Modulos Named in the Inaugural Gartner® Magic Quadrant™ for AI Governance PlatformsRead the

Press Release

AI Governance Platform

Modulos is the AI governance platform built for teams that need to operationalize EU AI Act compliance, manage AI risk, and prove conformity across regulatory frameworks. AI agents do the heavy lifting: quantifying risk in money, assessing controls, and mapping evidence. Run them once or on a schedule, across your whole portfolio. Your team reviews and decides.

The Governance Graph

The real framework library, drawn as one graph. Click two or more frameworks to see the controls they share: implement a control once and it counts toward every framework that maps it.

The Modulos governance graph

Framework library v1.0.31: click frameworks to compare their overlap

OCF-1 · Governance Structure · 10 frameworksMCF-23 · Risk Management at Inception · 9 frameworksMCF-53 · Technical Documentation · 9 frameworksMCF-67 · Production Data Drift Monitoring · 9 frameworksMCF-65 · Deployed AI System Performance Monitoring · 8 frameworksMCF-76 · Risk Management in Operation · 8 frameworksOCF-123 · Document availability and suitability · 8 frameworksOCF-131 · External provider control · 8 frameworksOCF-44 · AI Literacy and Awareness · 8 frameworksOCF-52 · Risk Management System · 8 frameworksOCF-95 · Risk criteria establishment · 8 frameworksOCF-97 · Risk assessment process · 8 frameworksMCF-32 · Data Bias Assessment · 7 frameworksMCF-55 · Testing Procedures · 7 frameworksMCF-58 · Model Fairness Testing · 7 frameworksMCF-61 · Deployment Acceptance · 7 frameworksMCF-68 · Deployed AI System Fairness Monitoring · 7 frameworksMCF-81 · Risk Management at Re-evaluation · 7 frameworksOCF-109 · Competence determination · 7 frameworksOCF-110 · Competence assurance · 7 frameworksOCF-111 · Competence development · 7 frameworksOCF-122 · Document review and approval · 7 frameworksOCF-125 · Document lifecycle · 7 frameworksOCF-47 · Documentation Keeping · 7 frameworksOCF-98 · Risk treatment process · 7 frameworksMCF-15 · Overall Requirements · 6 frameworksMCF-24 · Data Design Choices · 6 frameworksMCF-243 · Inventory of information and other associated assets · 6 frameworksMCF-25 · Data Collection · 6 frameworksMCF-253 · Information security in supplier relationships · 6 frameworksMCF-254 · Addressing information security within supplier agreements · 6 frameworksMCF-256 · Monitoring, review and change management of supplier services · 6 frameworksMCF-30 · Data Transformation · 6 frameworksMCF-42 · Model Fairness Metrics · 6 frameworksMCF-43 · Model Bias Assessment · 6 frameworksMCF-47 · Transparency for Users · 6 frameworksMCF-54 · Risk Management in Development · 6 frameworksMCF-56 · System Performance Testing · 6 frameworksMCF-59 · System Security Testing · 6 frameworksMCF-66 · Production Data Quality Monitoring · 6 frameworksMCF-72 · Model Retraining Conditions Monitoring · 6 frameworksOCF-115 · Communication content · 6 frameworksOCF-116 · Communication timing · 6 frameworksOCF-117 · Communication audience · 6 frameworksOCF-118 · Required documentation · 6 frameworksOCF-120 · Document identification and description · 6 frameworksOCF-121 · Document format and media · 6 frameworksOCF-124 · Document protection · 6 frameworksOCF-127 · Process planning and criteria · 6 frameworksOCF-128 · Process control implementation · 6 frameworksOCF-130 · Operational change · 6 frameworksOCF-140 · Audit execution objectivity · 6 frameworksOCF-141 · Audit reporting and records · 6 frameworksOCF-142 · Management review · 6 frameworksOCF-150 · Nonconformity reaction · 6 frameworksOCF-151 · Cause evaluation and prevention · 6 frameworksOCF-152 · Corrective action implementation · 6 frameworksMCF-139 · User Feedback Integration · 5 frameworksMCF-165 · Post-Market Monitoring System · 5 frameworksMCF-184 · Logging Capability · 5 frameworksMCF-234 · Information security risk assessment and documentation · 5 frameworksMCF-255 · Managing information security in the information and communication technology (ICT) supply chain · 5 frameworksMCF-26 · Data Privacy · 5 frameworksMCF-260 · Response to information security incidents · 5 frameworksMCF-28 · Data Assessment · 5 frameworksMCF-308 · Logging · 5 frameworksMCF-309 · Monitoring activities · 5 frameworksMCF-325 · Change management · 5 frameworksMCF-33 · Data Error Vetting and Correction · 5 frameworksMCF-352 · Verify model and code origin with integrity checks · 5 frameworksMCF-38 · Model Algorithm Selection · 5 frameworksMCF-44 · Model Bias Prevention and Mitigation · 5 frameworksMCF-57 · Model TIX Testing · 5 frameworksMCF-62 · Risk Management at Verification · 5 frameworksMCF-64 · Risk Management in Deployment · 5 frameworksMCF-75 · Updating of Technical Documentation · 5 frameworksOCF-10 · Nonconformity Management · 5 frameworksOCF-112 · Policy awareness · 5 frameworksOCF-126 · External document · 5 frameworksOCF-132 · Monitoring and measurement subject · 5 frameworksOCF-133 · Monitoring and measurement methods · 5 frameworksOCF-134 · Monitoring and measurement timing · 5 frameworksOCF-135 · Results analysis and evaluation timing · 5 frameworksOCF-136 · Internal audit conformance · 5 frameworksOCF-137 · Internal audit effectiveness control · 5 frameworksOCF-138 · Audit programme establishment · 5 frameworksOCF-139 · Audit planning and prioritization · 5 frameworksOCF-145 · Interested parties needs review · 5 frameworksOCF-146 · Performance and trends review · 5 frameworksOCF-148 · Management review results · 5 frameworksOCF-149 · Continual improvement · 5 frameworksOCF-170 · Management system roles and responsibilities · 5 frameworksOCF-86 · Interested parties requirements · 5 frameworksOCF-89 · Leadership and commitment · 5 frameworksOCF-94 · Risk and opportunity determination · 5 frameworksOCF-96 · Risk and opportunity action planning · 5 frameworksMCF-14 · Project Objectives · 4 frameworksMCF-16 · Risk Tiering · 4 frameworksMCF-164 · Post-Market Monitoring Plan · 4 frameworksMCF-167 · Transparent Deployment at Workplace · 4 frameworksMCF-182 · Information and instructions to the user · 4 frameworksMCF-183 · Updating information and instructions to the user · 4 frameworksMCF-232 · Allocating responsibilities · 4 frameworksMCF-242 · Information security in project management · 4 frameworksMCF-248 · Information transfer · 4 frameworksMCF-249 · Access control · 4 frameworksMCF-250 · Identity management · 4 frameworksMCF-252 · Access rights · 4 frameworksMCF-258 · Information security incident management planning and preparation · 4 frameworksMCF-259 · Assessment and decision on information security events · 4 frameworksMCF-262 · Collection of evidence · 4 frameworksMCF-263 · Information security during disruption · 4 frameworksMCF-264 · ICT readiness for business continuity · 4 frameworksMCF-267 · Protection of records · 4 frameworksMCF-269 · Independent review of information security · 4 frameworksMCF-270 · Compliance with policies, rules and standards for information security · 4 frameworksMCF-279 · Information security event reporting · 4 frameworksMCF-298 · Secure authentication · 4 frameworksMCF-299 · Capacity management · 4 frameworksMCF-301 · Management of technical vulnerabilities · 4 frameworksMCF-302 · Configuration management · 4 frameworksMCF-306 · Information backup · 4 frameworksMCF-307 · Redundancy of information processing facilities · 4 frameworksMCF-319 · Application security requirements · 4 frameworksMCF-322 · Security testing in development and acceptance · 4 frameworksMCF-330 · Implement input and output filtering · 4 frameworksMCF-337 · Enforce Strict Access Controls · 4 frameworksMCF-35 · Data Bias Prevention and Mitigation · 4 frameworksMCF-36 · Data Versioning · 4 frameworksMCF-37 · Model Training Process · 4 frameworksMCF-385 · Ensure that security controls are enforced independently from the LLM · 4 frameworksMCF-400 · Rate Limiting · 4 frameworksMCF-49 · System Deployment Robustness · 4 frameworksMCF-63 · Model Deployment Procedure · 4 frameworksMCF-69 · Deployed AI System Security Testing · 4 frameworksMCF-71 · Deployed AI System Pen Monitoring · 4 frameworksMCF-86 · Risk Management at Retirement · 4 frameworksOCF-103 · Planned change management · 4 frameworksOCF-11 · Nonconformity Reporting · 4 frameworksOCF-113 · Contribution awareness · 4 frameworksOCF-114 · Nonconformity implications awareness · 4 frameworksOCF-12 · Cooperation with Competent Authorities · 4 frameworksOCF-129 · Control effectiveness monitoring · 4 frameworksOCF-143 · Previous Management Review Actions · 4 frameworksOCF-144 · Issue changes review · 4 frameworksOCF-147 · Continual improvement opportunities · 4 frameworksOCF-171 · Management system objectives · 4 frameworksOCF-172 · Management system objectives planning and implementation · 4 frameworksOCF-173 · Resource documentation · 4 frameworksOCF-177 · Human resources · 4 frameworksOCF-2 · Technical Requirements · 4 frameworksOCF-3 · Risk Identification Policy · 4 frameworksOCF-32 · Responsible AI Stewardship · 4 frameworksOCF-48 · Developer Incident Reporting · 4 frameworksOCF-5 · Ethical Requirements · 4 frameworksOCF-72 · Leadership buy-in · 4 frameworksOCF-87 · Management system scope determination · 4 frameworksOCF-88 · Management system establishment and improvement · 4 frameworksOCF-9 · User Transparency Requirements · 4 frameworksMCF-121 · Minimal use of sensitive data · 3 frameworksMCF-130 · Privacy Impact assesment · 3 frameworksMCF-131 · Override Mechanism · 3 frameworksMCF-133 · Deployed AI System TIX Monitoring · 3 frameworksMCF-156 · Supply Chain and Integration Support · 3 frameworksMCF-157 · AI Impact Asssessment · 3 frameworksMCF-162 · Transparent Interaction with Natural Persons · 3 frameworksMCF-171 · Transparent Automated Decision-Making · 3 frameworksMCF-180 · Ensuring Intended Use · 3 frameworksMCF-185 · AI System Reclassification at and after Deployment · 3 frameworksMCF-192 · Supply Chain Conformity Evidence · 3 frameworksMCF-205 · Advanced Model Evaluation · 3 frameworksMCF-233 · Suppliers · 3 frameworksMCF-235 · Policies for information security · 3 frameworksMCF-236 · Information security roles and responsibilities · 3 frameworksMCF-239 · Contact with authorities · 3 frameworksMCF-241 · Threat intelligence · 3 frameworksMCF-244 · Acceptable use of information and other associated assets · 3 frameworksMCF-246 · Classification of information · 3 frameworksMCF-251 · Authentication information · 3 frameworksMCF-257 · Information security for use of cloud services · 3 frameworksMCF-261 · Learning from information security incidents · 3 frameworksMCF-27 · Data Access Control · 3 frameworksMCF-29 · Data Statistical Properties · 3 frameworksMCF-295 · Privileged access rights · 3 frameworksMCF-296 · Information access restriction · 3 frameworksMCF-300 · Protection against malware · 3 frameworksMCF-305 · Data leakage prevention · 3 frameworksMCF-31 · Data Labeling · 3 frameworksMCF-317 · Use of cryptography · 3 frameworksMCF-318 · Secure development life cycle · 3 frameworksMCF-320 · Secure system architecture and engineering principles · 3 frameworksMCF-321 · Secure coding · 3 frameworksMCF-328 · Constrain model behavior · 3 frameworksMCF-331 · Enforce privilege control and least privilege access · 3 frameworksMCF-332 · Require human approval for high-risk actions · 3 frameworksMCF-334 · Conduct adversarial testing and attack simulations · 3 frameworksMCF-34 · Data Split Strategy · 3 frameworksMCF-349 · Conduct AI Red Teaming for third-party models · 3 frameworksMCF-350 · Software and component bill of materials · 3 frameworksMCF-354 · Apply anomaly detection and robustness tests · 3 frameworksMCF-355 · Patch outdated components and APIs · 3 frameworksMCF-357 · Track data provenance with ML-BOM tools · 3 frameworksMCF-362 · Apply data version control to track manipulation · 3 frameworksMCF-378 · Execute extensions in user's context · 3 frameworksMCF-379 · Require user approval · 3 frameworksMCF-380 · Complete mediation · 3 frameworksMCF-39 · Performance Metrics · 3 frameworksMCF-394 · Risk Communication · 3 frameworksMCF-396 · User Interface Design · 3 frameworksMCF-40 · Model Explainability · 3 frameworksMCF-403 · Sandbox Techniques · 3 frameworksMCF-404 · Comprehensive Logging, Monitoring and Anomaly Detection · 3 frameworksMCF-407 · Limit Queued Actions and Scale Robustly · 3 frameworksMCF-410 · Access Controls · 3 frameworksMCF-419 · Automated Decision-Making Safeguards · 3 frameworksMCF-420 · Explainability Controls · 3 frameworksMCF-430 · Penetration Testing · 3 frameworksMCF-432 · Resilience and Availability · 3 frameworksMCF-443 · Privacy impact assessment · 3 frameworksMCF-51 · Model Poisoning · 3 frameworksMCF-60 · Model Pen Testing · 3 frameworksMCF-73 · Log Storage by Provider · 3 frameworksMCF-77 · Re-evaluation Procedure · 3 frameworksMCF-78 · Evaluate Operating Results · 3 frameworksMCF-84 · Retirement Data Deletion · 3 frameworksOCF-105 · Data resources · 3 frameworksOCF-119 · Effectiveness documentation · 3 frameworksOCF-13 · Existence of a Quality Management System · 3 frameworksOCF-14 · Existence of a AI Catalogue · 3 frameworksOCF-154 · AI roles and responsibilities · 3 frameworksOCF-174 · Data resources · 3 frameworksOCF-175 · Tooling resources · 3 frameworksOCF-176 · System and computing resources · 3 frameworksOCF-189 · Processor Management System · 3 frameworksOCF-213 · Processor Continuous Monitoring · 3 frameworksOCF-28 · Diversity and expertise across AI lifecycle · 3 frameworksOCF-334 · Communication methods · 3 frameworksOCF-4 · Risk Mitigation Policy · 3 frameworksOCF-41 · Data Protection Officer · 3 frameworksOCF-49 · Deployer Monitoring and Incident Handling · 3 frameworksOCF-68 · Internal Audit · 3 frameworksOCF-7 · Regulatory Requirements · 3 frameworksOCF-70 · Organisational Performance Improvement · 3 frameworksOCF-8 · Human Oversight Developer Requirements · 3 frameworksOCF-81 · Context assessment · 3 frameworksOCF-82 · Climate change relevance · 3 frameworksOCF-85 · Interested parties identification · 3 frameworksOCF-93 · AI roles and responsibilities · 3 frameworksMCF-116 · Developer-Operator Collaboration · 2 frameworksMCF-117 · Principles Tradeoff Disclosure · 2 frameworksMCF-125 · Impersonation disclosure · 2 frameworksMCF-151 · System, and Operator Registration · 2 frameworksMCF-152 · Accessibility · 2 frameworksMCF-153 · Disclosing Contact Information · 2 frameworksMCF-155 · AI System Reclassification in Development · 2 frameworksMCF-159 · Conformity Assessment · 2 frameworksMCF-160 · EU Declaration of Conformity and Conformity-Assessment Outputs · 2 frameworksMCF-161 · Conformity Marking · 2 frameworksMCF-163 · Computer-Generated Works Marking · 2 frameworksMCF-168 · Deployer Registration · 2 frameworksMCF-173 · Transparency of Biometric Categorisation · 2 frameworksMCF-174 · Transparency of Emotion Recognition · 2 frameworksMCF-175 · Transparency of Deepfakes · 2 frameworksMCF-176 · Transparency of Computer-Generated Text · 2 frameworksMCF-178 · Human Oversight Features and Tools · 2 frameworksMCF-179 · Human Oversight Deployer Requirements · 2 frameworksMCF-18 · Project Resources · 2 frameworksMCF-187 · Objectives to Processes Mapping · 2 frameworksMCF-189 · Communication Activities · 2 frameworksMCF-206 · Systemic Risks Assessment and Mitigation · 2 frameworksMCF-207 · Advanced Model Security · 2 frameworksMCF-208 · AI risk assessment and documentation · 2 frameworksMCF-210 · Documentation of AI system impact assessments · 2 frameworksMCF-213 · AI system requirements and specification · 2 frameworksMCF-215 · AI system verification and validation · 2 frameworksMCF-221 · Acquisition of data · 2 frameworksMCF-223 · Data provenance · 2 frameworksMCF-237 · Segregation of duties · 2 frameworksMCF-245 · Return of assets · 2 frameworksMCF-247 · Labelling of information · 2 frameworksMCF-271 · Documented operating procedures · 2 frameworksMCF-272 · Screening · 2 frameworksMCF-273 · Terms and conditions of employment · 2 frameworksMCF-274 · Information security awareness, education and training · 2 frameworksMCF-275 · Disciplinary process · 2 frameworksMCF-276 · Responsibilities after termination or change of employment · 2 frameworksMCF-290 · Supporting utilities · 2 frameworksMCF-293 · Secure disposal or re-use of equipment · 2 frameworksMCF-294 · User end point devices · 2 frameworksMCF-297 · Access to source code · 2 frameworksMCF-303 · Information deletion · 2 frameworksMCF-313 · Networks security · 2 frameworksMCF-314 · Security of network services · 2 frameworksMCF-315 · Segregation of networks · 2 frameworksMCF-316 · Web filtering · 2 frameworksMCF-323 · Outsourced development · 2 frameworksMCF-324 · Separation of development, test and production environments · 2 frameworksMCF-333 · Segregate and identify external content · 2 frameworksMCF-335 · Integrate Data Sanitization Techniques · 2 frameworksMCF-347 · Vet data suppliers and monitor security posture · 2 frameworksMCF-348 · Apply OWASP A06:2021 guidance to components · 2 frameworksMCF-351 · Audit AI license usage with BOM and tooling · 2 frameworksMCF-353 · Monitor collaborative development environments · 2 frameworksMCF-356 · Encrypt AI edge models with attestation APIs · 2 frameworksMCF-359 · Use sandboxing and anomaly filters for data · 2 frameworksMCF-363 · Use vector databases for user-supplied data · 2 frameworksMCF-364 · Test robustness with red teaming and FL · 2 frameworksMCF-367 · Adopt zero-trust and validate LLM outputs · 2 frameworksMCF-368 · Apply OWASP ASVS input validation and sanitization · 2 frameworksMCF-369 · Encode LLM output to prevent code execution · 2 frameworksMCF-370 · Use context-aware encoding for output destinations · 2 frameworksMCF-371 · Use parameterized queries for database interaction · 2 frameworksMCF-372 · Apply strict CSP to mitigate XSS from LLM output · 2 frameworksMCF-373 · Log and monitor for exploitation patterns in output · 2 frameworksMCF-374 · Minimize extensions · 2 frameworksMCF-375 · Minimize extension functionality · 2 frameworksMCF-376 · Avoid open-ended extensions · 2 frameworksMCF-377 · Minimize extension permissions · 2 frameworksMCF-381 · Sanitise LLM inputs and outputs · 2 frameworksMCF-386 · Permission and access control · 2 frameworksMCF-387 · Data validation & source authentication · 2 frameworksMCF-389 · Monitoring and Logging · 2 frameworksMCF-392 · Cross-Verification and Human Oversight · 2 frameworksMCF-393 · Automatic Validation Mechanisms · 2 frameworksMCF-397 · Training and Education · 2 frameworksMCF-399 · Limit Exposure of Logits and Logprobs · 2 frameworksMCF-401 · Resource Allocation Management · 2 frameworksMCF-402 · Timeouts and Throttling · 2 frameworksMCF-406 · Graceful Degradation · 2 frameworksMCF-41 · Model Interpretability · 2 frameworksMCF-411 · Centralized ML Model Inventory · 2 frameworksMCF-412 · Automated MLOps Deployment · 2 frameworksMCF-413 · Data Subject Access Portal · 2 frameworksMCF-414 · Data Rectification Interface · 2 frameworksMCF-415 · Data Erasure System · 2 frameworksMCF-416 · Processing Restriction Controls · 2 frameworksMCF-417 · Data Portability Export · 2 frameworksMCF-418 · Objection Processing System · 2 frameworksMCF-421 · Privacy by Design Architecture · 2 frameworksMCF-422 · Privacy by Default Configuration · 2 frameworksMCF-424 · Encryption at Rest · 2 frameworksMCF-425 · Encryption in Transit · 2 frameworksMCF-426 · Pseudonymization Implementation · 2 frameworksMCF-427 · Access Control System · 2 frameworksMCF-429 · Security Monitoring · 2 frameworksMCF-433 · Backup and Recovery · 2 frameworksMCF-435 · Logging & Audit Trail Integrity · 2 frameworksMCF-437 · Automated Decision Fairness Assessment · 2 frameworksMCF-438 · Privacy risk assessment and documentation · 2 frameworksMCF-439 · Identify and document purpose · 2 frameworksMCF-440 · Identify lawful basis · 2 frameworksMCF-441 · Determining when and how to obtain consent · 2 frameworksMCF-442 · Obtain and record consent · 2 frameworksMCF-447 · Determining and fulfilling obligations to PII principals · 2 frameworksMCF-448 · Determining information for PII principals · 2 frameworksMCF-449 · Providing information to PII principals · 2 frameworksMCF-45 · Bias Feedback Loops · 2 frameworksMCF-450 · Providing mechanism to modify or withdraw consent · 2 frameworksMCF-455 · Handling requests · 2 frameworksMCF-457 · Limit collection · 2 frameworksMCF-458 · Limit processing · 2 frameworksMCF-459 · Accuracy and quality · 2 frameworksMCF-46 · Model Retraining Conditions · 2 frameworksMCF-460 · PII minimization objectives · 2 frameworksMCF-461 · PII de-identification and deletion at the end of processing · 2 frameworksMCF-463 · Retention · 2 frameworksMCF-466 · Identify basis for PII transfer between jurisdictions · 2 frameworksMCF-467 · Countries and international organizations to which PII can be transferred · 2 frameworksMCF-468 · Records of transfer of PII · 2 frameworksMCF-50 · Model Tampering · 2 frameworksMCF-517 · Intent binding and drift detection · 2 frameworksMCF-518 · Tool invocation policy gate · 2 frameworksMCF-519 · Agent identities and delegation controls · 2 frameworksMCF-52 · Model Adversarial Attack Prevention · 2 frameworksMCF-520 · Attested registries and signed descriptors · 2 frameworksMCF-521 · Emergency revocation and quarantine · 2 frameworksMCF-522 · Secure inter-agent communication and discovery · 2 frameworksMCF-523 · Safe code execution pipeline · 2 frameworksMCF-524 · Memory governance and rollback · 2 frameworksMCF-525 · Blast-radius limits and circuit breakers · 2 frameworksMCF-526 · Trust-aware approval UX · 2 frameworksMCF-623 · Product and AI system version control and substantial-modification review · 2 frameworksMCF-624 · Risk acceptability criteria · 2 frameworksMCF-633 · Risk evaluation against acceptability criteria · 2 frameworksMCF-642 · Execute AI incident containment, remediation, and cease-use response · 2 frameworksMCF-669 · Retirement and end-of-support communication to deployers and users · 2 frameworksMCF-70 · Deployment Hardware Monitoring · 2 frameworksMCF-79 · Objectives Maintenance · 2 frameworksMCF-80 · Requirements Maintenance · 2 frameworksMCF-82 · Retirement Decision · 2 frameworksMCF-83 · Retirement Replacement · 2 frameworksMCF-85 · Retirement Data Retention · 2 frameworksOCF-15 · External Audit · 2 frameworksOCF-16 · Public Audit Release · 2 frameworksOCF-167 · Monitoring and measurement assignees · 2 frameworksOCF-168 · Alignment with other organizational policies · 2 frameworksOCF-169 · Review of the management system policy · 2 frameworksOCF-17 · Decision Challenge empowerment · 2 frameworksOCF-178 · Information Audit Process · 2 frameworksOCF-181 · Retention and Deletion Schedule · 2 frameworksOCF-184 · Special Categories Protection Framework · 2 frameworksOCF-187 · Accountability Framework · 2 frameworksOCF-190 · Records of Processing Register · 2 frameworksOCF-191 · DPO Designation and Independence · 2 frameworksOCF-193 · Breach Response Process · 2 frameworksOCF-199 · Contractual Transfer Safeguards · 2 frameworksOCF-20 · Value Influence Consent · 2 frameworksOCF-201 · Adequacy Monitoring · 2 frameworksOCF-202 · Derogation Documentation · 2 frameworksOCF-203 · Supervisory Authority Interface · 2 frameworksOCF-205 · Cross-Border Processing Register · 2 frameworksOCF-21 · Easy Access to Explanation · 2 frameworksOCF-210 · Sector-Specific Compliance · 2 frameworksOCF-218 · Processor Exit & Data Return · 2 frameworksOCF-219 · PII Role Determination · 2 frameworksOCF-234 · Privacy Policy Establishment · 2 frameworksOCF-252 · Secure acquisition, development, maintenance, and vulnerability governance · 2 frameworksOCF-26 · Safety Standard Cooperation · 2 frameworksOCF-27 · Impartiality in Significant Decisions · 2 frameworksOCF-29 · Consultation with decision subjects · 2 frameworksOCF-303 · Incident handling governance for in-scope services · 2 frameworksOCF-31 · Stakeholder Engagement · 2 frameworksOCF-321 · Regulatory compliance strategy · 2 frameworksOCF-329 · Authority information provision process · 2 frameworksOCF-336 · Risk owner identification · 2 frameworksOCF-34 · Opt-In Nudging Policy · 2 frameworksOCF-35 · Protection for Vulnerable Populations · 2 frameworksOCF-357 · Set data quality directives for AI · 2 frameworksOCF-36 · Training Against AI Influence · 2 frameworksOCF-371 · Non-compliance detection and market corrective action · 2 frameworksOCF-39 · Feedback Mechanisms on Rights Infringement · 2 frameworksOCF-42 · Safe Data Sharing Mechanisms · 2 frameworksOCF-45 · Deployer Human Oversight Policy · 2 frameworksOCF-46 · Conformity Assessment Policy · 2 frameworksOCF-51 · Deployer Transparency Policy · 2 frameworksOCF-54 · Context and Role · 2 frameworksOCF-55 · Organisational AI Requirements · 2 frameworksOCF-56 · Organisation-Wide Requirements Maintainance · 2 frameworksOCF-57 · Management System Establishment · 2 frameworksOCF-58 · Organisational AI Objectives · 2 frameworksOCF-59 · AI Objectives Maintenance · 2 frameworksOCF-6 · Legal Requirements · 2 frameworksOCF-60 · AI Policy Establishment · 2 frameworksOCF-61 · AI Policy Review · 2 frameworksOCF-62 · Change Management Process · 2 frameworksOCF-63 · Communication Strategy · 2 frameworksOCF-64 · Reporting of Concerns · 2 frameworksOCF-66 · Documented Information Management · 2 frameworksOCF-67 · Organisation Performance Monitoring · 2 frameworksOCF-73 · IPR Compliance · 2 frameworksMCF-115 · Carbon Impact requirements · 1 frameworkMCF-118 · Careful Design for High-Impact Systems · 1 frameworkMCF-119 · Smaller Models · 1 frameworkMCF-120 · Carbon Awareness in Operational parameters · 1 frameworkMCF-122 · Prevention Against Dual-Case Use · 1 frameworkMCF-123 · Equality of treatment · 1 frameworkMCF-124 · System accesibility · 1 frameworkMCF-126 · Impact Indices Development · 1 frameworkMCF-127 · Human Rights Due Diligence · 1 frameworkMCF-128 · Evaluation of Nudging Systems · 1 frameworkMCF-129 · Norm Conformity Metrics · 1 frameworkMCF-137 · Adversarial Attack Monitoring · 1 frameworkMCF-142 · Limitation and Capability Disclosure · 1 frameworkMCF-143 · Subtle Data Leakage · 1 frameworkMCF-144 · Model Inversion Defense Mechanisms · 1 frameworkMCF-147 · Fact-Checking Integration · 1 frameworkMCF-148 · Output Plausibility Monitoring · 1 frameworkMCF-150 · AI System Classification · 1 frameworkMCF-154 · Choice for Handling Sectoral Requirements · 1 frameworkMCF-166 · Log Storage by Deployer · 1 frameworkMCF-169 · Use Authorisation · 1 frameworkMCF-170 · Use Reporting · 1 frameworkMCF-172 · Explanation of Automated Decisions · 1 frameworkMCF-177 · Appointing Local Representative · 1 frameworkMCF-181 · Transparency Design Choices and Measures · 1 frameworkMCF-186 · Roles and Responsiblities · 1 frameworkMCF-188 · Human Resources Competence · 1 frameworkMCF-191 · AI System Classification Exemption · 1 frameworkMCF-193 · Storage and Transport Conditions · 1 frameworkMCF-194 · Obtaining Representative Mandate · 1 frameworkMCF-195 · Maintaining Representative Mandate · 1 frameworkMCF-196 · Modification Assistance · 1 frameworkMCF-197 · Integration Assistance · 1 frameworkMCF-198 · Prohibited AI Practices · 1 frameworkMCF-199 · AI Model Classification · 1 frameworkMCF-200 · Training Data Summary · 1 frameworkMCF-201 · Legal Compliance Strategy · 1 frameworkMCF-202 · Computational Resources Documentation · 1 frameworkMCF-203 · AI Model Classification Exemption · 1 frameworkMCF-204 · AI Model Reclassification · 1 frameworkMCF-209 · AI risk treatment implementation and review · 1 frameworkMCF-211 · Assessing AI system impact on individuals or groups of individuals · 1 frameworkMCF-212 · Assessing societal impacts of AI systems · 1 frameworkMCF-214 · Documentation of AI system design and development · 1 frameworkMCF-216 · AI system deployment · 1 frameworkMCF-217 · AI system operation and monitoring · 1 frameworkMCF-218 · AI system technical documentation · 1 frameworkMCF-219 · AI system recording of event logs · 1 frameworkMCF-220 · Data for development and enhancement of AI system · 1 frameworkMCF-222 · Quality of data for AI systems · 1 frameworkMCF-224 · Data preparation · 1 frameworkMCF-225 · System documentation and information for users · 1 frameworkMCF-226 · External reporting · 1 frameworkMCF-227 · Communication of incidents · 1 frameworkMCF-228 · Information for interested parties · 1 frameworkMCF-229 · Processes for responsible use of AI systems · 1 frameworkMCF-230 · Objectives for responsible use of AI system · 1 frameworkMCF-231 · Intended use of the AI system · 1 frameworkMCF-238 · Management responsibilities · 1 frameworkMCF-240 · Contact with special interest groups · 1 frameworkMCF-265 · Legal, statutory, regulatory and contractual requirements · 1 frameworkMCF-266 · Intellectual property rights · 1 frameworkMCF-268 · Privacy and protection of personal identifiable information (PII) · 1 frameworkMCF-277 · Confidentiality or non-disclosure agreements · 1 frameworkMCF-278 · Remote working · 1 frameworkMCF-280 · Physical security perimeters · 1 frameworkMCF-281 · Physical entry · 1 frameworkMCF-282 · Securing offices, rooms and facilities · 1 frameworkMCF-283 · Physical security monitoring · 1 frameworkMCF-284 · Protecting against physical and environmental threats · 1 frameworkMCF-285 · Working in secure areas · 1 frameworkMCF-286 · Clear desk and clear screen · 1 frameworkMCF-287 · Equipment siting and protection · 1 frameworkMCF-288 · Security of assets off-premises · 1 frameworkMCF-289 · Storage media · 1 frameworkMCF-291 · Cabling security · 1 frameworkMCF-292 · Equipment maintenance · 1 frameworkMCF-304 · Data masking · 1 frameworkMCF-310 · Clock synchronization · 1 frameworkMCF-311 · Use of privileged utility programs · 1 frameworkMCF-312 · Installation of software on operational systems · 1 frameworkMCF-326 · Test information · 1 frameworkMCF-327 · Protection of information systems during audit testing · 1 frameworkMCF-329 · Define and validate expected output formats · 1 frameworkMCF-336 · Robust Input Validation · 1 frameworkMCF-338 · Restrict Data Sources · 1 frameworkMCF-339 · Utilize Federated Learning · 1 frameworkMCF-340 · Incorporate Differential Privacy · 1 frameworkMCF-341 · Educate Users on Safe LLM Usage · 1 frameworkMCF-342 · Ensure Transparency in Data Usage · 1 frameworkMCF-343 · Conceal System Preamble · 1 frameworkMCF-344 · Reference Security Misconfiguration Best Practices · 1 frameworkMCF-345 · Homomorphic Encryption · 1 frameworkMCF-346 · Tokenization and Redaction · 1 frameworkMCF-358 · Vet data vendors and validate model outputs · 1 frameworkMCF-360 · Fine-tune models with targeted datasets · 1 frameworkMCF-361 · Restrict model access with infrastructure controls · 1 frameworkMCF-365 · Monitor training loss for anomalies · 1 frameworkMCF-366 · Use RAG and grounding during inference · 1 frameworkMCF-382 · Separate Sensitive Data from System Prompts · 1 frameworkMCF-383 · Avoid Reliance on System Prompts for Strict Behavior Control · 1 frameworkMCF-384 · Implement Guardrails · 1 frameworkMCF-388 · Data review for combination & classification · 1 frameworkMCF-390 · Retrieval-Augmented Generation (RAG) · 1 frameworkMCF-391 · Model Fine-Tuning · 1 frameworkMCF-395 · Secure Coding Practices · 1 frameworkMCF-398 · Input Validation · 1 frameworkMCF-405 · Watermarking · 1 frameworkMCF-408 · Adversarial Robustness Training · 1 frameworkMCF-409 · Glitch Token Filtering · 1 frameworkMCF-423 · Automated Processing Logs · 1 frameworkMCF-428 · Vulnerability Management · 1 frameworkMCF-431 · Secure Development · 1 frameworkMCF-434 · Key Management & Rotation · 1 frameworkMCF-436 · Test and Dev Data Anonymization · 1 frameworkMCF-444 · Contracts with PII processors · 1 frameworkMCF-445 · Joint PII controller · 1 frameworkMCF-446 · Records related to processing PII · 1 frameworkMCF-451 · Providing mechanism to object to PII processing · 1 frameworkMCF-452 · Access, correction or erasure · 1 frameworkMCF-453 · PII controllers’ obligations to inform third parties · 1 frameworkMCF-454 · Providing copy of PII processed · 1 frameworkMCF-456 · Automated decision making · 1 frameworkMCF-462 · Temporary files · 1 frameworkMCF-464 · Disposal · 1 frameworkMCF-465 · PII transmission controls · 1 frameworkMCF-469 · Records of PII disclosures to third parties · 1 frameworkMCF-470 · Customer agreement · 1 frameworkMCF-471 · Organization’s purposes · 1 frameworkMCF-472 · Marketing and advertising use · 1 frameworkMCF-473 · Infringing instruction · 1 frameworkMCF-474 · Customer obligations · 1 frameworkMCF-475 · Records related to processing PII · 1 frameworkMCF-476 · Comply with obligations to PII principals · 1 frameworkMCF-477 · Temporary files · 1 frameworkMCF-478 · Return, transfer or disposal of PII · 1 frameworkMCF-479 · PII transmission controls · 1 frameworkMCF-48 · Environmental Impact of Model · 1 frameworkMCF-480 · Basis for PII transfer between jurisdictions · 1 frameworkMCF-481 · Countries and international organizations to which PII can be transferred · 1 frameworkMCF-482 · Records of PII disclosures