AI Governance Frameworks & Standards

Frameworks & standards reference

AI frameworks, standards & regulations.

Frameworks and standards provide structured ways to assign accountability, manage AI risk, implement controls, and demonstrate oversight. Laws can add binding requirements, while security, testing, and assurance resources address specialized gaps.

Separate what applies from what helps. Then build a framework stack that covers the obligations, risks, and assurance needs that matter for the system.

The selection question

What should govern this AI system
for this use?

  1. Binding requirementsWhich laws, directives, contracts, or sector rules apply?
  2. Governance backboneWhich framework organizes accountability and risk?
  3. Overlays & assuranceWhich security, testing, impact, or audit methods close the gaps?
Most organizations need a stack rather than one universal framework.

01 / Choose by objective

Which framework should you use?

Choose the primary instrument based on the outcome you need. Then add the laws, security controls, testing methods, and sector requirements that the primary framework does not cover.

NIST AI RMF
Flexible risk backboneGood if you need a voluntary, vendor-neutral structure for governing and managing AI risk without certification. View entry.
ISO/IEC 42001
Formal management systemGood if you need organization-wide governance, repeatable management processes, and a certifiable AI management system. View entry.
EU AI Act
Legal complianceGood if EU market activity or covered AI roles create legal obligations; pair the Act with implementation guidance and applicable technical standards. View entry.
OWASP + CSA AICM
GenAI security controlsGood if the immediate problem is LLM, agent, application, or cloud-AI security rather than enterprise governance alone. See security resources.
IIA / ISACA
Audit and GRCGood if internal audit, assurance, or technology-risk teams need practitioner-oriented methods and evidence expectations. See assurance resources.
NIST TEVV + ISO 42005
Evaluation and impactGood if you need to test claims, structure impact assessment, or build an assurance case around AI behavior. See assurance resources.

Selection rule: a voluntary framework cannot replace a law, and a law rarely supplies every control needed to operate an AI program. Treat the recommendation as a stack, not a winner-take-all ranking.

02 / Build the stack

How do these frameworks fit together?

Use four layers. This keeps legal obligations separate from voluntary management practices and prevents security or assurance requirements from disappearing inside a general governance program.

Framework architectureFour layers

A practical four-layer stack

Binding requirements → governance backbone → domain controls → assurance

01 / Binding layer

Applicable laws, regulations, directives, contractual duties, and sector rules. Example: the EU AI Act or a U.S. state AI law.

02 / Governance backbone

An organization-level system for accountability and risk. Common choices include ISO/IEC 42001, NIST AI RMF, and public governance frameworks.

03 / Domain controls

Add controls for GenAI, agents, security, data quality, human oversight, impact assessment, or industry-specific requirements.

04 / Assurance

Define how the claims will be tested and evidenced. Use impact assessment, TEVV, internal audit, independent certification, or other assurance methods appropriate to the decision.

Enterprise governance
ISO/IEC 42001+ ISO/IEC 23894 + NIST AI RMF
EU high-risk AI
EU AI Act+ applicable harmonised standards + impact assessment + security controls
GenAI & agents
NIST GenAI Profile+ OWASP + CSA AICM + agent-specific governance
Audit & assurance
IIA / ISACA+ ISO 42005/42006 + NIST TEVV + evidence requirements

03 / Primary-source directory

Browse AI laws, standards, frameworks and assurance guidance.

Entries are grouped by function rather than prestige. Each entry links to the issuing organization, standards body, government source, or authoritative legal repository rather than a third-party summary. Draft and emerging work is labeled separately.

Law / regulation
Can create binding obligations within scope.Start with applicability before choosing voluntary frameworks.
Standard
Consensus or technical requirements.A standard may or may not be certifiable.
Framework
Organizes governance, risk, security, or assurance practices.Authority depends on the issuer and context.
Guidance / code
Helps interpret or implement requirements.Check whether the guidance is voluntary, contractual, regulatory, or sector-specific.

03.1 / Laws & policy

AI laws, regulations and government governance instruments

Start here when jurisdiction, public-sector use, procurement, disclosure, or legally significant AI obligations drive the decision. A law or directive is not interchangeable with a voluntary framework.

RegulationIn force / staged application

EU

European Union Artificial Intelligence Act — Regulation (EU) 2024/1689

The EU’s horizontal AI regulation, built around prohibited practices, risk classes, transparency duties, general-purpose AI obligations and governance.

Good if: You develop, deploy, import or distribute AI connected to the EU market and need to establish which legal duties apply.

Official source

Official guidanceCurrent

European Commission

EU AI Act implementation hub

The Commission’s central implementation page for the AI Act, including guidance, codes of practice, enforcement information and standardisation updates.

