Live · machine-readable · bijection-checked

Framework Coverage — every requirement, every artefact.

For each regulatory framework KYE Protocol™ maps to, this page lists every substantive requirement and the exact KYE™ artefact (schema, engine, agent, worker, PDP, evidence pack, audit event, …) that enforces it. Generated from internal<framework>/*.json on every build. The bijection-coverage gate verifies every citation resolves; npm run test:framework-coverage-bijection fails the merge if anything drifts.

Schema: kye.framework_coverage_report.v1. JSON: /compliance/coverage-report.generated.json.

Universal taxonomy: NIST 800-53 Rev 5 hub — every framework below crosswalks INTO this hub. Procurement question "do you map to X?" = one hop, deterministic.

Summary — 237 frameworks, 3033 requirements, 86% weighted coverage

Overall coverage is weighted: enforced = 1.0, designed = 0.5, advisory = 0.25, deferred/out-of-scope = 0.

Artefacts tagged with framework_coverage[]: 0 · generated 2026-09-06T02:58:32.223Z.

Per-framework coverage

FrameworkVersionReqsEnforcedDesignedAdvisoryDeferredCoverage
AAOIFI Financial Accounting Standards (FAS) AAOIFI Financial Accounting Standards (FAS) 13 1 1 0 0 75%
AAOIFI Auditing Standards (ASIFI) AAOIFI Auditing Standards for Islamic Financial Institutions (ASIFI) 7 2 4 0 0 67%
AAOIFI Governance Standards (GSIFI) AAOIFI Governance Standards for Islamic Financial Institutions (GSIFI) 11 5 5 0 0 75%
AAOIFI Shariah Standards AAOIFI Shariah Standards (as at 2023 compilation) 31 3 1 0 0 88%
ABA Model Rules of Professional Conduct (AI-relevant duties) Rules 1.1 / 1.4 / 1.5 / 1.6 / 5.1 / 5.3 + ABA Formal Opinion 512 (2023) 6 0 5 0 0 50%
AI-CAIQ (STAR-for-AI) — evidence-generated self-assessment 1.0 2 1 0 0 0 100%
AI Solutions Framework — Enterprise AI-Adoption Control Framework (IG1–IG3) 1.0 15 6 0 0 0 100%
CSA AI Controls Matrix (AICM) — execution-layer resolution 1.0 14 11 0 0 0 100%
AICPA SSTS — Statements on Standards for Tax Services 2024 4 0 4 0 0 50%
AIDA — Artificial Intelligence and Data Act (Bill C-27, federal) AIDA — Artificial Intelligence and Data Act, Part 3 of Bill C-27 (44th Parliament). Tabled; lapsed on prorogation Jan 2025. Mapped as a forward-looking design anchor, not enacted law. 5 0 0 5 0 25%
AIFMD / UCITS — Fund Manager Authority, Risk Management & Investment Limits Directive 2011/61/EU & Directive 2009/65/EC 4 4 0 0 0 100%
Alberta PIPA — Personal Information Protection Act (Alberta) Alberta PIPA — Personal Information Protection Act, S.A. 2003, c. P-6.5 (Alberta) 3 2 1 0 0 83%
API 580 / API 581 — Risk-Based Inspection (RBI) for fixed equipment in the oil, gas and petrochemical industry 2016 4 0 2 2 0 38%
APPI — Act on the Protection of Personal Information Act on the Protection of Personal Information (Act No. 57 of 2003), as amended by the 2020 amendment in force 1 April 2022 5 4 1 0 0 90%
APRA CPS 230 — Operational Risk Management CPS 230 (effective 1 July 2025) 6 5 1 0 0 92%
ASD Essential Eight + ASD AI guidance ASD Essential Eight Maturity Model (Nov 2023) + ASD AI guidance (2024) 4 4 0 0 0 100%
Datenschutzgesetz (DSG, BGBl. I Nr. 165/1999, as amended 2018) BGBl. I Nr. 165/1999 (as amended 2018) 3 2 1 0 0 83%
Australian Government Mandatory AI Guardrails Voluntary AI Safety Standard / Proposals Paper (DISR, September 2024) 10 9 0 0 0 100%
Australia Group — Biological & Chemical Dual-Use Export Controls 2023 4 0 4 0 0 50%
BC PIPA — Personal Information Protection Act (British Columbia) BC PIPA — Personal Information Protection Act, S.B.C. 2003, c. 63 (British Columbia) 3 3 0 0 0 100%