to third parties · 1 frameworkMCF-483 · Notification of PII disclosure requests · 1 frameworkMCF-484 · Legally binding PII disclosures · 1 frameworkMCF-485 · Disclosure of subcontractors used to process PII · 1 frameworkMCF-486 · Engagement of a subcontractor to process PII · 1 frameworkMCF-487 · Change of subcontractor to process PII · 1 frameworkMCF-488 · Policies for information security · 1 frameworkMCF-489 · Information security roles and responsibilities · 1 frameworkMCF-490 · Classification of information · 1 frameworkMCF-491 · Labelling of information · 1 frameworkMCF-492 · Information transfer · 1 frameworkMCF-493 · Identity management · 1 frameworkMCF-494 · Access rights · 1 frameworkMCF-495 · Addressing information security within supplier agreements · 1 frameworkMCF-496 · Information security incident management planning and preparation · 1 frameworkMCF-497 · Response to information security incidents · 1 frameworkMCF-498 · Legal, statutory, regulatory and contractual requirements · 1 frameworkMCF-499 · Protection of records · 1 frameworkMCF-500 · Independent review of information security · 1 frameworkMCF-501 · Compliance with policies, rules and standards for information security · 1 frameworkMCF-502 · Information security awareness, education and training · 1 frameworkMCF-503 · Confidentiality or non-disclosure agreements · 1 frameworkMCF-504 · Clear desk and clear screen · 1 frameworkMCF-505 · Storage media · 1 frameworkMCF-506 · Secure disposal or re-use of equipment · 1 frameworkMCF-507 · User endpoint devices · 1 frameworkMCF-508 · Secure authentication · 1 frameworkMCF-509 · Information backup · 1 frameworkMCF-510 · Logging · 1 frameworkMCF-511 · Use of cryptography · 1 frameworkMCF-512 · Secure development life cycle · 1 frameworkMCF-513 · Application security requirements · 1 frameworkMCF-514 · Secure system architecture and engineering principles · 1 frameworkMCF-515 · Outsourced development · 1 frameworkMCF-516 · Test information · 1 frameworkMCF-527 · Execute corrective actions for cybersecurity measure deficiencies · 1 frameworkMCF-528 · Assess AI-service incidents against NIS2 significant-incident criteria · 1 frameworkMCF-529 · Communicate significant incidents and threats to affected recipients · 1 frameworkMCF-530 · Submit NIS2 early warning within 24 hours · 1 frameworkMCF-531 · Submit NIS2 incident notification within 72 hours · 1 frameworkMCF-532 · Prepare NIS2 intermediate, final, and progress reports · 1 frameworkMCF-533 · Apply implementing-regulation significant-incident criteria to AI-service incidents · 1 frameworkMCF-534 · Submit trust-service incident notification within 24 hours · 1 frameworkMCF-535 · Maintain DORA service dependency and function mapping · 1 frameworkMCF-536 · Apply DORA-specific detection thresholds and escalation logic · 1 frameworkMCF-537 · Apply DORA major-incident classification logic at service level · 1 frameworkMCF-538 · Prepare staged DORA incident-reporting evidence at service level · 1 frameworkMCF-539 · Execute DORA digital operational resilience testing · 1 frameworkMCF-540 · Execute DORA TLPT participation and remediation · 1 frameworkMCF-541 · Execute DORA ICT third-party due diligence and concentration-risk review · 1 frameworkMCF-542 · Execute DORA contractual safeguards and exit-support measures · 1 frameworkMCF-543 · Maintain the DORA register-of-information evidence workflow · 1 frameworkMCF-544 · Execute DORA subcontracting assessment and flow-down review · 1 frameworkMCF-545 · Action-space and autonomy classification · 1 frameworkMCF-546 · Agentic risk-cell rubric (impact × likelihood) · 1 frameworkMCF-547 · Agent suitability gate · 1 frameworkMCF-548 · Oversight effectiveness metrics · 1 frameworkMCF-549 · Multi-agent system testing · 1 frameworkMCF-550 · Agent capability and escalation disclosure · 1 frameworkMCF-551 · Agent workflow testing and staged rollout · 1 frameworkMCF-552 · Agentic threat modelling · 1 frameworkMCF-553 · Third-party agent component transparency · 1 frameworkMCF-554 · Environmental and physical security for AI-service facilities and utilities · 1 frameworkMCF-555 · Hierarchy of risk control measures · 1 frameworkMCF-556 · Verification of risk control measures and re-analysis of introduced risks · 1 frameworkMCF-557 · Completeness of risk control review · 1 frameworkMCF-558 · Real-world conditions testing · 1 frameworkMCF-559 · Evaluation of overall residual risk · 1 frameworkMCF-560 · Post-market information review and resulting actions · 1 frameworkMCF-561 · Risk management review · 1 frameworkMCF-562 · Test plan · 1 frameworkMCF-563 · Test monitoring and test reporting · 1 frameworkMCF-564 · Residual risk evaluation · 1 frameworkMCF-565 · Pre-market and post-market information collection · 1 frameworkMCF-566 · Intended purpose documentation · 1 frameworkMCF-567 · Integration with product-realization and existing processes · 1 frameworkMCF-580 · AI cybersecurity framework definition and traceability · 1 frameworkMCF-581 · AI cybersecurity scope, context and asset inventory · 1 frameworkMCF-582 · AI-specific vulnerability identification process · 1 frameworkMCF-583 · AI-specific threat identification and scenarios · 1 frameworkMCF-584 · AI cybersecurity risk determination and acceptance · 1 frameworkMCF-585 · Data poisoning prevent/detect/respond/resolve/control measures · 1 frameworkMCF-586 · Model poisoning prevent/detect/respond/resolve/control measures · 1 frameworkMCF-587 · Adversarial examples / model evasion prevent/detect/respond/resolve/control measures · 1 frameworkMCF-588 · Confidentiality attack prevent/detect/respond/resolve/control measures · 1 frameworkMCF-589 · Model flaw prevent/detect/respond/resolve/control measures · 1 frameworkMCF-590 · AI cybersecurity test program (lifecycle triggers, attack-type coverage, acceptance criteria) · 1 frameworkMCF-591 · AI cybersecurity documentation dossier (Cl.12) and instructions for use · 1 frameworkMCF-592 · Generative AI threat coverage (prompt injection, instruction manipulation, output leakage) · 1 frameworkMCF-620 · Supplier evaluation, selection and monitoring · 1 frameworkMCF-622 · Design and development requirements control · 1 frameworkMCF-625 · Overall residual risk acceptability criteria · 1 frameworkMCF-626 · Risk management plan · 1 frameworkMCF-627 · Process for establishing and updating risk acceptability criteria · 1 frameworkMCF-628 · Risk management file · 1 frameworkMCF-629 · Reasonably foreseeable misuse identification · 1 frameworkMCF-630 · Identification of AI system characteristics related to risks · 1 frameworkMCF-631 · Hazard and risk-scenario identification · 1 frameworkMCF-632 · Risk estimation · 1 frameworkMCF-634 · Information security risk treatment implementation and review · 1 frameworkMCF-635 · Privacy risk treatment implementation and review · 1 frameworkMCF-636 · Customers · 1 frameworkMCF-637 · Assure material third-party AI dependencies affecting consumer interactions or outcomes · 1 frameworkMCF-638 · Support consumer-facing notices and challenge routes for AI-assisted interactions · 1 frameworkMCF-639 · Risk rating of the AI use case · 1 frameworkMCF-640 · Execute AI data handling and privacy controls for UAE consumer uses · 1 frameworkMCF-641 · Review deployed AI outcomes against consumer-protection expectations · 1 frameworkMCF-643 · Analyze overridden and ignored AI outputs · 1 frameworkMCF-644 · Record reference-pillar applicability and alignment for the AI system · 1 frameworkMCF-645 · Map the AI system's data flows and input/output points · 1 frameworkMCF-646 · Determine the automation level and the human role in the decision cycle · 1 frameworkMCF-647 · Verify risk-inventory completeness against a unified AI risk taxonomy · 1 frameworkMCF-648 · Characterize each risk by source, intent, timing, and origin · 1 frameworkMCF-649 · Estimate risk likelihood on the framework's four-level scale · 1 frameworkMCF-650 · Estimate risk impact on the framework's four-level scale · 1 frameworkMCF-651 · Determine risk levels via the 4x4 likelihood-impact matrix · 1 frameworkMCF-652 · Select and document a treatment strategy for each risk · 1 frameworkMCF-653 · Recompute residual risk with the initial assessment methodology · 1 frameworkMCF-654 · Analyze