> For the complete documentation index, see [llms.txt](https://docs.veedna.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.veedna.com/unifai/regulatory-compliance/compliance-coverage.md).

# Compliance Coverage

### Regulatory Standards Coverage Overview

Across all 16 standards: **101 sections/articles/clauses covered** out of 440 assessed, backed by **78 distinct policies** in the Lineaje policy library. \
"Covered" means at least one policy has documented, verified evidence against that clause — everything else is marked not-yet-covered, not assumed non-compliant.

| Standard                                                                | Category                | Sections Covered | Policies Mapped |
| ----------------------------------------------------------------------- | ----------------------- | ---------------- | --------------- |
| ISO/IEC 42001:2023                                                      | Cross-Industry Standard | 14/70            | 22              |
| IRAP (Information Security Registered Assessors Program)                | Cross-Industry Standard | 4/39             | 27              |
| EU AI Act (Regulation (EU) 2024/1689)                                   | National AI Regulation  | 14/18            | 55              |
| US Executive Order 14110 (Safe, Secure, and Trustworthy AI)             | National AI Regulation  | 3/35             | 3               |
| CERT-In AI Security Blueprint (India)                                   | National AI Regulation  | 4/14             | 49              |
| National Framework for the Assurance of AI in Government (Australia)    | National AI Regulation  | 12/40            | 23              |
| Policy for the Responsible Use of AI in Government (Australia)          | National AI Regulation  | 9/37             | 21              |
| Vietnam AI Law                                                          | National AI Regulation  | 3/6              | 22              |
| South Korea Framework Act on AI Development and Trust                   | National AI Regulation  | 6/33             | 17              |
| China CAC Interim Measures for the Management of Generative AI Services | National AI Regulation  | 9/49             | 16              |
| California SB 942 (AI Transparency Act)                                 | US State Law            | 5/16             | 10              |
| California AB 2013 (AI Training Data Transparency Act)                  | US State Law            | 3/22             | 5               |
| California AB 3030 (Healthcare AI Disclosure)                           | US State Law            | 4/12             | 5               |
| Colorado SB 26-189 (Automated Decision-Making Technology)               | US State Law            | 5/9              | 11              |
| Maryland HB 1202 (Facial Recognition in Employment)                     | US State Law            | 3/8              | 3               |
| Japan AI Basic Plan                                                     | National AI Regulation  | 3/32             | 3               |

### Supported Compliance Standards & Requirement Coverage

Each standard below is collapsed by default — expand the ones relevant to your conversation. Every entry lists the specific section, the guardrail type (Notification, Enforcement), how many policies back it, and what the mapped control does.

<details>

<summary>ISO/IEC 42001:2023 — 14/70 sections covered · 22 policies mapped</summary>

**Cross-Industry Standard**

* **6.1.1 — Actions to Address Risks and Opportunities (General)** *(Notification · 1 policy)* — Notifies stakeholders when a new AI risk or opportunity is identified.
* **6.1.2 — AI Risk Assessment** *(Notification · 1 policy)* — Runs a structured assessment of AI-specific risk factors.
* **7.5.3 — Control of Documented Information** *(Notification · 1 policy)* — Version-controls the AI management system's governing documents.
* **A.4.5 — System and Computing Resources** *(Enforced · 2 policies)* — Hardens the infrastructure and compute resources an AI system runs on.
* **A.6.2.6 — AI System Operation and Monitoring** *(Enforced · 1 policy)* — Monitors a deployed AI system's behavior during live operation.
* **A.6.2.7 — AI System Technical Documentation** *(Notification · 1 policy)* — Maintains technical documentation describing how the AI system works.
* **A.6.2.8 — AI System Recording of Event Logs** *(Notification · 1 policy)* — Records AI system events for later review and audit.
* **A.7.2 — Data for Development and Enhancement of AI System** *(Notification · 1 policy)* — Governs the data used to develop and improve AI systems.
* **A.7.3 — Acquisition of Data** *(Notification · 2 policies)* — Controls how data is sourced and onboarded for AI use.
* **A.7.5 — Data Provenance** *(Notification · 1 policy)* — Tracks where training and input data originated.
* **A.8.2 — System Documentation and Information for Users** *(Notification · 6 policies)* — Delivers user-facing documentation on system capability and limits.
* **A.8.4 — Communication of Incidents** *(Notification · 1 policy)* — Notifies stakeholders when an AI-related incident occurs.
* **A.9.2 — Processes for Responsible Use of AI Systems** *(Enforced · 2 policies)* — Enforces the operating procedures for responsible AI use.
* **A.9.4 — Intended Use of the AI System** *(Enforced · 1 policy)* — Constrains an AI system to its documented intended use.

