{
  "name": "Areebi AI Governance Framework Matrix",
  "description": "Clause-cited crosswalk of 12 AI governance frameworks across 15 governance dimensions.",
  "licence": "CC BY 4.0",
  "attribution": "Areebi AI Governance Framework Matrix - https://www.areebi.com/resources/ai-framework-matrix",
  "source": "https://www.areebi.com/resources/ai-framework-matrix",
  "cellCount": 180,
  "rows": [
    {
      "framework": "nist-ai-rmf",
      "frameworkName": "NIST AI Risk Management Framework 1.0",
      "frameworkType": "Voluntary",
      "jurisdiction": "United States (international reference)",
      "dimension": "governance",
      "dimensionLabel": "Governance + accountability",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "GOVERN-1 through GOVERN-6 require policies, roles, accountability structures, and board-level oversight for AI risk.",
      "clauseRef": "GOVERN 1.1-6.2",
      "sourceUrl": "https://www.nist.gov/itl/ai-risk-management-framework"
    },
    {
      "framework": "nist-ai-rmf",
      "frameworkName": "NIST AI Risk Management Framework 1.0",
      "frameworkType": "Voluntary",
      "jurisdiction": "United States (international reference)",
      "dimension": "risk-management",
      "dimensionLabel": "Risk management process",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "MAP, MEASURE, MANAGE functions are explicitly a risk-identification, measurement, and treatment lifecycle.",
      "clauseRef": "MAP 1.1-5.2; MEASURE 1.1-4.3; MANAGE 1.1-4.3",
      "sourceUrl": "https://www.nist.gov/itl/ai-risk-management-framework"
    },
    {
      "framework": "nist-ai-rmf",
      "frameworkName": "NIST AI Risk Management Framework 1.0",
      "frameworkType": "Voluntary",
      "jurisdiction": "United States (international reference)",
      "dimension": "data-handling",
      "dimensionLabel": "Data handling + minimisation",
      "coverage": 2,
      "coverageLabel": "Partial",
      "summary": "MAP-2 requires categorising data sources; MEASURE-2.10 requires evaluating privacy risks; no specific residency rules.",
      "clauseRef": "MAP 2.x; MEASURE 2.10",
      "sourceUrl": "https://www.nist.gov/itl/ai-risk-management-framework"
    },
    {
      "framework": "nist-ai-rmf",
      "frameworkName": "NIST AI Risk Management Framework 1.0",
      "frameworkType": "Voluntary",
      "jurisdiction": "United States (international reference)",
      "dimension": "model-lifecycle",
      "dimensionLabel": "Model lifecycle controls",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Full lifecycle is the framework: design (MAP), build and test (MEASURE), deploy and retire (MANAGE).",
      "clauseRef": "Entire framework",
      "sourceUrl": "https://www.nist.gov/itl/ai-risk-management-framework"
    },
    {
      "framework": "nist-ai-rmf",
      "frameworkName": "NIST AI Risk Management Framework 1.0",
      "frameworkType": "Voluntary",
      "jurisdiction": "United States (international reference)",
      "dimension": "transparency",
      "dimensionLabel": "Transparency + disclosure",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Transparent and accountable is a top-level characteristic; MEASURE-2.8 calls for transparency artifacts (model / system cards).",
      "clauseRef": "Section 3.5; MEASURE 2.8",
      "sourceUrl": "https://www.nist.gov/itl/ai-risk-management-framework"
    },
    {
      "framework": "nist-ai-rmf",
      "frameworkName": "NIST AI Risk Management Framework 1.0",
      "frameworkType": "Voluntary",
      "jurisdiction": "United States (international reference)",
      "dimension": "human-oversight",
      "dimensionLabel": "Human oversight + intervention",
      "coverage": 2,
      "coverageLabel": "Partial",
      "summary": "Safe, secure, resilient, accountable characteristics imply human oversight; MANAGE-2.3 covers human-AI configurations.",
      "clauseRef": "MANAGE 2.3; Section 3.5",
      "sourceUrl": "https://www.nist.gov/itl/ai-risk-management-framework"
    },
    {
      "framework": "nist-ai-rmf",
      "frameworkName": "NIST AI Risk Management Framework 1.0",
      "frameworkType": "Voluntary",
      "jurisdiction": "United States (international reference)",
      "dimension": "monitoring",
      "dimensionLabel": "Post-market monitoring + drift",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "MANAGE-4.1 requires post-deployment monitoring; MEASURE-2.6 requires evaluation throughout the lifecycle.",
      "clauseRef": "MANAGE 4.1-4.3; MEASURE 2.6",
      "sourceUrl": "https://www.nist.gov/itl/ai-risk-management-framework"
    },
    {
      "framework": "nist-ai-rmf",
      "frameworkName": "NIST AI Risk Management Framework 1.0",
      "frameworkType": "Voluntary",
      "jurisdiction": "United States (international reference)",
      "dimension": "incident-response",
      "dimensionLabel": "Incident + serious-incident reporting",
      "coverage": 2,
      "coverageLabel": "Partial",
      "summary": "MANAGE-4.3 covers ongoing monitoring and incident response; no mandatory reporting window.",
      "clauseRef": "MANAGE 4.3",
      "sourceUrl": "https://www.nist.gov/itl/ai-risk-management-framework"
    },
    {
      "framework": "nist-ai-rmf",
      "frameworkName": "NIST AI Risk Management Framework 1.0",
      "frameworkType": "Voluntary",
      "jurisdiction": "United States (international reference)",
      "dimension": "vendor-third-party",
      "dimensionLabel": "Vendor + third-party risk",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "GOVERN-6.1 and GOVERN-6.2 require third-party AI risk policies and due diligence.",
      "clauseRef": "GOVERN 6.1-6.2",
      "sourceUrl": "https://www.nist.gov/itl/ai-risk-management-framework"
    },
    {
      "framework": "nist-ai-rmf",
      "frameworkName": "NIST AI Risk Management Framework 1.0",
      "frameworkType": "Voluntary",
      "jurisdiction": "United States (international reference)",
      "dimension": "audit-documentation",
      "dimensionLabel": "Audit trail + documentation",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "MAP-1.6 and MEASURE-2.8 require documented assumptions, decisions, and evaluation results.",
      "clauseRef": "MAP 1.6; MEASURE 2.8",
      "sourceUrl": "https://www.nist.gov/itl/ai-risk-management-framework"
    },
    {
      "framework": "nist-ai-rmf",
      "frameworkName": "NIST AI Risk Management Framework 1.0",
      "frameworkType": "Voluntary",
      "jurisdiction": "United States (international reference)",
      "dimension": "access-security",
      "dimensionLabel": "Access control + security",
      "coverage": 2,
      "coverageLabel": "Partial",
      "summary": "Secure, resilient characteristic + MEASURE-2.7 covers security and resilience; defers to NIST SP 800-53 for controls.",
      "clauseRef": "MEASURE 2.7; Section 3.5",
      "sourceUrl": "https://www.nist.gov/itl/ai-risk-management-framework"
    },
    {
      "framework": "nist-ai-rmf",
      "frameworkName": "NIST AI Risk Management Framework 1.0",
      "frameworkType": "Voluntary",
      "jurisdiction": "United States (international reference)",
      "dimension": "bias-fairness",
      "dimensionLabel": "Bias + fairness testing",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Fair-with-harmful-bias-managed is a top characteristic; MEASURE-2.11 requires bias evaluation and supplemental AI 1270.",
      "clauseRef": "MEASURE 2.11; NIST SP 1270",
      "sourceUrl": "https://www.nist.gov/itl/ai-risk-management-framework"
    },
    {
      "framework": "nist-ai-rmf",
      "frameworkName": "NIST AI Risk Management Framework 1.0",
      "frameworkType": "Voluntary",
      "jurisdiction": "United States (international reference)",
      "dimension": "training-awareness",
      "dimensionLabel": "Training + AI literacy",
      "coverage": 2,
      "coverageLabel": "Partial",
      "summary": "GOVERN-2.2 and GOVERN-3.2 require training on AI risk roles and risk-aware culture.",
      "clauseRef": "GOVERN 2.2; GOVERN 3.2",
      "sourceUrl": "https://www.nist.gov/itl/ai-risk-management-framework"
    },
    {
      "framework": "nist-ai-rmf",
      "frameworkName": "NIST AI Risk Management Framework 1.0",
      "frameworkType": "Voluntary",
      "jurisdiction": "United States (international reference)",
      "dimension": "rights-redress",
      "dimensionLabel": "Data-subject rights + redress",
      "coverage": 1,
      "coverageLabel": "Mentioned",
      "summary": "Concept of redress in Section 3.5 (accountable + transparent), but no enforceable individual rights.",
      "clauseRef": "Section 3.5",
      "sourceUrl": "https://www.nist.gov/itl/ai-risk-management-framework"
    },
    {
      "framework": "nist-ai-rmf",
      "frameworkName": "NIST AI Risk Management Framework 1.0",
      "frameworkType": "Voluntary",
      "jurisdiction": "United States (international reference)",
      "dimension": "scope-applicability",
      "dimensionLabel": "Scope + applicability triggers",
      "coverage": 1,
      "coverageLabel": "Mentioned",
      "summary": "Voluntary across any AI system and any organisation; becomes binding only via procurement contracts or referenced statutes.",
      "clauseRef": "Section 2; Foreword",
      "sourceUrl": "https://www.nist.gov/itl/ai-risk-management-framework"
    },
    {
      "framework": "iso-42001",
      "frameworkName": "ISO/IEC 42001:2023 AI Management System",
      "frameworkType": "Industry standard",
      "jurisdiction": "International",
      "dimension": "governance",
      "dimensionLabel": "Governance + accountability",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Clauses 5.1-5.3 require leadership commitment, AI policy, and assigned organisational roles for the AIMS.",
      "clauseRef": "Clauses 5.1-5.3; A.2.x",
      "sourceUrl": "https://www.iso.org/standard/81230.html"
    },
    {
      "framework": "iso-42001",
      "frameworkName": "ISO/IEC 42001:2023 AI Management System",
      "frameworkType": "Industry standard",
      "jurisdiction": "International",
      "dimension": "risk-management",
      "dimensionLabel": "Risk management process",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Clause 6.1 requires AI risk assessment, treatment, and AI system impact assessment (Annex A.5).",
      "clauseRef": "Clause 6.1; A.5.1-A.5.5",
      "sourceUrl": "https://www.iso.org/standard/81230.html"
    },
    {
      "framework": "iso-42001",
      "frameworkName": "ISO/IEC 42001:2023 AI Management System",
      "frameworkType": "Industry standard",
      "jurisdiction": "International",
      "dimension": "data-handling",
      "dimensionLabel": "Data handling + minimisation",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Annex A.7 governs data for AI systems: provenance, quality, preparation, and data-management plans.",
      "clauseRef": "A.7.1-A.7.6",
      "sourceUrl": "https://www.iso.org/standard/81230.html"
    },
    {
      "framework": "iso-42001",
      "frameworkName": "ISO/IEC 42001:2023 AI Management System",
      "frameworkType": "Industry standard",
      "jurisdiction": "International",
      "dimension": "model-lifecycle",
      "dimensionLabel": "Model lifecycle controls",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Annex A.6 covers AI system lifecycle: design, development, verification, deployment, operation, retirement.",
      "clauseRef": "A.6.1-A.6.2",
      "sourceUrl": "https://www.iso.org/standard/81230.html"
    },
    {
      "framework": "iso-42001",
      "frameworkName": "ISO/IEC 42001:2023 AI Management System",
      "frameworkType": "Industry standard",
      "jurisdiction": "International",
      "dimension": "transparency",
      "dimensionLabel": "Transparency + disclosure",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Annex A.8 requires information for interested parties: system documentation, user docs, intended use.",
      "clauseRef": "A.8.1-A.8.5",
      "sourceUrl": "https://www.iso.org/standard/81230.html"
    },
    {
      "framework": "iso-42001",
      "frameworkName": "ISO/IEC 42001:2023 AI Management System",
      "frameworkType": "Industry standard",
      "jurisdiction": "International",
      "dimension": "human-oversight",
      "dimensionLabel": "Human oversight + intervention",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Annex A.9 requires human oversight and use of AI systems by humans in a defined manner.",
      "clauseRef": "A.9.1-A.9.4",
      "sourceUrl": "https://www.iso.org/standard/81230.html"
    },
    {
      "framework": "iso-42001",
      "frameworkName": "ISO/IEC 42001:2023 AI Management System",
      "frameworkType": "Industry standard",
      "jurisdiction": "International",
      "dimension": "monitoring",
      "dimensionLabel": "Post-market monitoring + drift",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Clause 9.1 + A.6.2 require performance monitoring, evaluation, and operational measurement of AI systems.",
      "clauseRef": "Clause 9.1; A.6.2.5-A.6.2.6",
      "sourceUrl": "https://www.iso.org/standard/81230.html"
