Taking longer than expected.
Reload the pageTaking longer than expected.
Reload the pageOpen reference data
A clause-by-clause crosswalk of 12 AI governance frameworks across 15 governance dimensions - 180 cells, 171 of them carrying a direct article, control or clause reference. Free to read, free to reuse with attribution.
Last reviewed 31 July 2026· Licensed CC BY 4.0
| Framework | Type | Jurisdiction | In force | Maximum penalty |
|---|---|---|---|---|
| NIST AI Risk Management Framework 1.0 | Voluntary | United States (international reference) | January 26, 2023 | No direct penalty (voluntary); becomes contractually binding via federal procurement and customer demands |
| ISO/IEC 42001:2023 AI Management System | Industry standard | International | December 18, 2023 | Certification withdrawal; no statutory penalty |
| EU AI Act (Regulation 2024/1689) | Regulatory | European Union (extraterritorial) | August 1, 2024 (staggered through August 2, 2027) | Up to EUR 35 million or 7% of global turnover (Article 99) |
| SOC 2 Trust Services Criteria | Industry standard | United States (de-facto international) | Continuously updated (2017 TSC + 2022 points of focus) | No statutory penalty; failed audit blocks customer procurement |
| HIPAA Privacy + Security Rules | Sectoral | United States (healthcare) | Privacy Rule 2003; Security Rule 2005; HITECH 2009 | USD 137 to USD 2,067,813 per violation; criminal up to 10 years (45 CFR 160.404, 42 USC 1320d-6) |
| GDPR (Regulation 2016/679, Articles 22, 25, 35) | Regulatory | European Union + EEA (extraterritorial via Article 3) | May 25, 2018 | Up to EUR 20 million or 4% global turnover (Article 83) |
| PCI DSS 4.0 | Industry standard | Global (card-payment ecosystem) | March 31, 2024 (4.0 mandatory); future-dated requirements by March 31, 2025 | USD 5,000 - USD 100,000 per month of non-compliance; card-brand fines + acquirer fees |
| FedRAMP Moderate / High (Rev. 5) | Sectoral | United States (federal government) | Rev. 5 baselines published May 2023; AI memo M-24-10 March 2024 | Contract termination; no procurement eligibility |
| Singapore Model AI Governance Framework + AI Verify | Voluntary | Singapore (international reference) | MGF 2.0 published 2024; AI Verify Toolkit 2023 | No direct penalty; sectoral regulators (e.g. MAS) treat alignment as expected |
| Colorado AI Act (SB 24-205) | Regulatory | Colorado, United States | February 1, 2026 | Unfair trade practice under Colorado Consumer Protection Act; up to USD 20,000 per violation |
| NIST AI 600-1 Generative AI Profile | Voluntary | United States (international reference) | July 26, 2024 | No direct penalty; binding via federal procurement or referenced statutes |
| NYC Local Law 144 (Automated Employment Decision Tools) | Sectoral | New York City, United States | Enforcement began July 5, 2023 | USD 500 - USD 1,500 per violation per day |
One section per governance dimension. Each row states how a framework treats that dimension and cites the specific clause, so the claim can be checked against the source text rather than taken on trust.
Whether the framework requires a named owner, board-level oversight, or written governance structure for AI.
| Framework | Coverage | What it requires | Clause |
|---|---|---|---|
| NIST AI RMF | Explicit | GOVERN-1 through GOVERN-6 require policies, roles, accountability structures, and board-level oversight for AI risk. | GOVERN 1.1-6.2 |
| ISO 42001 | Explicit | Clauses 5.1-5.3 require leadership commitment, AI policy, and assigned organisational roles for the AIMS. | Clauses 5.1-5.3; A.2.x |
| EU AI Act | Explicit | Article 17 requires a quality management system for high-risk providers; deployers need internal governance under Article 26. | Articles 17, 26 |
| SOC 2 | Explicit | CC1.1-CC1.5 require commitment to integrity, board oversight, structure / authority, competence, and accountability. | CC1.1-CC1.5 |
| HIPAA | Explicit | 164.308(a)(2) requires assigned Security Official; 164.530(a) requires Privacy Official and contact person. | 45 CFR 164.308(a)(2); 164.530(a) |
| GDPR | Explicit | Article 37 requires a Data Protection Officer for public bodies and large-scale processors; Article 24 controller responsibility. | Articles 24, 37 |
| PCI-DSS 4.0 | Partial | Requirement 12 maintains an information-security policy; 12.1 establishes responsibility, 12.4 manages program. | PCI 12.1-12.4 |
| FedRAMP | Explicit | PM family of controls (Program Management) requires senior official, plan, risk strategy; CA-1 / RA-1 policies. | PM-1, PM-2, PM-9; CA-1; RA-1 |
| Singapore MGF | Explicit | MGF Section 2 internal governance: senior management oversight, defined AI ethics committee, accountable role. | MGF Section 2 |
| Colorado AI Act | Explicit | Section 6-1-1703(3) deployers must implement a risk-management policy and program covering high-risk AI. | C.R.S. 6-1-1703(3) |
| NIST GenAI Profile | Explicit | GV-1.x through GV-6.x extend AI RMF GOVERN with GenAI-specific roles and senior leadership accountability. | GV-1.1 to GV-6.2 |
| NYC LL144 | Mentioned | Implicit: employer is accountable for ensuring bias audit and notices; no internal-governance prescription. | DCWP Rule 5-300 |
Whether a structured risk-identification, assessment, and treatment lifecycle is required.