BCBS 239 — Risk Data Aggregation & Risk Reporting Principles BCBS 239 (Principles for effective risk data aggregation and risk reporting, January 2013) 14 7 0 0 0 100%
Loi du 30 juillet 2018 — Belgian Data Protection Act Loi du 30 juillet 2018 relative à la protection des personnes physiques à l’égard des traitements de données à caractère personnel 3 2 1 0 0 83%
Personal Data Protection Act (amended 2019 to implement the GDPR) PDPA (amended 2019) 3 2 1 0 0 83%
Bank Negara Malaysia — Shariah Governance Policy Document 2019 BNM/RH/PD 028-100 (2019) 18 7 8 0 0 73%
Brunei — Syariah Financial Supervisory Board and BDCB Syariah Financial Supervisory Board Order + BDCB regulation 18 7 8 0 0 73%
BSI AIC4 — AI Cloud Service Compliance Criteria 2021 3 2 0 0 0 100%
Canada Consumer-Driven Banking Framework (open banking) Consumer-Driven Banking Framework — Consumer-Driven Banking Act (enacted via Budget Implementation Act, 2024, No. 1), framework being stood up by the Financial Consumer Agency of Canada 4 4 0 0 0 100%
Central Bank of Bahrain — Shariah Governance Module CBB Rulebook — Shariah Governance Module 18 7 8 0 0 73%
Central Bank of Kuwait — Shariah Supervisory Governance CBK Shariah supervisory governance instructions 18 7 8 0 0 73%
Central Bank of Nigeria — Non-Interest (Islamic) Financial Institutions CBN guidelines for non-interest financial institutions 18 7 8 0 0 73%
Central Bank of Oman — Islamic Banking Regulatory Framework (IBRF) CBO Islamic Banking Regulatory Framework (2012) 17 6 8 0 0 71%
CBUAE — Higher Shariah Authority and Shariah Governance Standard CBUAE Shariah Governance Standard (2020) 18 7 8 0 0 73%
CDSCO Medical Devices Rules 2017 Medical Devices Rules, 2017, as amended 5 2 0 0 0 100%
CERT-In Cyber Security Directions Directions dated 28 April 2022 under s.70B(6), Information Technology Act, 2000 5 2 0 0 0 100%
nFADP / revDSG — revised Federal Act on Data Protection (in force 1 Sept 2023) nFADP (in force 2023) 4 2 2 0 0 75%
CIPS — Cross-Border Interbank Payment System (RMB) — payment-authority governance CIPS participant and business rules (CIPS Co., Ltd. under People's Bank of China oversight) — cross-border interbank RMB payment system 6 3 2 0 0 80%
CISA CDM — Continuous Diagnostics and Mitigation (AI-agent asset accountability) CISA CDM Program — DEFEND capability areas A–D 11 11 0 0 0 100%
CLC Code of Conduct — Council for Licensed Conveyancers CLC Code of Conduct 4 0 3 1 0 44%
CLIA — US Clinical Laboratory Improvement Amendments (42 CFR Part 493) 42 CFR Part 493 6 3 1 0 0 88%
Colorado SB21-169 — Insurers' Use of External Consumer Data & AI Colorado SB21-169 (Restrict Insurers' Use of External Consumer Data; C.R.S. §10-3-1104.9) + Division of Insurance regulations 4 3 0 0 0 100%
UK Companies Act 2006 — Records, True & Fair Accounts & Companies House Filing 2006 5 0 5 0 0 50%
COSHH — Control of Substances Hazardous to Health Regulations 2002 (UK) 2002 3 0 3 0 0 50%
EU Cyber Resilience Act (CRA) Regulation (EU) 2024/2847 13 8 3 0 0 86%
CWC + BWC — Chemical Weapons Convention & Biological Weapons Convention 1997-2024 4 0 4 0 0 50%
Law 125(I)/2018 (providing for the protection of natural persons with regard to the processing of personal data) Law 125(I)/2018 3 2 1 0 0 83%
Zákon č. 110/2019 Sb., o zpracování osobních údajů Act 110/2019 Sb. 3 2 1 0 0 83%
BDSG — Bundesdatenschutzgesetz (Federal Data Protection Act, 2018) BDSG 2018 4 3 1 0 0 88%
Databeskyttelsesloven (Lov nr. 502 af 23. maj 2018) Lov nr. 502 (2018) 3 2 1 0 0 83%