    },
    {
      "framework": "iso-42001",
      "frameworkName": "ISO/IEC 42001:2023 AI Management System",
      "frameworkType": "Industry standard",
      "jurisdiction": "International",
      "dimension": "incident-response",
      "dimensionLabel": "Incident + serious-incident reporting",
      "coverage": 2,
      "coverageLabel": "Partial",
      "summary": "Clauses 10.1-10.2 require nonconformity correction; defers to ISO 27001 incident-response for security incidents.",
      "clauseRef": "Clauses 10.1-10.2",
      "sourceUrl": "https://www.iso.org/standard/81230.html"
    },
    {
      "framework": "iso-42001",
      "frameworkName": "ISO/IEC 42001:2023 AI Management System",
      "frameworkType": "Industry standard",
      "jurisdiction": "International",
      "dimension": "vendor-third-party",
      "dimensionLabel": "Vendor + third-party risk",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Annex A.10 governs third-party + customer relationships, supplier responsibilities, customer obligations.",
      "clauseRef": "A.10.1-A.10.4",
      "sourceUrl": "https://www.iso.org/standard/81230.html"
    },
    {
      "framework": "iso-42001",
      "frameworkName": "ISO/IEC 42001:2023 AI Management System",
      "frameworkType": "Industry standard",
      "jurisdiction": "International",
      "dimension": "audit-documentation",
      "dimensionLabel": "Audit trail + documentation",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Clause 7.5 requires documented information; Clause 9.2 internal audit; Clause 9.3 management review.",
      "clauseRef": "Clauses 7.5, 9.2, 9.3",
      "sourceUrl": "https://www.iso.org/standard/81230.html"
    },
    {
      "framework": "iso-42001",
      "frameworkName": "ISO/IEC 42001:2023 AI Management System",
      "frameworkType": "Industry standard",
      "jurisdiction": "International",
      "dimension": "access-security",
      "dimensionLabel": "Access control + security",
      "coverage": 2,
      "coverageLabel": "Partial",
      "summary": "Defers heavily to ISO 27001; A.6.2.7 covers security of AI systems; A.4.5 resources include data security.",
      "clauseRef": "A.6.2.7; references ISO 27001",
      "sourceUrl": "https://www.iso.org/standard/81230.html"
    },
    {
      "framework": "iso-42001",
      "frameworkName": "ISO/IEC 42001:2023 AI Management System",
      "frameworkType": "Industry standard",
      "jurisdiction": "International",
      "dimension": "bias-fairness",
      "dimensionLabel": "Bias + fairness testing",
      "coverage": 2,
      "coverageLabel": "Partial",
      "summary": "A.7.4 requires data-quality including representativeness; A.6.2.4 verification covers fairness as a quality criterion.",
      "clauseRef": "A.7.4; A.6.2.4",
      "sourceUrl": "https://www.iso.org/standard/81230.html"
    },
    {
      "framework": "iso-42001",
      "frameworkName": "ISO/IEC 42001:2023 AI Management System",
      "frameworkType": "Industry standard",
      "jurisdiction": "International",
      "dimension": "training-awareness",
      "dimensionLabel": "Training + AI literacy",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Clauses 7.2-7.3 require competence and awareness specifically for AI-related roles.",
      "clauseRef": "Clauses 7.2-7.3",
      "sourceUrl": "https://www.iso.org/standard/81230.html"
    },
    {
      "framework": "iso-42001",
      "frameworkName": "ISO/IEC 42001:2023 AI Management System",
      "frameworkType": "Industry standard",
      "jurisdiction": "International",
      "dimension": "rights-redress",
      "dimensionLabel": "Data-subject rights + redress",
      "coverage": 2,
      "coverageLabel": "Partial",
      "summary": "A.9.3 + A.10.4 cover users + customers receiving information and being able to contest outcomes.",
      "clauseRef": "A.9.3; A.10.4",
      "sourceUrl": "https://www.iso.org/standard/81230.html"
    },
    {
      "framework": "iso-42001",
      "frameworkName": "ISO/IEC 42001:2023 AI Management System",
      "frameworkType": "Industry standard",
      "jurisdiction": "International",
      "dimension": "scope-applicability",
      "dimensionLabel": "Scope + applicability triggers",
      "coverage": 2,
      "coverageLabel": "Partial",
      "summary": "Voluntary certifiable standard; binding only when adopted by an organisation or required by customer / regulator.",
      "clauseRef": "Clause 1; Clause 4",
      "sourceUrl": "https://www.iso.org/standard/81230.html"
    },
    {
      "framework": "eu-ai-act",
      "frameworkName": "EU AI Act (Regulation 2024/1689)",
      "frameworkType": "Regulatory",
      "jurisdiction": "European Union (extraterritorial)",
      "dimension": "governance",
      "dimensionLabel": "Governance + accountability",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Article 17 requires a quality management system for high-risk providers; deployers need internal governance under Article 26.",
      "clauseRef": "Articles 17, 26",
      "sourceUrl": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj"
    },
    {
      "framework": "eu-ai-act",
      "frameworkName": "EU AI Act (Regulation 2024/1689)",
      "frameworkType": "Regulatory",
      "jurisdiction": "European Union (extraterritorial)",
      "dimension": "risk-management",
      "dimensionLabel": "Risk management process",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Article 9 mandates a risk management system across the lifecycle of high-risk AI systems.",
      "clauseRef": "Article 9",
      "sourceUrl": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj"
    },
    {
      "framework": "eu-ai-act",
      "frameworkName": "EU AI Act (Regulation 2024/1689)",
      "frameworkType": "Regulatory",
      "jurisdiction": "European Union (extraterritorial)",
      "dimension": "data-handling",
      "dimensionLabel": "Data handling + minimisation",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Article 10 sets quality, governance, and bias-testing requirements for training, validation, and test datasets.",
      "clauseRef": "Article 10",
      "sourceUrl": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj"
    },
    {
      "framework": "eu-ai-act",
      "frameworkName": "EU AI Act (Regulation 2024/1689)",
      "frameworkType": "Regulatory",
      "jurisdiction": "European Union (extraterritorial)",
      "dimension": "model-lifecycle",
      "dimensionLabel": "Model lifecycle controls",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Article 9, 11, 17 cover risk management, technical documentation, and quality management across lifecycle.",
      "clauseRef": "Articles 9, 11, 17",
      "sourceUrl": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj"
    },
    {
      "framework": "eu-ai-act",
      "frameworkName": "EU AI Act (Regulation 2024/1689)",
      "frameworkType": "Regulatory",
      "jurisdiction": "European Union (extraterritorial)",
      "dimension": "transparency",
      "dimensionLabel": "Transparency + disclosure",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Article 13 (high-risk) and Article 50 (chatbots, synthetic content) impose user-disclosure obligations; Article 53 covers GPAI documentation.",
      "clauseRef": "Articles 13, 50, 53",
      "sourceUrl": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj"
    },
    {
      "framework": "eu-ai-act",
      "frameworkName": "EU AI Act (Regulation 2024/1689)",
      "frameworkType": "Regulatory",
      "jurisdiction": "European Union (extraterritorial)",
      "dimension": "human-oversight",
      "dimensionLabel": "Human oversight + intervention",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Article 14 mandates effective human oversight for high-risk AI; specific roles per Article 26 for deployers.",
      "clauseRef": "Articles 14, 26",
      "sourceUrl": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj"
    },
    {
      "framework": "eu-ai-act",
      "frameworkName": "EU AI Act (Regulation 2024/1689)",
      "frameworkType": "Regulatory",
      "jurisdiction": "European Union (extraterritorial)",
      "dimension": "monitoring",
      "dimensionLabel": "Post-market monitoring + drift",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Article 72 requires a post-market monitoring system for high-risk providers, with documented plan.",
      "clauseRef": "Article 72",
      "sourceUrl": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj"
    },
    {
      "framework": "eu-ai-act",
      "frameworkName": "EU AI Act (Regulation 2024/1689)",
      "frameworkType": "Regulatory",
      "jurisdiction": "European Union (extraterritorial)",
      "dimension": "incident-response",
      "dimensionLabel": "Incident + serious-incident reporting",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Article 73 requires serious-incident reporting to the market surveillance authority within 15 days (immediately for fatalities or critical infrastructure).",
      "clauseRef": "Article 73",
      "sourceUrl": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj"
    },
    {
      "framework": "eu-ai-act",
      "frameworkName": "EU AI Act (Regulation 2024/1689)",
      "frameworkType": "Regulatory",
      "jurisdiction": "European Union (extraterritorial)",
      "dimension": "vendor-third-party",
      "dimensionLabel": "Vendor + third-party risk",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Article 25 (provider becoming deployer / change of role) and Article 28 (importers and distributors due diligence).",
      "clauseRef": "Articles 25, 28",
      "sourceUrl": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj"
    },
    {
      "framework": "eu-ai-act",
      "frameworkName": "EU AI Act (Regulation 2024/1689)",
      "frameworkType": "Regulatory",
      "jurisdiction": "European Union (extraterritorial)",
      "dimension": "audit-documentation",
      "dimensionLabel": "Audit trail + documentation",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Articles 11-12 require technical documentation (Annex IV) and automated logging for high-risk AI systems.",
      "clauseRef": "Articles 11, 12; Annex IV",
      "sourceUrl": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj"
    },
    {
      "framework": "eu-ai-act",
      "frameworkName": "EU AI Act (Regulation 2024/1689)",
      "frameworkType": "Regulatory",
      "jurisdiction": "European Union (extraterritorial)",
      "dimension": "access-security",
      "dimensionLabel": "Access control + security",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Article 15 requires accuracy, robustness, and cybersecurity for high-risk AI systems.",
      "clauseRef": "Article 15",
      "sourceUrl": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj"
    },
    {
      "framework": "eu-ai-act",
      "frameworkName": "EU AI Act (Regulation 2024/1689)",
      "frameworkType": "Regulatory",
      "jurisdiction": "European Union (extraterritorial)",
      "dimension": "bias-fairness",
      "dimensionLabel": "Bias + fairness testing",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Article 10(5) requires bias detection and correction; Article 27 introduces fundamental-rights impact assessment for some deployers.",
      "clauseRef": "Articles 10(5), 27",
      "sourceUrl": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj"
    },
    {
      "framework": "eu-ai-act",
      "frameworkName": "EU AI Act (Regulation 2024/1689)",
      "frameworkType": "Regulatory",
      "jurisdiction": "European Union (extraterritorial)",
      "dimension": "training-awareness",
      "dimensionLabel": "Training + AI literacy",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Article 4 (AI literacy) requires providers and deployers to ensure staff operating AI have sufficient AI literacy.",
      "clauseRef": "Article 4",
      "sourceUrl": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj"
    },
    {
      "framework": "eu-ai-act",
      "frameworkName": "EU AI Act (Regulation 2024/1689)",
      "frameworkType": "Regulatory",
      "jurisdiction": "European Union (extraterritorial)",
      "dimension": "rights-redress",
      "dimensionLabel": "Data-subject rights + redress",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Article 86 grants affected persons a right to explanation of decisions; Article 85 a right to lodge complaints.",
      "clauseRef": "Articles 85, 86",
      "sourceUrl": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj"
    },
    {
      "framework": "eu-ai-act",
      "frameworkName": "EU AI Act (Regulation 2024/1689)",
      "frameworkType": "Regulatory",
      "jurisdiction": "European Union (extraterritorial)",
      "dimension": "scope-applicability",
      "dimensionLabel": "Scope + applicability triggers",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Article 2 extraterritorially binds providers and deployers when output is used in the EU.",
      "clauseRef": "Article 2",
      "sourceUrl": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj"
    },
    {
