NIST AI Risk Management Framework 1.0 (AI 100-1), checked from the code up.
Findings arrive already citing the clause they touch, so nobody has to translate a rule id into an obligation before the work can start.
Rules, not a questionnaire.
Values are followed across functions and files, so a finding is a real path from a real field to a real sink, not a keyword match.
Each rule names the clause it answers to. Where a mapping is partial or advisory, the page says so rather than implying certainty.
Nothing about this framework changes how the scan runs. Selecting it changes which obligations the same findings are reported against.
Code answers some obligations. Not all of them.
Every framework contains duties that are organisational rather than technical: appointing people, training them, keeping minutes, running assessments. No scanner can evidence those, and one that implies it can is selling you a false sense of finishing. What this covers is the part written in your software, which is the part nobody else can see.
Others in the same family.
Scan against NIST AI RMF.
Or run the container on your own runner. The scan happens in your pipeline and the source never reaches us.