AI GRC Frameworks & Standards

The regulations, standards, and reference documents forming the backbone of a mature AI governance programme.

European Union · 2024–26

EU Artificial Intelligence Act

The world's first comprehensive AI law. Risk-tiered approach — prohibited, high-risk, limited-risk, and minimal-risk AI. High-risk systems face conformity assessments, technical documentation, and post-market monitoring.

General-purpose AI models above 10²⁵ FLOPs face additional systemic risk obligations. Fines reach €35M or 7% of global turnover.

Read the EU AI Act →

Key Obligations

  • Risk classification for all AI systems
  • Conformity assessments for high-risk AI
  • Technical documentation and audit trails
  • Post-market monitoring obligations
  • GPAI model transparency requirements
  • Article 50 chatbot/AI content disclosure
United States · 2023+

NIST AI Risk Management Framework

Voluntary but widely adopted GRC structure with four core functions: Govern, Map, Measure, and Manage. Structured approach to identifying and mitigating AI risks across the entire lifecycle.

Version 2.0 includes updated governance guidance and expanded implementation resources.

NIST AI RMF →

Core Functions

  • Govern — policies, roles, accountability
  • Map — context, stakeholders, risk identification
  • Measure — assess and track AI risks
  • Manage — prioritise and respond to risks
  • Voluntary but globally referenced
International · 2023

ISO/IEC 42001:2023

International standard for AI Management Systems (AIMS). Certifiable, modelled on ISO 27001. Provides structural backbone for AI GRC programmes.

Demand for certification is rising as the EU AI Act references ISO standards. Particularly adopted in Europe and Asia-Pacific.

ISO/IEC 42001 →

Key Elements

  • AI policy and objectives
  • AI risk assessment methodology
  • Controls for responsible AI development
  • Continuous improvement cycle (PDCA)
  • Certifiable — audit-ready structure
  • Aligned with ISO 27001 annex structure
United Kingdom · 2023+

UK Pro-Innovation AI Approach

Principles-based, sector-led model. ICO, FCA, CMA, and Ofcom each apply existing powers to AI in their domains. The AI Safety Institute runs frontier model evaluations.

UK AI Policy →

Core Principles

  • Safety, security, and robustness
  • Appropriate transparency and explainability
  • Fairness
  • Accountability and governance
  • Contestability and redress
Singapore · 2023+

Singapore Model AI Governance Framework

MAS and IMDA co-developed one of the world's most detailed voluntary AI governance frameworks for financial services and general use. Widely respected as a balanced, innovation-friendly model.

Singapore AI Framework →

Key Features

  • Voluntary, principles-based approach
  • Internal governance structures
  • Decision-making model documentation
  • Operations management requirements
  • Stakeholder interaction guidance

Framework Comparison

FrameworkOriginTypeScopeStatus
EU AI ActEUMandatoryComprehensive risk-tiered AI regulationPhased enforcement 2024–27
NIST AI RMFUSVoluntaryRisk management (Govern, Map, Measure, Manage)v2.0 published
ISO/IEC 42001IntlCertifiableAI Management SystemsActive, demand rising
UK AI ApproachUKPrinciplesSector-led, regulator-appliedEvolving
Singapore MAIGFSGVoluntaryAI governance for financial servicesv2 published
OECD AI PrinciplesOECDPrinciplesHigh-level policy alignmentGlobal reference

Regulatory Timeline

Feb 2024

Prohibited Systems Banned

Social scoring, manipulative AI practices prohibited under EU AI Act.

Aug 2025

GPAI Model Obligations

General-purpose AI providers face transparency and documentation duties.

Aug 2026

Article 50 — Transparency Live

Chatbot disclosure and AI-generated content labelling now mandatory.

Dec 2026

AI-Generated NCII Prohibitions

New prohibitions on AI-generated non-consensual intimate imagery.

Dec 2027

High-Risk AI Full Obligations

Full conformity requirements enforced (extended by Digital Omnibus).