      "framework": "soc-2",
      "frameworkName": "SOC 2 Trust Services Criteria",
      "frameworkType": "Industry standard",
      "jurisdiction": "United States (de-facto international)",
      "dimension": "governance",
      "dimensionLabel": "Governance + accountability",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "CC1.1-CC1.5 require commitment to integrity, board oversight, structure / authority, competence, and accountability.",
      "clauseRef": "CC1.1-CC1.5",
      "sourceUrl": "https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2"
    },
    {
      "framework": "soc-2",
      "frameworkName": "SOC 2 Trust Services Criteria",
      "frameworkType": "Industry standard",
      "jurisdiction": "United States (de-facto international)",
      "dimension": "risk-management",
      "dimensionLabel": "Risk management process",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "CC3.1-CC3.4 require risk identification, fraud risk, change in environment, and risk-response selection.",
      "clauseRef": "CC3.1-CC3.4",
      "sourceUrl": "https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2"
    },
    {
      "framework": "soc-2",
      "frameworkName": "SOC 2 Trust Services Criteria",
      "frameworkType": "Industry standard",
      "jurisdiction": "United States (de-facto international)",
      "dimension": "data-handling",
      "dimensionLabel": "Data handling + minimisation",
      "coverage": 2,
      "coverageLabel": "Partial",
      "summary": "Confidentiality criteria C1.1-C1.2 cover identification, retention, destruction; Privacy criteria address PII; AI-specific data sourcing not explicit.",
      "clauseRef": "C1.1-C1.2; P1-P8 (Privacy)",
      "sourceUrl": "https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2"
    },
    {
      "framework": "soc-2",
      "frameworkName": "SOC 2 Trust Services Criteria",
      "frameworkType": "Industry standard",
      "jurisdiction": "United States (de-facto international)",
      "dimension": "model-lifecycle",
      "dimensionLabel": "Model lifecycle controls",
      "coverage": 1,
      "coverageLabel": "Mentioned",
      "summary": "CC8.1 covers change management; not AI-specific. Model training and validation handled implicitly through change controls.",
      "clauseRef": "CC8.1",
      "sourceUrl": "https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2"
    },
    {
      "framework": "soc-2",
      "frameworkName": "SOC 2 Trust Services Criteria",
      "frameworkType": "Industry standard",
      "jurisdiction": "United States (de-facto international)",
      "dimension": "transparency",
      "dimensionLabel": "Transparency + disclosure",
      "coverage": 2,
      "coverageLabel": "Partial",
      "summary": "CC2.1-CC2.3 require communication of objectives and quality information; Privacy P1.1 requires notice. No AI disclosure obligation.",
      "clauseRef": "CC2.1-CC2.3; P1.1",
      "sourceUrl": "https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2"
    },
    {
      "framework": "soc-2",
      "frameworkName": "SOC 2 Trust Services Criteria",
      "frameworkType": "Industry standard",
      "jurisdiction": "United States (de-facto international)",
      "dimension": "human-oversight",
      "dimensionLabel": "Human oversight + intervention",
      "coverage": 1,
      "coverageLabel": "Mentioned",
      "summary": "No direct human-oversight criterion; CC5.x activities are control activities driven by people, but not AI specific.",
      "clauseRef": "CC5.1-CC5.3",
      "sourceUrl": "https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2"
    },
    {
      "framework": "soc-2",
      "frameworkName": "SOC 2 Trust Services Criteria",
      "frameworkType": "Industry standard",
      "jurisdiction": "United States (de-facto international)",
      "dimension": "monitoring",
      "dimensionLabel": "Post-market monitoring + drift",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "CC4.1-CC4.2 require ongoing and separate evaluation, and communication of deficiencies.",
      "clauseRef": "CC4.1-CC4.2",
      "sourceUrl": "https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2"
    },
    {
      "framework": "soc-2",
      "frameworkName": "SOC 2 Trust Services Criteria",
      "frameworkType": "Industry standard",
      "jurisdiction": "United States (de-facto international)",
      "dimension": "incident-response",
      "dimensionLabel": "Incident + serious-incident reporting",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "CC7.3-CC7.5 require incident-management process: detection, response, evaluation, communication, recovery.",
      "clauseRef": "CC7.3-CC7.5",
      "sourceUrl": "https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2"
    },
    {
      "framework": "soc-2",
      "frameworkName": "SOC 2 Trust Services Criteria",
      "frameworkType": "Industry standard",
      "jurisdiction": "United States (de-facto international)",
      "dimension": "vendor-third-party",
      "dimensionLabel": "Vendor + third-party risk",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "CC9.2 explicitly requires vendor and business partner risk management.",
      "clauseRef": "CC9.2",
      "sourceUrl": "https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2"
    },
    {
      "framework": "soc-2",
      "frameworkName": "SOC 2 Trust Services Criteria",
      "frameworkType": "Industry standard",
      "jurisdiction": "United States (de-facto international)",
      "dimension": "audit-documentation",
      "dimensionLabel": "Audit trail + documentation",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Whole framework is audit-oriented; CC4.x requires monitoring activities and CC4.2 communicates deficiencies.",
      "clauseRef": "CC4.1-CC4.2; full TSC",
      "sourceUrl": "https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2"
    },
    {
      "framework": "soc-2",
      "frameworkName": "SOC 2 Trust Services Criteria",
      "frameworkType": "Industry standard",
      "jurisdiction": "United States (de-facto international)",
      "dimension": "access-security",
      "dimensionLabel": "Access control + security",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "CC6.1-CC6.8 cover logical and physical access, authentication, encryption, and infrastructure protection.",
      "clauseRef": "CC6.1-CC6.8",
      "sourceUrl": "https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2"
    },
    {
      "framework": "soc-2",
      "frameworkName": "SOC 2 Trust Services Criteria",
      "frameworkType": "Industry standard",
      "jurisdiction": "United States (de-facto international)",
      "dimension": "bias-fairness",
      "dimensionLabel": "Bias + fairness testing",
      "coverage": 0,
      "coverageLabel": "Not addressed",
      "summary": "Not addressed. SOC 2 does not require fairness or bias testing.",
      "clauseRef": "n/a",
      "sourceUrl": "https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2"
    },
    {
      "framework": "soc-2",
      "frameworkName": "SOC 2 Trust Services Criteria",
      "frameworkType": "Industry standard",
      "jurisdiction": "United States (de-facto international)",
      "dimension": "training-awareness",
      "dimensionLabel": "Training + AI literacy",
      "coverage": 2,
      "coverageLabel": "Partial",
      "summary": "CC1.4 requires competence; CC2.x requires communication. Security awareness training is standard practice but not enumerated for AI literacy.",
      "clauseRef": "CC1.4; CC2.x",
      "sourceUrl": "https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2"
    },
    {
      "framework": "soc-2",
      "frameworkName": "SOC 2 Trust Services Criteria",
      "frameworkType": "Industry standard",
      "jurisdiction": "United States (de-facto international)",
      "dimension": "rights-redress",
      "dimensionLabel": "Data-subject rights + redress",
      "coverage": 2,
      "coverageLabel": "Partial",
      "summary": "Privacy criteria P5.1-P5.2 cover individual rights of access and correction. No automated-decision rights.",
      "clauseRef": "P5.1-P5.2",
      "sourceUrl": "https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2"
    },
    {
      "framework": "soc-2",
      "frameworkName": "SOC 2 Trust Services Criteria",
      "frameworkType": "Industry standard",
      "jurisdiction": "United States (de-facto international)",
      "dimension": "scope-applicability",
      "dimensionLabel": "Scope + applicability triggers",
      "coverage": 2,
      "coverageLabel": "Partial",
      "summary": "Voluntary attestation chosen by service organisations; customer contracts make it effectively binding.",
      "clauseRef": "Engagement scope",
      "sourceUrl": "https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2"
    },
    {
      "framework": "hipaa",
      "frameworkName": "HIPAA Privacy + Security Rules",
      "frameworkType": "Sectoral",
      "jurisdiction": "United States (healthcare)",
      "dimension": "governance",
      "dimensionLabel": "Governance + accountability",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "164.308(a)(2) requires assigned Security Official; 164.530(a) requires Privacy Official and contact person.",
      "clauseRef": "45 CFR 164.308(a)(2); 164.530(a)",
      "sourceUrl": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164"
    },
    {
      "framework": "hipaa",
      "frameworkName": "HIPAA Privacy + Security Rules",
      "frameworkType": "Sectoral",
      "jurisdiction": "United States (healthcare)",
      "dimension": "risk-management",
      "dimensionLabel": "Risk management process",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "164.308(a)(1)(ii) requires a Risk Analysis and Risk Management process.",
      "clauseRef": "45 CFR 164.308(a)(1)",
      "sourceUrl": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164"
    },
    {
      "framework": "hipaa",
      "frameworkName": "HIPAA Privacy + Security Rules",
      "frameworkType": "Sectoral",
      "jurisdiction": "United States (healthcare)",
      "dimension": "data-handling",
      "dimensionLabel": "Data handling + minimisation",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "164.502(b) minimum necessary; 164.514(d) standards; 164.514(b) de-identification; restrictions on training-data use.",
      "clauseRef": "45 CFR 164.502(b); 164.514",
      "sourceUrl": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164"
    },
    {
      "framework": "hipaa",
      "frameworkName": "HIPAA Privacy + Security Rules",
      "frameworkType": "Sectoral",
      "jurisdiction": "United States (healthcare)",
      "dimension": "model-lifecycle",
      "dimensionLabel": "Model lifecycle controls",
      "coverage": 1,
      "coverageLabel": "Mentioned",
      "summary": "Not AI-specific. Security Rule covers system development implicitly through risk analysis on systems handling PHI.",
      "clauseRef": "164.308 (general)",
      "sourceUrl": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164"
    },
    {
      "framework": "hipaa",
      "frameworkName": "HIPAA Privacy + Security Rules",
      "frameworkType": "Sectoral",
      "jurisdiction": "United States (healthcare)",
      "dimension": "transparency",
      "dimensionLabel": "Transparency + disclosure",
      "coverage": 2,
      "coverageLabel": "Partial",
      "summary": "164.520 requires a Notice of Privacy Practices; no AI disclosure obligation, but FDA guidance applies to clinical AI.",
      "clauseRef": "45 CFR 164.520",
      "sourceUrl": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164"
    },
    {
      "framework": "hipaa",
      "frameworkName": "HIPAA Privacy + Security Rules",
      "frameworkType": "Sectoral",
      "jurisdiction": "United States (healthcare)",
      "dimension": "human-oversight",
      "dimensionLabel": "Human oversight + intervention",
      "coverage": 1,
      "coverageLabel": "Mentioned",
      "summary": "Not explicit. Implicitly required where automated tools affect treatment, payment, or operations through workforce-control standard.",
      "clauseRef": "164.530(b)",
      "sourceUrl": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164"
    },
    {
      "framework": "hipaa",
      "frameworkName": "HIPAA Privacy + Security Rules",
      "frameworkType": "Sectoral",
      "jurisdiction": "United States (healthcare)",
      "dimension": "monitoring",
      "dimensionLabel": "Post-market monitoring + drift",
      "coverage": 2,
      "coverageLabel": "Partial",
      "summary": "164.308(a)(1)(ii)(D) requires Information System Activity Review; periodic, not continuous.",
      "clauseRef": "45 CFR 164.308(a)(1)(ii)(D)",
      "sourceUrl": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164"
    },
    {
      "framework": "hipaa",
      "frameworkName": "HIPAA Privacy + Security Rules",
      "frameworkType": "Sectoral",
      "jurisdiction": "United States (healthcare)",
      "dimension": "incident-response",