DoD 5015.02-STD — Electronic Records Management Software Applications Design Criteria 2007 5 3 0 0 0 100%
Dodd-Frank §922 + SEC Rule 21F — Whistleblower Programme Dodd-Frank Act §922 (15 U.S.C. §78u-6) + SEC Rules 21F (whistleblower programme) 3 2 0 0 0 100%
DORA — Digital Operational Resilience Act Regulation (EU) 2022/2554 73 59 0 14 0 86%
DORA ICT Incident Reporting — Article 19 + classification RTS DORA — Regulation (EU) 2022/2554, Article 19 (ICT-related incident reporting) + RTS/ITS on incident classification and reporting 4 3 0 0 0 100%
Digital Personal Data Protection Act, 2023 Act No. 22 of 2023 8 3 0 0 0 100%
EC-Council ADG — Adopt · Defend · Govern 2026 35 33 0 2 0 96%
ECOA / Regulation B — Equal Credit Opportunity Act ECOA (15 U.S.C. §1691 et seq.) / Regulation B (12 C.F.R. Part 1002) 4 2 1 0 0 83%
EEOC Uniform Guidelines on Employee Selection Procedures Uniform Guidelines on Employee Selection Procedures (1978, 29 CFR Part 1607) 2 1 1 0 0 75%
Egypt FRA — Islamic Finance Shariah Supervision FRA Islamic finance regulations (sukuk, takaful) 18 7 8 0 0 73%
EN 18286:2025 — Quality management system for high-risk AI systems 2025 6 4 2 0 0 83%
LOPDGDD — Ley Orgánica 3/2018 de Protección de Datos Personales y garantía de los derechos digitales Ley Orgánica 3/2018 4 2 2 0 0 75%
EU Sixth Anti-Money Laundering Directive (6AMLD) Directive (EU) 2018/1673 4 0 4 0 0 50%
EU AI Act — Regulation (EU) 2024/1689 2024/1689 139 97 19 15 0 84%
EU AI Act — Article 50 chatbot transparency (Regulation (EU) 2024/1689) 2024/1689 3 2 0 0 0 100%
EU AI Act — Annex III High-Risk Insurance Regulation (EU) 2024/1689 (EU AI Act) — Annex III high-risk insurance use-cases (life & health risk assessment / pricing) 4 3 0 0 0 100%
EU DAC — Directive on Administrative Cooperation (DAC6 mandatory disclosure + DAC7) dac6-dac7 4 0 4 0 0 50%
EU Evidence Regulation 2020/1783 + eIDAS — Evidence Authenticity & Transmission Regulation (EU) 2020/1783 (taking of evidence in civil/commercial matters) + eIDAS Regulation (EU) 910/2014 (electronic evidence integrity) 3 2 0 0 0 100%
EU Whistleblower Directive — Directive (EU) 2019/1937 Directive (EU) 2019/1937 (protection of persons who report breaches of Union law) 4 3 0 0 0 100%
EW-AiRM — Enterprise-Wide AI Risk Management EW-AiRM — Enterprise-Wide AI Risk Management (Human-AI Institute / Markus Krebsz) 12 3 5 0 0 69%
FATF 40 Recommendations — International AML/CFT Standards 2012 (as amended) 5 5 0 0 0 100%
FCA COBS — Conduct of Business Sourcebook (UK Investment Conduct) FCA Handbook COBS 4 4 0 0 0 100%
FCA CONC — Consumer Credit Sourcebook FCA Handbook CONC — Consumer Credit Sourcebook 3 1 1 0 0 75%
FCA Consumer Duty (PRIN 2A) — Principle 12 & the four outcomes PRIN 2A 5 0 3 1 0 44%
FCA MCOB — Mortgage Conduct of Business (FCA Handbook) FCA Handbook 6 0 4 1 0 45%
UK FCA — Firm-Level Shariah Supervisory Board Model FCA/PRA firm-level governance (no separate Shariah regime) 17 6 8 0 0 71%
FCRA — Fair Credit Reporting Act Fair Credit Reporting Act (15 U.S.C. §1681 et seq.) / Regulation V (12 C.F.R. Part 1022) 6 3 1 0 0 88%
FDA + EMA — AI / Provenance Expectations for AI-Derived Candidates in Regulated Pipelines 2024-2025 4 0 4 0 0 50%
Fed SR 11-7 — Supervisory Guidance on Model Risk Management SR 11-7 / OCC 2011-12 (Supervisory Guidance on Model Risk Management, April 2011) 5 4 0 0 0 100%
FedRAMP — Federal Risk and Authorization Management Program Rev 5 159 144 0 15 0 93%
Tietosuojalaki (1050/2018) — Data Protection Act 1050/2018 3 2 1 0 0 83%
Loi Informatique et Libertés (Act No. 78-17, as amended) + CNIL Act No. 78-17 (as amended) 4 2 2 0 0 75%