| Framework | Coverage | What it requires | Clause |
|---|---|---|---|
| NIST AI RMF | Explicit | MAP, MEASURE, MANAGE functions are explicitly a risk-identification, measurement, and treatment lifecycle. | MAP 1.1-5.2; MEASURE 1.1-4.3; MANAGE 1.1-4.3 |
| ISO 42001 | Explicit | Clause 6.1 requires AI risk assessment, treatment, and AI system impact assessment (Annex A.5). | Clause 6.1; A.5.1-A.5.5 |
| EU AI Act | Explicit | Article 9 mandates a risk management system across the lifecycle of high-risk AI systems. | Article 9 |
| SOC 2 | Explicit | CC3.1-CC3.4 require risk identification, fraud risk, change in environment, and risk-response selection. | CC3.1-CC3.4 |
| HIPAA | Explicit | 164.308(a)(1)(ii) requires a Risk Analysis and Risk Management process. | 45 CFR 164.308(a)(1) |
| GDPR | Explicit | Article 35 DPIA required for high-risk processing (profiling, large-scale special category, systematic monitoring). | Article 35 |
| PCI-DSS 4.0 | Partial | Requirement 12.3 introduces Targeted Risk Analysis for customised-approach controls. | PCI 12.3 |
| FedRAMP | Explicit | RA-3 Risk Assessment, RA-7 Risk Response, PM-9 Risk Management Strategy across the system lifecycle. | RA-3; RA-7; PM-9 |
| Singapore MGF | Explicit | MGF Section 3 decision-making framework + risk-impact assessment matrix tied to harm severity and probability. | MGF Section 3; AI Verify principle 5 |
| Colorado AI Act | Explicit | Sections 6-1-1702(2) developer impact summary + 6-1-1703(2) deployer impact assessment annually + on substantial modification. | C.R.S. 6-1-1702(2); 6-1-1703(2) |
| NIST GenAI Profile | Explicit | Profile is a risk overlay; 12 GenAI risk categories drive MAP / MEASURE / MANAGE actions. | Section 2; Section 3 |
| NYC LL144 | Mentioned | Not a risk-management framework. Compliance is bias-audit + notice. | general |
Whether the framework constrains personal / sensitive data use, residency, retention, or training-data sourcing.
| Framework | Coverage | What it requires | Clause |
|---|---|---|---|
| NIST AI RMF | Partial | MAP-2 requires categorising data sources; MEASURE-2.10 requires evaluating privacy risks; no specific residency rules. | MAP 2.x; MEASURE 2.10 |
| ISO 42001 | Explicit | Annex A.7 governs data for AI systems: provenance, quality, preparation, and data-management plans. | A.7.1-A.7.6 |
| EU AI Act | Explicit | Article 10 sets quality, governance, and bias-testing requirements for training, validation, and test datasets. | Article 10 |
| SOC 2 | Partial | Confidentiality criteria C1.1-C1.2 cover identification, retention, destruction; Privacy criteria address PII; AI-specific data sourcing not explicit. | C1.1-C1.2; P1-P8 (Privacy) |
| HIPAA | Explicit | 164.502(b) minimum necessary; 164.514(d) standards; 164.514(b) de-identification; restrictions on training-data use. | 45 CFR 164.502(b); 164.514 |
| GDPR | Explicit | Article 5 principles (lawfulness, minimisation, accuracy, storage limitation, integrity); Articles 6, 9 lawful basis. | Articles 5, 6, 9 |
| PCI-DSS 4.0 | Explicit | Requirements 3.1-3.7 govern protection of stored CHD; requirements 4.x cover transmission. | PCI 3.x, 4.x |
| FedRAMP | Explicit | MP family (Media Protection), SI-12 information handling and retention, AC-21 information sharing. | MP-1 to MP-8; SI-12; AC-21 |
| Singapore MGF | Explicit | MGF Section 4(b) operations management of data; data quality, lineage, and minimisation. | MGF Section 4(b) |
| Colorado AI Act | Partial | Section 6-1-1702(2)(a)(VIII) developer must disclose data used to train; 6-1-1703 referencing data evaluation. | C.R.S. 6-1-1702(2)(a)(VIII) |
| NIST GenAI Profile | Explicit | MP-2.3 + MS-2.10 + MG-3.x explicitly cover training-data provenance, IP, privacy, and synthetic-data risks. | MP-2.3; MS-2.10; MG-3.x |
| NYC LL144 | Mentioned | Bias audit requires categorical data for subjects; otherwise no data-handling prescription. | 5-301 audit data |
Whether design, testing, validation, deployment, and retirement of AI models is governed.