      "dimensionLabel": "Incident + serious-incident reporting",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "164.308(a)(6) requires security-incident procedures; 164.400s require breach notification to HHS within 60 days.",
      "clauseRef": "45 CFR 164.308(a)(6); 164.400-414",
      "sourceUrl": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164"
    },
    {
      "framework": "hipaa",
      "frameworkName": "HIPAA Privacy + Security Rules",
      "frameworkType": "Sectoral",
      "jurisdiction": "United States (healthcare)",
      "dimension": "vendor-third-party",
      "dimensionLabel": "Vendor + third-party risk",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "164.504(e) Business Associate Contract is a hard requirement before disclosing PHI to a vendor.",
      "clauseRef": "45 CFR 164.504(e)",
      "sourceUrl": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164"
    },
    {
      "framework": "hipaa",
      "frameworkName": "HIPAA Privacy + Security Rules",
      "frameworkType": "Sectoral",
      "jurisdiction": "United States (healthcare)",
      "dimension": "audit-documentation",
      "dimensionLabel": "Audit trail + documentation",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "164.312(b) audit controls (mechanism to record + examine activity); 164.530(j) 6-year documentation retention.",
      "clauseRef": "45 CFR 164.312(b); 164.530(j)",
      "sourceUrl": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164"
    },
    {
      "framework": "hipaa",
      "frameworkName": "HIPAA Privacy + Security Rules",
      "frameworkType": "Sectoral",
      "jurisdiction": "United States (healthcare)",
      "dimension": "access-security",
      "dimensionLabel": "Access control + security",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "164.308, 164.310, 164.312 cover administrative, physical, and technical safeguards including encryption (addressable).",
      "clauseRef": "45 CFR 164.308-312",
      "sourceUrl": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164"
    },
    {
      "framework": "hipaa",
      "frameworkName": "HIPAA Privacy + Security Rules",
      "frameworkType": "Sectoral",
      "jurisdiction": "United States (healthcare)",
      "dimension": "bias-fairness",
      "dimensionLabel": "Bias + fairness testing",
      "coverage": 0,
      "coverageLabel": "Not addressed",
      "summary": "Not addressed. ONC has issued separate algorithmic-transparency rule for certified EHR developers (HTI-1).",
      "clauseRef": "n/a",
      "sourceUrl": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164"
    },
    {
      "framework": "hipaa",
      "frameworkName": "HIPAA Privacy + Security Rules",
      "frameworkType": "Sectoral",
      "jurisdiction": "United States (healthcare)",
      "dimension": "training-awareness",
      "dimensionLabel": "Training + AI literacy",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "164.308(a)(5) requires workforce security-awareness and training program.",
      "clauseRef": "45 CFR 164.308(a)(5)",
      "sourceUrl": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164"
    },
    {
      "framework": "hipaa",
      "frameworkName": "HIPAA Privacy + Security Rules",
      "frameworkType": "Sectoral",
      "jurisdiction": "United States (healthcare)",
      "dimension": "rights-redress",
      "dimensionLabel": "Data-subject rights + redress",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "164.524-528 grant access, amendment, and accounting of disclosures rights to patients.",
      "clauseRef": "45 CFR 164.524-528",
      "sourceUrl": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164"
    },
    {
      "framework": "hipaa",
      "frameworkName": "HIPAA Privacy + Security Rules",
      "frameworkType": "Sectoral",
      "jurisdiction": "United States (healthcare)",
      "dimension": "scope-applicability",
      "dimensionLabel": "Scope + applicability triggers",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Binds covered entities and business associates handling PHI; defined by 45 CFR 160.103.",
      "clauseRef": "45 CFR 160.103",
      "sourceUrl": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164"
    },
    {
      "framework": "gdpr",
      "frameworkName": "GDPR (Regulation 2016/679, Articles 22, 25, 35)",
      "frameworkType": "Regulatory",
      "jurisdiction": "European Union + EEA (extraterritorial via Article 3)",
      "dimension": "governance",
      "dimensionLabel": "Governance + accountability",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Article 37 requires a Data Protection Officer for public bodies and large-scale processors; Article 24 controller responsibility.",
      "clauseRef": "Articles 24, 37",
      "sourceUrl": "https://eur-lex.europa.eu/eli/reg/2016/679/oj"
    },
    {
      "framework": "gdpr",
      "frameworkName": "GDPR (Regulation 2016/679, Articles 22, 25, 35)",
      "frameworkType": "Regulatory",
      "jurisdiction": "European Union + EEA (extraterritorial via Article 3)",
      "dimension": "risk-management",
      "dimensionLabel": "Risk management process",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Article 35 DPIA required for high-risk processing (profiling, large-scale special category, systematic monitoring).",
      "clauseRef": "Article 35",
      "sourceUrl": "https://eur-lex.europa.eu/eli/reg/2016/679/oj"
    },
    {
      "framework": "gdpr",
      "frameworkName": "GDPR (Regulation 2016/679, Articles 22, 25, 35)",
      "frameworkType": "Regulatory",
      "jurisdiction": "European Union + EEA (extraterritorial via Article 3)",
      "dimension": "data-handling",
      "dimensionLabel": "Data handling + minimisation",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Article 5 principles (lawfulness, minimisation, accuracy, storage limitation, integrity); Articles 6, 9 lawful basis.",
      "clauseRef": "Articles 5, 6, 9",
      "sourceUrl": "https://eur-lex.europa.eu/eli/reg/2016/679/oj"
    },
    {
      "framework": "gdpr",
      "frameworkName": "GDPR (Regulation 2016/679, Articles 22, 25, 35)",
      "frameworkType": "Regulatory",
      "jurisdiction": "European Union + EEA (extraterritorial via Article 3)",
      "dimension": "model-lifecycle",
      "dimensionLabel": "Model lifecycle controls",
      "coverage": 2,
      "coverageLabel": "Partial",
      "summary": "Article 25 requires data protection by design and default; Article 32 security of processing across lifecycle.",
      "clauseRef": "Articles 25, 32",
      "sourceUrl": "https://eur-lex.europa.eu/eli/reg/2016/679/oj"
    },
    {
      "framework": "gdpr",
      "frameworkName": "GDPR (Regulation 2016/679, Articles 22, 25, 35)",
      "frameworkType": "Regulatory",
      "jurisdiction": "European Union + EEA (extraterritorial via Article 3)",
      "dimension": "transparency",
      "dimensionLabel": "Transparency + disclosure",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Articles 13-14 provide information; Article 22(3) requires meaningful information about automated decision logic.",
      "clauseRef": "Articles 13, 14, 22(3)",
      "sourceUrl": "https://eur-lex.europa.eu/eli/reg/2016/679/oj"
    },
    {
      "framework": "gdpr",
      "frameworkName": "GDPR (Regulation 2016/679, Articles 22, 25, 35)",
      "frameworkType": "Regulatory",
      "jurisdiction": "European Union + EEA (extraterritorial via Article 3)",
      "dimension": "human-oversight",
      "dimensionLabel": "Human oversight + intervention",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Article 22(3) right to obtain human intervention, express point of view, contest the decision.",
      "clauseRef": "Article 22(3)",
      "sourceUrl": "https://eur-lex.europa.eu/eli/reg/2016/679/oj"
    },
    {
      "framework": "gdpr",
      "frameworkName": "GDPR (Regulation 2016/679, Articles 22, 25, 35)",
      "frameworkType": "Regulatory",
      "jurisdiction": "European Union + EEA (extraterritorial via Article 3)",
      "dimension": "monitoring",
      "dimensionLabel": "Post-market monitoring + drift",
      "coverage": 2,
      "coverageLabel": "Partial",
      "summary": "Article 35(11) DPIA review where processing operations change; ongoing controller obligation under Article 24.",
      "clauseRef": "Articles 24, 35(11)",
      "sourceUrl": "https://eur-lex.europa.eu/eli/reg/2016/679/oj"
    },
    {
      "framework": "gdpr",
      "frameworkName": "GDPR (Regulation 2016/679, Articles 22, 25, 35)",
      "frameworkType": "Regulatory",
      "jurisdiction": "European Union + EEA (extraterritorial via Article 3)",
      "dimension": "incident-response",
      "dimensionLabel": "Incident + serious-incident reporting",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Article 33 requires breach notification to supervisory authority within 72 hours; Article 34 to data subjects.",
      "clauseRef": "Articles 33, 34",
      "sourceUrl": "https://eur-lex.europa.eu/eli/reg/2016/679/oj"
    },
    {
      "framework": "gdpr",
      "frameworkName": "GDPR (Regulation 2016/679, Articles 22, 25, 35)",
      "frameworkType": "Regulatory",
      "jurisdiction": "European Union + EEA (extraterritorial via Article 3)",
      "dimension": "vendor-third-party",
      "dimensionLabel": "Vendor + third-party risk",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Article 28 requires a written contract (DPA) with processors; Article 28(2)-28(4) constrain sub-processors.",
      "clauseRef": "Article 28",
      "sourceUrl": "https://eur-lex.europa.eu/eli/reg/2016/679/oj"
    },
    {
      "framework": "gdpr",
      "frameworkName": "GDPR (Regulation 2016/679, Articles 22, 25, 35)",
      "frameworkType": "Regulatory",
      "jurisdiction": "European Union + EEA (extraterritorial via Article 3)",
      "dimension": "audit-documentation",
      "dimensionLabel": "Audit trail + documentation",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Article 30 record of processing activities; Article 5(2) accountability principle; Article 24 demonstrable compliance.",
      "clauseRef": "Articles 5(2), 24, 30",
      "sourceUrl": "https://eur-lex.europa.eu/eli/reg/2016/679/oj"
    },
    {
      "framework": "gdpr",
      "frameworkName": "GDPR (Regulation 2016/679, Articles 22, 25, 35)",
      "frameworkType": "Regulatory",
      "jurisdiction": "European Union + EEA (extraterritorial via Article 3)",
      "dimension": "access-security",
      "dimensionLabel": "Access control + security",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Article 32 requires appropriate technical and organisational measures including pseudonymisation and encryption.",
      "clauseRef": "Article 32",
      "sourceUrl": "https://eur-lex.europa.eu/eli/reg/2016/679/oj"
    },
    {
      "framework": "gdpr",
      "frameworkName": "GDPR (Regulation 2016/679, Articles 22, 25, 35)",
      "frameworkType": "Regulatory",
      "jurisdiction": "European Union + EEA (extraterritorial via Article 3)",
      "dimension": "bias-fairness",
      "dimensionLabel": "Bias + fairness testing",
      "coverage": 2,
      "coverageLabel": "Partial",
      "summary": "Article 5(1)(a) lawful, fair, transparent; Recital 71 calls out discrimination prevention in profiling.",
      "clauseRef": "Article 5(1)(a); Recital 71",
      "sourceUrl": "https://eur-lex.europa.eu/eli/reg/2016/679/oj"
    },
    {
      "framework": "gdpr",
      "frameworkName": "GDPR (Regulation 2016/679, Articles 22, 25, 35)",
      "frameworkType": "Regulatory",
      "jurisdiction": "European Union + EEA (extraterritorial via Article 3)",
      "dimension": "training-awareness",
      "dimensionLabel": "Training + AI literacy",
      "coverage": 2,
      "coverageLabel": "Partial",
      "summary": "Article 39(1)(b) DPO duty to monitor compliance and awareness-raising / training of staff.",
      "clauseRef": "Article 39(1)(b)",
      "sourceUrl": "https://eur-lex.europa.eu/eli/reg/2016/679/oj"
    },
    {
      "framework": "gdpr",
      "frameworkName": "GDPR (Regulation 2016/679, Articles 22, 25, 35)",
      "frameworkType": "Regulatory",
      "jurisdiction": "European Union + EEA (extraterritorial via Article 3)",
      "dimension": "rights-redress",
      "dimensionLabel": "Data-subject rights + redress",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Articles 15-22 grant access, rectification, erasure, portability, object, and Article 22 automated-decision rights.",
      "clauseRef": "Articles 15-22",
      "sourceUrl": "https://eur-lex.europa.eu/eli/reg/2016/679/oj"
    },
    {
      "framework": "gdpr",
      "frameworkName": "GDPR (Regulation 2016/679, Articles 22, 25, 35)",
      "frameworkType": "Regulatory",
      "jurisdiction": "European Union + EEA (extraterritorial via Article 3)",
      "dimension": "scope-applicability",
      "dimensionLabel": "Scope + applicability triggers",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Article 3 extraterritorial: applies when controller / processor offers goods or services to EU data subjects or monitors their behaviour.",