AI incident root causes and institutionalize the lessons · 1 frameworkMCF-655 · Record the AI system context and use boundaries · 1 frameworkMCF-656 · Define decision approval and escalation paths for the AI system · 1 frameworkMCF-657 · Maintain the AI system lifecycle record and change plan · 1 frameworkMCF-658 · Implement risk treatment plans and verify their effectiveness · 1 frameworkMCF-659 · Record the residual-risk operating decision for the AI system · 1 frameworkMCF-660 · Bias requirements, values statement, and boundaries of acceptability · 1 frameworkMCF-661 · The Bias Profile · 1 frameworkMCF-662 · Stakeholder identification and attribute reference set · 1 frameworkMCF-663 · Dataset collection-condition and proxy metadata · 1 frameworkMCF-664 · Data-to-stakeholder representativeness mapping · 1 frameworkMCF-665 · Design and output bias evaluation record · 1 frameworkMCF-666 · Ongoing bias evaluation program · 1 frameworkMCF-667 · Bias risk and impact register with owner acceptance · 1 frameworkMCF-668 · Continuous-learning change governance · 1 frameworkMCF-670 · CRA applicability, classification, and route record · 1 frameworkMCF-671 · Release without known exploitable vulnerabilities · 1 frameworkMCF-672 · Secure-by-default configuration and reset · 1 frameworkMCF-673 · Product security-update capability and delivery · 1 frameworkMCF-674 · Unauthorized-access reporting capability · 1 frameworkMCF-675 · Product data, command, software, and configuration integrity · 1 frameworkMCF-676 · Product data minimisation · 1 frameworkMCF-677 · Resource-consumption and network-externality safeguards · 1 frameworkMCF-678 · Exploitation mitigation and blast-radius reduction · 1 frameworkMCF-679 · Secure user data and settings erasure and transfer · 1 frameworkMCF-680 · Fixed-vulnerability advisory and public disclosure · 1 frameworkMCF-681 · Product vulnerability reporting contact and intake · 1 frameworkMCF-682 · Third-party component vulnerability escalation and fix sharing · 1 frameworkMCF-683 · Support-period determination and end-of-support management · 1 frameworkMCF-684 · Independent AEDT bias audit · 1 frameworkMCF-685 · Public disclosure of bias audit results · 1 frameworkMCF-686 · Pre-use notice to candidates and employees · 1 frameworkMCF-687 · AEDT data transparency disclosures · 1 frameworkMCF-688 · ADMT coverage and role determination · 1 frameworkMCF-689 · Developer ADMT transparency package · 1 frameworkMCF-690 · Developer update notices and records · 1 frameworkMCF-691 · Pre-use ADMT notice at interaction points · 1 frameworkMCF-692 · Post-adverse-outcome disclosures · 1 frameworkMCF-693 · Consumer correction and human-review handling · 1 frameworkMCF-694 · ADMT compliance records and traceability · 1 frameworkMCF-74 · Monitoring of Environmental Impact · 1 frameworkOCF-100 · Objectives for responsible development of AI system · 1 frameworkOCF-101 · Processes for responsible AI system design and development · 1 frameworkOCF-102 · Objectives for responsible use of AI system · 1 frameworkOCF-104 · Resource documentation · 1 frameworkOCF-106 · Tooling resources · 1 frameworkOCF-107 · System and computing resources · 1 frameworkOCF-108 · Human resources · 1 frameworkOCF-153 · Policies related to AI · 1 frameworkOCF-155 · Reporting of concerns · 1 frameworkOCF-156 · AI resource documentation · 1 frameworkOCF-157 · Data resources · 1 frameworkOCF-158 · Tooling resources · 1 frameworkOCF-159 · System and computing resources · 1 frameworkOCF-160 · Human resources · 1 frameworkOCF-161 · AI system impact assessment process · 1 frameworkOCF-162 · Documentation of AI system impact assessments · 1 frameworkOCF-163 · Assessing AI system impact on individuals or groups of individuals · 1 frameworkOCF-164 · Assessing societal impacts of AI systems · 1 frameworkOCF-165 · Objectives for responsible development of AI system · 1 frameworkOCF-166 · Processes for responsible AI system design and development · 1 frameworkOCF-179 · Processing Principles Implementation · 1 frameworkOCF-18 · Auto-Investigation Trigger · 1 frameworkOCF-180 · Data Accuracy Maintenance · 1 frameworkOCF-182 · Legal Basis Assessment Framework · 1 frameworkOCF-183 · Consent Management Process · 1 frameworkOCF-185 · Criminal Data Processing Controls · 1 frameworkOCF-186 · Transparency Framework · 1 frameworkOCF-188 · Joint Controller Agreements · 1 frameworkOCF-19 · Critical Decision Opt-out · 1 frameworkOCF-192 · Codes and Certification Management · 1 frameworkOCF-194 · DPIA Methodology · 1 frameworkOCF-195 · DPIA Triggers and Review · 1 frameworkOCF-196 · Risk Scoring Framework · 1 frameworkOCF-197 · Prior Consultation Process · 1 frameworkOCF-198 · Transfer Impact Assessment · 1 frameworkOCF-200 · Binding Corporate Rules · 1 frameworkOCF-204 · Lead Authority Determination · 1 frameworkOCF-206 · Complaint Handling Process · 1 frameworkOCF-207 · Fine Risk Register · 1 frameworkOCF-208 · Liability and Insurance Framework · 1 frameworkOCF-209 · Employee Training Program · 1 frameworkOCF-211 · Data Classification Program · 1 frameworkOCF-212 · Secure Data Disposal · 1 frameworkOCF-214 · Children Age Verification · 1 frameworkOCF-215 · Legitimate Interests Assessment · 1 frameworkOCF-216 · Retention Exception Workflow · 1 frameworkOCF-217 · Change Management Privacy Review · 1 frameworkOCF-22 · Public Sector Source Code Availability · 1 frameworkOCF-220 · Climate Change Relevance Assessment · 1 frameworkOCF-221 · Privacy Context Enrichment · 1 frameworkOCF-222 · Role-aware Stakeholder Identification · 1 frameworkOCF-223 · Addressed Requirements Determination · 1 frameworkOCF-224 · Standards Conformance Expectations · 1 frameworkOCF-23 · Insurance for Damages · 1 frameworkOCF-235 · Privacy Policy Communication & Availability · 1 frameworkOCF-24 · Service and Honesty · 1 frameworkOCF-240 · Privacy Objectives Establishment · 1 frameworkOCF-241 · Planning to Achieve Privacy Objectives · 1 frameworkOCF-242 · PIMS Resourcing & Provisioning · 1 frameworkOCF-243 · PIMS Resource Adequacy Review · 1 frameworkOCF-244 · Determine NIS2 scope and entity classification · 1 frameworkOCF-245 · Manage Article 3 entity-list submissions and updates · 1 frameworkOCF-246 · Assess sector-act equivalence and residual NIS2 duties · 1 frameworkOCF-247 · Management-body approval and oversight of cybersecurity measures · 1 frameworkOCF-248 · Management-body cybersecurity training and competence tracking · 1 frameworkOCF-249 · Incident handling governance for in-scope services · 1 frameworkOCF-25 · Lethal Autonomous Weapons Control · 1 frameworkOCF-250 · Business continuity, backup, disaster recovery, crisis, and physical/environmental security governance · 1 frameworkOCF-251 · Direct-supplier and service-provider security governance · 1 frameworkOCF-253 · Cyber hygiene baseline and cybersecurity training governance · 1 frameworkOCF-254 · Cryptography and encryption governance · 1 frameworkOCF-255 · HR security, access-control, and asset governance · 1 frameworkOCF-256 · Authentication and secured communication governance · 1 frameworkOCF-257 · Determine implementing-act applicability and resulting obligations · 1 frameworkOCF-258 · Govern significant-incident qualification under NIS2 · 1 frameworkOCF-259 · Govern recipient incident and cyber-threat communication · 1 frameworkOCF-260 · Govern 24-hour early warning submissions · 1 frameworkOCF-261 · Govern 72-hour incident notifications · 1 frameworkOCF-262 · Govern intermediate, final, and progress reporting under NIS2 · 1 frameworkOCF-263 · Determine jurisdiction and manage EU representative obligations · 1 frameworkOCF-264 · Manage Article 27 registry submissions and updates · 1 frameworkOCF-265 · Govern domain registration data accuracy, publication, and lawful disclosure · 1 frameworkOCF-266 · Notify authorities of information-sharing arrangement changes · 1 frameworkOCF-267 · Govern voluntary NIS2 notifications · 1 frameworkOCF-268 · Manage supervisory cooperation and enforcement response · 1 frameworkOCF-269 · Determine DORA scope and entity category · 1 frameworkOCF-270 · Assess proportionality and simplified-framework eligibility under DORA · 1 frameworkOCF-271 · Govern DORA management-body approval and oversight · 1 frameworkOCF-272 · Maintain DORA