| Framework | Coverage | What it requires | Clause |
|---|---|---|---|
| NIST AI RMF | Explicit | Full lifecycle is the framework: design (MAP), build and test (MEASURE), deploy and retire (MANAGE). | Entire framework |
| ISO 42001 | Explicit | Annex A.6 covers AI system lifecycle: design, development, verification, deployment, operation, retirement. | A.6.1-A.6.2 |
| EU AI Act | Explicit | Article 9, 11, 17 cover risk management, technical documentation, and quality management across lifecycle. | Articles 9, 11, 17 |
| SOC 2 | Mentioned | CC8.1 covers change management; not AI-specific. Model training and validation handled implicitly through change controls. | CC8.1 |
| HIPAA | Mentioned | Not AI-specific. Security Rule covers system development implicitly through risk analysis on systems handling PHI. | 164.308 (general) |
| GDPR | Partial | Article 25 requires data protection by design and default; Article 32 security of processing across lifecycle. | Articles 25, 32 |
| PCI-DSS 4.0 | Mentioned | Not AI-specific. Requirement 6 covers secure software development for any in-scope system. | PCI 6.x |
| FedRAMP | Explicit | SA family (System and Services Acquisition), SA-3 SDLC, SA-11 developer security testing. | SA-3; SA-8; SA-11; SA-15 |
| Singapore MGF | Explicit | MGF Section 4 operations management spans development, testing, deployment, monitoring. | MGF Section 4 |
| Colorado AI Act | Partial | Developer (1702) covers training-data + intended uses; deployer (1703) covers deployment and monitoring. | C.R.S. 6-1-1702; 6-1-1703 |
| NIST GenAI Profile | Explicit | Full lifecycle, with GenAI-specific actions for pre-training, fine-tuning, prompt-engineering, evaluation, deployment. | MP-2.x; MS-2.x; MG-2.x |
| NYC LL144 | Mentioned | Substantial modifications trigger a new bias audit before continued use. | 5-301(a) |
Whether the framework requires user-facing notice, model cards, or downstream documentation.
| Framework | Coverage | What it requires | Clause |
|---|---|---|---|
| NIST AI RMF | Explicit | Transparent and accountable is a top-level characteristic; MEASURE-2.8 calls for transparency artifacts (model / system cards). | Section 3.5; MEASURE 2.8 |
| ISO 42001 | Explicit | Annex A.8 requires information for interested parties: system documentation, user docs, intended use. | A.8.1-A.8.5 |
| EU AI Act | Explicit | Article 13 (high-risk) and Article 50 (chatbots, synthetic content) impose user-disclosure obligations; Article 53 covers GPAI documentation. | Articles 13, 50, 53 |
| SOC 2 | Partial | CC2.1-CC2.3 require communication of objectives and quality information; Privacy P1.1 requires notice. No AI disclosure obligation. | CC2.1-CC2.3; P1.1 |
| HIPAA | Partial | 164.520 requires a Notice of Privacy Practices; no AI disclosure obligation, but FDA guidance applies to clinical AI. | 45 CFR 164.520 |
| GDPR | Explicit | Articles 13-14 provide information; Article 22(3) requires meaningful information about automated decision logic. | Articles 13, 14, 22(3) |
| PCI-DSS 4.0 | Not addressed | Not addressed. PCI DSS does not require user-facing AI disclosure. | n/a |
| FedRAMP | Partial | PT family (Personally Identifiable Information Transparency); M-24-10 requires public AI use-case inventory for rights / safety-impacting AI. | PT-1 to PT-7; M-24-10 Sec. 4 |
| Singapore MGF | Explicit | MGF Section 5 stakeholder interaction; AI Verify principle 8 transparency reports for tested models. | MGF Section 5; AI Verify principle 8 |
| Colorado AI Act | Explicit | Section 6-1-1703(4) deployer notice to consumers before / after consequential decision; explanation right. | C.R.S. 6-1-1703(4) |
| NIST GenAI Profile | Explicit | GV-1.3, MP-5.x, MS-2.8 cover model cards, system cards, synthetic-content labelling and provenance. | MS-2.8; MS-2.5 |
| NYC LL144 | Explicit | Public summary of bias audit on employer site; written notice to candidates 10 business days in advance. | 5-302; 5-303 |
Whether human-in-the-loop, contestability, or human review of automated decisions is required.
