Free Consultation
Home › AI governance framework landscape

The AI governance framework landscape

72 major AI governance laws, standards, frameworks and assurance instruments — what each one covers, how it differs from the ones next to it, and which of them this platform can actually evaluate your systems against. Reviewed 2026-08-30.

Instruments tracked
72
With executable rules
38
Tracked, not yet mapped
34
Review date
2026-08-30

What "covered" honestly means

Most vendors publish a single count of frameworks "supported". That number conflates two very different things: instruments a platform can check your system against, and instruments it has heard of. These are separated here, and the separation is the point.

Rules mapped
38 · 53%
Used elsewhere
3 · 4%
Named, not separate
3 · 4%
Tracked, not mapped
28 · 39%
StatusCountWhat it means
Rules mapped 38 A full entry in the regulation catalogue, with executable requirements this platform evaluates your systems against.
Used elsewhere 3 Used by the platform outside the regulation catalogue — in the risk methodology or the threat matrix — but not as a rules-carrying entry.
Named, not separate 3 Named inside another framework's description rather than tracked as its own assessable instrument.
Tracked, not mapped 28 Part of the tracked landscape with no rule mapping yet. Not a claim that nothing internally maps to it.

"Tracked, not mapped" is not a claim that nothing internally maps to an instrument. It means there is no standalone, executable entry for it — so this page does not pretend there is.

What gets mapped next, and why

The expansion order below comes from the source comparison's own recommendations, not from what would be quickest to add. Each of these needs real requirement mapping against the primary text before it can move to "Rules mapped" — an entry with invented requirements would be worse than no entry.

PriorityInstruments
P0
Immediate — closes a gap enterprises are asked about today
NIST AI 600-1 — Generative AI Profile
ISO/IEC 38507:2022 — Governance implications of AI
ISO/IEC 42005:2025 — AI System Impact Assessment
Singapore Model AI Governance Framework for Generative AI
Singapore Model AI Governance Framework for Agentic AI (v1.5, 2026)
AI Verify — AI Governance Testing Framework
EU General-Purpose AI Code of Practice (2025)
P1
Next — broadens international and lifecycle coverage
ISO/IEC 5338:2023 — AI system life cycle processes
ISO/IEC 5259-5:2025 — Data quality governance for analytics and ML
ISO/IEC TR 24027:2021 — Bias in AI systems
ISO/IEC TR 24028:2020 — Trustworthiness in AI
UNESCO Recommendation on the Ethics of Artificial Intelligence
Council of Europe Framework Convention on AI, Human Rights, Democracy and Rule of Law
Council of Europe HUDERIA Methodology
G7 Hiroshima AI Process Comprehensive Policy Framework / Code of Conduct
Hiroshima AI Process Reporting Framework
Japan AI Guidelines for Business Ver. 1.2 (2026)
Australia Guidance for AI Adoption (2025)
India AI Governance Guidelines (2025)
P2
Later — depth on practical baselines and engineering standards
IEEE/ISO/IEC 24748-7000:2022 — Ethical concerns during system design
IEEE 7001-2021 — Transparency of Autonomous Systems
IEEE 7003-2024 — Algorithmic Bias Considerations
UK AI Management Essentials (AIME)
UK AI Cyber Security Code of Practice
UK Algorithmic Transparency Recording Standard (ATRS)

Binding law & regulation · 23

Enforceable statutes, regulations and supervisory rules.

1 EU Artificial Intelligence Act (Regulation (EU) 2024/1689)

Rules mapped

Binding law — EU / extraterritorial

What it covers. Risk-tiered horizontal AI law covering prohibited practices, high-risk systems, transparency and general-purpose AI obligations.

How it differs. Unlike NIST or ISO, it is legally enforceable and attaches duties to provider/deployer roles, conformity assessment and market access.

What it means here. No catalog gap. Keep implementation mappings current as delegated acts, codes and transition dates evolve.  ·  See its mapped requirements →  ·  Source

2 General Data Protection Regulation (GDPR)

Rules mapped

Binding law — EU / EEA

What it covers. Personal-data governance, lawful processing, profiling and safeguards around automated decisions.

How it differs. It governs personal data rather than AI as a technology; an AI system can be compliant with the AI Act yet still fail GDPR duties.

What it means here. No catalog gap. Maintain explicit crosswalks between AI lifecycle controls, DPIAs and automated-decision safeguards.  ·  See its mapped requirements →  ·  Source

3 Illinois Biometric Information Privacy Act (BIPA)

Rules mapped

Binding law — Illinois, USA

What it covers. Consent, notice, retention and handling of biometric identifiers and information.

How it differs. Much narrower than broad AI frameworks, but materially higher litigation exposure because it targets biometric processing specifically.

