Compliance Coverage
Regulatory Standards Coverage Overview
Across all 16 standards: 101 sections/articles/clauses covered out of 440 assessed, backed by 78 distinct policies in the Lineaje policy library. "Covered" means at least one policy has documented, verified evidence against that clause — everything else is marked not-yet-covered, not assumed non-compliant.
ISO/IEC 42001:2023
Cross-Industry Standard
14/70
22
IRAP (Information Security Registered Assessors Program)
Cross-Industry Standard
4/39
27
EU AI Act (Regulation (EU) 2024/1689)
National AI Regulation
14/18
55
US Executive Order 14110 (Safe, Secure, and Trustworthy AI)
National AI Regulation
3/35
3
CERT-In AI Security Blueprint (India)
National AI Regulation
4/14
49
National Framework for the Assurance of AI in Government (Australia)
National AI Regulation
12/40
23
Policy for the Responsible Use of AI in Government (Australia)
National AI Regulation
9/37
21
Vietnam AI Law
National AI Regulation
3/6
22
South Korea Framework Act on AI Development and Trust
National AI Regulation
6/33
17
China CAC Interim Measures for the Management of Generative AI Services
National AI Regulation
9/49
16
California SB 942 (AI Transparency Act)
US State Law
5/16
10
California AB 2013 (AI Training Data Transparency Act)
US State Law
3/22
5
California AB 3030 (Healthcare AI Disclosure)
US State Law
4/12
5
Colorado SB 26-189 (Automated Decision-Making Technology)
US State Law
5/9
11
Maryland HB 1202 (Facial Recognition in Employment)
US State Law
3/8
3
Japan AI Basic Plan
National AI Regulation
3/32
3
Supported Compliance Standards & Requirement Coverage
Each standard below is collapsed by default — expand the ones relevant to your conversation. Every entry lists the specific section, the guardrail type (Notification, Enforcement), how many policies back it, and what the mapped control does.
ISO/IEC 42001:2023 — 14/70 sections covered · 22 policies mapped
Cross-Industry Standard
6.1.1 — Actions to Address Risks and Opportunities (General) (Notification · 1 policy) — Notifies stakeholders when a new AI risk or opportunity is identified.
6.1.2 — AI Risk Assessment (Notification · 1 policy) — Runs a structured assessment of AI-specific risk factors.
7.5.3 — Control of Documented Information (Notification · 1 policy) — Version-controls the AI management system's governing documents.
A.4.5 — System and Computing Resources (Enforced · 2 policies) — Hardens the infrastructure and compute resources an AI system runs on.
A.6.2.6 — AI System Operation and Monitoring (Enforced · 1 policy) — Monitors a deployed AI system's behavior during live operation.
A.6.2.7 — AI System Technical Documentation (Notification · 1 policy) — Maintains technical documentation describing how the AI system works.
A.6.2.8 — AI System Recording of Event Logs (Notification · 1 policy) — Records AI system events for later review and audit.
A.7.2 — Data for Development and Enhancement of AI System (Notification · 1 policy) — Governs the data used to develop and improve AI systems.
A.7.3 — Acquisition of Data (Notification · 2 policies) — Controls how data is sourced and onboarded for AI use.
A.7.5 — Data Provenance (Notification · 1 policy) — Tracks where training and input data originated.
A.8.2 — System Documentation and Information for Users (Notification · 6 policies) — Delivers user-facing documentation on system capability and limits.
A.8.4 — Communication of Incidents (Notification · 1 policy) — Notifies stakeholders when an AI-related incident occurs.
A.9.2 — Processes for Responsible Use of AI Systems (Enforced · 2 policies) — Enforces the operating procedures for responsible AI use.
A.9.4 — Intended Use of the AI System (Enforced · 1 policy) — Constrains an AI system to its documented intended use.
56 of 70 sections are not yet mapped to a policy.
IRAP (Information Security Registered Assessors Program) — 4/39 sections covered · 27 policies mapped
Cross-Industry Standard
9 — Assessment Scope — Access Management (Enforced + Notification · 12 policies) — Enforces identity and access controls across the AI stack.
10 — Assessment Scope — Incident Response (Notification · 2 policies) — Runs the incident-response workflow for AI security events.
15 — ISM Compliance — Control Assessment (Enforced · 11 policies) — Maps controls against Australia's Information Security Manual.
19 — Assessment Execution — Technical Testing (Enforced · 2 policies) — Runs technical security testing against the AI system.
35 of 39 sections are not yet mapped to a policy.
EU AI Act (Regulation (EU) 2024/1689) — 14/18 sections covered · 55 policies mapped
National AI Regulation
Art. 6 — Classification Rules for High-Risk AI Systems (Notification · 1 policy) — Flags whether a system meets Annex III's high-risk classification triggers.