FRC Ethical Standard — Integrity, Objectivity & Independence for Auditors & Accountants 2024 4 0 4 0 0 50%
FRCP e-Discovery — Rules 26 / 34 / 37 + FRE 502 (privilege) FRCP (2015 e-discovery amendments; Rules 26 / 34 / 37 + FRE 502) 4 3 0 0 0 100%
FRE 901 / 902 — Authentication & Self-Authentication of Evidence FRE 901 / 902 (Authentication & Self-Authentication; 2017 ESI amendments) 3 2 0 0 0 100%
FSA AI / Model Governance Expectations for Financial Institutions FSA AI Discussion Paper (June 2024) + Comprehensive Guidelines for Supervision of Major Banks / System Risk Management expectations 5 4 1 0 0 90%
GDPR — General Data Protection Regulation Regulation (EU) 2016/679 92 79 1 6 0 94%
GDPR Article 22 — Automated Decision-Making Regulation (EU) 2016/679 (GDPR) — Article 22 (automated individual decision-making, including profiling) + Articles 13–15 / Recital 71 4 3 0 0 0 100%
GDPR (Whistleblowing) — Special-Category & Data-Minimisation in Reports Regulation (EU) 2016/679 (GDPR) — whistleblowing data-protection slice (Art. 5, 6, 9, 15, 21) 3 2 0 0 0 100%
GENIUS Act — US payment stablecoin law GENIUS Act (Pub. L. 119-27, 2025) 10 4 2 0 0 83%
Google SRE — Change Management (progressive rollout & rollback) SRE Book 2 1 0 0 0 100%
Law 4624/2019 (measures implementing the GDPR) Law 4624/2019 3 2 1 0 0 83%
HAARF — Healthcare AI Agents Regulatory Framework 1.0 279 262 15 0 2 97%
HAiPECR — Human-AI Pre-deployment Evidence & Certification Record HAiPECR — Human-AI Pre-deployment Evidence & Certification Record (Human-AI Institute / Markus Krebsz, OECD-listed Apr 2023) 8 1 6 0 0 57%
HM Land Registry — Registration & Digital Identity Standard (Safe Harbour) Registration & Digital Identity Standard 4 0 3 0 0 50%
Homes England Capital Funding Guide — Shared Ownership (model lease) Capital Funding Guide — Shared Ownership 4 0 3 0 0 50%
Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Info Act, GDPR-aligned) Act CXII of 2011 3 2 1 0 0 83%
ICH Q1 — Stability Testing ICH Q1A(R2) (2003) 2 0 1 0 0 50%
ICH Q10 — Pharmaceutical Quality System ICH Q10 (2008) 5 3 1 0 0 88%
ICH Q2(R2) — Validation of Analytical Procedures ICH Q2(R2) (2023) 4 3 0 0 0 100%
ICH Q3 — Impurities ICH Q3A(R2)/Q3B(R2)/Q3C(R8)/Q3D(R2) 2 0 1 0 0 50%
ICH Q5 — Quality of Biotechnological Products ICH Q5A(R2)/Q5B/Q5C/Q5D/Q5E 2 0 1 0 0 50%
ICH Q6 — Specifications ICH Q6A/Q6B 2 0 1 0 0 50%
ICH Q7 — Good Manufacturing Practice for Active Pharmaceutical Ingredients ICH Q7 (2000) 5 4 0 0 0 100%
ICH Q8(R2) — Pharmaceutical Development ICH Q8(R2) (2009) 4 3 0 0 0 100%
ICH Q9(R1) — Quality Risk Management ICH Q9(R1) (2023) 4 3 0 0 0 100%
ICRAA — California Investigative Consumer Reporting Agencies Act California Investigative Consumer Reporting Agencies Act (ICRAA), Cal. Civ. Code §1786 et seq. 5 3 1 0 0 88%
Data Protection Act 2018 DPA 2018 4 3 1 0 0 88%
IEC 61508:2010 — Functional safety of electrical/electronic/programmable electronic safety-related systems 2010 6 0 5 1 0 46%
IEC 61511:2016 — Functional safety: Safety instrumented systems for the process industry sector 2016 5 0 4 1 0 45%
IFSB Prudential Standards (suite) IFSB prudential standards suite 9 4 3 0 0 79%
IFSB-10 — Guiding Principles on Shari'ah Governance Systems IFSB-10 (2009) 18 7 8 0 0 73%
IIFM Documentation Standards IIFM documentation standards 8 2 0 0 0 100%
IMDA AI Verify AI Verify (IMDA / AI Verify Foundation) 4 4 0 0 0 100%
Investment Mandate / IPS — Investment Policy Statement & Discretionary Mandate Authority 2026 4 0 4 0 0 50%
