User defined requirements
The Studio captures the objective, use case, information sensitivity and priority of 17 requirement categories. A plan is assembled from these selections. It does not inspect a live system.
Five evidence states
Documented: a register item marked Supported includes a source description. Partially Documented: an item needs review. Not Documented: a source is missing or evidence is needed. Not Tested: testing is explicitly needed, or no accuracy, reliability or latency evidence is recorded. Not Applicable: the reviewer marks the requirement out of scope for that system.
Evidence selection
The most recently saved register item for a system and requirement determines that matrix cell. Older entries remain visible in the register. A later incomplete record can supersede an earlier supported claim, so review the register before deciding.
Coverage counts
Counts show documented and partially documented cells among active requirements. Not Applicable cells are displayed separately. Coverage is not evidence quality, real world performance or a recommendation. There is no overall winner.
Testing and sources
All seeded systems and evidence are fictional. User entered test results are reported as user recorded observations, not independently verified tests. No live AI APIs, automated benchmarks or source validation run here.
Principles and independence
The framework is informed by general risk management practice and the voluntary NIST AI Risk Management Framework. It is not a conformity assessment or certification. Vendor participation does not guarantee favorable treatment. Paid participation must never influence independent evidence presentation.