Art. 9 — Risk Management System (Notification · 2 policies) — Continuous risk scoring across the AI inventory feeds a lifecycle risk-treatment record.
Art. 12 — Record-Keeping (Notification · 4 policies) — Automatic, tamper-aware logging of AI system events for a verifiable audit trail.
Art. 13 — Transparency to Deployers (Notification · 2 policies) — Structured disclosure of system behavior and limitations to downstream deployers.
Art. 14 — Human Oversight (Enforced · 5 policies) — Runtime checkpoints that gate high-risk automated actions behind human review.
Art. 15 — Accuracy, Robustness & Cybersecurity (Enforced + Notification · 20 policies) — Continuous testing and hardening against adversarial manipulation, evasion, and drift.
Art. 26 — Obligations of Deployers of High-Risk AI Systems (Notification · 1 policy) — Confirms deployer-side controls are in place before a high-risk system goes live.
Art. 50 — Transparency Obligations for AI Systems (Enforced + Notification · 2 policies) — Disclosure controls for chatbots and generated content, matching the Act's limited-risk tier.
Art. 53 — Obligations for GPAI Model Providers (Notification · 1 policy) — Baseline documentation and disclosure controls for general-purpose model providers.
Art. 55 — Obligations for GPAI Models with Systemic Risk (Enforced · 1 policy) — Additional safeguards for general-purpose models flagged as systemic risk.
Art. 73 — Reporting of Serious Incidents (Notification · 1 policy) — Structured reporting workflow for incidents that meet the Act's severity threshold.
Art. 86 — Right to Explanation of Individual Decisions (Notification · 1 policy) — Surfaces the reasoning behind an automated decision when an individual requests it.
Annex III — High-Risk AI Systems (per Art. 6(2)) (Enforced + Notification · 4 policies) — Classification controls flag Annex III use cases for the Act's heavier obligations.
Annex IV — Technical Documentation (per Art. 11(1)) (Notification · 1 policy) — Standardized technical documentation package required for high-risk systems.
Not covered: Article 5 (prohibited practices), Article 10 (data governance), Article 11 (technical documentation as a standalone article — the related Annex IV documentation obligation is covered), Article 72 (post-market monitoring).
US Executive Order 14110 (Safe, Secure, and Trustworthy AI) — 3/35 sections covered · 3 policies mapped
National AI Regulation
Sec. 4.4 — Reducing AI-CBRN Intersection Risks (Enforced · 1 policy) — Screens for AI use that intersects CBRN risk categories.
Sec. 4.5 — Reducing the Risks Posed by Synthetic Content (Enforced · 1 policy) — Marks and tracks AI-generated synthetic content.
Sec. 10.1(b) — OMB Guidance on Federal AI Risk Practices (Notification · 1 policy) — Aligns internal risk practice with federal OMB guidance.
32 of 35 sections are not yet mapped to a policy.
CERT-In AI Security Blueprint (India) — 4/14 sections covered · 49 policies mapped
National AI Regulation
7 — Technical Defensive Controls (Enforced · 6 policies) — Baseline hardening controls that defend AI systems against AI-assisted exploitation attempts.
9 — Vulnerability and Patch Management (Enforced · 1 policy) — Keeps known vulnerabilities in AI components tracked and remediated on a defined cadence.
10 — Incident Response and Cyber Resilience (Notification · 1 policy) — Structured incident response and recovery workflow for AI security events.
12 — Secure Adoption & Governance of AI Systems (Enforced + Notification · 41 policies) — By far the deepest mapping in the entire assessment — the bulk of technical guardrails for deployed AI.
10 of 14 sections are not yet mapped to a policy.
National Framework for the Assurance of AI in Government (Australia) — 12/40 sections covered · 23 policies mapped
National AI Regulation
§5 — Guiding Principles > Human-Centered (Enforced · 1 policy) — Keeps a human accountable for AI-assisted decisions.
§10 — Guiding Principles > Privacy-Preserving (Enforced · 8 policies) — Limits and governs personal data flowing through AI systems.
§13 — Governance > Governance Processes (Notification · 1 policy) — Documents the governance workflow behind each AI use case.
§21 — Technical Assurance > System Dev Assurance (Enforced · 1 policy) — Applies secure-development controls before an AI system ships.
§22 — Technical Assurance > Testing and Validation (Enforced · 1 policy) — Verifies a system behaves as specified before production.
§25 — Operational Assurance > Ongoing Monitoring (Notification · 2 policies) — Continuous monitoring of AI systems already in production.
§26 — Operational Assurance > Incident Management (Notification · 1 policy) — Structured response workflow when an AI incident occurs.