Good if: You need the current implementation layer around the legal text rather than the regulation alone.

Official source

Code of practiceCurrent

European Commission / AI Office

General-Purpose AI Code of Practice

A voluntary compliance tool for providers of general-purpose AI models addressing transparency, copyright and systemic-risk obligations.

Good if: You provide or govern GPAI models subject to the EU AI Act and want an implementation route aligned with the Commission.

Official source

Code of practiceCurrent

European Commission / AI Office

Code of Practice on Transparency of AI-Generated Content

Implementation support for AI Act transparency obligations concerning certain AI-generated or manipulated content.

Good if: Your systems generate or manipulate content that may trigger AI Act transparency and disclosure requirements.

Official source

Official guidanceCurrent

European Commission

Guidelines on the definition of an AI system

Commission guidance intended to support consistent interpretation of what falls within the AI Act definition of an AI system.

Good if: You are doing scoping work and first need to determine whether a system is within AI Act coverage.

Official source

Official guidanceCurrent

European Commission

Guidelines on prohibited AI practices

Commission guidance explaining the AI Act’s prohibited-practice provisions and their application.

Good if: You need an early legal-screening step before performing a broader high-risk or GPAI assessment.

Official source

Official guidanceCurrent

European Commission / AI Office

Guidelines for providers of general-purpose AI models

Guidance on scope and obligations for providers of general-purpose AI models under the AI Act.

Good if: You provide, modify or place a GPAI model on the EU market and need role-specific scoping guidance.

Official source

Regulatory templateCurrent

European Commission / AI Office

Public summary template for GPAI training content

The Commission template and explanatory notice for the public summary of content used to train general-purpose AI models.

Good if: You are a GPAI provider preparing documentation required by the EU AI Act.

Official source

Standardisation programmeIn development

European Commission / CEN-CENELEC

EU AI Act harmonised standards programme

The programme developing harmonised standards for high-risk AI requirements such as risk management, data governance, logging, transparency, human oversight, robustness, cybersecurity and conformity assessment.

Good if: You need to track the technical standards that may provide a presumption of conformity with AI Act requirements.

Official source

International treatyOpen for signature / implementation

Council of Europe

Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law

A legally significant international treaty framework addressing AI across human rights, democracy and rule-of-law protections.

Good if: You need a public-law and human-rights governance reference that extends beyond technical risk management.

Official source

Executive orderCurrent federal policy

United States

Executive Order 14179 — Removing Barriers to American Leadership in Artificial Intelligence

The 2025 executive order that reset U.S. executive-branch AI policy and directed development of an AI action plan.

Good if: You track current U.S. federal AI policy direction, especially for federal agencies and policy alignment.

Official source

Federal policy planCurrent

United States

America’s AI Action Plan

The federal policy plan focused on AI innovation, infrastructure and international leadership.

Good if: You need the current U.S. administration’s broad AI policy priorities rather than an enterprise control framework.

Official source

Federal memorandumCurrent

U.S. Office of Management and Budget

OMB M-25-21 — Accelerating Federal Use of AI through Innovation, Governance, and Public Trust

Governance requirements and practices for federal agency use of AI.

Good if: You work with U.S. federal agencies or need a public-sector governance reference for agency AI use.

Official source

Federal memorandumCurrent

U.S. Office of Management and Budget

OMB M-25-22 — Driving Efficient Acquisition of Artificial Intelligence in Government

Federal guidance for acquiring AI, including procurement and vendor considerations.

Good if: You govern third-party AI acquisition for a U.S. federal agency or sell AI into federal procurement.

Official source

Federal memorandumCurrent

U.S. Office of Management and Budget

OMB M-26-04 — Unbiased AI Principles

Federal principles intended to increase public trust through requirements concerning politically neutral and unbiased AI in covered federal contexts.

Good if: You track federal requirements affecting agency AI procurement, configuration or use.

Official source

Executive orderCurrent

United States

Executive Order 14365 — National Policy Framework for Artificial Intelligence

A federal policy instrument addressing the relationship between national AI policy and state-level regulation.

Good if: You monitor U.S. federal-state AI policy interaction and potential pre-emption strategy.

Official source

Legislative recommendationsPublished 2026

United States

A National Policy Framework for Artificial Intelligence — Legislative Recommendations

Executive-branch recommendations to Congress for a national statutory AI policy framework.

Good if: You track likely U.S. federal legislative directions and emerging compliance themes.

Official source

Government directiveCurrent

Government of Canada

Directive on Automated Decision-Making

Rules and governance requirements for automated decision systems used by the Government of Canada.