      "clauseRef": "Article 3",
      "sourceUrl": "https://eur-lex.europa.eu/eli/reg/2016/679/oj"
    },
    {
      "framework": "pci-dss",
      "frameworkName": "PCI DSS 4.0",
      "frameworkType": "Industry standard",
      "jurisdiction": "Global (card-payment ecosystem)",
      "dimension": "governance",
      "dimensionLabel": "Governance + accountability",
      "coverage": 2,
      "coverageLabel": "Partial",
      "summary": "Requirement 12 maintains an information-security policy; 12.1 establishes responsibility, 12.4 manages program.",
      "clauseRef": "PCI 12.1-12.4",
      "sourceUrl": "https://www.pcisecuritystandards.org/document_library/"
    },
    {
      "framework": "pci-dss",
      "frameworkName": "PCI DSS 4.0",
      "frameworkType": "Industry standard",
      "jurisdiction": "Global (card-payment ecosystem)",
      "dimension": "risk-management",
      "dimensionLabel": "Risk management process",
      "coverage": 2,
      "coverageLabel": "Partial",
      "summary": "Requirement 12.3 introduces Targeted Risk Analysis for customised-approach controls.",
      "clauseRef": "PCI 12.3",
      "sourceUrl": "https://www.pcisecuritystandards.org/document_library/"
    },
    {
      "framework": "pci-dss",
      "frameworkName": "PCI DSS 4.0",
      "frameworkType": "Industry standard",
      "jurisdiction": "Global (card-payment ecosystem)",
      "dimension": "data-handling",
      "dimensionLabel": "Data handling + minimisation",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Requirements 3.1-3.7 govern protection of stored CHD; requirements 4.x cover transmission.",
      "clauseRef": "PCI 3.x, 4.x",
      "sourceUrl": "https://www.pcisecuritystandards.org/document_library/"
    },
    {
      "framework": "pci-dss",
      "frameworkName": "PCI DSS 4.0",
      "frameworkType": "Industry standard",
      "jurisdiction": "Global (card-payment ecosystem)",
      "dimension": "model-lifecycle",
      "dimensionLabel": "Model lifecycle controls",
      "coverage": 1,
      "coverageLabel": "Mentioned",
      "summary": "Not AI-specific. Requirement 6 covers secure software development for any in-scope system.",
      "clauseRef": "PCI 6.x",
      "sourceUrl": "https://www.pcisecuritystandards.org/document_library/"
    },
    {
      "framework": "pci-dss",
      "frameworkName": "PCI DSS 4.0",
      "frameworkType": "Industry standard",
      "jurisdiction": "Global (card-payment ecosystem)",
      "dimension": "transparency",
      "dimensionLabel": "Transparency + disclosure",
      "coverage": 0,
      "coverageLabel": "Not addressed",
      "summary": "Not addressed. PCI DSS does not require user-facing AI disclosure.",
      "clauseRef": "n/a",
      "sourceUrl": "https://www.pcisecuritystandards.org/document_library/"
    },
    {
      "framework": "pci-dss",
      "frameworkName": "PCI DSS 4.0",
      "frameworkType": "Industry standard",
      "jurisdiction": "Global (card-payment ecosystem)",
      "dimension": "human-oversight",
      "dimensionLabel": "Human oversight + intervention",
      "coverage": 0,
      "coverageLabel": "Not addressed",
      "summary": "Not addressed.",
      "clauseRef": "n/a",
      "sourceUrl": "https://www.pcisecuritystandards.org/document_library/"
    },
    {
      "framework": "pci-dss",
      "frameworkName": "PCI DSS 4.0",
      "frameworkType": "Industry standard",
      "jurisdiction": "Global (card-payment ecosystem)",
      "dimension": "monitoring",
      "dimensionLabel": "Post-market monitoring + drift",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Requirement 10 covers logging, monitoring, and time-synced audit; 11.x covers testing.",
      "clauseRef": "PCI 10.x, 11.x",
      "sourceUrl": "https://www.pcisecuritystandards.org/document_library/"
    },
    {
      "framework": "pci-dss",
      "frameworkName": "PCI DSS 4.0",
      "frameworkType": "Industry standard",
      "jurisdiction": "Global (card-payment ecosystem)",
      "dimension": "incident-response",
      "dimensionLabel": "Incident + serious-incident reporting",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Requirement 12.10 requires incident-response plan, testing, training, and revision.",
      "clauseRef": "PCI 12.10",
      "sourceUrl": "https://www.pcisecuritystandards.org/document_library/"
    },
    {
      "framework": "pci-dss",
      "frameworkName": "PCI DSS 4.0",
      "frameworkType": "Industry standard",
      "jurisdiction": "Global (card-payment ecosystem)",
      "dimension": "vendor-third-party",
      "dimensionLabel": "Vendor + third-party risk",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Requirement 12.8 governs service-provider relationships including written acknowledgement of PCI responsibilities.",
      "clauseRef": "PCI 12.8",
      "sourceUrl": "https://www.pcisecuritystandards.org/document_library/"
    },
    {
      "framework": "pci-dss",
      "frameworkName": "PCI DSS 4.0",
      "frameworkType": "Industry standard",
      "jurisdiction": "Global (card-payment ecosystem)",
      "dimension": "audit-documentation",
      "dimensionLabel": "Audit trail + documentation",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Requirement 10 audit trail; 12.x documents policies; quarterly + annual evidence requirements.",
      "clauseRef": "PCI 10.x; 12.x",
      "sourceUrl": "https://www.pcisecuritystandards.org/document_library/"
    },
    {
      "framework": "pci-dss",
      "frameworkName": "PCI DSS 4.0",
      "frameworkType": "Industry standard",
      "jurisdiction": "Global (card-payment ecosystem)",
      "dimension": "access-security",
      "dimensionLabel": "Access control + security",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Requirements 7-9 cover access controls + physical security; requirement 8 MFA; requirement 4 cryptography.",
      "clauseRef": "PCI 7.x, 8.x, 9.x",
      "sourceUrl": "https://www.pcisecuritystandards.org/document_library/"
    },
    {
      "framework": "pci-dss",
      "frameworkName": "PCI DSS 4.0",
      "frameworkType": "Industry standard",
      "jurisdiction": "Global (card-payment ecosystem)",
      "dimension": "bias-fairness",
      "dimensionLabel": "Bias + fairness testing",
      "coverage": 0,
      "coverageLabel": "Not addressed",
      "summary": "Not addressed.",
      "clauseRef": "n/a",
      "sourceUrl": "https://www.pcisecuritystandards.org/document_library/"
    },
    {
      "framework": "pci-dss",
      "frameworkName": "PCI DSS 4.0",
      "frameworkType": "Industry standard",
      "jurisdiction": "Global (card-payment ecosystem)",
      "dimension": "training-awareness",
      "dimensionLabel": "Training + AI literacy",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Requirement 12.6 requires security-awareness training at least annually.",
      "clauseRef": "PCI 12.6",
      "sourceUrl": "https://www.pcisecuritystandards.org/document_library/"
    },
    {
      "framework": "pci-dss",
      "frameworkName": "PCI DSS 4.0",
      "frameworkType": "Industry standard",
      "jurisdiction": "Global (card-payment ecosystem)",
      "dimension": "rights-redress",
      "dimensionLabel": "Data-subject rights + redress",
      "coverage": 0,
      "coverageLabel": "Not addressed",
      "summary": "Not addressed.",
      "clauseRef": "n/a",
      "sourceUrl": "https://www.pcisecuritystandards.org/document_library/"
    },
    {
      "framework": "pci-dss",
      "frameworkName": "PCI DSS 4.0",
      "frameworkType": "Industry standard",
      "jurisdiction": "Global (card-payment ecosystem)",
      "dimension": "scope-applicability",
      "dimensionLabel": "Scope + applicability triggers",
      "coverage": 2,
      "coverageLabel": "Partial",
      "summary": "Triggered by storing, processing, or transmitting CHD / SAD; scope defined by CDE boundary.",
      "clauseRef": "Scope guidance",
      "sourceUrl": "https://www.pcisecuritystandards.org/document_library/"
    },
    {
      "framework": "fedramp",
      "frameworkName": "FedRAMP Moderate / High (Rev. 5)",
      "frameworkType": "Sectoral",
      "jurisdiction": "United States (federal government)",
      "dimension": "governance",
      "dimensionLabel": "Governance + accountability",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "PM family of controls (Program Management) requires senior official, plan, risk strategy; CA-1 / RA-1 policies.",
      "clauseRef": "PM-1, PM-2, PM-9; CA-1; RA-1",
      "sourceUrl": "https://www.fedramp.gov/"
    },
    {
      "framework": "fedramp",
      "frameworkName": "FedRAMP Moderate / High (Rev. 5)",
      "frameworkType": "Sectoral",
      "jurisdiction": "United States (federal government)",
      "dimension": "risk-management",
      "dimensionLabel": "Risk management process",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "RA-3 Risk Assessment, RA-7 Risk Response, PM-9 Risk Management Strategy across the system lifecycle.",
      "clauseRef": "RA-3; RA-7; PM-9",
      "sourceUrl": "https://www.fedramp.gov/"
    },
    {
      "framework": "fedramp",
      "frameworkName": "FedRAMP Moderate / High (Rev. 5)",
      "frameworkType": "Sectoral",
      "jurisdiction": "United States (federal government)",
      "dimension": "data-handling",
      "dimensionLabel": "Data handling + minimisation",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "MP family (Media Protection), SI-12 information handling and retention, AC-21 information sharing.",
      "clauseRef": "MP-1 to MP-8; SI-12; AC-21",
      "sourceUrl": "https://www.fedramp.gov/"
    },
    {
      "framework": "fedramp",
      "frameworkName": "FedRAMP Moderate / High (Rev. 5)",
      "frameworkType": "Sectoral",
      "jurisdiction": "United States (federal government)",
      "dimension": "model-lifecycle",
      "dimensionLabel": "Model lifecycle controls",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "SA family (System and Services Acquisition), SA-3 SDLC, SA-11 developer security testing.",
      "clauseRef": "SA-3; SA-8; SA-11; SA-15",
      "sourceUrl": "https://www.fedramp.gov/"
    },
    {
      "framework": "fedramp",
      "frameworkName": "FedRAMP Moderate / High (Rev. 5)",
      "frameworkType": "Sectoral",
      "jurisdiction": "United States (federal government)",
      "dimension": "transparency",
      "dimensionLabel": "Transparency + disclosure",
      "coverage": 2,
      "coverageLabel": "Partial",
      "summary": "PT family (Personally Identifiable Information Transparency); M-24-10 requires public AI use-case inventory for rights / safety-impacting AI.",
      "clauseRef": "PT-1 to PT-7; M-24-10 Sec. 4",
      "sourceUrl": "https://www.fedramp.gov/"
    },
    {
      "framework": "fedramp",
      "frameworkName": "FedRAMP Moderate / High (Rev. 5)",
      "frameworkType": "Sectoral",
      "jurisdiction": "United States (federal government)",
      "dimension": "human-oversight",
      "dimensionLabel": "Human oversight + intervention",
      "coverage": 2,
      "coverageLabel": "Partial",
      "summary": "M-24-10 Section 5 requires human consideration for rights / safety-impacting AI; no direct 800-53 control.",
      "clauseRef": "M-24-10 Sec. 5",
      "sourceUrl": "https://www.fedramp.gov/"
    },
    {
      "framework": "fedramp",
      "frameworkName": "FedRAMP Moderate / High (Rev. 5)",
      "frameworkType": "Sectoral",
      "jurisdiction": "United States (federal government)",
      "dimension": "monitoring",
      "dimensionLabel": "Post-market monitoring + drift",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "CA-7 Continuous Monitoring; AU-6 Audit Review; SI-4 System Monitoring; quarterly POAM updates.",
      "clauseRef": "CA-7; AU-6; SI-4",
      "sourceUrl": "https://www.fedramp.gov/"
    },
    {
      "framework": "fedramp",
      "frameworkName": "FedRAMP Moderate / High (Rev. 5)",
      "frameworkType": "Sectoral",
      "jurisdiction": "United States (federal government)",
      "dimension": "incident-response",
      "dimensionLabel": "Incident + serious-incident reporting",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "IR family (Incident Response) IR-1 to IR-10; reporting to US-CERT within 1 hour per OMB guidance.",
      "clauseRef": "IR-1 to IR-10",
      "sourceUrl": "https://www.fedramp.gov/"
    },
    {
      "framework": "fedramp",
      "frameworkName": "FedRAMP Moderate / High (Rev. 5)",
      "frameworkType": "Sectoral",
      "jurisdiction": "United States (federal government)",
      "dimension": "vendor-third-party",
      "dimensionLabel": "Vendor + third-party risk",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "SA-9 External System Services; SR family (Supply Chain Risk Management) added in Rev. 5.",
      "clauseRef": "SA-9; SR-1 to SR-12",
      "sourceUrl": "https://www.fedramp.gov/"
    },
    {
      "framework": "fedramp",
      "frameworkName": "FedRAMP Moderate / High (Rev. 5)",
      "frameworkType": "Sectoral",
      "jurisdiction": "United States (federal government)",
      "dimension": "audit-documentation",