What it means here. No catalog gap. Keep biometric-use-case triggers separate from general AI risk scoring.  ·  See its mapped requirements →  ·  Source

4 Illinois HB 3773 — AI in Employment (IHRA amendment)

Rules mapped

Binding law — Illinois, USA

What it covers. Employment use of AI, notice and discrimination-related duties.

How it differs. A domain-specific employment rule; it does not provide an enterprise-wide AI management system.

What it means here. No catalog gap. Map it to hiring controls, bias testing, notice and HR escalation workflows.  ·  See its mapped requirements →  ·  Source

5 Brazilian AI Bill (PL 2338/2023)

Rules mapped

Proposed / evolving law — Brazil

What it covers. National risk-based AI governance proposal with rights, duties and risk classification.

How it differs. Comparable in ambition to the EU AI Act but jurisdiction-specific and still dependent on legislative evolution.

What it means here. No catalog gap, but clearly label proposal/enactment status and refresh promptly when the legal text changes.  ·  See its mapped requirements →  ·  Source

6 California CCPA/CPRA ADMT Regulations + AB 2013

Rules mapped

Law / regulation — California, USA

What it covers. Automated decision-making/privacy obligations plus training-data transparency requirements for generative AI developers.

How it differs. Combines privacy/consumer-rights controls with AI transparency rather than creating a single comprehensive AI management law.

What it means here. No catalog gap. Separate privacy/ADMT duties from developer transparency evidence.  ·  See its mapped requirements →  ·  Source

7 Ontario AI Hiring Disclosure + Bill 194

Rules mapped

Law / public-sector and employment rules — Ontario, Canada

What it covers. AI-related hiring disclosure and public-sector digital/AI transparency and accountability requirements.

How it differs. Sector/use-case specific; narrower than ISO 42001 or NIST and more prescriptive for covered Ontario activities.

What it means here. No catalog gap. Maintain jurisdiction and organization-type applicability logic.  ·  See its mapped requirements →  ·  Source

8 Quebec Law 25 — Automated Decision-Making

Rules mapped

Binding privacy law — Quebec, Canada

What it covers. Notice and transparency duties for decisions based exclusively on automated processing, with privacy governance requirements.

How it differs. Focused on individual privacy and automated decisions rather than full AI lifecycle governance.

What it means here. No catalog gap. Link to privacy impact assessments and human-review/redress controls.  ·  See its mapped requirements →  ·  Source

9 Canada Directive on Automated Decision-Making + Algorithmic Impact Assessment

Rules mapped

Binding government directive — Canada — federal institutions

What it covers. Algorithmic Impact Assessment, transparency, explanation, testing and oversight for federal automated decision systems.

How it differs. Public-sector-specific and impact-level driven; it is not a private-sector enterprise framework.

What it means here. No catalog gap. Keep AIA scoring and required mitigation evidence as a distinct workflow.  ·  See its mapped requirements →  ·  Source

10 PIPEDA + OPC Generative-AI Principles

Rules mapped

Law + regulatory guidance — Canada — federal private sector

What it covers. Privacy, consent, accountability, transparency and responsible handling of personal information in AI/GenAI.

How it differs. Privacy-centric rather than a full AI risk/management system.

What it means here. No catalog gap. Crosswalk to data governance, privacy notices, consent and vendor data-use controls.  ·  See its mapped requirements →  ·  Source

15 China Algorithm, Deep Synthesis & Generative AI Measures

Rules mapped

Binding regulations — China

What it covers. Algorithm recommendation, deep synthesis and generative-AI service duties including content, security, labeling and provider controls.

How it differs. More service/content-control oriented than NIST/ISO and highly jurisdiction-specific.

What it means here. No catalog gap. Keep separate control families for algorithm filing, content, labeling and security assessments.  ·  See its mapped requirements →  ·  Source

16 Colorado ADMT Act (SB 26-189)

Rules mapped

Binding state law — Colorado, USA

What it covers. Automated decision systems used for consequential decisions, with consumer protections and developer/deployer duties.

How it differs. Outcome/use-case oriented rather than enterprise-wide management-system governance.

What it means here. No catalog gap. Map consequential-decision inventory, notices, assessments and consumer rights.  ·  See its mapped requirements →  ·  Source

17 Colorado SB 21-169 — AI / External Data in Insurance

Rules mapped

Binding law + regulation — Colorado, USA — insurance

What it covers. Prevention of unfair discrimination from external consumer data, algorithms and predictive models in insurance.

How it differs. Narrow insurance fairness regime with strong testing/governance implications, not a general AI framework.

