In partnership with

Speak naturally. Send without fixing.

Wispr Flow turns your voice into clean, professional text you can send the moment you stop talking. Not rough transcription you have to clean up. Actual polished text — ready for email, Slack, or any app.

Speak the way you think. Go on tangents. Change your mind mid-sentence. Flow strips the filler, fixes the grammar, and gives you text that reads like you spent five minutes writing it.

89% of messages sent with zero edits. Millions of professionals use Flow daily, including teams at OpenAI, Vercel, and Clay. Works on Mac, Windows, and iPhone.

Each edition of AI In Its Place delivers one clear, evidence-backed idea you can use. This week: the four frameworks everyone reaches for were graded against real LLM risk — and none of them scored well.

The Certificate That Covers Nothing

You bought the framework. You passed the audit. Then someone in accounting pasted a client contract into a chatbot.

Most organizations treat a GRC framework as a container that expands to hold whatever technology arrives next. That assumption held for cloud, and it mostly held for SaaS. It breaks with large language models, because LLMs generate content that looks authoritative and is sometimes wrong — a failure mode no control catalog was written to catch.

McIntosh et al. (2024) put that assumption to the test. They ran a structured content analysis of NIST CSF 2.0, COBIT 2019, ISO/IEC 27001:2022, and ISO/IEC 42001:2023, using both model-assisted coding and human expert validation, and scored each framework across three dimensions: how well it enables LLM adoption, how well it oversees LLM risk, and how closely it aligns with the EU AI Act.

What the Scoring Actually Showed

No framework cleared the bar.

ISO/IEC 42001:2023 came out ahead on enabling LLM use, which tracks with its design as an AI management system standard. COBIT 2019 aligned most closely with EU AI Act obligations. But the risk-oversight column is where the study gets uncomfortable: NIST CSF 2.0 scored 2 of 7 on LLM risk oversight, and ISO/IEC 42001:2023 — the AI standard — scored 4 of 7 (McIntosh et al., 2024).

The shared blind spot across all four was misleading content generation. Hallucination has no dedicated control in any of them. Neither does real-time bias in model output, nor LLM-specific incident response. The frameworks assume a system fails by breaking, leaking, or going offline. An LLM fails by confidently producing a plausible wrong answer that a human then acts on, and the control language simply has no hook for that.

The authors' conclusion is blunt: every framework evaluated, including the newest one built specifically for AI, needs enhancement before it can responsibly support LLM commercialization (McIntosh et al., 2024).

Where This Hits SMBs Hardest

Large enterprises absorb this gap with people. An enterprise reads the same finding, assigns a red-team function, writes supplemental controls, and moves on.

SMBs inherit the gap without the staff to patch it. Zaher (2025) found the strongest organizational predictor of AI governance maturity to be a dedicated responsible-AI team, followed by staff training investment and executive sponsorship — the exact three resources that are scarcest below a few hundred employees.

There's a second problem specific to smaller organizations: the certificate becomes the whole governance program. When ISO/IEC 42001 certification is the single most expensive compliance investment on the books, nobody wants to hear that it leaves hallucination oversight to the customer. That produces the worst posture available — real spend, documented controls, and an unmanaged failure mode sitting in daily workflows.

The Fix: Bolt On the Missing Control Layer

McIntosh et al. (2024) recommend human-expert-in-the-loop validation as the mechanism for closing the oversight gap. That is implementable without a governance department. Treat it as four supplemental controls layered on top of whatever framework you already run:

Classify by consequence, not by tool. For every LLM use case, ask what happens if the output is wrong and nobody catches it. Client deliverable, financial figure, security decision, or anything touching a regulated population goes in the high-consequence tier. Internal brainstorming does not.

Require a named verifier on high-consequence output. One person signs off that they checked the claims, not the grammar. Their name goes in the record. This is the human-in-the-loop control the study calls for, expressed as a job duty rather than a policy statement.

Log hallucinations as incidents. Your incident process already handles phishing and outages. Add a category for wrong AI output that reached a decision point. Three months of that log tells you exactly which use cases to restrict — evidence your framework will never generate on its own.

Write it into your Statement of Applicability. If you run ISO/IEC 42001 or 27001, document these as additional controls with your rationale. Auditors accept supplemental controls. They do not accept gaps you knew about and left open.

The value in this study isn't that the frameworks are bad. It's that they were graded, publicly, by researchers who published the scores — and the scores say your framework is a floor rather than a ceiling.

Pick the framework that fits your regulatory exposure, then spend the next quarter building the thin layer of human verification it doesn't give you.

Rhindon Cyber provides AI Governance education, basic tools for SMBs, and a SaaS application designed for SMBs up to 1,000 employees. Check out our new course on AI Risk Management for practitioners: https://learning.ai-in-its-place.com/courses/ai-risk-management

Rhindon Cyber AI Risk & Integrity Cloud (RAIC) AI Governance SaaS for SMBs: https://raic.rhindoncyber.com

References

International Organization for Standardization & International Electrotechnical Commission. (2023). Information technology — Artificial intelligence — Management system (ISO/IEC 42001:2023). https://www.iso.org/standard/42001

McIntosh, T. R., Susnjak, T., Liu, T., Watters, P., Xu, D., Liu, D., Nowrozy, R., & Halgamuge, M. N. (2024). From COBIT to ISO 42001: Evaluating cybersecurity frameworks for opportunities, risks, and regulatory compliance in commercializing large language models. Computers & Security, 144, 103964. https://doi.org/10.1016/j.cose.2024.103964

National Institute of Standards and Technology. (2024). The NIST Cybersecurity Framework (CSF) 2.0 (NIST CSWP 29). U.S. Department of Commerce. https://doi.org/10.6028/NIST.CSWP.29

Zaher, M. A. (2025). From principles to practice: A cross-sector assessment of responsible AI governance readiness. Financial Technology and Innovation, 5(1), 10–23. https://doi.org/10.54216/FinTech-I.050102