127 indexed

COMPLIANCECompliance controls

127 controls across 14 compliance frameworks, grouped by framework. For cross-framework Jaccard overlap see /explore/crosswalk. Authored by Adam Lundqvist.

7 in AI ACT · 127 total

IDTitleSummary
AI_ACT-Art10Data and data governance
AI ACTpentest:medium
High-risk AI systems making use of techniques involving training of models with data shall be developed on the basis of training, validation and testing data s…
AI_ACT-Art12Record keeping
AI ACTpentest:high
High-risk AI systems shall technically allow for the automatic recording of events (logs) over the duration of the lifetime of the system. The logging capabili…
AI_ACT-Art14Human oversight
AI ACTpentest:medium
High-risk AI systems shall be designed and developed in such a way that they can be effectively overseen by natural persons during the period in which they are…
AI_ACT-Art15Accuracy, robustness and cybersecurity
AI ACTpentest:high
High-risk AI systems shall be designed and developed in such a way that they achieve an appropriate level of accuracy, robustness, and cybersecurity, and perfo…
AI_ACT-Art72Post-market monitoring by providers
AI ACTpentest:medium
Providers shall establish and document a post-market monitoring system. The post-market monitoring system shall actively and systematically collect, document a…
AI_ACT-Art73Reporting of serious incidents
AI ACTpentest:high
Providers of high-risk AI systems placed on the Union market shall report any serious incident to the market surveillance authorities of the Member States wher…
AI_ACT-Art9Risk management system
AI ACTpentest:high
A risk management system shall be established, implemented, documented and maintained in relation to high-risk AI systems. It shall consist of a continuous ite…
Sourced from EUR-Lex (DORA, NIS2, GDPR, AI Act, CRA), ISO, NIST, OWASP, CIS, PCI SSC, ENISA TIBER-EU. Curated by Adam Lundqvist, Founder at SQUR.
Compliance controls — by framework | SQUR Knowledge Base