IRS Circular 230 — Regulations Governing Practice before the Internal Revenue Service 2014-rev 5 0 5 0 0 50%
ISA (UK) — International Standards on Auditing (UK) 2024 4 0 4 0 0 50%
ISO 14001 — Environmental Management Systems 2015 3 0 3 0 0 50%
ISO 15189:2022 — Medical laboratories — Requirements for quality and competence 2022 6 5 0 0 0 100%
ISO 15489-1:2016 — Information and Documentation · Records Management 2016 6 3 0 0 0 100%
ISO 16175-1:2020 — Processes and Functional Requirements for Software for Managing Records (digital records) 2020 5 3 0 0 0 100%
ISO/IEC 17025:2017 — General requirements for the competence of testing and calibration laboratories 2017 6 3 1 0 0 88%
ISO 21448:2022 — Safety Of The Intended Functionality (SOTIF) 2022 6 0 4 1 0 45%
ISO 23081-1:2017 — Managing Metadata for Records (records metadata) 2017 5 3 0 0 0 100%
ISO/IEC 27001:2022 — Information Security Management Annex A + Clauses 4-10 2022 118 83 6 29 0 79%
ISO/IEC 27035 — Incident Management ISO/IEC 27035 — Information security incident management (Parts 1–3) 4 3 0 0 0 100%
ISO 31000:2018 — Risk management — Guidelines 2018 5 0 2 3 0 35%
ISO/IEC 42001:2023 — AI Management System (AIMS) 2023 80 76 3 1 0 97%
ISO 45001 — Occupational Health & Safety Management Systems 2018 4 0 4 0 0 50%
ISO 55000 / ISO 55001:2014 — Asset management — Management systems 2014 4 0 3 1 0 44%
ISO 9000:2015 — Quality management systems (fundamentals & vocabulary) ISO 9000:2015 3 2 1 0 0 83%
ISO/IEC 20000-1 — Service Management (change management, §8.5.1) 2018 2 1 0 0 0 100%
ISO/IEC 38507:2022 — Governance implications of the use of AI by organizations ISO/IEC 38507:2022 12 8 4 0 0 83%
Codice in materia di protezione dei dati personali (D.Lgs. 196/2003, as amended by D.Lgs. 101/2018) D.Lgs. 196/2003 (am. 101/2018) 3 2 1 0 0 83%
IT Rules 2021 Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, as amended 4 1 0 0 0 100%
ITIL 4 — Change Enablement (change authority & assessment) 4 2 1 0 0 0 100%
Central Bank of Jordan — Islamic Banking Shariah Governance CBJ Islamic banking instructions 17 6 8 0 0 71%
Law Society Conveyancing Protocol Law Society Conveyancing Protocol 5 0 4 0 0 50%
Loi du 1er août 2018 portant organisation de la Commission nationale pour la protection des données Loi du 1er août 2018 3 2 1 0 0 83%
MAS FEAT Principles MAS FEAT Principles (2018) + Veritas 4 4 0 0 0 100%
MAS Project MindForge — AI Risk Management: Operationalisation Handbook 2024 7 0 7 0 0 50%
MAS Technology Risk Management Guidelines MAS Technology Risk Management Guidelines (Jan 2021) 4 3 1 0 0 88%
Mastercard Chargeback Standards — Dispute Resolution & Arbitration Mastercard Chargeback Standards — Dispute Resolution & Arbitration (Chargeback Guide) 4 3 0 0 0 100%
MHRA Medical Devices Regulations 2002 2002-as-amended-2024 53 50 3 0 0 97%
MHRA Post-Market Surveillance Regulations 2025 2025-06 36 36 0 0 0 100%
MHRA SaMD & AI Change Program 2023 41 41 0 0 0 100%
MiCA — Markets in Crypto-Assets Regulation Regulation (EU) 2023/1114 12 9 1 0 0 95%
MiFID II — Markets in Financial Instruments Directive II (Investment Services Conduct) Directive 2014/65/EU 4 4 0 0 0 100%
MIT AI Risk Repository — Domain Taxonomy 2024 (Domain Taxonomy v3) 5 0 3 2 0 40%
MoReq2010 — Modular Requirements for Records Systems 2011 5 3 0 0 0 100%
MOW Search Only Terms Contract (SOC) — publisher content-access authority Search Only Terms Contract: for Access and Use of Website, version socw/2 (Movement for an Open Web; drafted by Preiskel & Co LLP; canonical immutable URL https://m4ow.uk/socw/2.txt) 8 0 7 0 0 50%
MSHA — Mine Safety and Health Administration standards (30 CFR) 2024 4 0 3 1 0 44%
