Regulatory Framework Coverage

Last Audited: 2026-08-21
NUP AI-Native Verified
ISO/IEC 42001:2023 Cl. 6, 8, 9, 10EU AI Act Art. 9, 10, 11, 14, 15, 61NIST AI RMF 1.0 Govern, Map, Measure, Manage
In Plain Language

Organizations operating in regulated markets face a dual compliance challenge: they must adapt traditional quality and privacy frameworks (such as FDA SaMD, HIPAA, and NIST CSF) to accommodate non-deterministic software, while simultaneously complying with new, AI-specific statutory mandates (including the EU AI Act, ISO/IEC 42001, and NIST AI RMF). This topic provides an executive two-column reference of pre-mapped frameworks, complete with one-line scope summaries, mandatory audit deliverables, and clause citations, enabling legal and compliance stakeholders to conduct a 60-second gap analysis.

Architectural Orientation: The Dual-Layer Compliance Burden

Engineering and legal stakeholders often ask whether an established deterministic compliance program (e.g., ISO 13485, SOC 2, HIPAA) is sufficient for deploying generative and probabilistic AI systems. The answer is twofold: while traditional frameworks continue to govern infrastructure security and data confidentiality, they lack the governance mechanisms required to measure semantic drift, model hallucination, training data bias, and dynamic change control.

The Netspective Unified Process pre-maps compliance obligations across both layers, ensuring engineering teams produce the exact technical dossiers and continuous telemetry streams required by notified bodies and regulatory auditors.

Global AI Regulatory Landscape: Traditional vs. AI-Specific CoverageA jurisdictional landscape diagram mapping pre-covered regulatory frameworks across International, European Union, and United States standards.The Dual Regulatory Landscape for Probabilistic SystemsPre-mapped compliance coverage across International, European, and United States jurisdictions.AI-Specific NativeTraditional (Adapted)GLOBAL / INTERNATIONALVoluntary certifiable standardsISO/IEC 42001:2023AI Management System (AIMS)• Organizational AI risk management• Systemic post-market monitoringDeliverable: SoA & AIMS ManualIEEE 7000-2021Ethical System Design• Value elicitation & transparency• Harm & bias impact assessmentDeliverable: Value RegisterEUROPEAN UNIONBinding statutory legislationEU AI Act (Reg. 2024/1689)Comprehensive Risk-Tier Law• Art. 6: Risk Classification (4 Tiers)• Art. 9: Risk Management System• Art. 10: Training Data Governance• Art. 11: Technical Docs (Annex IV)• Art. 14: Human Oversight Design• Art. 15: Accuracy & Cybersecurity• Art. 61: Post-Market MonitoringDeliverable: Annex IV Dossier &EU Declaration of ConformityUNITED STATESSectoral guidance & federal frameworksNIST AI RMF & FDA PCCPTrustworthy AI & Medical SaMD• Govern, Map, Measure, Manage• Predetermined Change Plans (PCCP)Deliverable: AI RMF Profile / PCCPHIPAA & NIST CSF 2.0Traditional Security & Privacy• ePHI zero-retention API posture• Prompt injection threat modelsDeliverable: PHI Flow & Threat Model

1. Traditional Frameworks Applied to AI

Standard cybersecurity, medical device, and privacy regulations adapted to address AI infrastructure and data flow risks:

HIPAA Security Rule

US Department of Health & Human Services

Scope: AI systems processing Electronic Protected Health Information (ePHI)

Key Mandate: Access control, encryption, data de-identification, business associate agreements with LLM providers.
Artifact: PHI Data Flow Diagram & LLM Zero-Data-Retention Compliance Attestation45 CFR Part 160 & Part 164 Subparts A/C

NIST CSF 2.0

NIST

Scope: Cybersecurity risk management applied to AI infrastructure and models

Key Mandate: Protection against prompt injection, model theft, training data poisoning, and unauthorized inference access.
Artifact: AI System Cybersecurity Assessment & Threat ModelNIST Cybersecurity Framework 2.0 (Govern, Identify, Protect, Detect, Respond, Recover)

2. AI-Specific Regulations & Standards

Dedicated legal frameworks and management standards authored specifically for non-deterministic and autonomous systems:

EU AI Act (Regulation 2024/1689)

European Union

Scope: All AI systems placed on the EU market across 4 risk tiers

Key Mandate: Risk management system, data governance, technical documentation, record-keeping, human oversight, cybersecurity.
Artifact: Technical Documentation Dossier (Annex IV), EU Declaration of ConformityEU AI Act Articles 9, 10, 11, 14, 15

NIST AI RMF 1.0

National Institute of Standards and Technology (USA)