What it means here. No catalog gap. Maintain insurance-specific bias testing, documentation and governance evidence.  ·  See its mapped requirements →  ·  Source

18 Digital Operational Resilience Act (DORA)

Rules mapped

Binding law — EU — financial entities

What it covers. ICT risk management, resilience, incident reporting, third-party risk and testing for financial entities.

How it differs. Not AI-specific; it governs operational technology risk that AI systems and vendors may fall within.

What it means here. No catalog gap. Keep AI controls linked to ICT resilience and third-party concentration risk.  ·  See its mapped requirements →  ·  Source

24 NYC Local Law 144 — Automated Employment Decision Tools

Rules mapped

Binding local law — New York City, USA

What it covers. Bias audit, public notice and disclosure obligations for automated employment decision tools.

How it differs. Highly specific employment-use law; its independent bias-audit requirement is more concrete than broad principles frameworks.

What it means here. No catalog gap. Tie to employment tool inventory, annual audit evidence and notices.  ·  See its mapped requirements →  ·  Source

28 South Korea AI Basic Act

Rules mapped

Binding framework law — South Korea

What it covers. National AI governance framework covering high-impact/generative AI duties and industrial development.

How it differs. Combines innovation policy and risk obligations rather than following the EU’s exact conformity model.

What it means here. No catalog gap. Maintain effective dates, subordinate rules and high-impact applicability logic.  ·  See its mapped requirements →  ·  Source

29 Texas Responsible AI Governance Act (TRAIGA)

Rules mapped

Binding state law — Texas, USA

What it covers. Prohibitions and governance rules for specified AI practices, with public-sector and consumer-facing implications.

How it differs. State-law compliance overlay; less comprehensive than EU AI Act and different from voluntary risk frameworks.

What it means here. No catalog gap. Keep prohibited-use detection and state applicability logic distinct.  ·  See its mapped requirements →  ·  Source

32 FCA Consumer Duty (PRIN 2A)

Rules mapped

Binding conduct rules — United Kingdom — retail financial services

What it covers. Requires firms to deliver good outcomes for retail customers; AI use can affect products, support, value and consumer understanding.

How it differs. Not an AI framework; it is an outcomes rule that constrains how AI may be used in customer journeys.

What it means here. No catalog gap. Treat as an AI-use overlay linked to customer outcome testing.  ·  See its mapped requirements →  ·  Source

34 Equal Credit Opportunity Act / Regulation B — Adverse Action

Rules mapped

Binding law / regulation — United States — credit

What it covers. Nondiscrimination and specific-reason adverse-action requirements for credit decisions, including AI-assisted decisions.

How it differs. Rights/credit-law overlay; not a general AI governance program.

What it means here. No catalog gap. Link explainability and decision-reason controls directly to adverse-action obligations.  ·  See its mapped requirements →  ·  Source

35 Fair Credit Reporting Act (FCRA)

Rules mapped

Binding law — United States — consumer reports

What it covers. Accuracy, permissible purpose, disclosure and adverse-action duties involving consumer reports.

How it differs. Data/use-rights law that can govern AI inputs/decisions without being AI-specific.

What it means here. No catalog gap. Map data provenance, accuracy and adverse-action workflows.  ·  See its mapped requirements →  ·  Source

36 Title VII / ADA applied to AI hiring tools (EEOC)

Rules mapped

Binding civil-rights law + enforcement guidance — United States — employment

What it covers. Employment nondiscrimination and disability/accommodation rules as applied to algorithmic hiring and employment tools.

How it differs. Civil-rights compliance layer; focuses on outcomes and protected classes rather than AI system architecture.

What it means here. No catalog gap. Link bias testing, accommodations, validation and human review.  ·  See its mapped requirements →  ·  Source

70 U.S. OMB M-25-21 — Accelerating Federal Use of AI through Innovation, Governance, and Public Trust

Tracked, not mapped

Binding federal agency policy — United States — federal government

What it covers. Federal agency governance for AI use, including responsible adoption, risk safeguards, leadership/accountability and public trust.

How it differs. Government-internal governance policy rather than private-sector law; directly relevant to federal AI programs and vendors.

What it means here. Add for U.S. federal public-sector coverage and procurement-adjacent governance.  ·  Source

71 U.S. OMB M-25-22 — Driving Efficient Acquisition of AI in Government

Tracked, not mapped

Binding federal procurement policy — United States — federal government

What it covers. Requirements and principles for acquiring AI competitively, responsibly and with attention to vendor lock-in, privacy and government data.

How it differs. Procurement-specific governance, filling a third-party/vendor management gap not covered by general AI principles alone.

What it means here. Add as a procurement/vendor-risk overlay for organizations selling AI to or buying AI for government use.  ·  Source

ISO/IEC standards · 10

The international standards family — management systems, risk, impact assessment, lifecycle, data quality and bias.

