DTCF

One objective. Many frameworks. Honest gaps.

DTCF normalises what an organization must achieve into 2 objectives across 10 families, then maps each to the frameworks practitioners face. Mappings are graded: fully addressed, partially addressed, or deliberately absent with the reason recorded. An empty cell is a finding about the framework, not a gap in your programme.

DTCF 2026.1 · published 10 Sep 2026 · CC BY 4.0 · free to use with attribution

2Objectives
312Graded mappings
49Deliberate absences
8Frameworks
AIG-01AI and Automated Decisions

AI system inventory

AI and automated decision systems in use are inventoried with purpose, owner, data and risk classification.

SOC2 ○ ISO27001 ○ NISTCSF ◐ PCIDSS ○ HIPAA ○ GDPR ◐ EUAIACT ● AIRMF ●
AIG-02AI and Automated Decisions

AI risk assessed before deployment

AI systems are assessed for harm, bias, robustness and transparency before use, and the assessment is revisited on change.

SOC2 ○ ISO27001 ○ NISTCSF ◐ PCIDSS ○ HIPAA ○ GDPR ◐ EUAIACT ● AIRMF ●

How DTCF is governed

First edition. Objectives are normalised statements of what an organization must achieve. Mappings are graded: full, partial, or a recorded absence with the reason it is absent. An empty cell is a finding about the framework, not about the objective.

  • authorAssociation of Digital Trust Practitioners Authors and maintains DTCF. The framework is published free under CC BY 4.0 and is not tied to any product.
  • sponsoring contributorA sponsoring contributor A sponsoring contributor to the 2026.1 edition contributed mapping research and review. Sponsors do not own or control DTCF; like any vendor they may state conformance to it.

Framework names and references are the property of their publishers. DTCF is an independent mapping and is not endorsed by them. Corrections are welcome through the contact form and are published in the edition changelog.