*56 of 70 sections are not yet mapped to a policy.*

</details>

<details>

<summary>IRAP (Information Security Registered Assessors Program) — 4/39 sections covered · 27 policies mapped</summary>

**Cross-Industry Standard**

* **9 — Assessment Scope — Access Management** *(Enforced + Notification · 12 policies)* — Enforces identity and access controls across the AI stack.
* **10 — Assessment Scope — Incident Response** *(Notification · 2 policies)* — Runs the incident-response workflow for AI security events.
* **15 — ISM Compliance — Control Assessment** *(Enforced · 11 policies)* — Maps controls against Australia's Information Security Manual.
* **19 — Assessment Execution — Technical Testing** *(Enforced · 2 policies)* — Runs technical security testing against the AI system.

*35 of 39 sections are not yet mapped to a policy.*

</details>

<details>

<summary>EU AI Act (Regulation (EU) 2024/1689) — 14/18 sections covered · 55 policies mapped</summary>

**National AI Regulation**

* **Art. 6 — Classification Rules for High-Risk AI Systems** *(Notification · 1 policy)* — Flags whether a system meets Annex III's high-risk classification triggers.
* **Art. 9 — Risk Management System** *(Notification · 2 policies)* — Continuous risk scoring across the AI inventory feeds a lifecycle risk-treatment record.
* **Art. 12 — Record-Keeping** *(Notification · 4 policies)* — Automatic, tamper-aware logging of AI system events for a verifiable audit trail.
* **Art. 13 — Transparency to Deployers** *(Notification · 2 policies)* — Structured disclosure of system behavior and limitations to downstream deployers.
* **Art. 14 — Human Oversight** *(Enforced · 5 policies)* — Runtime checkpoints that gate high-risk automated actions behind human review.
* **Art. 15 — Accuracy, Robustness & Cybersecurity** *(Enforced + Notification · 20 policies)* — Continuous testing and hardening against adversarial manipulation, evasion, and drift.
* **Art. 26 — Obligations of Deployers of High-Risk AI Systems** *(Notification · 1 policy)* — Confirms deployer-side controls are in place before a high-risk system goes live.
* **Art. 50 — Transparency Obligations for AI Systems** *(Enforced + Notification · 2 policies)* — Disclosure controls for chatbots and generated content, matching the Act's limited-risk tier.
* **Art. 53 — Obligations for GPAI Model Providers** *(Notification · 1 policy)* — Baseline documentation and disclosure controls for general-purpose model providers.
* **Art. 55 — Obligations for GPAI Models with Systemic Risk** *(Enforced · 1 policy)* — Additional safeguards for general-purpose models flagged as systemic risk.
* **Art. 73 — Reporting of Serious Incidents** *(Notification · 1 policy)* — Structured reporting workflow for incidents that meet the Act's severity threshold.
* **Art. 86 — Right to Explanation of Individual Decisions** *(Notification · 1 policy)* — Surfaces the reasoning behind an automated decision when an individual requests it.
* **Annex III — High-Risk AI Systems (per Art. 6(2))** *(Enforced + Notification · 4 policies)* — Classification controls flag Annex III use cases for the Act's heavier obligations.
* **Annex IV — Technical Documentation (per Art. 11(1))** *(Notification · 1 policy)* — Standardized technical documentation package required for high-risk systems.

Not covered: Article 5 (prohibited practices), Article 10 (data governance), Article 11 (technical documentation as a standalone article — the related Annex IV documentation obligation is covered), Article 72 (post-market monitoring).

</details>

<details>

<summary>US Executive Order 14110 (Safe, Secure, and Trustworthy AI) — 3/35 sections covered · 3 policies mapped</summary>

**National AI Regulation**

* **Sec. 4.4 — Reducing AI-CBRN Intersection Risks** *(Enforced · 1 policy)* — Screens for AI use that intersects CBRN risk categories.
* **Sec. 4.5 — Reducing the Risks Posed by Synthetic Content** *(Enforced · 1 policy)* — Marks and tracks AI-generated synthetic content.
* **Sec. 10.1(b) — OMB Guidance on Federal AI Risk Practices** *(Notification · 1 policy)* — Aligns internal risk practice with federal OMB guidance.