management-body training and competence · 1 frameworkOCF-273 · Govern the DORA ICT risk-management framework · 1 frameworkOCF-274 · Govern independent DORA control review and assurance · 1 frameworkOCF-275 · Govern ICT capacity availability and resilience under DORA · 1 frameworkOCF-276 · Maintain DORA inventories and dependency records · 1 frameworkOCF-277 · Govern ICT risk identification and vulnerability management under DORA · 1 frameworkOCF-278 · Govern ICT protection and prevention under DORA · 1 frameworkOCF-279 · Govern ICT detection and alerting under DORA · 1 frameworkOCF-280 · Govern ICT response recovery and crisis management under DORA · 1 frameworkOCF-281 · Govern backup restoration and recovery objectives under DORA · 1 frameworkOCF-282 · Govern post-incident learning and resilience improvement under DORA · 1 frameworkOCF-283 · Govern crisis communication and external disclosure under DORA · 1 frameworkOCF-284 · Govern the DORA ICT-related incident management process · 1 frameworkOCF-285 · Govern DORA major-incident classification and assessment · 1 frameworkOCF-286 · Govern staged DORA major-incident reporting · 1 frameworkOCF-287 · Govern voluntary significant cyber threat notifications under DORA · 1 frameworkOCF-288 · Maintain DORA annual incident cost and loss estimation capability · 1 frameworkOCF-289 · Govern DORA payment-related incident reporting readiness · 1 frameworkOCF-290 · Govern DORA digital operational resilience testing · 1 frameworkOCF-291 · Scope and prepare DORA threat-led penetration testing · 1 frameworkOCF-292 · Govern ICT third-party risk strategy and lifecycle under DORA · 1 frameworkOCF-293 · Manage DORA key contractual provisions for ICT third-party services · 1 frameworkOCF-294 · Maintain the DORA register of information and reporting readiness · 1 frameworkOCF-295 · Govern DORA subcontracting of ICT services supporting critical or important functions · 1 frameworkOCF-296 · Govern Article 45 cyber-threat information-sharing participation · 1 frameworkOCF-297 · Human tradecraft continuity · 1 frameworkOCF-298 · Central agent catalogue and identity reconciliation · 1 frameworkOCF-299 · Agentic oversight and user training · 1 frameworkOCF-30 · Society Consultation · 1 frameworkOCF-300 · Govern general ICT third-party risk management and concentration risk under DORA · 1 frameworkOCF-301 · Govern DORA ICT security awareness, resilience training, and technology monitoring · 1 frameworkOCF-302 · Execute corrective action for self-identified NIS2 cybersecurity measure non-compliance · 1 frameworkOCF-304 · Direct-supplier and service-provider security governance · 1 frameworkOCF-305 · Govern recipient incident and cyber-threat communication · 1 frameworkOCF-306 · Govern DORA TLPT testers and test execution · 1 frameworkOCF-307 · Close and remediate DORA threat-led penetration testing · 1 frameworkOCF-322 · Serious incident reporting procedure and timelines · 1 frameworkOCF-323 · Resources for the quality management system · 1 frameworkOCF-324 · Regulatory and risk accountability roles · 1 frameworkOCF-325 · QMS-functioning risk planning · 1 frameworkOCF-326 · QMS management review and change control · 1 frameworkOCF-327 · Quality objectives and planning · 1 frameworkOCF-328 · QMS competence determination and evidence · 1 frameworkOCF-33 · Wellbeing Metrics Learning · 1 frameworkOCF-330 · Competence for fundamental-rights risk management · 1 frameworkOCF-331 · Top-management review of the risk management system · 1 frameworkOCF-332 · Risk management policy for risk acceptability criteria · 1 frameworkOCF-333 · Information security policy establishment · 1 frameworkOCF-335 · Objectives, feedback, and risk status review inputs · 1 frameworkOCF-337 · Information security programme documentation · 1 frameworkOCF-338 · AI risk assessment alignment with AI policy and objectives · 1 frameworkOCF-339 · AI management system documentation · 1 frameworkOCF-340 · Determine UAE Consumer AI scope and in-scope AI uses · 1 frameworkOCF-341 · Govern UAE Consumer AI accountability and management oversight · 1 frameworkOCF-342 · Maintain and risk-rate the AI and ML inventory · 1 frameworkOCF-343 · Assess and govern consumer-protection impacts of AI uses · 1 frameworkOCF-344 · Govern fairness and non-discrimination for AI uses · 1 frameworkOCF-345 · Govern transparency and explainability for UAE consumer-facing AI uses · 1 frameworkOCF-346 · Govern human oversight and escalation for UAE AI uses · 1 frameworkOCF-347 · Govern AI data handling, privacy, confidentiality, and security in the UAE context · 1 frameworkOCF-348 · Govern model validation and independent challenge for AI uses · 1 frameworkOCF-349 · Govern third-party AI dependencies in the UAE consumer context · 1 frameworkOCF-350 · Govern ongoing monitoring and outcome review for AI uses · 1 frameworkOCF-351 · Govern AI incident response, resilience, and remediation · 1 frameworkOCF-352 · Govern consumer human review, complaints, and redress for AI decisions · 1 frameworkOCF-353 · Maintain UAE AI recordkeeping and supervisory-readiness evidence · 1 frameworkOCF-354 · Assess and use AI for fraud and financial-crime detection · 1 frameworkOCF-355 · Collaborate on trustworthy AI and publish responsible-AI case studies · 1 frameworkOCF-356 · AI risk classification methodology · 1 frameworkOCF-358 · Independently review the AI model development process · 1 frameworkOCF-359 · Derive sector-specific AI controls from applicable sector requirements · 1 frameworkOCF-360 · Set AI risk documentation and register standards · 1 frameworkOCF-361 · Derive role-based AI training from system risks and treatment plans · 1 frameworkOCF-362 · Equip the internal AI policy function · 1 frameworkOCF-363 · Regulatory Instrument Watch and Readiness · 1 frameworkOCF-364 · Breach Notification Readiness · 1 frameworkOCF-365 · DPO Appointment Trigger Assessment · 1 frameworkOCF-366 · Privacy-Law Applicability Determination · 1 frameworkOCF-367 · Processor Instruction, Duration and Co-processor Governance · 1 frameworkOCF-368 · Regulatory Decision Grievance Management · 1 frameworkOCF-369 · Bias-process governance interface · 1 frameworkOCF-37 · Informed Autonomous Decision-making · 1 frameworkOCF-370 · Sensitive-attribute representation and external advocacy · 1 frameworkOCF-372 · Portfolio support-period governance · 1 frameworkOCF-373 · Component and SBOM operations · 1 frameworkOCF-374 · Security-update operations · 1 frameworkOCF-375 · Product-security testing program · 1 frameworkOCF-376 · Coordinated vulnerability disclosure governance · 1 frameworkOCF-377 · Impacted-user cybersecurity notification · 1 frameworkOCF-378 · CRA actively exploited vulnerability reporting · 1 frameworkOCF-379 · CRA reporting of severe incidents having an impact on the security of a product with digital elements · 1 frameworkOCF-38 · Norm Differentiation · 1 frameworkOCF-380 · ADMT notice and disclosure infrastructure · 1 frameworkOCF-381 · Meaningful-human-review capability · 1 frameworkOCF-382 · ADMT records program · 1 frameworkOCF-383 · ADMT liability posture and contract hygiene · 1 frameworkOCF-384 · Colorado rulemaking and codification watch · 1 frameworkOCF-40 · Understanding AI Application in Sustainability · 1 frameworkOCF-43 · Sensitive data storage within jurisdiction · 1 frameworkOCF-50 · Deployer Cooperation with Competent Authorities · 1 frameworkOCF-65 · Reporting to Stakeholders · 1 frameworkOCF-71 · Impact Assessment Process · 1 frameworkOCF-83 · AI system purpose consideration · 1 frameworkOCF-84 · AI system role determination · 1 frameworkOCF-90 · AI policy · 1 frameworkOCF-91 · Alignment with other organizational policies · 1 frameworkOCF-92 · Review of the AI policy · 1 frameworkOCF-99 · AI system impact assessment process · 1 frameworkEU AI ActCBUAE Consumer AISaudi AI Risk (SDAIA)FINMA AIMAS FEATUAE AI EthicsSingapore MGFColorado SB 26-189NYC Local Law 144ISO/IEC 42001NIST AI RMFprEN 18282EN 18286prEN 18228IEEE 7003GDPRUAE PDPLISO/IEC 27701ISO/IEC 27001NIS2DORACRAOWASP LLM Top 10OWASP Agentic Top 10Microsoft Supplier DPR
25 frameworks · 945 controls · 450 shared by 2+ · the brightest dots serve up to 10 frameworks at once
AI regulationAI standardsPrivacySecurity & resilience
10× efficiency in GRC work