Good if: You operate in Canadian federal government contexts or want a mature public-sector automated-decision governance model.

Official source

Assessment toolCurrent

Government of Canada

Algorithmic Impact Assessment

A structured assessment used with Canada’s Directive on Automated Decision-Making to determine impact levels and related requirements.

Good if: You need a practical public-sector impact-assessment model tied to governance consequences.

Official source

State lawEnacted

State of Colorado

Colorado Consumer Protections for Artificial Intelligence — SB24-205

A state AI law focused on high-risk AI systems, developers, deployers and algorithmic discrimination protections.

Good if: You develop or deploy covered high-risk AI systems in Colorado and need state-specific legal scoping.

Official source

State lawEffective 2026

State of Texas

Texas Responsible Artificial Intelligence Governance Act — HB 149

Texas legislation establishing AI-related consumer protections, restrictions, disclosures and a regulatory sandbox structure.

Good if: You develop or deploy AI in Texas and need to identify obligations that sit alongside general consumer-protection law.

Official source

State lawEnacted

State of Utah

Utah Artificial Intelligence Policy Act — SB 149

Utah legislation addressing generative-AI disclosures, regulated occupations and an AI policy office and learning laboratory.

Good if: You use generative AI in Utah consumer or regulated-profession contexts.

Official source

National lawCurrent

Republic of Korea

Artificial Intelligence Basic Act

South Korea’s national AI framework law covering AI industry development and governance requirements.

Good if: You develop or provide AI services in South Korea and need national statutory requirements.

Official source

Administrative measureCurrent

China

Interim Measures for the Management of Generative Artificial Intelligence Services

National rules governing the provision of generative AI services to the public in China.

Good if: You provide public-facing generative AI services within the Chinese regulatory environment.

Official source

Administrative measureCurrent

China

Measures for Labelling AI-Generated Synthetic Content

Rules establishing requirements for identifying and labelling certain AI-generated or synthetic content.

Good if: Your AI product produces synthetic content for users in China and requires content-provenance or labelling controls.

Official source

Administrative measureEffective 2026

China

Interim Measures for Personified Interactive Artificial Intelligence Services

Rules addressing personified interactive AI services and related provider responsibilities.

Good if: You operate conversational or personified AI services in China and need product-specific governance requirements.

Official source

National lawIn force

Vietnam

Vietnam Law on Artificial Intelligence — Law No. 134/2025/QH15

Vietnam’s dedicated national AI law, issued in December 2025 and effective 1 March 2026, establishing a comprehensive legal framework for the development, provision, deployment, and use of AI.

Good if: You develop, provide, deploy, or use AI in Vietnam and need to determine obligations under the country’s dedicated national AI law.

Official source

National lawIn force

Japan

Japan AI Act — Act No. 53 of 2025

Japan’s national AI law, formally the Act on the Promotion of Research and Development and Utilization of Artificial Intelligence-Related Technology. It was promulgated in June 2025 and fully entered into force on 1 September 2025.

Good if: You operate in Japan and need the statutory layer that now sits above Japan’s business and implementation guidance.

Official source

03.2 / Public frameworks

Government and public-sector frameworks

These instruments are generally voluntary guidance or public-sector governance mechanisms rather than laws. They are useful when an organization needs an implementation model, especially where no single regulation supplies one.

Risk frameworkPublished / under revision

NIST

NIST AI Risk Management Framework 1.0

A voluntary framework organized around Govern, Map, Measure and Manage for incorporating trustworthiness considerations into AI risk management.

Good if: You want a flexible, vendor-neutral AI risk backbone without pursuing certification.

Official source

Implementation resourcesCurrent

NIST

NIST AI RMF Playbook and crosswalk resources

Implementation suggestions and crosswalk material supporting application of the AI RMF.

Good if: You already use the AI RMF and need more operational prompts, mappings and implementation support.

Official source

Risk profilePublished

NIST

NIST AI 600-1 — Generative AI Profile

A companion profile to the AI RMF focused on risks and risk-management considerations specific to generative AI.

Good if: Generative AI is material to your environment and the general AI RMF needs a GenAI-specific overlay.

Official source

Government guidancePublished

Japan — METI / MIC

AI Guidelines for Business Ver. 1.0

Japanese government guidance consolidating governance considerations for organizations developing, providing and using AI.

Good if: You operate in Japan or want an organization-level governance guide that addresses developers and business users.

Official source

Governance frameworkPublished

Singapore — PDPC / IMDA

Model AI Governance Framework — Second Edition

A practical governance framework for responsible organizational deployment of AI, including internal governance, human involvement, operations and stakeholder communication.