NAIC Model Bulletin on the Use of AI by Insurers NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers (adopted December 2023) 4 3 0 0 0 100%
NERC CIP — Critical Infrastructure Protection Reliability Standards (North American bulk electric system) 2024 5 0 3 2 0 40%
NIS2 — Network and Information Security Directive Directive (EU) 2022/2555 42 37 1 4 0 92%
NIS2 Incident Reporting — Article 23 (24h / 72h) NIS2 — Directive (EU) 2022/2555, Article 23 (incident reporting: 24h early warning / 72h notification / final report) 3 2 0 0 0 100%
NIST SP 800-207 — Zero Trust Architecture 1.0 (August 2020) 40 36 2 2 0 94%
NIST SP 800-53 Rev 5 — Configuration Management (CM) family Rev 5 2 1 0 0 0 100%
NIST AI Risk Management Framework 1.0 + Playbook 1.0 100 87 9 4 0 93%
NIST Cybersecurity Framework 2.0 — Core + Tiers + Profiles 2.0 (February 2024) 130 105 10 15 0 88%
NIST CSF 2.0 — RESPOND & RECOVER NIST Cybersecurity Framework 2.0 (2024) — RESPOND (RS) + RECOVER (RC) Functions 4 3 0 0 0 100%
UAVG — Uitvoeringswet Algemene verordening gegevensbescherming (GDPR Implementation Act, 2018) UAVG 2018 3 2 1 0 0 83%
Personopplysningsloven (LOV-2018-06-15-38) — GDPR incorporated via the EEA Agreement LOV-2018-06-15-38 3 2 1 0 0 83%
Nucleic-Acid Synthesis Screening — IBBIS Common Mechanism + IGSC Harmonized Screening Protocol 2023 4 0 4 0 0 50%
NYC Local Law 144 — Automated Employment Decision Tools 2023 (in force 2023-07-05) 3 1 2 0 0 67%
NYDFS Insurance Circular Letter on AI NYDFS Insurance Circular Letter No. 7 (2024) — Use of AI Systems and External Consumer Data in Underwriting and Pricing 4 3 0 0 0 100%
NZ Algorithm Charter for Aotearoa New Zealand Algorithm Charter for Aotearoa New Zealand (2020) 3 3 0 0 0 100%
New Zealand Privacy Act 2020 Privacy Act 2020 (NZ) 4 3 1 0 0 88%
OCC AI Supervisory Expectations — Model Risk · Third-Party Risk · New-Activity / Filing Readiness 2024 8 0 7 0 0 50%
OECD Good Laboratory Practice (Principles, 1998) + FDA 21 CFR Part 58 — non-clinical lab data integrity 1998 (No. 1) + FDA 21 CFR 58 6 4 1 0 0 90%
OECD Pillar Two — GloBE Rules (Global Minimum Tax) & BEPS 2023-globe 4 0 4 0 0 50%
OJK / DSN-MUI — Indonesian Shariah Governance OJK Shariah governance regulations + DSN-MUI fatawa 18 7 8 0 0 73%
OSFI Guideline B-10 — Third-Party Risk Management OSFI Guideline B-10 — Third-Party Risk Management (effective 1 May 2024) 3 3 0 0 0 100%
OSFI Guideline B-13 — Technology & Cyber Risk Management OSFI Guideline B-13 — Technology and Cyber Risk Management (effective 1 January 2024) 4 4 0 0 0 100%
OSFI Guideline E-23 — Model Risk Management OSFI Guideline E-23 — Model Risk Management (revised, effective 1 May 2027; applies to all federally regulated financial institutions, model definition expanded to include AI/ML) 4 3 0 1 0 81%
OSHA PSM — Process Safety Management of Highly Hazardous Chemicals (29 CFR 1910.119) 1992 4 0 3 1 0 44%
OWASP Top 10 for Agentic Applications (Agentic AI Threats & Mitigations) 2025 8 0 5 3 0 41%
PCI DSS 4.0 — Payment Card Industry Data Security Standard 4.0 146 111 1 34 0 82%
PCMLTFA / FINTRAC — Anti-Money-Laundering & Terrorist-Financing PCMLTFA — Proceeds of Crime (Money Laundering) and Terrorist Financing Act, S.C. 2000, c. 17, and its Regulations (consolidated current-to-2024), administered by FINTRAC 4 3 1 0 0 88%
Permit-to-Work Systems (HSE HSG250 guidance) HSG250 3 0 3 0 0 50%
PHIPA (Ontario) — Personal Health Information Protection Act, 2004 PHIPA — Personal Health Information Protection Act, 2004, S.O. 2004, c. 3, Sched. A (consolidated current-to-2024, incl. electronic-audit-log + de-identification amendments) 6 5 1 0 0 92%