| Framework | Coverage | What it requires | Clause |
|---|---|---|---|
| NIST AI RMF | Partial | Safe, secure, resilient, accountable characteristics imply human oversight; MANAGE-2.3 covers human-AI configurations. | MANAGE 2.3; Section 3.5 |
| ISO 42001 | Explicit | Annex A.9 requires human oversight and use of AI systems by humans in a defined manner. | A.9.1-A.9.4 |
| EU AI Act | Explicit | Article 14 mandates effective human oversight for high-risk AI; specific roles per Article 26 for deployers. | Articles 14, 26 |
| SOC 2 | Mentioned | No direct human-oversight criterion; CC5.x activities are control activities driven by people, but not AI specific. | CC5.1-CC5.3 |
| HIPAA | Mentioned | Not explicit. Implicitly required where automated tools affect treatment, payment, or operations through workforce-control standard. | 164.530(b) |
| GDPR | Explicit | Article 22(3) right to obtain human intervention, express point of view, contest the decision. | Article 22(3) |
| PCI-DSS 4.0 | Not addressed | Not addressed. | n/a |
| FedRAMP | Partial | M-24-10 Section 5 requires human consideration for rights / safety-impacting AI; no direct 800-53 control. | M-24-10 Sec. 5 |
| Singapore MGF | Explicit | MGF Section 3 human-over-the-loop / human-in-the-loop / human-out-of-the-loop decision matrix. | MGF Section 3 |
| Colorado AI Act | Partial | Section 6-1-1703(4)(b) consumer right to correction + appeal opportunity, implying human review path. | C.R.S. 6-1-1703(4)(b) |
| NIST GenAI Profile | Explicit | Human-AI Configuration is one of the 12 named risks; actions across MG-2.x mitigate over-reliance. | Risk Category 12; MG-2.x |
| NYC LL144 | Partial | Tool must not be sole basis under broader EEOC guidance; LL144 itself constrains automated tools that substantially assist decisions. | Local Law 144 Sec. 1 |
Whether continuous monitoring, drift detection, or post-deployment surveillance is required.
| Framework | Coverage | What it requires | Clause |
|---|---|---|---|
| NIST AI RMF | Explicit | MANAGE-4.1 requires post-deployment monitoring; MEASURE-2.6 requires evaluation throughout the lifecycle. | MANAGE 4.1-4.3; MEASURE 2.6 |
| ISO 42001 | Explicit | Clause 9.1 + A.6.2 require performance monitoring, evaluation, and operational measurement of AI systems. | Clause 9.1; A.6.2.5-A.6.2.6 |
| EU AI Act | Explicit | Article 72 requires a post-market monitoring system for high-risk providers, with documented plan. | Article 72 |
| SOC 2 | Explicit | CC4.1-CC4.2 require ongoing and separate evaluation, and communication of deficiencies. | CC4.1-CC4.2 |
| HIPAA | Partial | 164.308(a)(1)(ii)(D) requires Information System Activity Review; periodic, not continuous. | 45 CFR 164.308(a)(1)(ii)(D) |
| GDPR | Partial | Article 35(11) DPIA review where processing operations change; ongoing controller obligation under Article 24. | Articles 24, 35(11) |
| PCI-DSS 4.0 | Explicit | Requirement 10 covers logging, monitoring, and time-synced audit; 11.x covers testing. | PCI 10.x, 11.x |
| FedRAMP | Explicit | CA-7 Continuous Monitoring; AU-6 Audit Review; SI-4 System Monitoring; quarterly POAM updates. | CA-7; AU-6; SI-4 |
| Singapore MGF | Explicit | MGF Section 4(d) deployment and monitoring; periodic re-testing and review. | MGF Section 4(d) |
| Colorado AI Act | Explicit | Section 6-1-1703(2)(c) annual impact assessment; ongoing review for algorithmic discrimination. | C.R.S. 6-1-1703(2)(c) |
| NIST GenAI Profile | Explicit | MG-4.1 + MS-3.x cover continuous monitoring, drift, and red-team cadence for GenAI. | MG-4.x; MS-3.x |
| NYC LL144 | Partial | Annual bias audit required before continued use; substantial modification triggers re-audit. | 5-301(a) |
Whether incidents must be detected, escalated, and reported to a regulator within a defined window.