20 ISO/IEC 23894:2023 — AI Risk Management

Rules mapped

International standard / guidance — Global

What it covers. AI-specific guidance for identifying, assessing, treating and monitoring risk, aligned with ISO 31000.

How it differs. Risk-management guidance only; unlike ISO 42001 it is not an AI management-system certification standard.

What it means here. No catalog gap. Keep explicit crosswalk to ISO 42001 controls and organization risk appetite.  ·  See its mapped requirements →  ·  Source

22 ISO/IEC 42001:2023 — AI Management System (AIMS)

Rules mapped

Certifiable management-system standard — Global

What it covers. Organization-wide AI management system covering leadership, planning, risk, lifecycle controls, performance evaluation and improvement.

How it differs. Unlike NIST, it is structured as a certifiable management system; unlike the EU AI Act, it is voluntary unless contractually required.

What it means here. No catalog gap. This should remain one of AutoGovern’s primary control backbones.  ·  See its mapped requirements →  ·  Source

39 ISO 31000:2018 — Risk Management Guidelines

Used elsewhere

International risk-management standard — Global

What it covers. Enterprise risk-management principles and process used as the parent model for risk identification, analysis, treatment and monitoring.

How it differs. Generic enterprise risk standard, not AI-specific. It provides the risk architecture that ISO/IEC 23894 specializes for AI.

What it means here. Make it a first-class crosswalk so AI risk can connect cleanly to enterprise risk registers.  ·  Source

43 ISO/IEC 38507:2022 — Governance implications of AI

Tracked, not mapped

International governance standard — Global

What it covers. Guidance for boards and governing bodies on directing and overseeing organizational use of AI.

How it differs. Board/governing-body focus is distinct from ISO 42001’s management-system requirements and ISO 23894’s risk process.

What it means here. High-priority addition for board accountability, oversight and governance operating-model coverage.  ·  Expansion priority P0  ·  Source

44 ISO/IEC 42005:2025 — AI System Impact Assessment

Named, not separate

International standard — Global

What it covers. Structured AI system impact assessment focused on effects on individuals, groups and society across the lifecycle.

How it differs. Goes deeper on impact assessment than ISO 42001/23894 and aligns with emerging regulatory AIA requirements.

What it means here. High-priority standalone framework; use it to standardize impact assessments across jurisdictions.  ·  Expansion priority P0  ·  Source

45 ISO/IEC 42006:2025 — AIMS audit and certification bodies

Named, not separate

International conformity-assessment standard — Global

What it covers. Requirements for bodies that audit and certify AI management systems against ISO/IEC 42001.

How it differs. Targets certifiers rather than ordinary AI developers/deployers; important for assurance credibility and certification ecosystem design.

What it means here. Add as assurance-reference coverage, especially if AutoGovern produces ISO 42001 audit-ready evidence.  ·  Source

46 ISO/IEC 5338:2023 — AI system life cycle processes

Tracked, not mapped

International lifecycle standard — Global

What it covers. Defines AI-specific lifecycle processes for development, acquisition, operation and improvement.

How it differs. Process-engineering/lifecycle standard rather than governance principles; strengthens stage-gate and lifecycle evidence.

What it means here. Add as a technical lifecycle crosswalk to make governance controls traceable to engineering processes.  ·  Expansion priority P1  ·  Source

47 ISO/IEC 5259-5:2025 — Data quality governance for analytics and ML

Tracked, not mapped

International data-governance standard — Global

What it covers. Governance framework for directing and overseeing data quality used in analytics and machine learning.

How it differs. Targets data-quality governance specifically, an area often treated only as one control inside broader AI frameworks.

What it means here. High-value addition for training data, provenance, quality ownership and board-level data accountability.  ·  Expansion priority P1  ·  Source

48 ISO/IEC TR 24027:2021 — Bias in AI systems

Tracked, not mapped

Technical report / guidance — Global

What it covers. Bias sources, measurement and treatment across the AI lifecycle.

How it differs. More technically focused on bias assessment than broad fairness principles.

What it means here. Add as a fairness/bias evidence reference behind AutoGovern bias controls and testing requirements.  ·  Expansion priority P1  ·  Source

49 ISO/IEC TR 24028:2020 — Trustworthiness in AI

Tracked, not mapped

Technical report / guidance — Global

What it covers. Trustworthiness topics including transparency, explainability, reliability, safety, security, privacy and resilience.

How it differs. A cross-cutting trustworthiness reference rather than a management-system or legal framework.

What it means here. Useful supporting reference for AutoGovern’s risk taxonomy and assurance evidence.  ·  Expansion priority P1  ·  Source

NIST · 2

The US voluntary framework family, including the generative-AI profile.