Good if: You want a pragmatic enterprise governance baseline with strong implementation orientation.

Official source

GenAI frameworkPublished

Singapore — IMDA / AI Verify Foundation

Model AI Governance Framework for Generative AI

A governance framework extending Singapore’s approach to generative AI risks across accountability, data, development, incidents, testing, security and content provenance.

Good if: You need a GenAI governance overlay rather than a traditional-AI-only model.

Official source

Agentic AI frameworkPublished 2026

Singapore — IMDA

Model AI Governance Framework for Agentic AI v1.5

A framework focused on governance issues arising from AI agents that can plan, act, use tools and interact with external systems.

Good if: You are deploying AI agents and need governance beyond ordinary chatbot or model-risk controls.

Official source

Testing framework & toolkitCurrent

Singapore — IMDA / AI Verify Foundation

AI Verify

A testing and governance ecosystem for assessing AI systems against responsible-AI principles using technical tests and process checks.

Good if: You want practical AI testing support that can complement governance documentation.

Official source

Government guidanceCurrent

Australian Government / National AI Centre

Guidance for AI Adoption — Foundations

Six essential practices for responsible AI governance and adoption, developed as the evolution of Australia’s earlier Voluntary AI Safety Standard.

Good if: You need a clear organizational starting point for responsible AI adoption in Australia.

Official source

Historical implementation standardEvolved

Australian Government / National AI Centre

Voluntary AI Safety Standard

The earlier ten-guardrail Australian framework; the government now directs readers to the newer Guidance for AI Adoption.

Good if: You need historical continuity, mappings or evidence tied to the 2024 guardrails.

Official source

Government playbookCurrent

UK Government

AI Playbook for the UK Government

Practical guidance for responsible use of AI across UK government organizations.

Good if: You govern AI use in public-sector settings and want operational guidance rather than a certification standard.

Official source

Ethics & governance frameworkCurrent

UK Government

Data and AI Ethics Framework

A government framework for responsible data and AI work, emphasizing transparency, accountability and public benefit.

Good if: You are designing or reviewing public-sector data and AI initiatives in the UK.

Official source

National governance frameworkCurrent

India — MeitY / IndiaAI Mission

India AI Governance Guidelines

India’s national principle-based AI governance framework, released in November 2025, organized around seven guiding principles, six governance pillars, an implementation action plan, and practical guidance for industry and regulators.

Good if: You operate in India and need the country’s current national governance framework for safe, responsible, and inclusive AI adoption.

Official source

03.3 / Standards

ISO/IEC and IEEE AI standards

Formal standards can define management systems, risk processes, terminology, lifecycle practices, data quality, explainability, impact assessment, certification and specialized technical requirements. They are not all certifiable, and buying one standard does not automatically create a complete AI governance program.

Management-system standardPublished

ISO/IEC

ISO/IEC 42001:2023 — Artificial intelligence management system

Organization-wide requirements for establishing, implementing, maintaining and continually improving an AI management system.

Good if: You want a formal enterprise AI management system and a pathway to third-party certification.

Official source

Risk-management standardPublished

ISO/IEC

ISO/IEC 23894:2023 — Guidance on AI risk management

Guidance for integrating AI-specific risk management into organizational activities and functions.

Good if: You need an AI-specific risk process that can complement ISO 42001 or existing enterprise risk management.

Official source

Governance standardPublished

ISO/IEC

ISO/IEC 38507:2022 — Governance implications of the use of AI by organizations

Governance guidance for governing bodies on the organizational use of AI.

Good if: Board, executive or governance-level accountability is the primary design problem.

Official source

Impact-assessment standardPublished

ISO/IEC

ISO/IEC 42005:2025 — AI system impact assessment

Guidance for conducting and documenting AI system impact assessments across an AI system lifecycle.

Good if: You need a repeatable impact-assessment process tied to governance and evidence.

Official source

Conformity-assessment standardPublished

ISO/IEC

ISO/IEC 42006:2025 — Requirements for bodies providing audit and certification of AI management systems

Requirements for organizations that audit and certify AI management systems.

Good if: You are concerned with the competence, consistency or independence of ISO 42001 certification activities.

Official source

Foundational standardPublished

ISO/IEC

ISO/IEC 22989:2022 — AI concepts and terminology

Core AI terminology and concepts used across the ISO/IEC AI standards ecosystem.

Good if: You need consistent definitions before mapping requirements across teams or frameworks.

Official source

Technical frameworkPublished

ISO/IEC

ISO/IEC 23053:2022 — Framework for AI systems using machine learning

A generic framework for describing AI systems that use machine-learning technology.

