AI Compliance Frameworks

Choose a framework. Read the guide to understand it, or use a worksheet to record evidence and next actions for your team.

DORA

DORA establishes a comprehensive framework for digital operational resilience in the EU financial sector. It sets uniform requirements for the security of network and information systems supporting business processes of financial entities.

19 tracked updates for DORA

NIS2

NIS2 is the EU's updated directive on cybersecurity, replacing the original NIS Directive. It significantly expands the scope of sectors and entities covered, strengthens security requirements, and introduces more stringent enforcement measures.

21 tracked updates for NIS2

ISO 27001

ISO 27001 is the international standard for information security management systems (ISMS). It provides a systematic approach to managing sensitive information through risk assessment, security controls, and continuous improvement.

154 tracked updates for ISO 27001

SOC 2 + AI

SOC 2 + AI extends the traditional SOC 2 trust services criteria to address AI-specific risks. It covers security, availability, processing integrity, confidentiality, and privacy as they apply to AI systems, including model governance, bias monitoring, and AI transparency.

162 tracked updates for SOC 2 + AI

FINMA

FINMA provides regulatory guidance on the use of AI and machine learning in Swiss financial services. It covers model risk management, explainability, data governance, and supervisory expectations for banks and insurance companies using AI.

19 tracked updates for FINMA