AI Agents That Do the Work

Human-in-the-loop AI agents automate the heavy lifting while you stay in control. Each one runs on demand or on a schedule, so a single assessment becomes a continuous practice.

SCOUTAI assistant

Scout Assistant

Ask compliance questions in plain English. Scout knows your organization, projects, and where your evidence gaps are.

  • Understands your controls, risks, and compliance status
  • Searches your GitHub, Confluence, Google Drive for evidence
  • Watch reasoning unfold in real-time with source citations
Scout Assistant chat interface showing compliance questions and contextual answers
CTL-AGTControl assessment agent

Control Assessment Agent

Automatically evaluates control implementation and generates structured assessments with a readiness score.

Before
2–4 hours
per control
After
5 min
AI + review
  • Readiness scoring with gap identification
  • Prioritized recommendations with citations
Control Assessment Agent showing automated evaluations and gap identification
EVD-AGT

Evidence Agent

Upload documents and the agent generates metadata, summaries, and control mapping suggestions. You review before accepting.

15–30 min2 minper document
RSK-AGT

Risk Agent

Automates risk quantification using Fermi estimation. Investigates context, calculates risk values, and audits its own reasoning before delivering results.

Fermi estimationMulti-agent pipeline
Human-in-the-Loop: every AI recommendation requires human approval.

Easy Integration with your AI Stack

Connect Scout to your docs and repos. Feed operational metrics into runtime testing.

GitHub

GitHub

Code repositories

Bitbucket

Bitbucket

Code repositories

Azure

Azure

Cloud platform

AWS

AWS

Cloud platform

Google Drive

Google Drive

Document storage

Confluence

Confluence

Wiki & documentation

Jira

Jira

Project management

Snowflake

Snowflake

Data warehouse queries

Prometheus

Prometheus

Infrastructure monitoring

Datadog

Datadog

Observability platform

Langfuse

Langfuse

LLM observability

MLflow

MLflow

ML experiment tracking

Jupyter

Jupyter

Notebook analysis

Vijil

Vijil

AI security testing

Claude Console

Claude Console

Claude Code usage

Copilot Studio

Copilot Studio

Agent governance

REST API
Python SDK

Push operational metrics from CI/CD pipelines with the Python SDK. Metrics feed runtime tests that link directly to controls.

pip install modulos-client
from modulos_client.testing import log_metric

# Push a fairness metric from your CI pipeline
log_metric(
    metric_id="demographic_parity",
    value=0.92,
    project_id="loan-approval-model"
)

Runtime Tests

Verify that controls hold in production. Every test result links to the control it validates and becomes audit-ready evidence.

Metric Tests

Set pass/fail conditions on operational metrics from Prometheus, Datadog, AWS CloudWatch, and other sources. Tests run on a daily, weekly, or monthly schedule, and failures notify control owners automatically.

Threshold checksScheduled runsAuto-notification

Agent Tests

Define compliance checks in natural language, as a test objective with pass criteria, and an AI agent executes them across connected systems. Multi-step, cross-system inspections that go beyond simple thresholds, producing structured verdicts with evidence and reasoning.

Natural language testsCross-system inspectionChange-aware reports

Enterprise-Ready Security

Built for organizations with serious compliance requirements.

SOC 2 Type II

Independently audited security controls

Data Encryption

AES-256 at rest, TLS 1.3 in transit

Data Residency

EU, US, UAE, Singapore & more regions

SSO & RBAC

8 distinct roles across organization and project scope, with separation of duties enforced by default

Flexible Deployment Solutions

Choose the deployment model that fits your organization's security, compliance, and operational needs.

SaaS

Best for: SMEs and enterprises with standard cloud requirements.

Quick to deploy and easy to scale. Ideal for teams that want to move fast without managing infrastructure. Available through cloud marketplaces.

Private Cloud / VPC

Best for: Enterprises with stricter data protection needs or complex infrastructure setups.

Run Modulos in your own dedicated cloud environment for enhanced security, data control, and compliance.

Trusted by leading organizations

Modulos customers include A-ZN, SCSK, ETH, PwC, Berner Fachhochschule, Mobile Health, Serai, CertX, aDigital, JobCloud, Xayn, Beyond Gravity, Armasuisse.

A-ZN
SCSK
ETH
PwC
Berner Fachhochschule
Mobile Health
Serai
CertX

FAQ about the platform

Because someone will ask for the record: a regulator, an auditor, a customer running due diligence, or your own board. Modulos is that system of record. Every AI system is registered with an owner and a lifecycle stage, every control is mapped to the frameworks that require it, every piece of evidence stays attached to the claim it supports, and every risk carries a monetary value. When the question comes, you export the answer instead of assembling it.

See the Platform on Your Own Terms

Walk through the governance graph in a demo: how one control counts across the EU AI Act, ISO/IEC 42001, and NIST AI RMF, and where the agents hand your team hours back. Comparing vendors first? Start with the buyer's guide.