| Framework | Coverage | What it requires | Clause |
|---|---|---|---|
| NIST AI RMF | Partial | MANAGE-4.3 covers ongoing monitoring and incident response; no mandatory reporting window. | MANAGE 4.3 |
| ISO 42001 | Partial | Clauses 10.1-10.2 require nonconformity correction; defers to ISO 27001 incident-response for security incidents. | Clauses 10.1-10.2 |
| EU AI Act | Explicit | Article 73 requires serious-incident reporting to the market surveillance authority within 15 days (immediately for fatalities or critical infrastructure). | Article 73 |
| SOC 2 | Explicit | CC7.3-CC7.5 require incident-management process: detection, response, evaluation, communication, recovery. | CC7.3-CC7.5 |
| HIPAA | Explicit | 164.308(a)(6) requires security-incident procedures; 164.400s require breach notification to HHS within 60 days. | 45 CFR 164.308(a)(6); 164.400-414 |
| GDPR | Explicit | Article 33 requires breach notification to supervisory authority within 72 hours; Article 34 to data subjects. | Articles 33, 34 |
| PCI-DSS 4.0 | Explicit | Requirement 12.10 requires incident-response plan, testing, training, and revision. | PCI 12.10 |
| FedRAMP | Explicit | IR family (Incident Response) IR-1 to IR-10; reporting to US-CERT within 1 hour per OMB guidance. | IR-1 to IR-10 |
| Singapore MGF | Partial | MGF Section 5(b) crisis management; AI Verify includes incident escalation testing, but no statutory deadline. | MGF Section 5(b) |
| Colorado AI Act | Explicit | Section 6-1-1703(7) deployer must notify Attorney General within 90 days of discovering algorithmic discrimination. | C.R.S. 6-1-1703(7) |
| NIST GenAI Profile | Explicit | MG-3.x + MG-4.1 include incident-response workflows specific to confabulation, IP, and dangerous content. | MG-3.x; MG-4.1 |
| NYC LL144 | Not addressed | Not addressed in LL144 itself. | n/a |
Whether due diligence on AI vendors, sub-processors, and foundation-model providers is required.
| Framework | Coverage | What it requires | Clause |
|---|---|---|---|
| NIST AI RMF | Explicit | GOVERN-6.1 and GOVERN-6.2 require third-party AI risk policies and due diligence. | GOVERN 6.1-6.2 |
| ISO 42001 | Explicit | Annex A.10 governs third-party + customer relationships, supplier responsibilities, customer obligations. | A.10.1-A.10.4 |
| EU AI Act | Explicit | Article 25 (provider becoming deployer / change of role) and Article 28 (importers and distributors due diligence). | Articles 25, 28 |
| SOC 2 | Explicit | CC9.2 explicitly requires vendor and business partner risk management. | CC9.2 |
| HIPAA | Explicit | 164.504(e) Business Associate Contract is a hard requirement before disclosing PHI to a vendor. | 45 CFR 164.504(e) |
| GDPR | Explicit | Article 28 requires a written contract (DPA) with processors; Article 28(2)-28(4) constrain sub-processors. | Article 28 |
| PCI-DSS 4.0 | Explicit | Requirement 12.8 governs service-provider relationships including written acknowledgement of PCI responsibilities. | PCI 12.8 |
| FedRAMP | Explicit | SA-9 External System Services; SR family (Supply Chain Risk Management) added in Rev. 5. | SA-9; SR-1 to SR-12 |
| Singapore MGF | Partial | MGF references third-party model use within Section 4 operations; AI Verify checks for supplier accountability. | MGF Section 4 |
| Colorado AI Act | Explicit | Section 6-1-1702 developer obligations flow to deployers via documentation requirements; deployer relies on developer disclosures. | C.R.S. 6-1-1702(2)(b) |
| NIST GenAI Profile | Explicit | Value Chain + Component Integration is risk category 10; GV-6.x extends third-party AI risk governance to GenAI. | Risk Category 10; GV-6.x |
| NYC LL144 | Partial | Employer may rely on vendor bias-audit if the employer can show the AEDT was independently audited; LL144 documentation flows from vendor. | 5-301; 5-302 |
Whether immutable logs, technical documentation, or evidence retention are required.
