Compliance Frameworks Overview
TruthVouch supports 55+ compliance frameworks spanning 22 jurisdictions. This page organizes frameworks by region and explains what each requires. Use it to understand which regulations apply to your organization and systems.
Framework Selection Guide
Not sure which frameworks apply to you? Answer these questions:

- Where do your users live? (Determines regional compliance rules)
- What industry are you in? (Finance, healthcare, education, SaaS, etc.)
- Are you pursuing certifications? (ISO 42001, SOC 2, etc.)
- Who are your customers? (Government requires NIST AI RMF; enterprises want SOC 2, etc.)
Once you know, find the matching frameworks below and enable them in your compliance program.
Regional Frameworks
European Union & UK
| Framework | Scope | Articles/Controls | Auto-Coverage | Notes |
|---|---|---|---|---|
| EU AI Act | High-risk AI systems | 37 articles | 100% | Mandatory if serving EU users; risk classification, documentation, incident reporting |
| GDPR | Personal data processing | 99 articles | 95% | Data protection, DPIAs, breach notification, data subject rights |
| UK AI Safety | Emerging AI regulation | 8 principles | 80% | Post-Brexit UK AI governance framework |
| UK GDPR | UK data protection | 99 articles | 95% | Similar to GDPR with UK-specific amendments |
Read more: EU AI Act Deep Dive, GDPR Compliance
United States & Canada
| Framework | Scope | Controls | Auto-Coverage | Notes |
|---|---|---|---|---|
| NIST AI RMF | AI Risk Management | 4 functions (Govern, Map, Measure, Manage) | 90% | US government preference; widely adopted by enterprises |
| CCPA | California privacy | 6 categories | 85% | Consumer privacy rights; expanding to CPRA |
| AIDA | Canadian AI Act | 8 principles | 80% | Proposed; similar to EU AI Act |
| State AI Laws | Colorado, Utah, Florida | Various | 75% | Emerging state-level AI regulations |
Read more: NIST AI RMF Guide
Global Standards (Any Jurisdiction)
| Framework | Scope | Controls | Auto-Coverage | Notes |
|---|---|---|---|---|
| ISO 42001 | AI Management System | 22 controls | 100% | Certification available; growing enterprise adoption |
| SOC 2 Type II | Service Organization Controls | 5 trust areas | 90% | Required for SaaS companies; auditor-verified |
| ISO 27001 | Information Security | 114 controls | 95% | Foundation for data security; complements AI frameworks |
| COBIT 2019 | IT Governance | 40 processes | 80% | Enterprise governance; AI governance subset |
Read more: ISO 42001 Guide, SOC 2 Guide
Healthcare & Life Sciences
| Framework | Scope | Controls | Auto-Coverage | Notes |
|---|---|---|---|---|
| HIPAA | US healthcare privacy & security | 18 safeguards | 90% | Mandatory for healthcare organizations; PHI protection |
| FDA AI Guidance | AI/ML in medical devices | 6 areas | 85% | Pre-market and post-market requirements |
| HL7 FHIR | Healthcare data interoperability | 12 profiles | 80% | Standards for health data exchange |
Read more: HIPAA Compliance
Finance & Insurance
| Framework | Scope | Controls | Auto-Coverage | Notes |
|---|---|---|---|---|
| FINRA | US brokerage/investment AI | 8 rules | 85% | Algorithmic trading, robo-advice, market manipulation |
| Prudential Regulation | Insurance & banking | 12 controls | 80% | UK/EU banking supervision; AI governance requirements |
| FINMA | Swiss financial AI | 10 guidelines | 80% | Swiss banking regulation |
| Singapore MAS | Singapore financial AI | 8 guidelines | 85% | Monetary Authority of Singapore; growing focus |
Read more: Finance & Insurance section
Privacy Laws (Global)
| Framework | Scope | Controls | Auto-Coverage | Notes |
|---|---|---|---|---|
| LGPD | Brazil privacy | 10 principles | 85% | South America’s GDPR equivalent |
| PDPA | Singapore privacy | 9 principles | 85% | Asia-Pacific privacy law |
| India DPDP | India data protection | 8 principles | 80% | India’s new privacy framework |
| South Korea POPIA | Korea personal information | 7 obligations | 80% | East Asia privacy regulation |
| Japan APPI | Japan privacy | 8 principles | 80% | Japan’s privacy law with AI amendments |
| Australia Privacy Act | Australia privacy | 13 principles | 85% | Australian Privacy Principles; growing AI focus |
Read more: Other Frameworks
Emerging Regulations
| Framework | Scope | Status | Auto-Coverage | Notes |
|---|---|---|---|---|
| China CAC AI Rules | AI content moderation | Enacted 2023 | 75% | China’s AI governance; content safety focus |