23 NIST AI Risk Management Framework 1.0

Rules mapped

Voluntary framework — United States / global reference

What it covers. Govern, Map, Measure and Manage functions for trustworthy AI risk management across the lifecycle.

How it differs. Outcome-based and flexible; less prescriptive than ISO 42001 and not legally binding like the EU AI Act.

What it means here. No catalog gap. NIST is being revised in 2026, so versioning and migration support should be explicit.  ·  See its mapped requirements →  ·  Source

42 NIST AI 600-1 — Generative AI Profile

Named, not separate

Voluntary NIST profile — United States / global reference

What it covers. GenAI-specific companion to NIST AI RMF that identifies risks and suggested risk-management actions for generative AI.

How it differs. Adds GenAI-specific risks and actions that the generic AI RMF does not spell out.

What it means here. Create a standalone profile with direct mappings for hallucination/confabulation, content integrity, misuse, privacy, security and human factors.  ·  Expansion priority P0  ·  Source

IEEE standards · 3

Ethical design, transparency and algorithmic-bias engineering standards.

50 IEEE/ISO/IEC 24748-7000:2022 — Ethical concerns during system design

Tracked, not mapped

International ethical-design process standard — Global

What it covers. Process for eliciting ethical values and tracing them into requirements, risk treatment and system design.

How it differs. Operationalizes ethics during engineering rather than leaving ethics as high-level principles.

What it means here. Add as a design-time governance layer for value-sensitive requirements and traceability.  ·  Expansion priority P2  ·  Source

51 IEEE 7001-2021 — Transparency of Autonomous Systems

Tracked, not mapped

IEEE standard — Global

What it covers. Defines measurable/testable transparency levels for autonomous systems.

How it differs. More testable and system-specific than general transparency principles in OECD/NIST/ISO.

What it means here. Add as a transparency assurance reference, especially for autonomous and agentic systems.  ·  Expansion priority P2  ·  Source

52 IEEE 7003-2024 — Algorithmic Bias Considerations

Tracked, not mapped

IEEE standard — Global

What it covers. Processes and methods to address algorithmic bias, validation data and application boundaries.

How it differs. Adds detailed bias engineering and validation practices beyond high-level fairness obligations.

What it means here. Add as a supporting bias-control framework, especially for employment, credit and insurance use cases.  ·  Expansion priority P2  ·  Source

International principles & treaties · 8

Intergovernmental principles, treaty frameworks and multilateral codes.

21 OECD AI Principles

Rules mapped

Intergovernmental principles — Global / OECD adherents

What it covers. Human-centric trustworthy AI principles plus policy recommendations for governments.

How it differs. High-level values and policy direction, not an auditable control catalogue or certification scheme.

What it means here. No catalog gap. Use mainly as principles/outcomes layer mapped to operational controls.  ·  See its mapped requirements →  ·  Source

53 UNESCO Recommendation on the Ethics of Artificial Intelligence

Tracked, not mapped

Intergovernmental ethics standard — Global / UNESCO member states

What it covers. Human-rights-centered ethics framework covering fairness, privacy, transparency, human oversight, sustainability, accountability and policy actions.

How it differs. Broader societal and human-rights lens than enterprise risk frameworks; includes sustainability and public policy dimensions.

What it means here. High-priority principles layer for global/public-sector and human-rights-oriented governance.  ·  Expansion priority P1  ·  Source

54 Council of Europe Framework Convention on AI, Human Rights, Democracy and Rule of Law

Tracked, not mapped

Legally binding international treaty framework — Council of Europe parties / signatories

What it covers. Treaty-level obligations to align AI lifecycle activities with human rights, democracy and the rule of law.

How it differs. Unlike voluntary ethics frameworks, this creates an international legal governance layer centered on fundamental rights.

What it means here. High-priority addition for organizations operating in participating jurisdictions and public-sector contexts.  ·  Expansion priority P1  ·  Source

55 Council of Europe HUDERIA Methodology

Tracked, not mapped

Human-rights risk and impact assessment methodology — Europe / adaptable globally

What it covers. Methodology for assessing AI impacts on human rights, democracy and rule of law; includes the COBRA model.

How it differs. Deeper rights-impact methodology than generic AI risk assessments.

What it means here. Add as a specialized impact-assessment option alongside ISO 42005 and regulatory AIAs.  ·  Expansion priority P1  ·  Source

56 G7 Hiroshima AI Process Comprehensive Policy Framework / Code of Conduct

Tracked, not mapped

International voluntary governance framework — G7 + global reference

What it covers. Guiding principles and voluntary code of conduct for advanced AI systems, including risk testing, incident handling, transparency and security.