§27 — Operational Assurance > Lifecycle Management (Notification · 1 policy) — Tracks an AI system from deployment through retirement.
§28 — Risk-Based Assurance > AI Risk Classification (Notification · 1 policy) — Classifies systems by risk tier to set assurance depth.
§29 — Risk-Based Assurance > Requirements by Risk Level (Notification · 2 policies) — Scales control requirements to the assigned risk level.
§30 — Use Case Considerations > Automated Decision-Making (Enforced + Notification · 2 policies) — Extra scrutiny for systems that decide about people.
§38 — Transparency & Accountability > Transparency Measures (Notification · 2 policies) — Public-facing disclosure of AI use and its limitations.
28 of 40 sections are not yet mapped to a policy.
Policy for the Responsible Use of AI in Government (Australia) — 9/37 sections covered · 21 policies mapped
National AI Regulation
§12 — Strategy & Oversight > AI Transparency Statement (Notification · 1 policy) — Publishes a standing statement of how AI is used.
§17 — Preparedness & Operations > Principles (Enforced + Notification · 2 policies) — Baseline operating principles before AI use begins.
§18 — Preparedness & Ops > Operationalise Responsible AI Use (Notification · 1 policy) — Turns responsible-AI principles into day-to-day practice.
§20 — Preparedness & Ops > AI Technical Standard (Enforced + Notification · 5 policies) — The policy's deepest mapping: the technical baseline every in-scope AI system must meet.
§24 — AI Use Case Impact Assessment > Principles (Notification · 1 policy) — Principles behind every use-case impact assessment.
§26 — AI Use Case Impact Assessment > In-Scope Use Cases (Notification · 1 policy) — Confirms which use cases fall under the policy's scope.
§28 — AI Use Case Impact Assessment > High-Risk Use Cases (Enforced + Notification · 3 policies) — Heavier assessment requirements for high-risk use cases.
§30 — Appendix A: Related Frameworks > AI (Enforced · 6 policies) — Second-deepest mapping: alignment with related AI governance frameworks.
§31 — Appendix A: Related Frameworks > Automated Decisions (Notification · 1 policy) — Aligns automated-decision handling with related frameworks.
28 of 37 sections are not yet mapped to a policy.
Vietnam AI Law — 3/6 sections covered · 22 policies mapped
National AI Regulation
1 — A Risk-Based Framework for AI Governance (Notification · 1 policy) — Classifies AI systems by risk tier to set governance depth.
3 — Additional Safeguards for High-Risk AI Systems (Enforced + Notification · 20 policies) — The law's deepest mapping: extra safeguards for high-risk AI systems.
5 — Enforcement and Accountability (Notification · 1 policy) — Structured accountability workflow when an AI incident occurs.
3 of 6 sections are not yet mapped to a policy.
South Korea Framework Act on AI Development and Trust — 6/33 sections covered · 17 policies mapped
National AI Regulation
Art. 2 — Definitions (incl. High-Impact AI) (Notification · 1 policy) — Classifies whether a system meets the high-impact AI definition.
Art. 3 — Basic Principles and Obligations of the Nation (Notification · 2 policies) — Baseline national obligations applied to in-scope AI systems.
Art. 13 — Support for AI Tech Dev & Safe Use (Enforced · 1 policy) — Includes shutdown provisions for unsafe AI system behavior.
Art. 31 — Obligation to Ensure AI Transparency (Enforced + Notification · 7 policies) — The broadest mapping in this framework: disclosure and documentation controls.
Art. 32 — Obligation to Ensure AI Safety (Enforced + Notification · 4 policies) — Safety-testing and risk-mitigation controls before and during operation.
Art. 33 — Confirmation of High-Impact AI (Para. 1) (Enforced + Notification · 2 policies) — Classification controls that flag systems meeting the high-impact threshold.
27 of 33 sections are not yet mapped to a policy.
China CAC Interim Measures for the Management of Generative AI Services — 9/49 sections covered · 16 policies mapped
National AI Regulation
3.2.1 — Data & Training: Training Data Quality (Notification · 1 policy) — Screens training data for quality issues before use.
3.2.2 — Data & Training: Personal Info Protection (Enforced · 9 policies) — The measure's deepest mapping: personal-information protection controls for training and use.
3.3.1 — Algorithm Transparency: Disclosure Requirements (Notification · 1 policy) — Discloses algorithmic logic to meet transparency requirements.
3.3.2 — Algorithm Transparency: Mechanisms (Notification · 1 policy) — Implements the disclosure mechanism itself, not just the requirement.
3.4.1 — User Rights: Informed Consent (Notification · 1 policy) — Captures informed consent before generative AI processes user data.