| Saudi Arabia GOSI | AI governance | Draft 2024 | 70% | Middle East AI framework |
| UAE AI Strategy | AI governance | Guidance 2023 | 70% | United Arab Emirates AI principles |
Framework Coverage by System Type
Generative AI (ChatGPT-like Systems)
Applies to: Chatbots, content generation, code assistants, summarization tools
Required Frameworks:
- EU AI Act (high-risk classification)
- GDPR (if processing EU personal data)
- ISO 42001 (certification path)
- NIST AI RMF (if US government customer)
Recommended:
- SOC 2 (customer trust)
- CCPA (US operations)
Recommendation Engines
Applies to: Product recommendations, job recommendations, loan approvals, content ranking
Required Frameworks:
- EU AI Act (likely high-risk)
- GDPR (data processing)
- ISO 42001
Recommended:
- NIST AI RMF
- Domain-specific (FINRA for lending, HIPAA for health)
Computer Vision / Biometric Systems
Applies to: Facial recognition, identity verification, medical imaging, surveillance
Required Frameworks:
- EU AI Act (very likely high-risk)
- GDPR (biometric data)
- ISO 42001
Recommended:
- NIST AI RMF
- HIPAA (if medical imaging)
Autonomous Decision-Making
Applies to: Credit decisions, hiring, benefits eligibility, content moderation
Required Frameworks:
- EU AI Act (high-risk, Article 4)
- GDPR (automated decision-making, Article 22)
- ISO 42001
- NIST AI RMF
Recommended:
- CCPA (consumer rights)
- Domain-specific (FINRA for finance, FDA for medical)
Framework Relationships
EU AI Act + GDPR
These overlap but serve different purposes:
- EU AI Act — Focuses on AI system transparency, risk management, and testing
- GDPR — Focuses on personal data processing, individual rights, and DPIAs
Example: A recommendation system for job openings
- EU AI Act: Document system, perform bias testing, provide explanation to rejected candidates
- GDPR: Conduct DPIA, document legal basis for processing, honor data subject access requests
NIST AI RMF + ISO 42001
Both define AI governance but with different structures:
- NIST AI RMF — 4-function framework (Govern, Map, Measure, Manage); strategic
- ISO 42001 — 22 controls; more prescriptive; certification-ready
Best practice: Map NIST functions to ISO 42001 controls. Most organizations adopt both for US government credibility + global certification.
SOC 2 + ISO 27001
- SOC 2 — Service organization controls; auditor-verified; required for SaaS
- ISO 27001 — Information security management system; often a prerequisite for SOC 2
Recommendation: Start with ISO 27001 as foundation; SOC 2 audit validates it.
How to Decide Which Frameworks Apply
Step 1: Map Your Operations
Fill in this table:
| Question | Answer | Implies |
|---|---|---|
| Do you have EU users? | Yes/No | EU AI Act + GDPR required |
| Do you process health data? | Yes/No | HIPAA (US) or confidentiality laws |
| Are you SaaS? | Yes/No | SOC 2 recommended |
| Do you have government customers? | Yes/No | NIST AI RMF required |
| Do you pursue ISO certification? | Yes/No | ISO 42001 required |
| Are you in finance? | Yes/No | FINRA, Prudential, or equivalent |
| Do you operate in specific regions? | [List] | Regional privacy laws (CCPA, LGPD, etc.) |
Step 2: Enable Frameworks in TruthVouch
- Go to Compliance > Frameworks
- Check frameworks that match your profile
- Click Save
- Compliance AI maps all your registered AI systems to framework requirements
Step 3: Run a Scan
- Go to Scans > New Scan
- Select the frameworks you just enabled
- Click Start Scan
See which controls you’re passing and which gaps to remediate.
Framework Implementation Timeline
When starting a compliance program, prioritize frameworks by deadline and impact:
Immediate (0-3 months):
- EU AI Act (if serving EU)
- GDPR (if processing EU data)
- ISO 42001 (certification path)
Short-term (3-6 months):
- NIST AI RMF (if US government customer)
- SOC 2 (if SaaS)
- Domain-specific (HIPAA, FINRA, etc.)
Medium-term (6-12 months):
- Regional privacy (CCPA, LGPD, PDPA, etc.)
- Emerging regulations (China CAC, etc.)
Next Steps
- Start with a specific framework? Pick one below:
- EU AI Act — 37 articles, high-risk classification
- GDPR — Personal data protection
- ISO 42001 — AI Management System
- NIST AI RMF — US framework
- SOC 2 — Service organization controls
- HIPAA — Healthcare privacy
- Other Frameworks — CCPA, LGPD, China, and more
- Ready to scan? Go to Running Scans