How it differs. Frontier/advanced-AI focused, sitting between high-level principles and company safety frameworks.

What it means here. High-priority addition for advanced/foundation model governance and international interoperability.  ·  Expansion priority P1  ·  Source

57 Hiroshima AI Process Reporting Framework

Tracked, not mapped

Voluntary reporting / accountability framework — G7 / OECD

What it covers. Operational reporting mechanism for organizations implementing the Hiroshima Code of Conduct.

How it differs. Turns voluntary principles into comparable transparency and accountability disclosures.

What it means here. Add as an evidence/reporting template for frontier-model providers and advanced AI programs.  ·  Expansion priority P1  ·  Source

58 ASEAN Guide on AI Governance and Ethics (2024)

Tracked, not mapped

Regional voluntary governance guide — ASEAN

What it covers. Practical governance guidance for organizations developing and deploying traditional AI, designed for regional interoperability.

How it differs. Regional implementation guide similar in spirit to Singapore’s model but designed for ASEAN-wide alignment.

What it means here. Add as a regional framework for Southeast Asia coverage.  ·  Source

59 Expanded ASEAN Guide on AI Governance and Ethics — Generative AI (2025)

Tracked, not mapped

Regional GenAI governance guide — ASEAN

What it covers. GenAI policy guidance across accountability, data, deployment, incident reporting, testing, security, provenance, safety research and public good.

How it differs. Extends ASEAN governance specifically for GenAI ecosystem risks.

What it means here. Add as a separate GenAI regional overlay rather than folding it into traditional AI guidance.  ·  Source

National frameworks & guidance · 24

Country-level voluntary frameworks, guidance and public-sector policy.

11 Canada Voluntary Code of Conduct on Advanced Generative AI

Rules mapped

Voluntary code — Canada

What it covers. Responsible development and management of advanced generative AI, including safety, fairness, transparency and monitoring.

How it differs. GenAI-specific and voluntary; more focused than ISO 42001 and less formal than a certifiable management system.

What it means here. No catalog gap. Consider deeper model-provider and GenAI lifecycle evidence templates.  ·  See its mapped requirements →  ·  Source

12 Artificial Intelligence and Data Act (AIDA, Bill C-27) — lapsed

Rules mapped

Historical / lapsed proposal — Canada

What it covers. Former proposed federal high-impact AI regime.

How it differs. Unlike live frameworks, it is not currently an enforceable compliance target; its value is historical/contextual.

What it means here. Keep it marked historical so users do not treat it as a current obligation.  ·  See its mapped requirements →  ·  Source

13 OSFI Guideline E-23 — Model Risk Management

Rules mapped

Regulatory guidance — Canada — federally regulated financial institutions

What it covers. Lifecycle model risk governance, validation, inventory, controls and oversight for models including AI/ML.

How it differs. Sector-specific model risk framework; stronger validation/governance emphasis than general AI ethics frameworks.

What it means here. No catalog gap. Preserve banking-specific model inventory, validation and independent challenge controls.  ·  See its mapped requirements →  ·  Source

14 Canadian AI Standards (CSA ISO/IEC 42001 & 23894, CAN/DGSI 101)

Rules mapped

Standards / guidance — Canada

What it covers. Canadian adoption and use of international AI management/risk standards plus domestic guidance.

How it differs. A standards layer rather than a statute; supports consistency and assurance without itself creating broad legal penalties.

What it means here. No catalog gap. Distinguish certification-capable ISO 42001 from guidance-only standards.  ·  See its mapped requirements →  ·  Source

19 EU Financial Supervisors AI Guidance (EBA, ESMA, EIOPA)

Rules mapped

Supervisory guidance — EU — financial services

What it covers. Supervisory expectations for AI use in financial services, including governance, consumer protection and model risk.

How it differs. Sector supervisory layer that sits on top of horizontal EU law and financial rules.

What it means here. No catalog gap. Treat as sector overlay rather than substitute for EU AI Act/GDPR/DORA.  ·  See its mapped requirements →  ·  Source

25 NY DFS Circular Letter No. 7 (2024) — AI in Underwriting & Pricing

Rules mapped

Regulatory guidance — New York, USA — insurance

What it covers. Governance and anti-discrimination expectations for insurers using AI/external data in underwriting and pricing.

How it differs. Insurance supervisory expectations, not a horizontal AI law.

What it means here. No catalog gap. Keep fairness, governance, validation and documentation controls insurance-specific.  ·  See its mapped requirements →  ·  Source

26 Singapore Model AI Governance Framework

Rules mapped

Voluntary framework — Singapore / international reference

What it covers. Practical organizational governance for traditional AI: internal structures, human involvement, operations management and stakeholder communication.