PIPEDA — Personal Information Protection and Electronic Documents Act PIPEDA — S.C. 2000, c. 5 (Schedule 1 fair-information principles, consolidated current-to-2024) 6 5 1 0 0 92%
Ustawa z dnia 10 maja 2018 r. o ochronie danych osobowych (Personal Data Protection Act) Ustawa z 10 maja 2018 3 2 1 0 0 83%
PMDA Software-as-a-Medical-Device (SaMD) Pathway Pharmaceuticals and Medical Devices Act (PMD Act) SaMD pathway + PMDA review framework, including the SaMD two-step approval (DASH) scheme 5 4 1 0 0 90%
PRA SS1/23 — Model Risk Management Principles for Banks PRA SS1/23 (Model risk management principles for banks, May 2023; effective May 2024) 6 5 0 0 0 100%
Privacy Act 1988 (Cth) — ADM transparency + APPs Privacy Act 1988 (Cth) — ADM transparency amendments + Australian Privacy Principles 4 4 0 0 0 100%
PSD2 / PSD3 — EU Payment Services Directive 2015/2366 + RTS (EU) 2018/389 + PSD3 proposal COM(2023)366 61 59 1 1 0 98%
PSD2 SCA & Unauthorised-Transaction Liability (Arts. 72-74, 97) PSD2 — Directive (EU) 2015/2366, Arts. 72-74 + 97 (SCA & unauthorised-transaction liability) 4 3 0 0 0 100%
Lei n.º 58/2019 (assegura a execução do RGPD) Lei n.º 58/2019 3 2 1 0 0 83%
Qatar Central Bank — Shariah Supervision and Governance QCB Islamic banking instructions 17 6 8 0 0 71%
Quebec Law 25 — Private Sector personal-information modernisation Quebec Law 25 — Act to modernize legislative provisions as regards the protection of personal information (2021, c.25), amending the Private Sector Act (CQLR c. P-39.1), fully in force 22 Sept 2024 5 3 2 0 0 80%
RBI IT Governance Master Direction Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices 6 2 0 0 0 100%
RBNZ BS11 — Outsourcing Policy RBNZ BS11 Outsourcing Policy 3 3 0 0 0 100%
Reg E — EFTA Error Resolution (12 CFR 1005.11) EFTA / Regulation E — 12 CFR Part 1005 (error resolution, §1005.11) 4 3 0 0 0 100%
Reg Z — TILA Billing-Error Resolution (12 CFR 1026.13) TILA / Regulation Z — 12 CFR Part 1026 (billing-error resolution, §1026.13) 4 3 0 0 0 100%
RIDDOR — Reporting of Injuries, Diseases and Dangerous Occurrences Regulations 2013 (UK) 2013 3 0 3 0 0 50%
Law No. 190/2018 (implementing measures for the GDPR) Law No. 190/2018 3 2 1 0 0 83%
SAFR — Safeguards for Agentic Finance at Runtime SAFR v1.0 (July 2026) 14 12 2 0 0 93%
Saudi Central Bank — Shariah Governance Framework SAMA Shariah Governance Framework (2020) 17 6 8 0 0 71%
State Bank of Pakistan — Shariah Governance Framework SBP Shariah Governance Framework (2018) 18 7 8 0 0 73%
Lag (2018:218) med kompletterande bestämmelser till EU:s dataskyddsförordning Lag (2018:218) 3 2 1 0 0 83%
SEBI CSCRF Cybersecurity and Cyber Resilience Framework (CSCRF) 6 2 0 0 0 100%
SEC Cyber Disclosure — Item 1.05 (4 business days) SEC Cybersecurity Disclosure Rules (2023) — Regulation S-K Item 1.05 (material incident, 8-K, four business days) + Item 106 3 2 0 0 0 100%
SEC Investment Adviser Fiduciary Duty — Advisers Act of 1940 (Duty of Care & Loyalty) Investment Advisers Act of 1940 4 4 0 0 0 100%
The Sedona Principles — Best Practices for Electronic Document Production The Sedona Principles, Third Edition (2018) 3 2 0 0 0 100%
Singapore SASH — Detecting Offensive Cyber Agents (Defence-in-Depth) 2026 (SASH) 4 0 1 3 0 31%
Act No. 18/2018 Coll. on Personal Data Protection Act No. 18/2018 Coll. 3 2 1 0 0 83%
SOC 2 — Trust Services Criteria TSC 2017 (revised 2022) 61 54 2 5 0 92%
Production Action Authority — SOC 2 CC8 Change Management 2017 TSC 2 1 0 0 0 100%
