Docs · Obligation frameworks

One evidence base, many standards

Norcaster records what your AI systems did at runtime — every decision, redaction, block, approval, provider attribution and eval run on gatewayed traffic. The same records project onto whichever framework your reviewer works from. Norcaster evidences; your auditor, certification body, regulator or counsel judges. Nothing here is a statement that an organisation meets any of these frameworks.

Every framework view below is generated from the same obligations catalogue the product renders in the Obligations Map and stamps on audit bundles, so this page cannot drift from what a reviewer sees in the workspace.

The honesty contract

Every row in every framework carries one of three tags, and the tag is decided by what is stored, never by what would be convenient to claim.

  • Runtime-evidencedA stored field backs the row and a permalink opens the exact records. No human judgment is implied.
  • Runtime + attestationStored records are the inputs; the organisation records the judgment as an attestation with an owner and a review date. Both lanes are shown side by side.
  • Requires attestationNo stored field backs the row yet. It is never lit by runtime data, and the reason is printed next to it.

Which views an organisation works from is an organisation setting (Settings → Governance frameworks): in-scope views are listed first on the Obligations Map and Audit Bundles and the primary one opens by default, while every other view stays reachable. Residency tags on providers and the organisation's residency allowlist produce suggestions with their reason; nothing is enabled automatically, and every change is recorded in the platform audit trail. The setting changes nothing about what is recorded, enforced or exported. The Evidence hub shows the reverse view — for each stored record type, every row it backs across the in-scope views, with the live record count and never a status. Each framework also states what stays outsideNorcaster's evidence scope — on the map and inside every bundle — and carries a validation status. A mapping is marked draft until an external reviewer (a certification body, auditor, or the customer's compliance function) has walked its rows; the draft sentence is printed on the map header and on every bundle until then.

Frameworks at a glance

FrameworkRegion · kindRowsRuntime / mixed / attestedStatusCatalogue
EU AI ActEU · Regulation124 / 7 / 1Norcaster's own mapping — no external validation on record2026.12
SOC 2 (TSC)US, used globally · Attestation standard (AICPA)95 / 2 / 2Norcaster's own mapping — no external validation on record2026.13
DORAEU · Regulation (financial entities)91 / 7 / 1Norcaster's own mapping — no external validation on record2026.14
NIST AI RMFUS, used globally · Voluntary framework114 / 7 / 0Norcaster's own mapping — no external validation on record2026.12
ISO/IEC 27001Global · Certifiable standard (Annex A controls)94 / 3 / 2Norcaster's own mapping — no external validation on record2026.10
ISO/IEC 42001Global · Certifiable standard (Annex A controls)112 / 8 / 1Norcaster's own mapping — no external validation on record2026.10
GDPREU / EEA · Regulation112 / 8 / 1Norcaster's own mapping — no external validation on record2026.12
HIPAAUS · Regulation (health)93 / 5 / 1Norcaster's own mapping — no external validation on record2026.11
PCI DSSGlobal (payment brands) · Industry standard (v4.0)62 / 3 / 1Norcaster's own mapping — no external validation on record2026.11

EU AI Act

EU · Regulation · Deployers and providers of AI systems with EU exposure · catalogue 2026.12 · Norcaster's own mapping — no external validation on record

An audit bundle is the evidence package for a review period — what was enforced, what was redacted, what changed, and which deployments were in scope. It does not state compliance; your advisor interprets the record.

EU AI Act Art. 12 · Logging & traceability

Runtime-evidenced

Evidence: run traces · Owner: Platform operator

EU AI Act Art. 12 · Decision / record-keeping

Runtime-evidenced

Evidence: enforcement decisions · Owner: Platform operator

Art. 10 + GDPR · Data minimisation / PII redaction

Runtime-evidenced

Evidence: redaction events · Owner: Security / DPO

Provider vs deployer · Provider / model identification

Runtime-evidenced

Evidence: provider attribution · Owner: Platform operator

EU AI Act Art. 9 · Incidents & flags

Runtime + attestation

Evidence: blocked events · Owner: Risk owner / DPO

EU AI Act Art. 26 · AI system inventory

Runtime + attestation

Evidence: register rows · Owner: Deployer / product owner

GDPR Art. 30 · Records of processing (RoPA)