| Framework | Coverage | What it requires | Clause |
|---|---|---|---|
| NIST AI RMF | Explicit | MAP-1.6 and MEASURE-2.8 require documented assumptions, decisions, and evaluation results. | MAP 1.6; MEASURE 2.8 |
| ISO 42001 | Explicit | Clause 7.5 requires documented information; Clause 9.2 internal audit; Clause 9.3 management review. | Clauses 7.5, 9.2, 9.3 |
| EU AI Act | Explicit | Articles 11-12 require technical documentation (Annex IV) and automated logging for high-risk AI systems. | Articles 11, 12; Annex IV |
| SOC 2 | Explicit | Whole framework is audit-oriented; CC4.x requires monitoring activities and CC4.2 communicates deficiencies. | CC4.1-CC4.2; full TSC |
| HIPAA | Explicit | 164.312(b) audit controls (mechanism to record + examine activity); 164.530(j) 6-year documentation retention. | 45 CFR 164.312(b); 164.530(j) |
| GDPR | Explicit | Article 30 record of processing activities; Article 5(2) accountability principle; Article 24 demonstrable compliance. | Articles 5(2), 24, 30 |
| PCI-DSS 4.0 | Explicit | Requirement 10 audit trail; 12.x documents policies; quarterly + annual evidence requirements. | PCI 10.x; 12.x |
| FedRAMP | Explicit | AU family (Audit and Accountability) AU-1 to AU-16; SSP, SAR, POAM artifacts required. | AU-1 to AU-16 |
| Singapore MGF | Explicit | AI Verify generates a structured report including process and technical evidence; MGF Section 2 requires policy documentation. | AI Verify report; MGF Section 2 |
| Colorado AI Act | Explicit | Section 6-1-1703(2)(c) impact assessment documentation retained for at least 3 years. | C.R.S. 6-1-1703(2)(c) |
| NIST GenAI Profile | Explicit | MS-2.8 documentation; MS-1.3 evidence retention; specific GenAI evaluation evidence. | MS-1.3; MS-2.8 |
| NYC LL144 | Explicit | Independent annual bias audit + public summary, available for at least 6 months from posting. | 5-301; 5-302 |
Whether identity, access, encryption, key management, and infrastructure security are required.
| Framework | Coverage | What it requires | Clause |
|---|---|---|---|
| NIST AI RMF | Partial | Secure, resilient characteristic + MEASURE-2.7 covers security and resilience; defers to NIST SP 800-53 for controls. | MEASURE 2.7; Section 3.5 |
| ISO 42001 | Partial | Defers heavily to ISO 27001; A.6.2.7 covers security of AI systems; A.4.5 resources include data security. | A.6.2.7; references ISO 27001 |
| EU AI Act | Explicit | Article 15 requires accuracy, robustness, and cybersecurity for high-risk AI systems. | Article 15 |
| SOC 2 | Explicit | CC6.1-CC6.8 cover logical and physical access, authentication, encryption, and infrastructure protection. | CC6.1-CC6.8 |
| HIPAA | Explicit | 164.308, 164.310, 164.312 cover administrative, physical, and technical safeguards including encryption (addressable). | 45 CFR 164.308-312 |
| GDPR | Explicit | Article 32 requires appropriate technical and organisational measures including pseudonymisation and encryption. | Article 32 |
| PCI-DSS 4.0 | Explicit | Requirements 7-9 cover access controls + physical security; requirement 8 MFA; requirement 4 cryptography. | PCI 7.x, 8.x, 9.x |
| FedRAMP | Explicit | AC, IA, SC families cover access, identification, system + communications protection. | AC-1 to AC-25; IA-1 to IA-12; SC-1 to SC-51 |
| Singapore MGF | Partial | MGF Section 4(c) operations management security; AI Verify principle 10 security and robustness. | MGF Section 4(c); AI Verify principle 10 |
| Colorado AI Act | Mentioned | Not the focus; reasonable-care duty implies appropriate safeguards. | C.R.S. 6-1-1701 general |
| NIST GenAI Profile | Explicit | Information Security risk category 8; MG-2.x mitigations across prompt-injection, jailbreaks, model exfiltration. | Risk Category 8; MG-2.x |
| NYC LL144 | Not addressed | Not addressed. | n/a |
Whether bias audits, fairness metrics, or disparate-impact testing are required.