*32 of 35 sections are not yet mapped to a policy.*

</details>

<details>

<summary>CERT-In AI Security Blueprint (India) — 4/14 sections covered · 49 policies mapped</summary>

**National AI Regulation**

* **7 — Technical Defensive Controls** *(Enforced · 6 policies)* — Baseline hardening controls that defend AI systems against AI-assisted exploitation attempts.
* **9 — Vulnerability and Patch Management** *(Enforced · 1 policy)* — Keeps known vulnerabilities in AI components tracked and remediated on a defined cadence.
* **10 — Incident Response and Cyber Resilience** *(Notification · 1 policy)* — Structured incident response and recovery workflow for AI security events.
* **12 — Secure Adoption & Governance of AI Systems** *(Enforced + Notification · 41 policies)* — By far the deepest mapping in the entire assessment — the bulk of technical guardrails for deployed AI.

*10 of 14 sections are not yet mapped to a policy.*

</details>

<details>

<summary>National Framework for the Assurance of AI in Government (Australia) — 12/40 sections covered · 23 policies mapped</summary>

**National AI Regulation**

* **§5 — Guiding Principles > Human-Centered** *(Enforced · 1 policy)* — Keeps a human accountable for AI-assisted decisions.
* **§10 — Guiding Principles > Privacy-Preserving** *(Enforced · 8 policies)* — Limits and governs personal data flowing through AI systems.
* **§13 — Governance > Governance Processes** *(Notification · 1 policy)* — Documents the governance workflow behind each AI use case.
* **§21 — Technical Assurance > System Dev Assurance** *(Enforced · 1 policy)* — Applies secure-development controls before an AI system ships.
* **§22 — Technical Assurance > Testing and Validation** *(Enforced · 1 policy)* — Verifies a system behaves as specified before production.
* **§25 — Operational Assurance > Ongoing Monitoring** *(Notification · 2 policies)* — Continuous monitoring of AI systems already in production.
* **§26 — Operational Assurance > Incident Management** *(Notification · 1 policy)* — Structured response workflow when an AI incident occurs.
* **§27 — Operational Assurance > Lifecycle Management** *(Notification · 1 policy)* — Tracks an AI system from deployment through retirement.
* **§28 — Risk-Based Assurance > AI Risk Classification** *(Notification · 1 policy)* — Classifies systems by risk tier to set assurance depth.
* **§29 — Risk-Based Assurance > Requirements by Risk Level** *(Notification · 2 policies)* — Scales control requirements to the assigned risk level.
* **§30 — Use Case Considerations > Automated Decision-Making** *(Enforced + Notification · 2 policies)* — Extra scrutiny for systems that decide about people.
* **§38 — Transparency & Accountability > Transparency Measures** *(Notification · 2 policies)* — Public-facing disclosure of AI use and its limitations.

*28 of 40 sections are not yet mapped to a policy.*

</details>

<details>

<summary>Policy for the Responsible Use of AI in Government (Australia) — 9/37 sections covered · 21 policies mapped</summary>

**National AI Regulation**

* **§12 — Strategy & Oversight > AI Transparency Statement** *(Notification · 1 policy)* — Publishes a standing statement of how AI is used.
* **§17 — Preparedness & Operations > Principles** *(Enforced + Notification · 2 policies)* — Baseline operating principles before AI use begins.
* **§18 — Preparedness & Ops > Operationalise Responsible AI Use** *(Notification · 1 policy)* — Turns responsible-AI principles into day-to-day practice.
* **§20 — Preparedness & Ops > AI Technical Standard** *(Enforced + Notification · 5 policies)* — The policy's deepest mapping: the technical baseline every in-scope AI system must meet.
* **§24 — AI Use Case Impact Assessment > Principles** *(Notification · 1 policy)* — Principles behind every use-case impact assessment.
* **§26 — AI Use Case Impact Assessment > In-Scope Use Cases** *(Notification · 1 policy)* — Confirms which use cases fall under the policy's scope.
* **§28 — AI Use Case Impact Assessment > High-Risk Use Cases** *(Enforced + Notification · 3 policies)* — Heavier assessment requirements for high-risk use cases.
* **§30 — Appendix A: Related Frameworks > AI** *(Enforced · 6 policies)* — Second-deepest mapping: alignment with related AI governance frameworks.
* **§31 — Appendix A: Related Frameworks > Automated Decisions** *(Notification · 1 policy)* — Aligns automated-decision handling with related frameworks.