Good if: You need a common technical model for describing ML-based AI system components and relationships.

Official source

Lifecycle standardPublished

ISO/IEC

ISO/IEC 5338:2023 — AI system life cycle processes

Processes for defining, controlling and improving the lifecycle of AI systems.

Good if: Your governance model needs to connect requirements to development, deployment, operation and retirement.

Official source

Implementation guidancePublished

ISO/IEC

ISO/IEC 5339:2024 — Guidance for AI applications

Guidance supporting the application of AI concepts and lifecycle considerations in organizational contexts.

Good if: You need implementation guidance that complements broader AI lifecycle and management-system standards.

Official source

Data governance standardPublished

ISO/IEC

ISO/IEC 8183:2023 — Data life cycle framework

A framework for data lifecycle processes relevant to analytics and AI.

Good if: Data provenance, data lifecycle responsibilities and data quality are central governance concerns.

Official source

Data-quality seriesPublished

ISO/IEC

ISO/IEC 5259 series — Data quality for analytics and machine learning

A multi-part standards series covering data quality terminology, measures, management requirements and process frameworks for analytics and machine learning.

Good if: Training, evaluation or production data quality is a core assurance dependency.

Official source

Technical specificationPublished

ISO/IEC

ISO/IEC TS 6254:2025 — Explainability and interpretability

Objectives and approaches for explaining and interpreting machine-learning models and AI-system behavior and outputs.

Good if: Stakeholders need a structured way to define and evaluate explainability objectives.

Official source

Technical reportPublished

ISO/IEC

ISO/IEC TR 24028:2020 — Overview of trustworthiness in AI

A survey of AI trustworthiness concepts including transparency, explainability, controllability, reliability, safety, security and privacy.

Good if: You need foundational trustworthiness vocabulary and risk context rather than a certification checklist.

Official source

Standards catalogueContinuously updated

ISO/IEC

ISO/IEC JTC 1/SC 42 AI standards catalogue

The authoritative catalogue for published and developing ISO/IEC artificial-intelligence standards.

Good if: You need to verify the complete current SC 42 portfolio rather than rely on a static secondary list.

Official source

Engineering standardPublished

IEEE

IEEE 7000-2021 — Addressing ethical concerns during system design

A process for incorporating value-based and ethical considerations into system design.

Good if: You need to connect ethical concerns to system-engineering activities and documented design decisions.

Official source

Transparency standardPublished

IEEE

IEEE 7001-2021 — Transparency of autonomous systems

A standard focused on transparency requirements for autonomous systems.

Good if: Transparency requirements need to be engineered into an autonomous or intelligent system.

Official source

Bias-management standardPublished

IEEE

IEEE 7003-2024 — Algorithmic bias considerations

A process-oriented standard for identifying and addressing sources of algorithmic bias.

Good if: Bias identification, governance and remediation require a dedicated engineering process.

Official source

Impact standardPublished

IEEE

IEEE 7010-2020 — Well-being metrics for ethical AI

A standard for considering and assessing impacts of autonomous and intelligent systems on human well-being.

Good if: You need a human-impact perspective that extends beyond technical performance metrics.

Official source

Evaluation standardPublished

IEEE

IEEE 2841-2022 — Framework and process for deep-learning evaluation

A framework for evaluating deep-learning algorithms and systems.

Good if: You need a structured evaluation process for deep-learning performance and quality.

Official source

Standards catalogueContinuously updated

IEEE Standards Association

IEEE Autonomous and Intelligent Systems standards portfolio

IEEE’s portfolio covering ethics, transparency, privacy, bias, fail-safe design, well-being and related autonomous-system concerns.

Good if: You need to identify specialized IEEE standards beyond the most commonly cited 7000-series documents.

Official source

03.4 / Security

AI security frameworks, threat knowledge bases and control catalogs

Security artifacts fill gaps that broad governance frameworks often leave open. Use them as overlays for threat modeling, secure development, GenAI application security, agent security and control design.

Security risk listCurrent

OWASP GenAI Security Project

OWASP Top 10 for LLM and Generative AI Applications

A prioritized set of security risks affecting LLM and generative-AI applications, supported by mitigation guidance.

Good if: You build or assess LLM applications and need an application-security threat baseline.

Official source

Security programmeCurrent / evolving

OWASP

OWASP GenAI Security Project — Top 10 and agentic security resources

The broader OWASP GenAI programme covering LLM security, agentic applications, controls and related implementation resources.

Good if: You need to track emerging application and agentic-AI security guidance beyond one Top 10 release.