      "dimensionLabel": "Audit trail + documentation",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "AU family (Audit and Accountability) AU-1 to AU-16; SSP, SAR, POAM artifacts required.",
      "clauseRef": "AU-1 to AU-16",
      "sourceUrl": "https://www.fedramp.gov/"
    },
    {
      "framework": "fedramp",
      "frameworkName": "FedRAMP Moderate / High (Rev. 5)",
      "frameworkType": "Sectoral",
      "jurisdiction": "United States (federal government)",
      "dimension": "access-security",
      "dimensionLabel": "Access control + security",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "AC, IA, SC families cover access, identification, system + communications protection.",
      "clauseRef": "AC-1 to AC-25; IA-1 to IA-12; SC-1 to SC-51",
      "sourceUrl": "https://www.fedramp.gov/"
    },
    {
      "framework": "fedramp",
      "frameworkName": "FedRAMP Moderate / High (Rev. 5)",
      "frameworkType": "Sectoral",
      "jurisdiction": "United States (federal government)",
      "dimension": "bias-fairness",
      "dimensionLabel": "Bias + fairness testing",
      "coverage": 1,
      "coverageLabel": "Mentioned",
      "summary": "Not in 800-53 directly; M-24-10 Sec. 5(c) requires equity / fairness assessment for rights-impacting AI.",
      "clauseRef": "M-24-10 Sec. 5(c)",
      "sourceUrl": "https://www.fedramp.gov/"
    },
    {
      "framework": "fedramp",
      "frameworkName": "FedRAMP Moderate / High (Rev. 5)",
      "frameworkType": "Sectoral",
      "jurisdiction": "United States (federal government)",
      "dimension": "training-awareness",
      "dimensionLabel": "Training + AI literacy",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "AT family (Awareness and Training) AT-1 to AT-6; role-based training requirement.",
      "clauseRef": "AT-1 to AT-6",
      "sourceUrl": "https://www.fedramp.gov/"
    },
    {
      "framework": "fedramp",
      "frameworkName": "FedRAMP Moderate / High (Rev. 5)",
      "frameworkType": "Sectoral",
      "jurisdiction": "United States (federal government)",
      "dimension": "rights-redress",
      "dimensionLabel": "Data-subject rights + redress",
      "coverage": 2,
      "coverageLabel": "Partial",
      "summary": "PT-2, PT-3 PII transparency; M-24-10 Sec. 5(d) opt-out / human alternative for rights-impacting AI.",
      "clauseRef": "PT-2; PT-3; M-24-10 Sec. 5(d)",
      "sourceUrl": "https://www.fedramp.gov/"
    },
    {
      "framework": "fedramp",
      "frameworkName": "FedRAMP Moderate / High (Rev. 5)",
      "frameworkType": "Sectoral",
      "jurisdiction": "United States (federal government)",
      "dimension": "scope-applicability",
      "dimensionLabel": "Scope + applicability triggers",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Cloud services for federal agencies; M-24-10 adds AI-specific obligations on agency AI use cases.",
      "clauseRef": "OMB Circular A-130; M-24-10",
      "sourceUrl": "https://www.fedramp.gov/"
    },
    {
      "framework": "singapore-mgf",
      "frameworkName": "Singapore Model AI Governance Framework + AI Verify",
      "frameworkType": "Voluntary",
      "jurisdiction": "Singapore (international reference)",
      "dimension": "governance",
      "dimensionLabel": "Governance + accountability",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "MGF Section 2 internal governance: senior management oversight, defined AI ethics committee, accountable role.",
      "clauseRef": "MGF Section 2",
      "sourceUrl": "https://www.imda.gov.sg/about-imda/emerging-technology-and-innovation/artificial-intelligence"
    },
    {
      "framework": "singapore-mgf",
      "frameworkName": "Singapore Model AI Governance Framework + AI Verify",
      "frameworkType": "Voluntary",
      "jurisdiction": "Singapore (international reference)",
      "dimension": "risk-management",
      "dimensionLabel": "Risk management process",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "MGF Section 3 decision-making framework + risk-impact assessment matrix tied to harm severity and probability.",
      "clauseRef": "MGF Section 3; AI Verify principle 5",
      "sourceUrl": "https://www.imda.gov.sg/about-imda/emerging-technology-and-innovation/artificial-intelligence"
    },
    {
      "framework": "singapore-mgf",
      "frameworkName": "Singapore Model AI Governance Framework + AI Verify",
      "frameworkType": "Voluntary",
      "jurisdiction": "Singapore (international reference)",
      "dimension": "data-handling",
      "dimensionLabel": "Data handling + minimisation",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "MGF Section 4(b) operations management of data; data quality, lineage, and minimisation.",
      "clauseRef": "MGF Section 4(b)",
      "sourceUrl": "https://www.imda.gov.sg/about-imda/emerging-technology-and-innovation/artificial-intelligence"
    },
    {
      "framework": "singapore-mgf",
      "frameworkName": "Singapore Model AI Governance Framework + AI Verify",
      "frameworkType": "Voluntary",
      "jurisdiction": "Singapore (international reference)",
      "dimension": "model-lifecycle",
      "dimensionLabel": "Model lifecycle controls",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "MGF Section 4 operations management spans development, testing, deployment, monitoring.",
      "clauseRef": "MGF Section 4",
      "sourceUrl": "https://www.imda.gov.sg/about-imda/emerging-technology-and-innovation/artificial-intelligence"
    },
    {
      "framework": "singapore-mgf",
      "frameworkName": "Singapore Model AI Governance Framework + AI Verify",
      "frameworkType": "Voluntary",
      "jurisdiction": "Singapore (international reference)",
      "dimension": "transparency",
      "dimensionLabel": "Transparency + disclosure",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "MGF Section 5 stakeholder interaction; AI Verify principle 8 transparency reports for tested models.",
      "clauseRef": "MGF Section 5; AI Verify principle 8",
      "sourceUrl": "https://www.imda.gov.sg/about-imda/emerging-technology-and-innovation/artificial-intelligence"
    },
    {
      "framework": "singapore-mgf",
      "frameworkName": "Singapore Model AI Governance Framework + AI Verify",
      "frameworkType": "Voluntary",
      "jurisdiction": "Singapore (international reference)",
      "dimension": "human-oversight",
      "dimensionLabel": "Human oversight + intervention",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "MGF Section 3 human-over-the-loop / human-in-the-loop / human-out-of-the-loop decision matrix.",
      "clauseRef": "MGF Section 3",
      "sourceUrl": "https://www.imda.gov.sg/about-imda/emerging-technology-and-innovation/artificial-intelligence"
    },
    {
      "framework": "singapore-mgf",
      "frameworkName": "Singapore Model AI Governance Framework + AI Verify",
      "frameworkType": "Voluntary",
      "jurisdiction": "Singapore (international reference)",
      "dimension": "monitoring",
      "dimensionLabel": "Post-market monitoring + drift",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "MGF Section 4(d) deployment and monitoring; periodic re-testing and review.",
      "clauseRef": "MGF Section 4(d)",
      "sourceUrl": "https://www.imda.gov.sg/about-imda/emerging-technology-and-innovation/artificial-intelligence"
    },
    {
      "framework": "singapore-mgf",
      "frameworkName": "Singapore Model AI Governance Framework + AI Verify",
      "frameworkType": "Voluntary",
      "jurisdiction": "Singapore (international reference)",
      "dimension": "incident-response",
      "dimensionLabel": "Incident + serious-incident reporting",
      "coverage": 2,
      "coverageLabel": "Partial",
      "summary": "MGF Section 5(b) crisis management; AI Verify includes incident escalation testing, but no statutory deadline.",
      "clauseRef": "MGF Section 5(b)",
      "sourceUrl": "https://www.imda.gov.sg/about-imda/emerging-technology-and-innovation/artificial-intelligence"
    },
    {
      "framework": "singapore-mgf",
      "frameworkName": "Singapore Model AI Governance Framework + AI Verify",
      "frameworkType": "Voluntary",
      "jurisdiction": "Singapore (international reference)",
      "dimension": "vendor-third-party",
      "dimensionLabel": "Vendor + third-party risk",
      "coverage": 2,
      "coverageLabel": "Partial",
      "summary": "MGF references third-party model use within Section 4 operations; AI Verify checks for supplier accountability.",
      "clauseRef": "MGF Section 4",
      "sourceUrl": "https://www.imda.gov.sg/about-imda/emerging-technology-and-innovation/artificial-intelligence"
    },
    {
      "framework": "singapore-mgf",
      "frameworkName": "Singapore Model AI Governance Framework + AI Verify",
      "frameworkType": "Voluntary",
      "jurisdiction": "Singapore (international reference)",
      "dimension": "audit-documentation",
      "dimensionLabel": "Audit trail + documentation",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "AI Verify generates a structured report including process and technical evidence; MGF Section 2 requires policy documentation.",
      "clauseRef": "AI Verify report; MGF Section 2",
      "sourceUrl": "https://www.imda.gov.sg/about-imda/emerging-technology-and-innovation/artificial-intelligence"
    },
    {
      "framework": "singapore-mgf",
      "frameworkName": "Singapore Model AI Governance Framework + AI Verify",
      "frameworkType": "Voluntary",
      "jurisdiction": "Singapore (international reference)",
      "dimension": "access-security",
      "dimensionLabel": "Access control + security",
      "coverage": 2,
      "coverageLabel": "Partial",
      "summary": "MGF Section 4(c) operations management security; AI Verify principle 10 security and robustness.",
      "clauseRef": "MGF Section 4(c); AI Verify principle 10",
      "sourceUrl": "https://www.imda.gov.sg/about-imda/emerging-technology-and-innovation/artificial-intelligence"
    },
    {
      "framework": "singapore-mgf",
      "frameworkName": "Singapore Model AI Governance Framework + AI Verify",
      "frameworkType": "Voluntary",
      "jurisdiction": "Singapore (international reference)",
      "dimension": "bias-fairness",
      "dimensionLabel": "Bias + fairness testing",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "AI Verify principle 7 fairness with quantitative testing; MGF Section 4(b) data quality including representativeness.",
      "clauseRef": "AI Verify principle 7; MGF Section 4(b)",
      "sourceUrl": "https://www.imda.gov.sg/about-imda/emerging-technology-and-innovation/artificial-intelligence"
    },
    {
      "framework": "singapore-mgf",
      "frameworkName": "Singapore Model AI Governance Framework + AI Verify",
      "frameworkType": "Voluntary",
      "jurisdiction": "Singapore (international reference)",
      "dimension": "training-awareness",
      "dimensionLabel": "Training + AI literacy",
      "coverage": 2,
      "coverageLabel": "Partial",
      "summary": "MGF Section 2 references training; less prescriptive than ISO 42001 or EU AI Act Article 4.",
      "clauseRef": "MGF Section 2",
      "sourceUrl": "https://www.imda.gov.sg/about-imda/emerging-technology-and-innovation/artificial-intelligence"
    },
    {
      "framework": "singapore-mgf",
      "frameworkName": "Singapore Model AI Governance Framework + AI Verify",
      "frameworkType": "Voluntary",
      "jurisdiction": "Singapore (international reference)",
      "dimension": "rights-redress",
      "dimensionLabel": "Data-subject rights + redress",
      "coverage": 2,
      "coverageLabel": "Partial",
      "summary": "MGF Section 5 stakeholder interaction includes channels for feedback and contestation.",
      "clauseRef": "MGF Section 5",
      "sourceUrl": "https://www.imda.gov.sg/about-imda/emerging-technology-and-innovation/artificial-intelligence"
    },
    {
      "framework": "singapore-mgf",
      "frameworkName": "Singapore Model AI Governance Framework + AI Verify",
      "frameworkType": "Voluntary",
      "jurisdiction": "Singapore (international reference)",
      "dimension": "scope-applicability",
      "dimensionLabel": "Scope + applicability triggers",
      "coverage": 1,
      "coverageLabel": "Mentioned",
      "summary": "Voluntary; binding only where MAS FEAT or sectoral regulators reference it.",
      "clauseRef": "MGF foreword",
      "sourceUrl": "https://www.imda.gov.sg/about-imda/emerging-technology-and-innovation/artificial-intelligence"
    },
    {
      "framework": "colorado-ai-act",
      "frameworkName": "Colorado AI Act (SB 24-205)",
      "frameworkType": "Regulatory",
      "jurisdiction": "Colorado, United States",
      "dimension": "governance",
      "dimensionLabel": "Governance + accountability",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Section 6-1-1703(3) deployers must implement a risk-management policy and program covering high-risk AI.",
      "clauseRef": "C.R.S. 6-1-1703(3)",
      "sourceUrl": "https://leg.colorado.gov/bills/sb24-205"
