Skip to content
    Back to Regulatory Radar
    ImportantFramework UpdateOctober 10, 2023

    HITRUST CSF v11.2 Released with AI Risk Management Sources

    HITRUST released CSF v11.2.0 on October 10, 2023, adding NIST AI RMF v1.0, ISO/IEC 23894, and ISO 31000 as authoritative sources together with a new selectable Artificial Intelligence Risk Management compliance factor. The release also added ISO 27001:2022 and ISO 27002:2022, the Ontario Personal Health Information Protection Act, and VA Directive 6500 as sources, refreshed mappings for 23 NYCRR 500, the FTC Red Flags Rule, and Nevada Title 52 603A, and began an initial wave of requirement statement consolidation to reduce overlap within the CSF.

    HITRUSTNIST CSFHIPAAHealthcareSaaSFinTech

    Key Analytics

    October 10, 2023
    Event Date
    Time Remaining
    August 24, 2026
    Last Verified
    3
    Frameworks Affected

    Impact Analysis

    The Artificial Intelligence Risk Management compliance factor gave organizations a way to incorporate AI governance requirements based on NIST AI RMF and ISO guidance into HITRUST assessments, an early formal AI assurance option among major certification frameworks. The ISO 27001:2022 and 27002:2022 mappings helped organizations pursuing both certifications align evidence to the current ISO revision. Requirement statement consolidation reduced duplicated assessment effort, and the refreshed state and sector mappings kept regulatory factor selections current for covered organizations.

    Recommended Actions

    • Determine whether the Artificial Intelligence Risk Management compliance factor applies to in-scope systems and select it in MyCSF where relevant
    • Map existing ISO 27001:2022 and 27002:2022 evidence against the updated CSF authoritative source mappings
    • Review consolidated requirement statements when creating new assessment objects on v11.2 to avoid documenting against retired duplicates

    Always verify requirements with official regulatory sources.

    Estimated Remediation Effort

    Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.

    A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.

    Analyst estimate
    Moderate45-100 hours
    Key Workstreams
    • Remap ISO 27001:2022 and 27002:2022 evidence to the updated authoritative sources
    • Select and scope the AI Risk Management factor in MyCSF where relevant
    • Rework assessment objects onto consolidated requirement statements

    The Cost of Waiting

    Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.

    Start preparing nowModerate · 45-100 hours
    Start cold under pressureSignificant · 110-240 hours

    Roughly 65 to 140 hours avoided by preparing early

    Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.

    Related Events