Official source

Control frameworkPublished 2026

Cloud Security Alliance

AI Controls Matrix v1.1

A large AI-focused control matrix spanning governance, development, infrastructure, security, privacy and operational domains, with mappings to other standards.

Good if: You need a detailed control catalog suitable for cloud and enterprise AI control design.

Official source

Compliance criteriaPublished

German Federal Office for Information Security (BSI)

AI Cloud Service Compliance Criteria Catalogue — AIC4

Security and compliance criteria for AI services delivered through cloud environments.

Good if: You assess AI cloud services and need security-oriented criteria from a national cybersecurity authority.

Official source

Cybersecurity standardPublished

ETSI

ETSI EN 304 223 — Baseline Cyber Security Requirements for AI Models and Systems

Lifecycle security requirements for AI models and systems, covering secure design, development, deployment, maintenance and end of life.

Good if: You need a formal AI-specific cybersecurity baseline rather than a general software-security framework.

Official source

Cybersecurity frameworkPublished

ENISA

Multilayer Framework for Good Cybersecurity Practices for AI

A three-layer approach combining cybersecurity foundations, AI-specific practices and sector-specific cybersecurity for AI.

Good if: You need an EU cybersecurity-agency framework connecting general security practice with AI-specific risks.

Official source

Threat knowledge baseCurrent

MITRE

MITRE ATLAS

A knowledge base of adversary tactics and techniques for attacks against AI-enabled systems, modeled in a structure similar to ATT&CK.

Good if: You perform AI threat modeling, red teaming, detection engineering or adversarial-risk analysis.

Official source

Industry security frameworkCurrent

Google

Secure AI Framework — SAIF

A conceptual framework for protecting AI systems and managing AI-specific security risks across development and deployment.

Good if: You need a security architecture reference from a major AI and cloud provider.

Official source

Cybersecurity codePublished

UK Government

UK AI Cyber Security Code of Practice

A lifecycle code of practice setting expectations for AI cybersecurity across developers, system operators and data custodians.

Good if: You want government-backed AI cybersecurity practices aligned with emerging standardisation work.

Official source

03.5 / Assurance & audit

AI assurance, evaluation and audit frameworks

These artifacts are most useful when the question is not merely whether controls exist, but whether claims about an AI system can be tested, evidenced and independently reviewed.

Evaluation frameworkInitial public draft

NIST

NIST AI 200-2 — TEVV-Athlon Framework for Evaluating AI Systems

A developing framework for test, evaluation, verification and validation of AI systems.

Good if: You need a structured TEVV reference and want to track where NIST evaluation practice is heading.

Official source

Resource & evaluation hubCurrent

NIST

NIST AI Resource Center

NIST’s central AI risk and evaluation resource environment, including AI RMF resources and supporting material.

Good if: You need official NIST implementation, measurement or evaluation resources in one place.

Official source

Evaluation guidanceCurrent / draft releases

NIST Center for AI Standards and Innovation

CAISI Guidelines

Official guidelines covering advanced-model, benchmark and agent evaluation topics as CAISI work develops.

Good if: You track emerging U.S. federal evaluation practice for advanced AI systems and agents.

Official source

Assurance guidancePublished

UK Government

Introduction to AI Assurance

A public-sector introduction to AI assurance concepts, roles and approaches.

Good if: You need to explain or design an assurance function before selecting specific technical testing methods.

Official source

Assurance techniques catalogueCurrent

UK Government

Portfolio of AI Assurance Techniques

A catalogue of assurance techniques and examples that can support trustworthy AI claims across the lifecycle.

Good if: You need to choose among impact assessment, audit, testing, verification and other assurance methods.

Official source

Governance & assurance toolkitCurrent

UK Government

Responsible AI Toolkit

A collection of tools and guidance supporting responsible AI development and deployment.

Good if: You need practical public-sector resources that bridge governance, assurance and implementation.

Official source

Audit frameworkPublished 2024

The Institute of Internal Auditors

The IIA’s Artificial Intelligence Auditing Framework, 2nd Edition

Guidance for internal auditors covering AI governance, management, risk, controls and the internal-audit role.

Good if: Internal audit needs a structured approach for AI assurance and advisory work.

Official source

Testing frameworkCurrent

Singapore — IMDA / AI Verify Foundation

AI Verify testing framework and toolkit

Process and technical testing support for responsible-AI principles and governance checks.

Good if: You need hands-on testing capabilities that complement policy and governance documentation.

Official source

Certification scheme requirementsPublished 2026

Cloud Security Alliance

STAR for AI certification requirements

Requirements supporting CSA’s STAR for AI certification ecosystem and assurance over AI-related controls.