Runtime + attestation

Evidence: organisation's own records · Owner: DPO

EU AI Act Art. 15 · Accuracy / robustness

Runtime + attestation

Evidence: organisation's own records · Owner: Product / ML owner

EU AI Act Art. 14 · Human oversight

Runtime + attestation

Evidence: approval-gate decisions · Owner: Compliance / ops lead

EU AI Act Art. 9 · Risk management

Runtime + attestation

Evidence: organisation's own records · Owner: Risk owner

EU AI Act Art. 11 · Technical documentation

Requires attestation

Evidence: organisation's own records · Owner: Deployer / legal

Evidence boundary · Gateway coverage / estate completeness

Runtime + attestation

Evidence: organisation's own records · Owner: Deployer / platform operator

EU AI Act readiness evidence

SOC 2 (TSC)

US, used globally · Attestation standard (AICPA) · Service organisations in a SOC 2 examination · catalogue 2026.13 · Norcaster's own mapping — no external validation on record

Scope: in-scope AI systems routed through the Norcaster gateway — evidence for the AI-runtime slice of a SOC 2 examination, not an organization-wide assessment.

A SOC 2 bundle is the evidence package for the AI-runtime slice of your SOC 2 audit period — what was enforced, what was redacted, what changed, mapped to the Trust Services Criteria your auditor samples. It is not a SOC 2 report; only a licensed CPA firm can attest.

TSC CC6.1–6.3 · Logical access controls

Requires attestation

Evidence: organisation's own records · Owner: Security / IT admin

TSC CC6.6–6.7 · System boundaries & transmission

Runtime-evidenced

Evidence: blocked events · Owner: Platform operator

TSC CC7.1–7.2 · Monitoring & anomaly detection

Runtime-evidenced

Evidence: enforcement decisions · Owner: Platform operator

TSC CC7.3–7.5 · Incident management

Runtime + attestation

Evidence: blocked events · Owner: Risk owner / ops lead

TSC CC8.1 · Change management

Runtime-evidenced

Evidence: enforcement decisions · Owner: Platform operator

TSC CC3 / CC9 · Risk assessment & vendor management

Requires attestation

Evidence: organisation's own records · Owner: Risk owner

TSC A1 · Availability

Runtime + attestation

Evidence: run traces · Owner: Platform operator

TSC PI1 · Processing integrity (AI calls)

Runtime-evidenced

Evidence: enforcement decisions, approval-gate decisions · Owner: Platform operator

TSC C1 · Confidentiality

Runtime-evidenced

Evidence: redaction events · Owner: Security / DPO

Outside Norcaster's evidence scope

  • HR and personnel controls
  • endpoint management
  • physical security
  • business continuity and disaster-recovery programs
  • organization-wide vendor management
  • the Privacy category

SOC 2 scopes an entire service organization. Norcaster is an evidence source for the AI-runtime slice; your readiness platform and auditor cover the rest.

SOC 2 runtime evidence

DORA

EU · Regulation (financial entities) · Banks, insurers, investment firms and their ICT third-party providers · catalogue 2026.14 · Norcaster's own mapping — no external validation on record

Scope: the AI-inference ICT services routed through the Norcaster gateway — evidence for the AI slice of a financial entity's DORA programme, not the entity-wide ICT estate.

A DORA bundle is the evidence package for the AI-inference ICT services in scope for a review period — what was enforced, which providers served which systems, what failed over, what changed — mapped to the DORA articles your ICT risk function and supervisor work from. It is not a register of information or an incident report; the entity determines compliance.