How it differs. More implementation-oriented than high-level ethics principles, but older than Singapore’s GenAI and Agentic AI extensions.

What it means here. Catalogued, but AutoGovern should split newer GenAI and Agentic AI frameworks into standalone entries.  ·  See its mapped requirements →  ·  Source

27 MAS FEAT Principles + AI Model Risk Management Guidance

Rules mapped

Regulatory / supervisory guidance — Singapore — financial institutions

What it covers. Fairness, Ethics, Accountability and Transparency plus model risk practices for financial institutions.

How it differs. Financial-sector and outcome-focused; narrower than general AI management systems.

What it means here. No catalog gap. Maintain model validation, fairness and accountability evidence for regulated financial use.  ·  See its mapped requirements →  ·  Source

30 UK pro-innovation AI framework + ICO guidance

Rules mapped

Principles-based regulatory framework + guidance — United Kingdom

What it covers. Cross-sector principles implemented through existing regulators, supplemented by privacy/data-protection guidance.

How it differs. Decentralized and regulator-led rather than one horizontal AI statute.

What it means here. No catalog gap. Expand with newer UK assurance, AIME, transparency and cyber-security instruments.  ·  See its mapped requirements →  ·  Source

31 PRA SS1/23 — Model Risk Management Principles for Banks

Rules mapped

Supervisory statement — United Kingdom — banks

What it covers. Bank model risk governance, model identification, development, validation, governance and controls.

How it differs. Model-risk specific and sector-regulated; AI is governed as part of broader model risk.

What it means here. No catalog gap. Preserve independent validation and board accountability mappings.  ·  See its mapped requirements →  ·  Source

33 SR 26-2 — Interagency Model Risk Management Guidance

Rules mapped

Banking guidance — United States — banking

What it covers. Model risk governance and validation expectations for banking organizations.

How it differs. Sector model-risk guidance, emphasizing validation and effective challenge rather than AI ethics broadly.

What it means here. No catalog gap. Maintain banking applicability and model validation workflow.  ·  See its mapped requirements →  ·  Source

37 Financial Services AI Risk Management Framework (FS AI RMF)

Rules mapped

Voluntary sector framework — United States — financial services

What it covers. Financial-services-specific AI risk management practices aligned with sector governance needs.

How it differs. Sector-tailored adaptation of broader AI risk principles.

What it means here. No catalog gap. Keep crosswalks to NIST, banking model risk and consumer-protection obligations.  ·  See its mapped requirements →  ·  Source

38 NAIC Model Bulletin on the Use of AI Systems by Insurers

Rules mapped

State-adopted model guidance — United States — insurance

What it covers. Insurer governance programs, controls and documentation to prevent unfair trade/discrimination from AI systems.

How it differs. Insurance-specific governance layer adopted through state supervisory practice, not a universal federal rule.

What it means here. No catalog gap. Track state adoption and insurer governance evidence separately.  ·  See its mapped requirements →  ·  Source

60 Singapore Model AI Governance Framework for Generative AI

Tracked, not mapped

Voluntary GenAI governance framework — Singapore / global reference

What it covers. Nine-dimension framework for a trusted GenAI ecosystem across model development, accountability, security, content provenance and other controls.

How it differs. More current and GenAI-specific than the traditional Singapore Model AI Governance Framework already catalogued.

What it means here. High-priority addition; split Singapore traditional AI, GenAI and Agentic AI into distinct versioned frameworks.  ·  Expansion priority P0  ·  Source

61 Singapore Model AI Governance Framework for Agentic AI (v1.5, 2026)

Tracked, not mapped

Voluntary agentic-AI governance framework — Singapore / global reference

What it covers. Guidance on bounding agent powers, human accountability, lifecycle technical controls, third-party/multi-agent risk and user responsibility.

How it differs. One of the first governance frameworks focused specifically on autonomous/agentic AI rather than static models.

What it means here. Very high-priority addition because AutoGovern already emphasizes agentic AI risk and controls.  ·  Expansion priority P0  ·  Source

62 AI Verify — AI Governance Testing Framework

Tracked, not mapped

Testing / assurance framework and toolkit — Singapore / global reference

What it covers. Standardized tests and process checks across 11 governance principles including fairness, explainability, robustness, accountability and human agency.

How it differs. Provides executable assurance/testing, not just policy requirements.

What it means here. High-priority addition to connect AutoGovern policy/control assertions to measurable technical evidence.  ·  Expansion priority P0  ·  Source

63 Japan AI Guidelines for Business Ver. 1.2 (2026)

Tracked, not mapped

National voluntary guidance — Japan

What it covers. Non-binding guidance for AI developers, providers and business users, integrating Japan’s earlier R&D, utilization and governance guidance.