3.5.3 — Provider Obligations: Technical Measures (Notification · 1 policy) — Baseline technical measures required of generative AI service providers.
6.1 — AI-Generated Content Marking (Enforced · 1 policy) — Marks AI-generated content so it's identifiable as synthetic.
7.1 — Incident Management (Notification · 1 policy) — Structured workflow for managing generative-AI service incidents.
7.2 — Incident Reporting Obligations (Notification · 1 policy) — Reports qualifying incidents to the relevant regulatory authority.
40 of 49 sections are not yet mapped to a policy.
California SB 942 (AI Transparency Act) — 5/16 sections covered · 10 policies mapped
US State Law
§3 — AI Use Disclosure (Enforced + Notification · 3 policies) — Discloses to users when they're interacting with an AI system.
§4 — High-Risk AI System Requirements (Enforced + Notification · 3 policies) — Applies the Act's heavier controls to high-risk AI systems.
§5 — Automated Decision-Making (Enforced · 1 policy) — Extra scrutiny for systems that make automated decisions about people.
§6 — Documentation and Recordkeeping (Notification · 2 policies) — Maintains the records required under the Act's documentation duties.
§7 — Explainability and Transparency (Notification · 1 policy) — Surfaces an explanation of AI system behavior on request.
11 of 16 sections are not yet mapped to a policy.
California AB 2013 (AI Training Data Transparency Act) — 3/22 sections covered · 5 policies mapped
US State Law
§2 — Disclose Data Sources & Scope (Notification · 1 policy) — Documents the sources and scope of training data used.
§3 — Disclose Data Acquisition Methods (Notification · 1 policy) — Documents how training data was acquired.
§6 — Training Data Documentation (Notification · 3 policies) — Produces the public-facing training-data documentation the Act requires.
19 of 22 sections are not yet mapped to a policy.
California AB 3030 (Healthcare AI Disclosure) — 4/12 sections covered · 5 policies mapped
US State Law
§2 — Disclosure Must Precede AI Use in Patient Care (Notification · 1 policy) — Surfaces disclosure to the patient before AI is used in care.
§3 — Required Disclosure Content Elements (Notification · 2 policies) — Includes the specific content elements the disclosure must contain.
§6 — Recordkeeping of Disclosures and Patient Acknowledgment (Notification · 1 policy) — Records that a disclosure was made and acknowledged.
§8 — Oversight of AI Performance, Bias/Error Monitoring (Enforced · 1 policy) — Monitors clinical AI performance for bias and error drift.
8 of 12 sections are not yet mapped to a policy.
Colorado SB 26-189 (Automated Decision-Making Technology) — 5/9 sections covered · 11 policies mapped
US State Law
§6-1-1701 — Definitions (Enforced + Notification · 2 policies) — Classifies systems against the statute's automated-decision definitions.
§6-1-1702 — Developer Responsibilities — Documentation (Notification · 3 policies) — Produces the developer-side documentation the statute requires.
§6-1-1703 — Deployer Record Keeping (Notification · 2 policies) — Maintains deployer-side records of automated-decision use.
§6-1-1704 — Deployer Disclosures — Notices, Adverse Outcomes (Notification · 2 policies) — Issues required notices, including on adverse automated decisions.
§6-1-1705 — Consumer Rights — Correction, Human Review (Enforced · 2 policies) — Supports consumer rights to correction and human review.
4 of 9 sections are not yet mapped to a policy.
Maryland HB 1202 (Facial Recognition in Employment) — 3/8 sections covered · 3 policies mapped
US State Law
§1 — Bans Facial Recognition in Hiring, Discipline, Monitoring (Enforced · 1 policy) — Blocks facial-recognition use in the employment contexts the law bans.
§5 — Requires Written, Specific, Informed, Revocable Consent (Notification · 1 policy) — Captures the written, revocable consent the law requires.
§6 — Requires Reasonable Security, Retention Limits, Deletion (Notification · 1 policy) — Applies security, retention-limit, and deletion controls to biometric data.
5 of 8 sections are not yet mapped to a policy.
Japan AI Basic Plan — 3/32 sections covered · 3 policies mapped
National AI Regulation
3.8 — Trustworthy AI: Transparent, Explainable, Fair, Accountable (Notification · 1 policy) — Applies transparency and explainability controls to AI decisions.
6.1 — Human-Centric AI: Augments Human Judgment in Decisions (Enforced · 1 policy) — Keeps human judgment in the loop for AI-assisted decisions.
7.1 — Healthcare: AI-Assisted Diagnosis, Treatment, Drug Discovery (Notification · 1 policy) — Applies oversight controls to AI-assisted diagnosis and treatment.
29 of 32 sections are not yet mapped to a policy.
Last updated