*28 of 37 sections are not yet mapped to a policy.*

</details>

<details>

<summary>Vietnam AI Law — 3/6 sections covered · 22 policies mapped</summary>

**National AI Regulation**

* **1 — A Risk-Based Framework for AI Governance** *(Notification · 1 policy)* — Classifies AI systems by risk tier to set governance depth.
* **3 — Additional Safeguards for High-Risk AI Systems** *(Enforced + Notification · 20 policies)* — The law's deepest mapping: extra safeguards for high-risk AI systems.
* **5 — Enforcement and Accountability** *(Notification · 1 policy)* — Structured accountability workflow when an AI incident occurs.

*3 of 6 sections are not yet mapped to a policy.*

</details>

<details>

<summary>South Korea Framework Act on AI Development and Trust — 6/33 sections covered · 17 policies mapped</summary>

**National AI Regulation**

* **Art. 2 — Definitions (incl. High-Impact AI)** *(Notification · 1 policy)* — Classifies whether a system meets the high-impact AI definition.
* **Art. 3 — Basic Principles and Obligations of the Nation** *(Notification · 2 policies)* — Baseline national obligations applied to in-scope AI systems.
* **Art. 13 — Support for AI Tech Dev & Safe Use** *(Enforced · 1 policy)* — Includes shutdown provisions for unsafe AI system behavior.
* **Art. 31 — Obligation to Ensure AI Transparency** *(Enforced + Notification · 7 policies)* — The broadest mapping in this framework: disclosure and documentation controls.
* **Art. 32 — Obligation to Ensure AI Safety** *(Enforced + Notification · 4 policies)* — Safety-testing and risk-mitigation controls before and during operation.
* **Art. 33 — Confirmation of High-Impact AI (Para. 1)** *(Enforced + Notification · 2 policies)* — Classification controls that flag systems meeting the high-impact threshold.

*27 of 33 sections are not yet mapped to a policy.*

</details>

<details>

<summary>China CAC Interim Measures for the Management of Generative AI Services — 9/49 sections covered · 16 policies mapped</summary>

**National AI Regulation**

* **3.2.1 — Data & Training: Training Data Quality** *(Notification · 1 policy)* — Screens training data for quality issues before use.
* **3.2.2 — Data & Training: Personal Info Protection** *(Enforced · 9 policies)* — The measure's deepest mapping: personal-information protection controls for training and use.
* **3.3.1 — Algorithm Transparency: Disclosure Requirements** *(Notification · 1 policy)* — Discloses algorithmic logic to meet transparency requirements.
* **3.3.2 — Algorithm Transparency: Mechanisms** *(Notification · 1 policy)* — Implements the disclosure mechanism itself, not just the requirement.
* **3.4.1 — User Rights: Informed Consent** *(Notification · 1 policy)* — Captures informed consent before generative AI processes user data.
* **3.5.3 — Provider Obligations: Technical Measures** *(Notification · 1 policy)* — Baseline technical measures required of generative AI service providers.
* **6.1 — AI-Generated Content Marking** *(Enforced · 1 policy)* — Marks AI-generated content so it's identifiable as synthetic.
* **7.1 — Incident Management** *(Notification · 1 policy)* — Structured workflow for managing generative-AI service incidents.
* **7.2 — Incident Reporting Obligations** *(Notification · 1 policy)* — Reports qualifying incidents to the relevant regulatory authority.

*40 of 49 sections are not yet mapped to a policy.*

</details>

<details>

<summary>California SB 942 (AI Transparency Act) — 5/16 sections covered · 10 policies mapped</summary>

**US State Law**

* **§3 — AI Use Disclosure** *(Enforced + Notification · 3 policies)* — Discloses to users when they're interacting with an AI system.
* **§4 — High-Risk AI System Requirements** *(Enforced + Notification · 3 policies)* — Applies the Act's heavier controls to high-risk AI systems.
* **§5 — Automated Decision-Making** *(Enforced · 1 policy)* — Extra scrutiny for systems that make automated decisions about people.
* **§6 — Documentation and Recordkeeping** *(Notification · 2 policies)* — Maintains the records required under the Act's documentation duties.
* **§7 — Explainability and Transparency** *(Notification · 1 policy)* — Surfaces an explanation of AI system behavior on request.