    },
    {
      "framework": "colorado-ai-act",
      "frameworkName": "Colorado AI Act (SB 24-205)",
      "frameworkType": "Regulatory",
      "jurisdiction": "Colorado, United States",
      "dimension": "risk-management",
      "dimensionLabel": "Risk management process",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Sections 6-1-1702(2) developer impact summary + 6-1-1703(2) deployer impact assessment annually + on substantial modification.",
      "clauseRef": "C.R.S. 6-1-1702(2); 6-1-1703(2)",
      "sourceUrl": "https://leg.colorado.gov/bills/sb24-205"
    },
    {
      "framework": "colorado-ai-act",
      "frameworkName": "Colorado AI Act (SB 24-205)",
      "frameworkType": "Regulatory",
      "jurisdiction": "Colorado, United States",
      "dimension": "data-handling",
      "dimensionLabel": "Data handling + minimisation",
      "coverage": 2,
      "coverageLabel": "Partial",
      "summary": "Section 6-1-1702(2)(a)(VIII) developer must disclose data used to train; 6-1-1703 referencing data evaluation.",
      "clauseRef": "C.R.S. 6-1-1702(2)(a)(VIII)",
      "sourceUrl": "https://leg.colorado.gov/bills/sb24-205"
    },
    {
      "framework": "colorado-ai-act",
      "frameworkName": "Colorado AI Act (SB 24-205)",
      "frameworkType": "Regulatory",
      "jurisdiction": "Colorado, United States",
      "dimension": "model-lifecycle",
      "dimensionLabel": "Model lifecycle controls",
      "coverage": 2,
      "coverageLabel": "Partial",
      "summary": "Developer (1702) covers training-data + intended uses; deployer (1703) covers deployment and monitoring.",
      "clauseRef": "C.R.S. 6-1-1702; 6-1-1703",
      "sourceUrl": "https://leg.colorado.gov/bills/sb24-205"
    },
    {
      "framework": "colorado-ai-act",
      "frameworkName": "Colorado AI Act (SB 24-205)",
      "frameworkType": "Regulatory",
      "jurisdiction": "Colorado, United States",
      "dimension": "transparency",
      "dimensionLabel": "Transparency + disclosure",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Section 6-1-1703(4) deployer notice to consumers before / after consequential decision; explanation right.",
      "clauseRef": "C.R.S. 6-1-1703(4)",
      "sourceUrl": "https://leg.colorado.gov/bills/sb24-205"
    },
    {
      "framework": "colorado-ai-act",
      "frameworkName": "Colorado AI Act (SB 24-205)",
      "frameworkType": "Regulatory",
      "jurisdiction": "Colorado, United States",
      "dimension": "human-oversight",
      "dimensionLabel": "Human oversight + intervention",
      "coverage": 2,
      "coverageLabel": "Partial",
      "summary": "Section 6-1-1703(4)(b) consumer right to correction + appeal opportunity, implying human review path.",
      "clauseRef": "C.R.S. 6-1-1703(4)(b)",
      "sourceUrl": "https://leg.colorado.gov/bills/sb24-205"
    },
    {
      "framework": "colorado-ai-act",
      "frameworkName": "Colorado AI Act (SB 24-205)",
      "frameworkType": "Regulatory",
      "jurisdiction": "Colorado, United States",
      "dimension": "monitoring",
      "dimensionLabel": "Post-market monitoring + drift",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Section 6-1-1703(2)(c) annual impact assessment; ongoing review for algorithmic discrimination.",
      "clauseRef": "C.R.S. 6-1-1703(2)(c)",
      "sourceUrl": "https://leg.colorado.gov/bills/sb24-205"
    },
    {
      "framework": "colorado-ai-act",
      "frameworkName": "Colorado AI Act (SB 24-205)",
      "frameworkType": "Regulatory",
      "jurisdiction": "Colorado, United States",
      "dimension": "incident-response",
      "dimensionLabel": "Incident + serious-incident reporting",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Section 6-1-1703(7) deployer must notify Attorney General within 90 days of discovering algorithmic discrimination.",
      "clauseRef": "C.R.S. 6-1-1703(7)",
      "sourceUrl": "https://leg.colorado.gov/bills/sb24-205"
    },
    {
      "framework": "colorado-ai-act",
      "frameworkName": "Colorado AI Act (SB 24-205)",
      "frameworkType": "Regulatory",
      "jurisdiction": "Colorado, United States",
      "dimension": "vendor-third-party",
      "dimensionLabel": "Vendor + third-party risk",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Section 6-1-1702 developer obligations flow to deployers via documentation requirements; deployer relies on developer disclosures.",
      "clauseRef": "C.R.S. 6-1-1702(2)(b)",
      "sourceUrl": "https://leg.colorado.gov/bills/sb24-205"
    },
    {
      "framework": "colorado-ai-act",
      "frameworkName": "Colorado AI Act (SB 24-205)",
      "frameworkType": "Regulatory",
      "jurisdiction": "Colorado, United States",
      "dimension": "audit-documentation",
      "dimensionLabel": "Audit trail + documentation",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Section 6-1-1703(2)(c) impact assessment documentation retained for at least 3 years.",
      "clauseRef": "C.R.S. 6-1-1703(2)(c)",
      "sourceUrl": "https://leg.colorado.gov/bills/sb24-205"
    },
    {
      "framework": "colorado-ai-act",
      "frameworkName": "Colorado AI Act (SB 24-205)",
      "frameworkType": "Regulatory",
      "jurisdiction": "Colorado, United States",
      "dimension": "access-security",
      "dimensionLabel": "Access control + security",
      "coverage": 1,
      "coverageLabel": "Mentioned",
      "summary": "Not the focus; reasonable-care duty implies appropriate safeguards.",
      "clauseRef": "C.R.S. 6-1-1701 general",
      "sourceUrl": "https://leg.colorado.gov/bills/sb24-205"
    },
    {
      "framework": "colorado-ai-act",
      "frameworkName": "Colorado AI Act (SB 24-205)",
      "frameworkType": "Regulatory",
      "jurisdiction": "Colorado, United States",
      "dimension": "bias-fairness",
      "dimensionLabel": "Bias + fairness testing",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Core duty: avoid algorithmic discrimination defined in Section 6-1-1701(1).",
      "clauseRef": "C.R.S. 6-1-1701(1)",
      "sourceUrl": "https://leg.colorado.gov/bills/sb24-205"
    },
    {
      "framework": "colorado-ai-act",
      "frameworkName": "Colorado AI Act (SB 24-205)",
      "frameworkType": "Regulatory",
      "jurisdiction": "Colorado, United States",
      "dimension": "training-awareness",
      "dimensionLabel": "Training + AI literacy",
      "coverage": 1,
      "coverageLabel": "Mentioned",
      "summary": "Implicit in reasonable-care standard; not separately enumerated.",
      "clauseRef": "general",
      "sourceUrl": "https://leg.colorado.gov/bills/sb24-205"
    },
    {
      "framework": "colorado-ai-act",
      "frameworkName": "Colorado AI Act (SB 24-205)",
      "frameworkType": "Regulatory",
      "jurisdiction": "Colorado, United States",
      "dimension": "rights-redress",
      "dimensionLabel": "Data-subject rights + redress",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Section 6-1-1703(4) consumer right to know, right to correct data, right to appeal.",
      "clauseRef": "C.R.S. 6-1-1703(4)",
      "sourceUrl": "https://leg.colorado.gov/bills/sb24-205"
    },
    {
      "framework": "colorado-ai-act",
      "frameworkName": "Colorado AI Act (SB 24-205)",
      "frameworkType": "Regulatory",
      "jurisdiction": "Colorado, United States",
      "dimension": "scope-applicability",
      "dimensionLabel": "Scope + applicability triggers",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Binds developers + deployers of high-risk AI affecting Colorado consumers; small-business deployer exemption with conditions.",
      "clauseRef": "C.R.S. 6-1-1703(6) exemption",
      "sourceUrl": "https://leg.colorado.gov/bills/sb24-205"
    },
    {
      "framework": "nist-genai-profile",
      "frameworkName": "NIST AI 600-1 Generative AI Profile",
      "frameworkType": "Voluntary",
      "jurisdiction": "United States (international reference)",
      "dimension": "governance",
      "dimensionLabel": "Governance + accountability",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "GV-1.x through GV-6.x extend AI RMF GOVERN with GenAI-specific roles and senior leadership accountability.",
      "clauseRef": "GV-1.1 to GV-6.2",
      "sourceUrl": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf"
    },
    {
      "framework": "nist-genai-profile",
      "frameworkName": "NIST AI 600-1 Generative AI Profile",
      "frameworkType": "Voluntary",
      "jurisdiction": "United States (international reference)",
      "dimension": "risk-management",
      "dimensionLabel": "Risk management process",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Profile is a risk overlay; 12 GenAI risk categories drive MAP / MEASURE / MANAGE actions.",
      "clauseRef": "Section 2; Section 3",
      "sourceUrl": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf"
    },
    {
      "framework": "nist-genai-profile",
      "frameworkName": "NIST AI 600-1 Generative AI Profile",
      "frameworkType": "Voluntary",
      "jurisdiction": "United States (international reference)",
      "dimension": "data-handling",
      "dimensionLabel": "Data handling + minimisation",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "MP-2.3 + MS-2.10 + MG-3.x explicitly cover training-data provenance, IP, privacy, and synthetic-data risks.",
      "clauseRef": "MP-2.3; MS-2.10; MG-3.x",
      "sourceUrl": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf"
    },
    {
      "framework": "nist-genai-profile",
      "frameworkName": "NIST AI 600-1 Generative AI Profile",
      "frameworkType": "Voluntary",
      "jurisdiction": "United States (international reference)",
      "dimension": "model-lifecycle",
      "dimensionLabel": "Model lifecycle controls",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Full lifecycle, with GenAI-specific actions for pre-training, fine-tuning, prompt-engineering, evaluation, deployment.",
      "clauseRef": "MP-2.x; MS-2.x; MG-2.x",
      "sourceUrl": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf"
    },
    {
      "framework": "nist-genai-profile",
      "frameworkName": "NIST AI 600-1 Generative AI Profile",
      "frameworkType": "Voluntary",
      "jurisdiction": "United States (international reference)",
      "dimension": "transparency",
      "dimensionLabel": "Transparency + disclosure",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "GV-1.3, MP-5.x, MS-2.8 cover model cards, system cards, synthetic-content labelling and provenance.",
      "clauseRef": "MS-2.8; MS-2.5",
      "sourceUrl": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf"
    },
    {
      "framework": "nist-genai-profile",
      "frameworkName": "NIST AI 600-1 Generative AI Profile",
      "frameworkType": "Voluntary",
      "jurisdiction": "United States (international reference)",
      "dimension": "human-oversight",
      "dimensionLabel": "Human oversight + intervention",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Human-AI Configuration is one of the 12 named risks; actions across MG-2.x mitigate over-reliance.",
      "clauseRef": "Risk Category 12; MG-2.x",
      "sourceUrl": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf"
    },
    {
      "framework": "nist-genai-profile",
      "frameworkName": "NIST AI 600-1 Generative AI Profile",
      "frameworkType": "Voluntary",
      "jurisdiction": "United States (international reference)",
      "dimension": "monitoring",
      "dimensionLabel": "Post-market monitoring + drift",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "MG-4.1 + MS-3.x cover continuous monitoring, drift, and red-team cadence for GenAI.",
      "clauseRef": "MG-4.x; MS-3.x",
      "sourceUrl": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf"
    },
    {
      "framework": "nist-genai-profile",
      "frameworkName": "NIST AI 600-1 Generative AI Profile",
      "frameworkType": "Voluntary",
      "jurisdiction": "United States (international reference)",
      "dimension": "incident-response",
      "dimensionLabel": "Incident + serious-incident reporting",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "MG-3.x + MG-4.1 include incident-response workflows specific to confabulation, IP, and dangerous content.",
      "clauseRef": "MG-3.x; MG-4.1",
      "sourceUrl": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf"
    },
    {
      "framework": "nist-genai-profile",
      "frameworkName": "NIST AI 600-1 Generative AI Profile",
      "frameworkType": "Voluntary",
      "jurisdiction": "United States (international reference)",
      "dimension": "vendor-third-party",
      "dimensionLabel": "Vendor + third-party risk",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Value Chain + Component Integration is risk category 10; GV-6.x extends third-party AI risk governance to GenAI.",
      "clauseRef": "Risk Category 10; GV-6.x",
      "sourceUrl": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf"
    },
    {
      "framework": "nist-genai-profile",
      "frameworkName": "NIST AI 600-1 Generative AI Profile",
