JK
Back to Compliance

Framework requirements inventory

What each framework requires on the core governance topics — data, ownership, risk, oversight and more — at article/clause level. One control, evidenced once, can satisfy several frameworks at the same time. Illustrative reference.

11 topics

Lawful basis & purpose

Process personal data only on a valid legal basis, for a specified, legitimate purpose, and not beyond it.

GDPR

Art. 5(1)(b), 6

Purpose limitation; a lawful basis is required to process.

EU AI Act

Art. 5

Prohibited AI practices set the outer bounds of permitted purpose.

EIOPA

Proportionality

Use of AI must be proportionate to the business purpose.

ISO 42001

Cl. 6.1 · A.2

AI objectives and policy define and bound intended use.

NIST AI RMF

GOVERN 1.1

Intended purpose and context are documented.

Data minimisation & quality

Use only the data you need, keep it accurate and representative, and govern training/input data quality.

GDPR

Art. 5(1)(c)·(d)

Adequate, relevant, limited to what is necessary; kept accurate.

EU AI Act

Art. 10

Data governance: relevant, representative, error-free training data.

ISO 42001

A.7

Data for AI systems — provenance, quality and preparation controls.

NIST AI RMF

MAP 2.3 · MEASURE 2.x

Data quality and representativeness assessed.

EIOPA

Data governance

Data accuracy, completeness and appropriateness.

Personal data & privacy by design

Build in data protection by design and default; protect special-category data; assess automated-decision impact.

GDPR

Art. 25, 9, 22

Privacy by design/default; special-category data; automated decisions.

EU AI Act

Art. 10

Special-category data only under strict conditions for bias correction.

ISO 42001

A.7

Controls over personal and sensitive data used by AI.

OWASP LLM

LLM06

Sensitive-information disclosure controls.

EIOPA

Data governance

Protect policyholder personal data across the AI lifecycle.

Ownership & accountability

Name an accountable owner; define roles and responsibilities across the AI value chain.

GDPR

Art. 5(2), 24

Accountability principle; controller responsibility to demonstrate compliance.

EU AI Act

Art. 16, 26

Provider and deployer obligations and responsibilities.

ISO 42001

Cl. 5.3 · A.3

Roles, responsibilities and authorities; internal organisation.

NIST AI RMF

GOVERN 2.x

Roles and accountability structures are defined and resourced.

EIOPA

Governance

Clear accountability; AI within the system of governance.

Risk & impact assessment

Run a documented risk and impact assessment before and during deployment, sized to the risk.

GDPR

Art. 35

Data Protection Impact Assessment (DPIA) for high-risk processing.

EU AI Act

Art. 9, 27

Risk-management system; Fundamental Rights Impact Assessment.

ISO 42001

Cl. 6.1 · A.5

AI risk assessment and AI system impact assessment.

NIST AI RMF

MAP · MEASURE

Identify, analyse and measure risks across the lifecycle.

EIOPA

Risk management

AI risks integrated into the risk-management system.

Human oversight

Keep a human able to understand, intervene in and override AI decisions that affect people.

EU AI Act

Art. 14

Effective human oversight of high-risk AI.

GDPR

Art. 22

Right not to be subject to solely automated decisions.

ISO 42001

A.9

Controls over the responsible use of AI systems.

NIST AI RMF

MANAGE 2.x

Mechanisms to oversee, intervene and decommission.

EIOPA

Human oversight

Human-in-command for material decisions.

Transparency & information

Tell people when AI is used and provide meaningful information about how it works and affects them.

GDPR

Art. 13–14

Information to data subjects, incl. logic of automated decisions.

EU AI Act

Art. 13, 50

Transparency to deployers; disclosure of AI interaction.

ISO 42001

A.8

Information for interested parties.

NIST AI RMF

GOVERN 4 · MEASURE

Transparency and explainability are documented.

EIOPA

Transparency

Explainability appropriate to the audience.

Security & robustness

Protect AI systems and data against attack, misuse and failure; ensure accuracy and resilience.

GDPR

Art. 32

Security of processing appropriate to the risk.

EU AI Act

Art. 15

Accuracy, robustness and cybersecurity.

OWASP LLM

LLM01–LLM10

Prompt injection, data leakage and other LLM-specific risks.

ISO 42001

A.6

AI system lifecycle controls incl. security.

NIST AI RMF

MANAGE 2.x

Resourced response to AI security incidents.

Record-keeping & documentation

Maintain documentation, logs and records sufficient to demonstrate compliance and trace decisions.

GDPR

Art. 30

Records of processing activities.

EU AI Act

Art. 11, 12, 18

Technical documentation, automatic logging, record retention.

ISO 42001

Cl. 7.5

Documented information control.

NIST AI RMF

GOVERN

Policies, processes and documentation maintained.

EIOPA

Documentation

Audit trail proportionate to materiality.

Monitoring & post-deployment

Monitor performance and drift in production; review and improve; report serious incidents.

EU AI Act

Art. 72

Post-market monitoring of high-risk AI.

ISO 42001

Cl. 9

Monitoring, internal audit and management review.

NIST AI RMF

MEASURE · MANAGE

Ongoing monitoring of performance and risk.

EIOPA

Monitoring

Continuous monitoring of AI outcomes.

GDPR

Art. 5(2)

Ongoing demonstration of compliance.

Third-party & vendor AI

Govern AI you obtain from vendors and processors; allocate responsibility along the value chain.

GDPR

Art. 28

Processor obligations and data-processing agreements.

EU AI Act

Art. 25

Responsibilities along the AI value chain.

ISO 42001

A.10

Third-party relationship controls.

NIST AI RMF

GOVERN 6

Third-party risks and dependencies addressed.

EIOPA

Outsourcing

Outsourcing and third-party AI under the governance system.