Good if: You need to track emerging independent assurance options around CSA’s AI Controls Matrix.

Official source

03.6 / Professional & industry

Professional, industry and frontier-AI frameworks

These frameworks can be highly useful but should be labeled by provenance. A professional-body framework or vendor self-governance model is not equivalent to law, an independent consensus standard, or third-party certification.

Professional frameworkPublished 2026

ISACA

Governing AI Across its Lifecycle: A Framework for Risk Practitioners

A lifecycle governance framework aimed at risk practitioners, connecting governance stages with practical artifacts and oversight activities.

Good if: Risk, audit or GRC teams need a practitioner-oriented operating model across the AI lifecycle.

Official source

Professional frameworkPublished 2026

EC-Council

ADG — Adopt, Defend, Govern Framework

A twelve-control model spanning AI adoption, security and governance with mappings to major external frameworks.

Good if: You want a compact practitioner framework that combines governance and defensive security concerns.

Official source

Industry reference frameworkPublished

IBM

IBM AI Safety and Governance Framework

IBM’s framework for governing AI safety and trustworthiness practices across the AI lifecycle.

Good if: You want a major-enterprise reference model and will distinguish vendor practice from independent standards.

Official source

Industry standardCurrent

Microsoft

Microsoft Responsible AI Standard

Microsoft’s internal responsible-AI requirements and practices for designing, developing and deploying AI systems.

Good if: You need a mature vendor implementation reference for operationalizing responsible-AI principles.

Official source

Frontier safety frameworkCurrent

OpenAI

OpenAI Preparedness Framework

A framework for tracking and managing severe risks associated with increasingly capable frontier models.

Good if: You study frontier-model capability thresholds, safeguards and deployment decision processes.

Official source

Frontier governance frameworkPublished 2026

OpenAI

OpenAI Frontier Governance Framework

A governance framework connecting frontier-AI safety and security practices with emerging legal and policy expectations.

Good if: You need a current frontier-model governance reference from a leading model developer.

Official source

Frontier safety policyCurrent / versioned

Anthropic

Responsible Scaling Policy

Anthropic’s versioned policy for scaling safeguards as model capabilities and risks increase.

Good if: You compare frontier-model scaling thresholds, capability evaluations and safeguard commitments.

Official source

Frontier safety frameworkCurrent / versioned

Google DeepMind

Frontier Safety Framework

Google DeepMind’s framework for identifying critical capability levels and applying safeguards to frontier models.

Good if: You compare frontier-lab approaches to capability thresholds, evaluations and risk mitigation.

Official source

Industry governance frameworkPublished

World Economic Forum AI Governance Alliance

Presidio AI Framework

A generative-AI governance framework emphasizing shared responsibility, lifecycle guardrails and earlier risk mitigation.

Good if: You need a cross-ecosystem GenAI governance model spanning model creators, adapters and users.

Official source

03.7 / Emerging

AI standards and governance work now emerging

Emerging work includes proposed legislation, draft standards, standards-development work items, and forthcoming regulatory instruments. These entries are included for planning and monitoring; they should not be treated as current requirements unless their status says otherwise.

Framework revisionIn development

NIST

NIST AI RMF revision

NIST is revising AI RMF 1.0 as AI capabilities, deployment patterns and risk-management practice evolve.

Good if: You use AI RMF 1.0 and need to anticipate changes to your governance baseline.

Official source

Sector profileIn development

NIST

NIST Critical Infrastructure AI RMF Profile

A developing AI RMF profile intended for critical-infrastructure risk management.

Good if: You operate critical infrastructure and want to track sector-specific adaptation of the AI RMF.

Official source

Standards-development initiativeDraft releases

NIST

NIST AI Standards Zero Drafts

A pilot process publishing early AI standards drafts for broader public participation before formal standardisation.

Good if: You want visibility into emerging U.S. standards concepts before they reach mature publication.

Official source

Standards initiativeLaunched 2026

NIST / CAISI

NIST AI Agent Standards Initiative

A standards initiative focused on interoperable, secure and trustworthy AI agents, including protocols, identity and security research.

Good if: Agentic AI is on your roadmap and you need to track emerging interoperability and security standards.

Official source

Implementation guidanceUnder development

ISO/IEC

ISO/IEC 42003 — Guidance for implementing ISO/IEC 42001

Developing guidance intended to support implementation of AI management systems based on ISO/IEC 42001.

Good if: You use ISO 42001 and want to plan for more detailed implementation guidance.

Official source

Conformity assessmentUnder development

ISO/IEC

ISO/IEC 42007 — Conformity assessment scheme requirements

Developing requirements concerning conformity-assessment schemes for AI management systems.

