AI GRC Frameworks & Standards

The regulations, standards, and reference documents forming the backbone of a mature AI governance programme.

Frameworks & Standards Comparison

AI-specific regimes only. Dates reflect the position as of August 2026 — the EU high-risk deadline moved in July 2026.

FrameworkOriginTypeScopeIn force sinceDeadline to comply
EU AI ActEUMandatoryComprehensive risk-tiered AI regulation1 Aug 2024Transparency live 2 Aug 2026 · high-risk 2 Dec 2027 · embedded AI 2 Aug 2028
Korea AI Basic ActKoreaMandatoryHigh-impact and generative AI, extraterritorial22 Jan 2026In force now · fines deferred under grace period
Colorado ADMT ActUS · COMandatoryAutomated decisions affecting consumersSigned 14 May 20261 Jan 2027
ISO/IEC 42001IntlCertifiableAI management systems, modelled on ISO 27001Dec 2023No legal deadline — driven by customer and tender dates
NIST AI RMFUSVoluntaryRisk management: Govern, Map, Measure, ManageJan 2023No legal deadline — arrives via contract terms
UK approachUKSectoralNo AI Act; ICO, Ofcom and FCA apply existing lawNo AI-specific deadline — existing duties already apply
Singapore MAIGFSGVoluntaryModel AI governance framework2020, v2No legal deadline

Regulatory Timeline

Feb 2024

Prohibited Systems Banned

Social scoring, manipulative AI practices prohibited under EU AI Act.

Aug 2025

GPAI Model Obligations

General-purpose AI providers face transparency and documentation duties.

Aug 2026

Article 50 โ€” Transparency Live

Chatbot disclosure and AI-generated content labelling now mandatory.

Dec 2026

AI-Generated NCII Prohibitions

New prohibitions on AI-generated non-consensual intimate imagery.

Dec 2027

High-Risk AI Full Obligations

Full conformity requirements enforced (extended by Digital Omnibus).

European Union ยท 2024โ€“26

EU Artificial Intelligence Act

The world's first comprehensive AI law. Risk-tiered approach โ€” prohibited, high-risk, limited-risk, and minimal-risk AI. High-risk systems face conformity assessments, technical documentation, and post-market monitoring.

General-purpose AI models above 10ยฒโต FLOPs face additional systemic risk obligations. Fines reach โ‚ฌ35M or 7% of global turnover.

Read the EU AI Act โ†’

Key Obligations

  • Risk classification for all AI systems
  • Conformity assessments for high-risk AI
  • Technical documentation and audit trails
  • Post-market monitoring obligations
  • GPAI model transparency requirements
  • Article 50 chatbot/AI content disclosure
United States ยท 2023+

NIST AI Risk Management Framework

Voluntary but widely adopted GRC structure with four core functions: Govern, Map, Measure, and Manage. Structured approach to identifying and mitigating AI risks across the entire lifecycle.

Version 2.0 includes updated governance guidance and expanded implementation resources.

NIST AI RMF โ†’

Core Functions

  • Govern โ€” policies, roles, accountability
  • Map โ€” context, stakeholders, risk identification
  • Measure โ€” assess and track AI risks
  • Manage โ€” prioritise and respond to risks
  • Voluntary but globally referenced
International ยท 2023

ISO/IEC 42001:2023

International standard for AI Management Systems (AIMS). Certifiable, modelled on ISO 27001. Provides structural backbone for AI GRC programmes.

Demand for certification is rising as the EU AI Act references ISO standards. Particularly adopted in Europe and Asia-Pacific.

ISO/IEC 42001 โ†’

Key Elements

  • AI policy and objectives
  • AI risk assessment methodology
  • Controls for responsible AI development
  • Continuous improvement cycle (PDCA)
  • Certifiable โ€” audit-ready structure
  • Aligned with ISO 27001 annex structure
United Kingdom ยท 2023+

UK Pro-Innovation AI Approach

Principles-based, sector-led model. ICO, FCA, CMA, and Ofcom each apply existing powers to AI in their domains. The AI Safety Institute runs frontier model evaluations.

UK AI Policy โ†’

Core Principles

  • Safety, security, and robustness
  • Appropriate transparency and explainability
  • Fairness
  • Accountability and governance
  • Contestability and redress
Singapore ยท 2023+

Singapore Model AI Governance Framework

MAS and IMDA co-developed one of the world's most detailed voluntary AI governance frameworks for financial services and general use. Widely respected as a balanced, innovation-friendly model.

Singapore AI Framework โ†’

Key Features

  • Voluntary, principles-based approach
  • Internal governance structures
  • Decision-making model documentation
  • Operations management requirements
  • Stakeholder interaction guidance