Frameworks & standards reference
AI frameworks, standards & regulations.
Frameworks and standards provide structured ways to assign accountability, manage AI risk, implement controls, and demonstrate oversight. Laws can add binding requirements, while security, testing, and assurance resources address specialized gaps.
Separate what applies from what helps. Then build a framework stack that covers the obligations, risks, and assurance needs that matter for the system.
The selection question
What should govern this AI system
for this use?
-
Binding requirementsWhich laws, directives, contracts, or sector rules apply?
-
Governance backboneWhich framework organizes accountability and risk?
-
Overlays & assuranceWhich security, testing, impact, or audit methods close the gaps?
01 / Choose by objective
Which framework should you use?
Choose the primary instrument based on the outcome you need. Then add the laws, security controls, testing methods, and sector requirements that the primary framework does not cover.
- NIST AI RMF
- Flexible risk backboneGood if you need a voluntary, vendor-neutral structure for governing and managing AI risk without certification. View entry.
- ISO/IEC 42001
- Formal management systemGood if you need organization-wide governance, repeatable management processes, and a certifiable AI management system. View entry.
- EU AI Act
- Legal complianceGood if EU market activity or covered AI roles create legal obligations; pair the Act with implementation guidance and applicable technical standards. View entry.
- OWASP + CSA AICM
- GenAI security controlsGood if the immediate problem is LLM, agent, application, or cloud-AI security rather than enterprise governance alone. See security resources.
- IIA / ISACA
- Audit and GRCGood if internal audit, assurance, or technology-risk teams need practitioner-oriented methods and evidence expectations. See assurance resources.
- NIST TEVV + ISO 42005
- Evaluation and impactGood if you need to test claims, structure impact assessment, or build an assurance case around AI behavior. See assurance resources.
Selection rule: a voluntary framework cannot replace a law, and a law rarely supplies every control needed to operate an AI program. Treat the recommendation as a stack, not a winner-take-all ranking.
02 / Build the stack
How do these frameworks fit together?
Use four layers. This keeps legal obligations separate from voluntary management practices and prevents security or assurance requirements from disappearing inside a general governance program.
A practical four-layer stack
Binding requirements → governance backbone → domain controls → assurance
Applicable laws, regulations, directives, contractual duties, and sector rules. Example: the EU AI Act or a U.S. state AI law.
An organization-level system for accountability and risk. Common choices include ISO/IEC 42001, NIST AI RMF, and public governance frameworks.
Add controls for GenAI, agents, security, data quality, human oversight, impact assessment, or industry-specific requirements.
Define how the claims will be tested and evidenced. Use impact assessment, TEVV, internal audit, independent certification, or other assurance methods appropriate to the decision.
- Enterprise governance
- ISO/IEC 42001+ ISO/IEC 23894 + NIST AI RMF
- EU high-risk AI
- EU AI Act+ applicable harmonised standards + impact assessment + security controls
- GenAI & agents
- NIST GenAI Profile+ OWASP + CSA AICM + agent-specific governance
- Audit & assurance
- IIA / ISACA+ ISO 42005/42006 + NIST TEVV + evidence requirements
03 / Primary-source directory
Browse AI laws, standards, frameworks and assurance guidance.
Entries are grouped by function rather than prestige. Each entry links to the issuing organization, standards body, government source, or authoritative legal repository rather than a third-party summary. Draft and emerging work is labeled separately.
- Law / regulation
- Can create binding obligations within scope.Start with applicability before choosing voluntary frameworks.
- Standard
- Consensus or technical requirements.A standard may or may not be certifiable.
- Framework
- Organizes governance, risk, security, or assurance practices.Authority depends on the issuer and context.
- Guidance / code
- Helps interpret or implement requirements.Check whether the guidance is voluntary, contractual, regulatory, or sector-specific.
04 / Related publications
Related publications & research
Not every influential AI publication is a framework, standard, or binding rule. This directory focuses on instruments that organizations can directly use to structure governance, interpret obligations, implement controls, test systems, or conduct assurance. Broader principles, declarations, research reports, and policy publications are treated separately so they are not presented as equivalent to laws or implementable standards.
Examples include ethics principles, declarations, recommendations, white papers, policy reports, transparency or safety reports, and academic or professional research. These materials can still shape governance decisions, regulatory expectations, and assurance practice even when they do not create a control framework of their own.
Use this directory when you need an implementable governance, legal, security, testing, or assurance instrument. Use related publications when you need broader policy context, research, principles, or interpretive material.
05 / Use & maintenance
How to use this directory
Use this directory to identify the laws, standards, frameworks, security resources, and assurance methods relevant to an AI system or program. Which instruments apply depends on jurisdiction, organizational role, sector, system type, use case, and contractual requirements.
Each entry is classified by type and status and links to its issuing or authoritative source. Current instruments are distinguished from drafts, proposed legislation, and other emerging work so readers can see what applies now and what may change.
For implementation and assurance work, record the exact title, version, publication date, and source used. Preserve the version relied upon for an assessment so later reviewers can reconstruct the basis for the decision.