Framework requirements inventory
What each framework requires on the core governance topics — data, ownership, risk, oversight and more — at article/clause level. One control, evidenced once, can satisfy several frameworks at the same time. Illustrative reference.
11 topics
Lawful basis & purpose
Process personal data only on a valid legal basis, for a specified, legitimate purpose, and not beyond it.
Art. 5(1)(b), 6
Purpose limitation; a lawful basis is required to process.
Art. 5
Prohibited AI practices set the outer bounds of permitted purpose.
Proportionality
Use of AI must be proportionate to the business purpose.
Cl. 6.1 · A.2
AI objectives and policy define and bound intended use.
GOVERN 1.1
Intended purpose and context are documented.
Data minimisation & quality
Use only the data you need, keep it accurate and representative, and govern training/input data quality.
Art. 5(1)(c)·(d)
Adequate, relevant, limited to what is necessary; kept accurate.
Art. 10
Data governance: relevant, representative, error-free training data.
A.7
Data for AI systems — provenance, quality and preparation controls.
MAP 2.3 · MEASURE 2.x
Data quality and representativeness assessed.
Data governance
Data accuracy, completeness and appropriateness.
Personal data & privacy by design
Build in data protection by design and default; protect special-category data; assess automated-decision impact.
Art. 25, 9, 22
Privacy by design/default; special-category data; automated decisions.
Art. 10
Special-category data only under strict conditions for bias correction.
A.7
Controls over personal and sensitive data used by AI.
LLM06
Sensitive-information disclosure controls.
Data governance
Protect policyholder personal data across the AI lifecycle.
Ownership & accountability
Name an accountable owner; define roles and responsibilities across the AI value chain.
Art. 5(2), 24
Accountability principle; controller responsibility to demonstrate compliance.
Art. 16, 26
Provider and deployer obligations and responsibilities.
Cl. 5.3 · A.3
Roles, responsibilities and authorities; internal organisation.
GOVERN 2.x
Roles and accountability structures are defined and resourced.
Governance
Clear accountability; AI within the system of governance.
Risk & impact assessment
Run a documented risk and impact assessment before and during deployment, sized to the risk.
Art. 35
Data Protection Impact Assessment (DPIA) for high-risk processing.
Art. 9, 27
Risk-management system; Fundamental Rights Impact Assessment.
Cl. 6.1 · A.5
AI risk assessment and AI system impact assessment.
MAP · MEASURE
Identify, analyse and measure risks across the lifecycle.
Risk management
AI risks integrated into the risk-management system.
Human oversight
Keep a human able to understand, intervene in and override AI decisions that affect people.
Art. 14
Effective human oversight of high-risk AI.
Art. 22
Right not to be subject to solely automated decisions.
A.9
Controls over the responsible use of AI systems.
MANAGE 2.x
Mechanisms to oversee, intervene and decommission.
Human oversight
Human-in-command for material decisions.
Transparency & information
Tell people when AI is used and provide meaningful information about how it works and affects them.
Art. 13–14
Information to data subjects, incl. logic of automated decisions.
Art. 13, 50
Transparency to deployers; disclosure of AI interaction.
A.8
Information for interested parties.
GOVERN 4 · MEASURE
Transparency and explainability are documented.
Transparency
Explainability appropriate to the audience.
Security & robustness
Protect AI systems and data against attack, misuse and failure; ensure accuracy and resilience.
Art. 32
Security of processing appropriate to the risk.
Art. 15
Accuracy, robustness and cybersecurity.
LLM01–LLM10
Prompt injection, data leakage and other LLM-specific risks.
A.6
AI system lifecycle controls incl. security.
MANAGE 2.x
Resourced response to AI security incidents.
Record-keeping & documentation
Maintain documentation, logs and records sufficient to demonstrate compliance and trace decisions.
Art. 30
Records of processing activities.
Art. 11, 12, 18
Technical documentation, automatic logging, record retention.
Cl. 7.5
Documented information control.
GOVERN
Policies, processes and documentation maintained.
Documentation
Audit trail proportionate to materiality.
Monitoring & post-deployment
Monitor performance and drift in production; review and improve; report serious incidents.
Art. 72
Post-market monitoring of high-risk AI.
Cl. 9
Monitoring, internal audit and management review.
MEASURE · MANAGE
Ongoing monitoring of performance and risk.
Monitoring
Continuous monitoring of AI outcomes.
Art. 5(2)
Ongoing demonstration of compliance.
Third-party & vendor AI
Govern AI you obtain from vendors and processors; allocate responsibility along the value chain.
Art. 28
Processor obligations and data-processing agreements.
Art. 25
Responsibilities along the AI value chain.
A.10
Third-party relationship controls.
GOVERN 6
Third-party risks and dependencies addressed.
Outsourcing
Outsourcing and third-party AI under the governance system.