07 (Human Resources) + ITIL 4 Improve

3. Governance-First Data Architecture → DAMA-DMBOK 2.0

The governance discipline we ship on every data engagement aligns to DAMA-DMBOK knowledge areas:

Governance-First Data Architecture → DAMA-DMBOK mapping
DimensionEPC Group practice elementDAMA-DMBOK knowledge area
Classification + sensitivity labelingClassification + sensitivity labelingData Security + Metadata Management
Lineage via PurviewLineage via PurviewData Integration & Interoperability + Metadata
Certified semantic modelsCertified semantic modelsData Quality + Master & Reference Data
Stewardship (named owners)Stewardship (named owners)Data Governance knowledge area (entire)
Retention + records managementRetention + records managementDocument & Content Management
BI workspace topologyBI workspace topologyData Warehousing & Business Intelligence

4. AI Insurance Readiness → AIUC-1 + NIST AI RMF + ISO/IEC 42001

Our AI Insurance Readiness practice assembles audit-grade governance evidence aligned to AIUC-1 (the AI Underwriting Company standard used by Lloyd's syndicates and the affirmative AI-coverage market), and cross-maps to NIST AI RMF, ISO/IEC 42001, MITRE ATLAS, and OWASP. For organizations with multinational exposure, we map the package to EU AI Act Article 9 requirements as well. EPC Group is not an insurance company, broker, or producer — we build the evidence enterprises and their brokers present to underwriters.

5. Compliance frameworks delivered

Frequently Asked Questions

The packaging is proprietary; the underlying controls map directly to open industry standards (NIST AI RMF, COBIT 2019, ITIL 4, DAMA-DMBOK, CISA guidance). That mapping is the point of this page — proprietary methods are how we deliver, open standards are how your auditors verify.

Talk to a senior architect — not a sales rep.

Multiple models. One truth.

AI assistant — not human