      "frameworkType": "Voluntary",
      "jurisdiction": "United States (international reference)",
      "dimension": "audit-documentation",
      "dimensionLabel": "Audit trail + documentation",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "MS-2.8 documentation; MS-1.3 evidence retention; specific GenAI evaluation evidence.",
      "clauseRef": "MS-1.3; MS-2.8",
      "sourceUrl": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf"
    },
    {
      "framework": "nist-genai-profile",
      "frameworkName": "NIST AI 600-1 Generative AI Profile",
      "frameworkType": "Voluntary",
      "jurisdiction": "United States (international reference)",
      "dimension": "access-security",
      "dimensionLabel": "Access control + security",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Information Security risk category 8; MG-2.x mitigations across prompt-injection, jailbreaks, model exfiltration.",
      "clauseRef": "Risk Category 8; MG-2.x",
      "sourceUrl": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf"
    },
    {
      "framework": "nist-genai-profile",
      "frameworkName": "NIST AI 600-1 Generative AI Profile",
      "frameworkType": "Voluntary",
      "jurisdiction": "United States (international reference)",
      "dimension": "bias-fairness",
      "dimensionLabel": "Bias + fairness testing",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Harmful Bias and Homogenization risk category 11; MS-2.11 GenAI bias evaluation actions.",
      "clauseRef": "Risk Category 11; MS-2.11",
      "sourceUrl": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf"
    },
    {
      "framework": "nist-genai-profile",
      "frameworkName": "NIST AI 600-1 Generative AI Profile",
      "frameworkType": "Voluntary",
      "jurisdiction": "United States (international reference)",
      "dimension": "training-awareness",
      "dimensionLabel": "Training + AI literacy",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "GV-2.x extends AI RMF training requirements with GenAI-specific role training and content review training.",
      "clauseRef": "GV-2.x",
      "sourceUrl": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf"
    },
    {
      "framework": "nist-genai-profile",
      "frameworkName": "NIST AI 600-1 Generative AI Profile",
      "frameworkType": "Voluntary",
      "jurisdiction": "United States (international reference)",
      "dimension": "rights-redress",
      "dimensionLabel": "Data-subject rights + redress",
      "coverage": 1,
      "coverageLabel": "Mentioned",
      "summary": "Affected-stakeholder feedback in MP-1.x; no enforceable individual rights.",
      "clauseRef": "MP-1.x",
      "sourceUrl": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf"
    },
    {
      "framework": "nist-genai-profile",
      "frameworkName": "NIST AI 600-1 Generative AI Profile",
      "frameworkType": "Voluntary",
      "jurisdiction": "United States (international reference)",
      "dimension": "scope-applicability",
      "dimensionLabel": "Scope + applicability triggers",
      "coverage": 1,
      "coverageLabel": "Mentioned",
      "summary": "Voluntary; becomes binding via federal AI procurement, EO 14110 references, or contract.",
      "clauseRef": "Section 1 (Audience)",
      "sourceUrl": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf"
    },
    {
      "framework": "nyc-ll144",
      "frameworkName": "NYC Local Law 144 (Automated Employment Decision Tools)",
      "frameworkType": "Sectoral",
      "jurisdiction": "New York City, United States",
      "dimension": "governance",
      "dimensionLabel": "Governance + accountability",
      "coverage": 1,
      "coverageLabel": "Mentioned",
      "summary": "Implicit: employer is accountable for ensuring bias audit and notices; no internal-governance prescription.",
      "clauseRef": "DCWP Rule 5-300",
      "sourceUrl": "https://rules.cityofnewyork.us/wp-content/uploads/2023/04/DCWP-NOA-for-Use-of-Automated-Employment-Decisionmaking-Tools-2.pdf"
    },
    {
      "framework": "nyc-ll144",
      "frameworkName": "NYC Local Law 144 (Automated Employment Decision Tools)",
      "frameworkType": "Sectoral",
      "jurisdiction": "New York City, United States",
      "dimension": "risk-management",
      "dimensionLabel": "Risk management process",
      "coverage": 1,
      "coverageLabel": "Mentioned",
      "summary": "Not a risk-management framework. Compliance is bias-audit + notice.",
      "clauseRef": "general",
      "sourceUrl": "https://rules.cityofnewyork.us/wp-content/uploads/2023/04/DCWP-NOA-for-Use-of-Automated-Employment-Decisionmaking-Tools-2.pdf"
    },
    {
      "framework": "nyc-ll144",
      "frameworkName": "NYC Local Law 144 (Automated Employment Decision Tools)",
      "frameworkType": "Sectoral",
      "jurisdiction": "New York City, United States",
      "dimension": "data-handling",
      "dimensionLabel": "Data handling + minimisation",
      "coverage": 1,
      "coverageLabel": "Mentioned",
      "summary": "Bias audit requires categorical data for subjects; otherwise no data-handling prescription.",
      "clauseRef": "5-301 audit data",
      "sourceUrl": "https://rules.cityofnewyork.us/wp-content/uploads/2023/04/DCWP-NOA-for-Use-of-Automated-Employment-Decisionmaking-Tools-2.pdf"
    },
    {
      "framework": "nyc-ll144",
      "frameworkName": "NYC Local Law 144 (Automated Employment Decision Tools)",
      "frameworkType": "Sectoral",
      "jurisdiction": "New York City, United States",
      "dimension": "model-lifecycle",
      "dimensionLabel": "Model lifecycle controls",
      "coverage": 1,
      "coverageLabel": "Mentioned",
      "summary": "Substantial modifications trigger a new bias audit before continued use.",
      "clauseRef": "5-301(a)",
      "sourceUrl": "https://rules.cityofnewyork.us/wp-content/uploads/2023/04/DCWP-NOA-for-Use-of-Automated-Employment-Decisionmaking-Tools-2.pdf"
    },
    {
      "framework": "nyc-ll144",
      "frameworkName": "NYC Local Law 144 (Automated Employment Decision Tools)",
      "frameworkType": "Sectoral",
      "jurisdiction": "New York City, United States",
      "dimension": "transparency",
      "dimensionLabel": "Transparency + disclosure",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Public summary of bias audit on employer site; written notice to candidates 10 business days in advance.",
      "clauseRef": "5-302; 5-303",
      "sourceUrl": "https://rules.cityofnewyork.us/wp-content/uploads/2023/04/DCWP-NOA-for-Use-of-Automated-Employment-Decisionmaking-Tools-2.pdf"
    },
    {
      "framework": "nyc-ll144",
      "frameworkName": "NYC Local Law 144 (Automated Employment Decision Tools)",
      "frameworkType": "Sectoral",
      "jurisdiction": "New York City, United States",
      "dimension": "human-oversight",
      "dimensionLabel": "Human oversight + intervention",
      "coverage": 2,
      "coverageLabel": "Partial",
      "summary": "Tool must not be sole basis under broader EEOC guidance; LL144 itself constrains automated tools that substantially assist decisions.",
      "clauseRef": "Local Law 144 Sec. 1",
      "sourceUrl": "https://rules.cityofnewyork.us/wp-content/uploads/2023/04/DCWP-NOA-for-Use-of-Automated-Employment-Decisionmaking-Tools-2.pdf"
    },
    {
      "framework": "nyc-ll144",
      "frameworkName": "NYC Local Law 144 (Automated Employment Decision Tools)",
      "frameworkType": "Sectoral",
      "jurisdiction": "New York City, United States",
      "dimension": "monitoring",
      "dimensionLabel": "Post-market monitoring + drift",
      "coverage": 2,
      "coverageLabel": "Partial",
      "summary": "Annual bias audit required before continued use; substantial modification triggers re-audit.",
      "clauseRef": "5-301(a)",
      "sourceUrl": "https://rules.cityofnewyork.us/wp-content/uploads/2023/04/DCWP-NOA-for-Use-of-Automated-Employment-Decisionmaking-Tools-2.pdf"
    },
    {
      "framework": "nyc-ll144",
      "frameworkName": "NYC Local Law 144 (Automated Employment Decision Tools)",
      "frameworkType": "Sectoral",
      "jurisdiction": "New York City, United States",
      "dimension": "incident-response",
      "dimensionLabel": "Incident + serious-incident reporting",
      "coverage": 0,
      "coverageLabel": "Not addressed",
      "summary": "Not addressed in LL144 itself.",
      "clauseRef": "n/a",
      "sourceUrl": "https://rules.cityofnewyork.us/wp-content/uploads/2023/04/DCWP-NOA-for-Use-of-Automated-Employment-Decisionmaking-Tools-2.pdf"
    },
    {
      "framework": "nyc-ll144",
      "frameworkName": "NYC Local Law 144 (Automated Employment Decision Tools)",
      "frameworkType": "Sectoral",
      "jurisdiction": "New York City, United States",
      "dimension": "vendor-third-party",
      "dimensionLabel": "Vendor + third-party risk",
      "coverage": 2,
      "coverageLabel": "Partial",
      "summary": "Employer may rely on vendor bias-audit if the employer can show the AEDT was independently audited; LL144 documentation flows from vendor.",
      "clauseRef": "5-301; 5-302",
      "sourceUrl": "https://rules.cityofnewyork.us/wp-content/uploads/2023/04/DCWP-NOA-for-Use-of-Automated-Employment-Decisionmaking-Tools-2.pdf"
    },
    {
      "framework": "nyc-ll144",
      "frameworkName": "NYC Local Law 144 (Automated Employment Decision Tools)",
      "frameworkType": "Sectoral",
      "jurisdiction": "New York City, United States",
      "dimension": "audit-documentation",
      "dimensionLabel": "Audit trail + documentation",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Independent annual bias audit + public summary, available for at least 6 months from posting.",
      "clauseRef": "5-301; 5-302",
      "sourceUrl": "https://rules.cityofnewyork.us/wp-content/uploads/2023/04/DCWP-NOA-for-Use-of-Automated-Employment-Decisionmaking-Tools-2.pdf"
    },
    {
      "framework": "nyc-ll144",
      "frameworkName": "NYC Local Law 144 (Automated Employment Decision Tools)",
      "frameworkType": "Sectoral",
      "jurisdiction": "New York City, United States",
      "dimension": "access-security",
      "dimensionLabel": "Access control + security",
      "coverage": 0,
      "coverageLabel": "Not addressed",
      "summary": "Not addressed.",
      "clauseRef": "n/a",
      "sourceUrl": "https://rules.cityofnewyork.us/wp-content/uploads/2023/04/DCWP-NOA-for-Use-of-Automated-Employment-Decisionmaking-Tools-2.pdf"
    },
    {
      "framework": "nyc-ll144",
      "frameworkName": "NYC Local Law 144 (Automated Employment Decision Tools)",
      "frameworkType": "Sectoral",
      "jurisdiction": "New York City, United States",
      "dimension": "bias-fairness",
      "dimensionLabel": "Bias + fairness testing",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Core obligation: annual bias audit computing selection-rate / impact-ratio by sex, race / ethnicity, and intersectional categories.",
      "clauseRef": "5-301",
      "sourceUrl": "https://rules.cityofnewyork.us/wp-content/uploads/2023/04/DCWP-NOA-for-Use-of-Automated-Employment-Decisionmaking-Tools-2.pdf"
    },
    {
      "framework": "nyc-ll144",
      "frameworkName": "NYC Local Law 144 (Automated Employment Decision Tools)",
      "frameworkType": "Sectoral",
      "jurisdiction": "New York City, United States",
      "dimension": "training-awareness",
      "dimensionLabel": "Training + AI literacy",
      "coverage": 0,
      "coverageLabel": "Not addressed",
      "summary": "Not addressed.",
      "clauseRef": "n/a",
      "sourceUrl": "https://rules.cityofnewyork.us/wp-content/uploads/2023/04/DCWP-NOA-for-Use-of-Automated-Employment-Decisionmaking-Tools-2.pdf"
    },
    {
      "framework": "nyc-ll144",
      "frameworkName": "NYC Local Law 144 (Automated Employment Decision Tools)",
      "frameworkType": "Sectoral",
      "jurisdiction": "New York City, United States",
      "dimension": "rights-redress",
      "dimensionLabel": "Data-subject rights + redress",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Candidate notice + opportunity to request information about data type, source, and retention.",
      "clauseRef": "5-303",
      "sourceUrl": "https://rules.cityofnewyork.us/wp-content/uploads/2023/04/DCWP-NOA-for-Use-of-Automated-Employment-Decisionmaking-Tools-2.pdf"
    },
    {
      "framework": "nyc-ll144",
      "frameworkName": "NYC Local Law 144 (Automated Employment Decision Tools)",
      "frameworkType": "Sectoral",
      "jurisdiction": "New York City, United States",
      "dimension": "scope-applicability",
      "dimensionLabel": "Scope + applicability triggers",
      "coverage": 3,
      "coverageLabel": "Explicit",
      "summary": "Triggered when an AEDT is used to substantially assist or replace discretionary employment decisions on NYC residents.",
      "clauseRef": "Local Law 144 Sec. 20-870",
      "sourceUrl": "https://rules.cityofnewyork.us/wp-content/uploads/2023/04/DCWP-NOA-for-Use-of-Automated-Employment-Decisionmaking-Tools-2.pdf"
    }
  ]
}