DORA Art. 5–6 · Governance & ICT risk-management framework

Runtime + attestation

Evidence: enforcement decisions · Owner: Management body / risk owner

DORA Art. 8 · Identification of ICT assets & dependencies

Runtime + attestation

Evidence: register rows, provider attribution · Owner: Deployer / platform operator

DORA Art. 9–10 · Protection, prevention & detection

Runtime-evidenced

Evidence: enforcement decisions, blocked events · Owner: Platform operator

DORA Art. 11 · Response & recovery

Runtime + attestation

Evidence: run traces, audited stop/resume rows · Owner: Platform operator / ops lead

DORA Art. 17–19 · ICT-related incident management & classification

Runtime + attestation

Evidence: blocked events · Owner: Risk owner / ops lead

DORA Art. 24–25 · Digital operational resilience testing

Runtime + attestation

Evidence: eval runs · Owner: Product / ML owner

DORA Art. 28(3) · Register of ICT third-party arrangements

Runtime + attestation

Evidence: provider attribution · Owner: ICT third-party risk owner

DORA Art. 29 · ICT concentration risk

Runtime + attestation

Evidence: provider attribution · Owner: ICT third-party risk owner

DORA Art. 30 · Key contractual provisions

Requires attestation

Evidence: organisation's own records · Owner: Legal / procurement

Outside Norcaster's evidence scope

  • the entity-wide ICT estate (core banking, payments, networks)
  • threat-led penetration testing (Art. 26)
  • oversight of critical ICT third-party providers (Art. 31–44)
  • payment-related incident reporting (Art. 23)
  • information-sharing arrangements (Art. 45)
  • the register of information itself and the ICT contracts it lists

DORA scopes a financial entity's entire ICT estate. Norcaster is an evidence source for the AI-inference ICT services it gateways; the entity's ICT risk function and competent authority cover the rest.

NIST AI RMF

US, used globally · Voluntary framework · Organisations aligning an AI risk programme; the reference Texas TRAIGA names · catalogue 2026.12 · Norcaster's own mapping — no external validation on record

Scope: AI systems routed through the Norcaster gateway — runtime evidence for the MEASURE and MANAGE slice of the organisation's NIST AI RMF alignment (AI RMF 1.0 with the Generative AI Profile, NIST AI 600-1), and recorded inputs to GOVERN and MAP. NIST AI RMF is voluntary; alignment is the organisation's own declaration, not a certification.

A NIST AI RMF bundle is the evidence package for the AI systems in scope for a review period — decisions, detections, redactions, approvals, provider attribution and eval runs — mapped to the MEASURE and MANAGE subcategories your AI risk programme reports against. NIST AI RMF is voluntary and has no certification; the organisation declares its own alignment.

AI RMF GOVERN 1.2–1.5 · AI policies & risk-management process

Runtime + attestation

Evidence: enforcement decisions · Owner: Risk owner / AI governance lead

AI RMF GOVERN 1.6 · AI system inventory

Runtime + attestation

Evidence: register rows · Owner: Deployer / product owner

AI RMF GOVERN 6.1–6.2 / MAP 4.2 · Third-party AI risk & components

Runtime + attestation

Evidence: provider attribution, run traces · Owner: Risk owner / procurement

AI RMF MAP 1.1 / 1.5 · Context, intended purpose & risk tolerance

Runtime + attestation

Evidence: register rows · Owner: Product owner / AI governance lead

AI RMF MEASURE 2.3 / 2.5 · Validity & reliability

Runtime + attestation

Evidence: eval runs · Owner: Product / ML owner

AI RMF MEASURE 2.7 · Security & resilience

Runtime-evidenced

Evidence: blocked events, enforcement decisions · Owner: Platform operator

AI RMF MEASURE 2.8 · Transparency & accountability

Runtime-evidenced

Evidence: enforcement decisions, run traces · Owner: Platform operator

AI RMF MEASURE 2.10 · Privacy

Runtime-evidenced

Evidence: redaction events · Owner: Security / privacy officer

AI RMF MANAGE 2.4 · Supersede, disengage or deactivate

Runtime + attestation

Evidence: approval-gate decisions, audited stop/resume rows · Owner: Compliance / ops lead

AI RMF MANAGE 2.3 / 4.3 · Incident response & communication

Runtime + attestation

Evidence: blocked events · Owner: Risk owner / ops lead

AI RMF MANAGE 3.1–3.2 / 4.1 · Post-deployment & third-party monitoring

Runtime-evidenced

Evidence: enforcement decisions, provider attribution, run traces · Owner: Platform operator

Outside Norcaster's evidence scope

  • workforce, culture and accountability structures (GOVERN 2–4)
  • external stakeholder engagement and impact assessment (GOVERN 5, MAP 5, MEASURE 4)
  • fairness and bias evaluation (MEASURE 2.11)
  • environmental impact (MEASURE 2.12)
  • development-time testing of models the organisation does not train (MEASURE 2.1–2.2)
  • explainability and interpretability (MEASURE 2.9)

NIST AI RMF spans an organisation's whole AI risk programme. Norcaster is an evidence source for the runtime slice of MEASURE and MANAGE and records inputs to GOVERN and MAP; the programme itself is the organisation's.