| Framework | Coverage | What it requires | Clause |
|---|---|---|---|
| NIST AI RMF | Explicit | Fair-with-harmful-bias-managed is a top characteristic; MEASURE-2.11 requires bias evaluation and supplemental AI 1270. | MEASURE 2.11; NIST SP 1270 |
| ISO 42001 | Partial | A.7.4 requires data-quality including representativeness; A.6.2.4 verification covers fairness as a quality criterion. | A.7.4; A.6.2.4 |
| EU AI Act | Explicit | Article 10(5) requires bias detection and correction; Article 27 introduces fundamental-rights impact assessment for some deployers. | Articles 10(5), 27 |
| SOC 2 | Not addressed | Not addressed. SOC 2 does not require fairness or bias testing. | n/a |
| HIPAA | Not addressed | Not addressed. ONC has issued separate algorithmic-transparency rule for certified EHR developers (HTI-1). | n/a |
| GDPR | Partial | Article 5(1)(a) lawful, fair, transparent; Recital 71 calls out discrimination prevention in profiling. | Article 5(1)(a); Recital 71 |
| PCI-DSS 4.0 | Not addressed | Not addressed. | n/a |
| FedRAMP | Mentioned | Not in 800-53 directly; M-24-10 Sec. 5(c) requires equity / fairness assessment for rights-impacting AI. | M-24-10 Sec. 5(c) |
| Singapore MGF | Explicit | AI Verify principle 7 fairness with quantitative testing; MGF Section 4(b) data quality including representativeness. | AI Verify principle 7; MGF Section 4(b) |
| Colorado AI Act | Explicit | Core duty: avoid algorithmic discrimination defined in Section 6-1-1701(1). | C.R.S. 6-1-1701(1) |
| NIST GenAI Profile | Explicit | Harmful Bias and Homogenization risk category 11; MS-2.11 GenAI bias evaluation actions. | Risk Category 11; MS-2.11 |
| NYC LL144 | Explicit | Core obligation: annual bias audit computing selection-rate / impact-ratio by sex, race / ethnicity, and intersectional categories. | 5-301 |
Whether staff training, AI literacy, or operator competence is required.
| Framework | Coverage | What it requires | Clause |
|---|---|---|---|
| NIST AI RMF | Partial | GOVERN-2.2 and GOVERN-3.2 require training on AI risk roles and risk-aware culture. | GOVERN 2.2; GOVERN 3.2 |
| ISO 42001 | Explicit | Clauses 7.2-7.3 require competence and awareness specifically for AI-related roles. | Clauses 7.2-7.3 |
| EU AI Act | Explicit | Article 4 (AI literacy) requires providers and deployers to ensure staff operating AI have sufficient AI literacy. | Article 4 |
| SOC 2 | Partial | CC1.4 requires competence; CC2.x requires communication. Security awareness training is standard practice but not enumerated for AI literacy. | CC1.4; CC2.x |
| HIPAA | Explicit | 164.308(a)(5) requires workforce security-awareness and training program. | 45 CFR 164.308(a)(5) |
| GDPR | Partial | Article 39(1)(b) DPO duty to monitor compliance and awareness-raising / training of staff. | Article 39(1)(b) |
| PCI-DSS 4.0 | Explicit | Requirement 12.6 requires security-awareness training at least annually. | PCI 12.6 |
| FedRAMP | Explicit | AT family (Awareness and Training) AT-1 to AT-6; role-based training requirement. | AT-1 to AT-6 |
| Singapore MGF | Partial | MGF Section 2 references training; less prescriptive than ISO 42001 or EU AI Act Article 4. | MGF Section 2 |
| Colorado AI Act | Mentioned | Implicit in reasonable-care standard; not separately enumerated. | general |
| NIST GenAI Profile | Explicit | GV-2.x extends AI RMF training requirements with GenAI-specific role training and content review training. | GV-2.x |
| NYC LL144 | Not addressed | Not addressed. | n/a |
Whether affected individuals have rights to explanation, contest, or human review.
| Framework | Coverage | What it requires | Clause |
|---|---|---|---|
| NIST AI RMF | Mentioned | Concept of redress in Section 3.5 (accountable + transparent), but no enforceable individual rights. | Section 3.5 |
| ISO 42001 | Partial | A.9.3 + A.10.4 cover users + customers receiving information and being able to contest outcomes. | A.9.3; A.10.4 |
| EU AI Act | Explicit | Article 86 grants affected persons a right to explanation of decisions; Article 85 a right to lodge complaints. | Articles 85, 86 |
| SOC 2 | Partial | Privacy criteria P5.1-P5.2 cover individual rights of access and correction. No automated-decision rights. | P5.1-P5.2 |
| HIPAA | Explicit | 164.524-528 grant access, amendment, and accounting of disclosures rights to patients. | 45 CFR 164.524-528 |
| GDPR | Explicit | Articles 15-22 grant access, rectification, erasure, portability, object, and Article 22 automated-decision rights. | Articles 15-22 |
| PCI-DSS 4.0 | Not addressed | Not addressed. | n/a |
| FedRAMP | Partial | PT-2, PT-3 PII transparency; M-24-10 Sec. 5(d) opt-out / human alternative for rights-impacting AI. | PT-2; PT-3; M-24-10 Sec. 5(d) |
| Singapore MGF | Partial | MGF Section 5 stakeholder interaction includes channels for feedback and contestation. | MGF Section 5 |
| Colorado AI Act | Explicit | Section 6-1-1703(4) consumer right to know, right to correct data, right to appeal. | C.R.S. 6-1-1703(4) |
| NIST GenAI Profile | Mentioned | Affected-stakeholder feedback in MP-1.x; no enforceable individual rights. | MP-1.x |
| NYC LL144 | Explicit | Candidate notice + opportunity to request information about data type, source, and retention. | 5-303 |
Who the framework binds, with what jurisdictional reach, and what triggers compliance.