How it differs. Role-based and innovation-friendly, with strong operational guidance rather than a single punitive AI statute.

What it means here. High-priority jurisdictional addition for Japan/APAC coverage.  ·  Expansion priority P1  ·  Source

64 Australia Guidance for AI Adoption (2025)

Tracked, not mapped

National voluntary governance guidance — Australia

What it covers. Six essential practices for responsible AI governance, evolving the earlier Voluntary AI Safety Standard/10 guardrails.

How it differs. Practical adoption baseline for organizations, aligned to ISO 42001 and NIST but simplified for implementation.

What it means here. High-priority jurisdictional addition; use the 2025 guidance as the current baseline and retain older guardrails as historical mapping.  ·  Expansion priority P1  ·  Source

65 India AI Governance Guidelines (2025)

Tracked, not mapped

National principle-based governance framework — India

What it covers. Seven-principle, risk-based and techno-legal governance framework relying on existing laws, sector regulators and new coordinating/safety institutions.

How it differs. Light-touch and principle-based rather than a new horizontal AI statute; emphasizes innovation, proportionality and existing legal mechanisms.

What it means here. High-priority jurisdictional addition for India coverage.  ·  Expansion priority P1  ·  Source

66 UAE AI Ethics Principles & Guidelines

Tracked, not mapped

National ethics / self-governance framework — United Arab Emirates

What it covers. Eight principles including fairness, accountability, transparency, explainability, robustness, safety, human-centered values and sustainability.

How it differs. Values/ethics-led self-governance framework with less prescriptive compliance machinery than ISO or statutory regimes.

What it means here. Add for Middle East coverage and as a principles layer mapped to operational controls.  ·  Source

67 UK AI Management Essentials (AIME)

Tracked, not mapped

Voluntary self-assessment baseline — United Kingdom

What it covers. Practical management self-assessment distilled primarily from ISO/IEC 42001, NIST AI RMF and the EU AI Act.

How it differs. Simplifies complex frameworks into an accessible baseline, especially for SMEs; not a certification.

What it means here. High-priority addition because it directly overlaps AutoGovern’s target value proposition and could be offered as a quick-readiness profile.  ·  Expansion priority P2  ·  Source

68 UK AI Cyber Security Code of Practice

Tracked, not mapped

Cybersecurity code / implementation guidance — United Kingdom

What it covers. Baseline cyber-security principles for organizations developing and deploying AI systems.

How it differs. Security-control specific; complements rather than replaces AI governance/risk frameworks.

What it means here. Add as a security control overlay alongside OWASP for a government-backed baseline.  ·  Expansion priority P2  ·  Source

69 UK Algorithmic Transparency Recording Standard (ATRS)

Tracked, not mapped

Mandatory public-sector transparency standard — United Kingdom — central government / public sector

What it covers. Standardized public disclosure of algorithmic tools, ownership, rationale, data, model details, risks, mitigations and impact assessments.

How it differs. A transparency-recording standard with mandatory scope for central government, not a general private-sector AI framework.

What it means here. Add for public-sector governance and to strengthen AutoGovern’s transparency/documentation outputs.  ·  Expansion priority P2  ·  Source

72 EU General-Purpose AI Code of Practice (2025)

Tracked, not mapped

Voluntary compliance code under binding law — European Union

What it covers. Three chapters covering Transparency, Copyright, and Safety & Security to help GPAI providers demonstrate AI Act compliance.

How it differs. Operationalizes AI Act provider obligations for GPAI models; more detailed and model-provider-specific than the AI Act entry alone.

What it means here. Very high-priority addition for any platform claiming EU AI Act/GPAI readiness.  ·  Expansion priority P0  ·  Source

Security & risk taxonomies · 2

Application-security risk lists and research risk repositories.

40 OWASP Top 10 for LLM / GenAI Applications

Used elsewhere

Security best-practice framework — Global

What it covers. Critical application-security risks for LLM/GenAI systems such as prompt injection, sensitive data disclosure, supply-chain risk and excessive agency.

How it differs. Security-focused, not a governance certification or legal framework. It fills technical control depth that policy frameworks often lack.

What it means here. Promote the current OWASP GenAI release to a versioned standalone security framework and map its risks to AutoGovern controls.  ·  Source

41 MIT AI Risk Repository

Used elsewhere

Risk taxonomy / evidence repository — Global

What it covers. Living database and taxonomies of AI risks compiled from many frameworks and research sources.

How it differs. It is a risk discovery/reference corpus, not a prescriptive compliance standard.

What it means here. Keep it as a risk-identification source and expose traceability from AutoGovern risk categories to repository domains.  ·  Source