Scope: Voluntary framework for managing risks in design, development, and use of AI

Key Mandate: Four core functions: GOVERN, MAP, MEASURE, MANAGE across trustworthiness characteristics.
Artifact: AI Risk Management Playbook & Trustworthiness ProfileNIST Special Publication 1270 / AI 100-1

ISO/IEC 42001:2023

ISO / IEC

Scope: Certifiable AI Management System (AIMS) standard for organizations

Key Mandate: Systemic organizational AI governance, risk assessment, continuous monitoring, and supplier management.
Artifact: Statement of Applicability (SoA) & AI Management System ManualISO/IEC 42001:2023 Clauses 6, 8, 9, 10

FDA AI/ML SaMD & PCCP Guidance

US Food and Drug Administration (FDA)

Scope: Software as a Medical Device incorporating machine learning algorithms

Key Mandate: Good Machine Learning Practice (GMLP) and Predetermined Change Control Plans for planned model evolution.
Artifact: Predetermined Change Control Plan (PCCP) & Clinical Performance Validation ReportFDA Docket FDA-2022-D-2628 / GMLP 10 Principles

IEEE 7000-2021

IEEE Computer Society

Scope: Model process for addressing ethical concerns during system design

Key Mandate: Eliciting ethical values, translating them into system requirements, and risk-assessing ethical impacts.
Artifact: Ethical Value Register & Impact Assessment DocumentIEEE Standard 7000-2021 Clause 5

60-Second Quick-Scan Compliance Matrix

FrameworkTypeGoverning BodyMandatory Audit DeliverableKey Clause Citation
EU AI Act (Regulation 2024/1689)AI-SpecificEuropean UnionTechnical Documentation Dossier (Annex IV), EU Declaration of ConformityEU AI Act Articles 9, 10, 11, 14, 15
NIST AI RMF 1.0AI-SpecificNational Institute of Standards and Technology (USA)AI Risk Management Playbook & Trustworthiness ProfileNIST Special Publication 1270 / AI 100-1
ISO/IEC 42001:2023AI-SpecificISO / IECStatement of Applicability (SoA) & AI Management System ManualISO/IEC 42001:2023 Clauses 6, 8, 9, 10
FDA AI/ML SaMD & PCCP GuidanceAI-SpecificUS Food and Drug Administration (FDA)Predetermined Change Control Plan (PCCP) & Clinical Performance Validation ReportFDA Docket FDA-2022-D-2628 / GMLP 10 Principles
IEEE 7000-2021AI-SpecificIEEE Computer SocietyEthical Value Register & Impact Assessment DocumentIEEE Standard 7000-2021 Clause 5
HIPAA Security RuleTraditionalUS Department of Health & Human ServicesPHI Data Flow Diagram & LLM Zero-Data-Retention Compliance Attestation45 CFR Part 160 & Part 164 Subparts A/C
NIST CSF 2.0TraditionalNISTAI System Cybersecurity Assessment & Threat ModelNIST Cybersecurity Framework 2.0 (Govern, Identify, Protect, Detect, Respond, Recover)

Where to Go for Detailed Compliance Matrices & Operational SOPs

This page provides high-level framework orientation. For step-by-step Standard Operating Procedures (SOPs), audit dossier templates, and integration with existing Quality Management Systems, consult our specialized tracks:

Try This with AI: Regulatory Gap Analysis Prompt

Use this prompt in your AI assistant to audit a project proposal against applicable AI regulations.

Act as a Principal Regulatory & AI Compliance Counsel. Perform a jurisdictional gap analysis for the following AI application: - Product Description: [e.g., Clinical trial protocol matching chatbot processing EHR patient records] - Target Jurisdictions: [e.g., European Union & United States] - Technology Stack: [e.g., Claude 3.5 Sonnet fine-tuned model via AWS Bedrock with vector embeddings] Analyze: 1. Determine the exact risk tier under the EU AI Act (Article 6 / High-Risk vs. General Purpose AI). 2. Identify applicable FDA SaMD and HIPAA Security Rule obligations for patient health records. 3. List the top 5 mandatory compliance artifacts (e.g. EU Annex IV dossier, HIPAA zero-retention attestation) required prior to production launch.
Next in Core Concepts

Topic 7: Artifact Generation for Probabilistic Systems

Proceed to Topic 7
Previous Section
Deterministic Unified Process
Next Track
The Four Layers of LLM Engineering

Community Discussion & Feedback

Attributed peer feedback and official Netspective architecture notes.

Was this documentation helpful?(100% found this helpful • 0 ratings)

Leave Feedback or Question

○ Loading user info...
0/2000 chars

Discussion (0)

Loading discussion thread...