| Framework | Coverage | What it requires | Clause |
|---|---|---|---|
| NIST AI RMF | Mentioned | Voluntary across any AI system and any organisation; becomes binding only via procurement contracts or referenced statutes. | Section 2; Foreword |
| ISO 42001 | Partial | Voluntary certifiable standard; binding only when adopted by an organisation or required by customer / regulator. | Clause 1; Clause 4 |
| EU AI Act | Explicit | Article 2 extraterritorially binds providers and deployers when output is used in the EU. | Article 2 |
| SOC 2 | Partial | Voluntary attestation chosen by service organisations; customer contracts make it effectively binding. | Engagement scope |
| HIPAA | Explicit | Binds covered entities and business associates handling PHI; defined by 45 CFR 160.103. | 45 CFR 160.103 |
| GDPR | Explicit | Article 3 extraterritorial: applies when controller / processor offers goods or services to EU data subjects or monitors their behaviour. | Article 3 |
| PCI-DSS 4.0 | Partial | Triggered by storing, processing, or transmitting CHD / SAD; scope defined by CDE boundary. | Scope guidance |
| FedRAMP | Explicit | Cloud services for federal agencies; M-24-10 adds AI-specific obligations on agency AI use cases. | OMB Circular A-130; M-24-10 |
| Singapore MGF | Mentioned | Voluntary; binding only where MAS FEAT or sectoral regulators reference it. | MGF foreword |
| Colorado AI Act | Explicit | Binds developers + deployers of high-risk AI affecting Colorado consumers; small-business deployer exemption with conditions. | C.R.S. 6-1-1703(6) exemption |
| NIST GenAI Profile | Mentioned | Voluntary; becomes binding via federal AI procurement, EO 14110 references, or contract. | Section 1 (Audience) |
| NYC LL144 | Explicit | Triggered when an AEDT is used to substantially assist or replace discretionary employment decisions on NYC residents. | Local Law 144 Sec. 20-870 |
Coverage is rated on a four-point scale: explicit (the framework directly mandates it), partial (addressed, but narrower than the dimension implies), mentioned (referenced without a concrete obligation), and not addressed. Ratings are our reading of the source text, and the clause reference is included in every cell precisely so you can disagree with us and check.
This is a comparison of what each framework requires. It is not legal advice, and it does not tell you which framework applies to your organisation - scope triggers differ, and several of these apply simultaneously.
Frameworks change. This matrix was last reviewed on 31 July 2026. Where a framework has staggered commencement dates, the “in force” column gives the range rather than a single date.
Areebi AI Governance Framework Matrix - https://www.areebi.com/resources/ai-framework-matrix. Last reviewed 31 July 2026. Licensed CC BY 4.0.
Reuse it, chart it, embed it in a board pack - attribution is the only condition. The CSV and JSON carry the same data.
A detailed comparison of the NIST AI Risk Management Framework and ISO/IEC 42001. Scope, certifiability, audit model, structure, governance coverage, technical lifecycle coverage, when to use one vs the other vs both, and how Areebi maps to each.
Read moreGuideAn auditor-grade mapping of AICPA Trust Services Criteria to LLM systems. Covers CC6 logical access for inference endpoints, CC7 incident management for prompt injection and drift, A1 inference availability, PI1 output integrity, and P1-P8 privacy of training data.
Read moreGuideA detailed 12-month roadmap to ISO/IEC 42001:2023 certification for AI Management Systems (AIMS). Four phases mapped to months 1-12 covering scope and gap analysis, policy and risk management, operations and monitoring, and audit preparation through Stage 1 and Stage 2. Comparison to ISO/IEC 27001 (overlap and differences), NIST AI RMF crosswalk, and a practical accreditation-body shortlist (ANSI/UL, BSI, DNV, SGS).
Read moreGuideAn 87-question RFP template for AI Control Plane evaluation, mapped to NIST AI 600-1, ISO 42001, SOC 2, EU AI Act, Gartner TRiSM, and ENISA AI threat landscape references.
Read moreGuideAn opinionated OKR template for CISOs running an AI governance programme in 2026. Twelve quarterly objectives covering policy coverage, control implementation, vendor management, training, incident response, and regulatory readiness - each tied to a NIST AI 600-1 function, ISO/IEC 42001:2023 control, or EU AI Act article, with a default first-quarter target a programme manager can adopt without redrafting.
Read moreComplianceHow to comply with the NIST AI Risk Management Framework. Map AI RMF core functions - Govern, Map, Measure, Manage - to enterprise controls with Areebi.
Read more