SOX §404 — Internal Control over Financial Reporting (tax-provision controls) 2002 4 4 0 0 0 100%
SOX §806 — Whistleblower Anti-Retaliation (18 U.S.C. §1514A) Sarbanes-Oxley Act §806 (18 U.S.C. §1514A) — whistleblower anti-retaliation 3 2 0 0 0 100%
Central Bank of Sudan — High Shariah Supervisory Board CBOS High Shariah Supervisory Board framework 18 7 8 0 0 73%
TARGET2 / T2 RTGS (ECB) — payment-authority governance incl. Settlement Finality Directive 98/26/EC ECB TARGET Guideline (EU) 2022/912 (ECB/2022/8) — T2 RTGS harmonised conditions + Directive 98/26/EC (Settlement Finality Directive) Arts 3 & 5 7 4 1 0 0 90%
TBS Directive on Automated Decision-Making (Canada federal government) Treasury Board Directive on Automated Decision-Making (in force; latest amendments effective 2023) 4 4 0 0 0 100%
The IIA's Three Lines Model (2020) 2020 6 0 3 3 0 38%
TKBB — Participation Banking Standards (Türkiye) TKBB participation-banking standards + BDDK regulation 18 7 8 0 0 73%
UK AI Assurance (DSIT) 2024-11 roadmap 31 28 2 1 0 94%
UK AI Regulatory Framework 2023-03 white paper / 2024-02 response 33 22 6 5 0 80%
AI Testing and Assurance Framework for the Public Sector 2024 3 2 1 0 0 83%
Algorithmic Transparency Recording Standard (ATRS) ATRS v3.0 (2025) 5 3 1 0 0 88%
UK CPR Part 31 + PD 57AD — Disclosure & the Disclosure Certificate CPR Part 31 + Practice Direction 57AD (Disclosure in the Business and Property Courts, 2022) 3 2 0 0 0 100%
UK Failure to Prevent Fraud (Economic Crime and Corporate Transparency Act 2023) ECCTA 2023 (in force 1 Sep 2025) 4 0 2 2 0 38%
UK Equality Act 2010 2010 2 1 1 0 0 75%
UK Faster Payments (FPS) — payment-authority governance UK Faster Payment System rules (Pay.UK scheme rules) + PSR APP-scam reimbursement requirement for Faster Payments (October 2024) 7 3 2 0 0 80%
UK GAAP — FRS 102 / FRS 105 Recognition, Measurement & Disclosure 2024 4 0 4 0 0 50%
AI Playbook for the UK Government Feb 2025 4 3 1 0 0 88%
HMT Magenta Book — Evaluation Guidance 2020 (Central Government Guidance on Evaluation) 3 1 1 0 0 75%
UK Money Laundering Regulations 2017 (MLR 2017) SI 2017/692 (as amended) 4 0 3 1 0 44%
UK Making Tax Digital (MTD) — Digital Record-Keeping & API Filing 2024 4 0 4 0 0 50%
HMT Orange Book — Management of Risk 2023 (Management of Risk) + Portfolio Risk Management Guidance 3 2 1 0 0 83%
UK PIDA — Public Interest Disclosure Act 1998 (ERA 1996 Part IVA) UK Public Interest Disclosure Act 1998 (Employment Rights Act 1996, Part IVA) 3 2 0 0 0 100%
UK Senior Managers & Certification Regime (SM&CR) 2016 (FCA/PRA, as amended) 4 0 3 1 0 44%
UNESCO Recommendation on the Ethics of Artificial Intelligence (2021) 2021 9 3 4 1 0 66%
US 2 CFR 200 — Uniform Guidance 2 C.F.R. Part 200 (Uniform Guidance) 8 3 2 0 0 80%
US Bank Secrecy Act / FinCEN — AML Program, CDD & SAR Requirements 31 U.S.C. 5311 et seq.; 31 CFR Chapter X 4 4 0 0 0 100%
US EO 14110 — Safe, Secure & Trustworthy AI (biosecurity / dual-use provisions) 2023 4 0 4 0 0 50%
US State AI-Chatbot Laws — consumer chatbot safeguards 2024-2026 9 5 0 0 0 100%
Visa Compelling Evidence 3.0 (CE3.0) Visa Compelling Evidence 3.0 (CE3.0) — remedied-dispute evidence requirements (Visa Rules, fraud reason code 10.4) 4 3 0 0 0 100%
Voluntary Code of Conduct — Advanced Generative AI (Canada) Voluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI Systems (ISED, September 2023) 3 0 0 3 0 25%
Wolfsberg Group AML Principles & Guidance current 3 0 3 0 0 50%

Click a framework to see the per-requirement deep-link to the KYE™ artefact(s) enforcing it.