*11 of 16 sections are not yet mapped to a policy.*

</details>

<details>

<summary>California AB 2013 (AI Training Data Transparency Act) — 3/22 sections covered · 5 policies mapped</summary>

**US State Law**

* **§2 — Disclose Data Sources & Scope** *(Notification · 1 policy)* — Documents the sources and scope of training data used.
* **§3 — Disclose Data Acquisition Methods** *(Notification · 1 policy)* — Documents how training data was acquired.
* **§6 — Training Data Documentation** *(Notification · 3 policies)* — Produces the public-facing training-data documentation the Act requires.

*19 of 22 sections are not yet mapped to a policy.*

</details>

<details>

<summary>California AB 3030 (Healthcare AI Disclosure) — 4/12 sections covered · 5 policies mapped</summary>

**US State Law**

* **§2 — Disclosure Must Precede AI Use in Patient Care** *(Notification · 1 policy)* — Surfaces disclosure to the patient before AI is used in care.
* **§3 — Required Disclosure Content Elements** *(Notification · 2 policies)* — Includes the specific content elements the disclosure must contain.
* **§6 — Recordkeeping of Disclosures and Patient Acknowledgment** *(Notification · 1 policy)* — Records that a disclosure was made and acknowledged.
* **§8 — Oversight of AI Performance, Bias/Error Monitoring** *(Enforced · 1 policy)* — Monitors clinical AI performance for bias and error drift.

*8 of 12 sections are not yet mapped to a policy.*

</details>

<details>

<summary>Colorado SB 26-189 (Automated Decision-Making Technology) — 5/9 sections covered · 11 policies mapped</summary>

**US State Law**

* **§6-1-1701 — Definitions** *(Enforced + Notification · 2 policies)* — Classifies systems against the statute's automated-decision definitions.
* **§6-1-1702 — Developer Responsibilities — Documentation** *(Notification · 3 policies)* — Produces the developer-side documentation the statute requires.
* **§6-1-1703 — Deployer Record Keeping** *(Notification · 2 policies)* — Maintains deployer-side records of automated-decision use.
* **§6-1-1704 — Deployer Disclosures — Notices, Adverse Outcomes** *(Notification · 2 policies)* — Issues required notices, including on adverse automated decisions.
* **§6-1-1705 — Consumer Rights — Correction, Human Review** *(Enforced · 2 policies)* — Supports consumer rights to correction and human review.

*4 of 9 sections are not yet mapped to a policy.*

</details>

<details>

<summary>Maryland HB 1202 (Facial Recognition in Employment) — 3/8 sections covered · 3 policies mapped</summary>

**US State Law**

* **§1 — Bans Facial Recognition in Hiring, Discipline, Monitoring** *(Enforced · 1 policy)* — Blocks facial-recognition use in the employment contexts the law bans.
* **§5 — Requires Written, Specific, Informed, Revocable Consent** *(Notification · 1 policy)* — Captures the written, revocable consent the law requires.
* **§6 — Requires Reasonable Security, Retention Limits, Deletion** *(Notification · 1 policy)* — Applies security, retention-limit, and deletion controls to biometric data.

*5 of 8 sections are not yet mapped to a policy.*

</details>

<details>

<summary>Japan AI Basic Plan — 3/32 sections covered · 3 policies mapped</summary>

**National AI Regulation**

* **3.8 — Trustworthy AI: Transparent, Explainable, Fair, Accountable** *(Notification · 1 policy)* — Applies transparency and explainability controls to AI decisions.
* **6.1 — Human-Centric AI: Augments Human Judgment in Decisions** *(Enforced · 1 policy)* — Keeps human judgment in the loop for AI-assisted decisions.
* **7.1 — Healthcare: AI-Assisted Diagnosis, Treatment, Drug Discovery** *(Notification · 1 policy)* — Applies oversight controls to AI-assisted diagnosis and treatment.

*29 of 32 sections are not yet mapped to a policy.*

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.veedna.com/unifai/regulatory-compliance/compliance-coverage.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