Good if: You track the maturation of certification and conformity structures around AI management systems.

Official source

Human-oversight standardFinal draft stage

ISO/IEC

ISO/IEC 42105 — Human oversight of AI systems

A developing standard focused on human oversight across AI-system contexts.

Good if: Human oversight is a key control and you want to anticipate a dedicated international standard.

Official source

Logging standardFinal draft stage

ISO/IEC

ISO/IEC 24970 — AI system logging

A developing standard focused on logging for AI systems.

Good if: Traceability, monitoring and audit evidence depend on reliable AI-system logs.

Official source

GenAI risk guidanceUnder development

ISO/IEC

ISO/IEC 25568 — Generative AI risk management guidance

Developing guidance specifically addressing risk management for generative AI.

Good if: Your existing AI risk process needs a future international GenAI-specific overlay.

Official source

Process assessmentUnder development

ISO/IEC

ISO/IEC 25704 — AI lifecycle process assessment

A developing approach for assessing AI lifecycle processes.

Good if: You need evidence about process capability and maturity rather than only control existence.

Official source

Incident reportingUnder development

ISO/IEC

ISO/IEC 25870 — AI incident reporting data

A developing standard addressing data used to report and exchange information about AI incidents.

Good if: You are designing AI incident-management and external reporting processes.

Official source

Testing standardUnder publication

ISO/IEC

ISO/IEC 42119-3 — AI verification and validation

A developing testing standard focused on verification and validation of AI systems.

Good if: Assurance work requires more formalized verification and validation methods.

Official source

Testing standardUnder development

ISO/IEC

ISO/IEC 42119-7 — AI red teaming

A developing international standard focused on red-team testing of AI systems.

Good if: You are formalizing adversarial testing and want to anticipate an international red-teaming standard.

Official source

Evaluation standardUnder development

ISO/IEC

ISO/IEC 42119-8 — Prompt-based quality assessment for generative AI

A developing standard addressing prompt-based assessment methods for generative AI quality.

Good if: You need repeatable GenAI evaluation methods tied to prompts and response quality.

Official source

Draft harmonised standardIn development

CEN-CENELEC JTC 21

prEN 18286 — AI Quality Management System for EU AI Act regulatory purposes

A European quality-management standard being developed specifically to support high-risk AI provider obligations under the EU AI Act.

Good if: You need to anticipate EU-specific quality-management expectations rather than assume ISO 42001 alone provides AI Act conformity.

Official source

Standards work programmeActive

ETSI

ETSI AI conformance and GenAI security work programme

Ongoing ETSI work extends AI cybersecurity into conformance assessment, incident reporting, GenAI harms and inter-agent communication.

Good if: You need visibility into near-term AI cybersecurity standards beyond EN 304 223.

Official source

Proposed legislationUnder development

Malaysia — Ministry of Digital / AI Malaysia

Malaysia — Proposed AI Governance Bill

Malaysia does not yet have a dedicated AI law, but the government is developing a proposed AI Governance Bill intended to establish a common legal framework for the responsible development, deployment, and use of AI.

Good if: You operate in Malaysia and need to anticipate the country’s emerging statutory AI-governance regime while continuing to apply current privacy, cybersecurity, online-safety, and sector requirements.

Official source

04 / Related publications

Related publications & research

Not every influential AI publication is a framework, standard, or binding rule. This directory focuses on instruments that organizations can directly use to structure governance, interpret obligations, implement controls, test systems, or conduct assurance. Broader principles, declarations, research reports, and policy publications are treated separately so they are not presented as equivalent to laws or implementable standards.

Examples include ethics principles, declarations, recommendations, white papers, policy reports, transparency or safety reports, and academic or professional research. These materials can still shape governance decisions, regulatory expectations, and assurance practice even when they do not create a control framework of their own.

Use this directory when you need an implementable governance, legal, security, testing, or assurance instrument. Use related publications when you need broader policy context, research, principles, or interpretive material.

05 / Use & maintenance

How to use this directory

Use this directory to identify the laws, standards, frameworks, security resources, and assurance methods relevant to an AI system or program. Which instruments apply depends on jurisdiction, organizational role, sector, system type, use case, and contractual requirements.

Each entry is classified by type and status and links to its issuing or authoritative source. Current instruments are distinguished from drafts, proposed legislation, and other emerging work so readers can see what applies now and what may change.

For implementation and assurance work, record the exact title, version, publication date, and source used. Preserve the version relied upon for an assessment so later reviewers can reconstruct the basis for the decision.

Back to the beginning