ISO/IEC 27001

Global · Certifiable standard (Annex A controls) · Organisations with an information security management system audit · catalogue 2026.10 · Norcaster's own mapping — no external validation on record

Scope: AI systems routed through the Norcaster gateway — evidence for the AI-runtime slice of an information security management system audit (ISO/IEC 27001:2022 Annex A), not the organisation-wide ISMS.

An ISO/IEC 27001 bundle is the evidence package for the AI-runtime slice of your ISMS audit period — logging, monitoring, masking and leakage prevention, change and incident inputs, supplier attribution — mapped to the Annex A controls your auditor samples. It is not a certificate; only an accredited certification body certifies.

ISO/IEC 27001 A.5.1–5.2 · Information security policies & roles

Requires attestation

Evidence: organisation's own records · Owner: Security lead

ISO/IEC 27001 A.5.15–5.18 · Access control & identity

Requires attestation

Evidence: organisation's own records · Owner: Security / IT admin

ISO/IEC 27001 A.5.19–5.23 · Supplier relationships & cloud services

Runtime + attestation

Evidence: provider attribution, run traces · Owner: Security / procurement

ISO/IEC 27001 A.5.24–5.28 · Information security incident management

Runtime + attestation

Evidence: blocked events · Owner: Security / ops lead

ISO/IEC 27001 A.5.34 · Privacy & protection of PII

Runtime + attestation

Evidence: redaction events · Owner: Security / DPO

ISO/IEC 27001 A.8.11–8.12 · Data masking & data leakage prevention

Runtime-evidenced

Evidence: redaction events, blocked events · Owner: Platform operator

ISO/IEC 27001 A.8.15 · Logging

Runtime-evidenced

Evidence: run traces, enforcement decisions · Owner: Platform operator

ISO/IEC 27001 A.8.16 · Monitoring activities

Runtime-evidenced

Evidence: enforcement decisions, blocked events · Owner: Platform operator

ISO/IEC 27001 A.8.32 · Change management

Runtime-evidenced

Evidence: enforcement decisions · Owner: Platform operator

Outside Norcaster's evidence scope

  • the management-system clauses (4–10) and the Statement of Applicability
  • people controls (A.6)
  • physical and environmental controls (A.7)
  • the organisation's own endpoints, networks, cryptography and backups (A.8.1–8.10, 8.13–8.14, 8.20–8.24)
  • secure development of the organisation's own software (A.8.25–8.31)

ISO/IEC 27001 scopes an organisation's whole ISMS. Norcaster is an evidence source for the AI-runtime slice; Norcaster's own posture is published in the Trust Center and certified separately.

ISO/IEC 42001

Global · Certifiable standard (Annex A controls) · Organisations building an AI management system · catalogue 2026.10 · Norcaster's own mapping — no external validation on record

Scope: AI systems routed through the Norcaster gateway — evidence for the ISO/IEC 42001 Annex A controls an AI management system audit samples at runtime, not the management-system clauses (4–10).

An ISO/IEC 42001 bundle is the evidence package for the runtime-operating Annex A controls in your AI management system audit period — event logs, operation and monitoring, deployment, data handling, incidents, responsible use and third-party inputs. It is not a certificate; only an accredited certification body certifies.

ISO/IEC 42001 A.2.2–2.4 · AI policy

Runtime + attestation

Evidence: enforcement decisions · Owner: AI governance lead

ISO/IEC 42001 A.3.2 · Roles & responsibilities

Requires attestation

Evidence: organisation's own records · Owner: AI governance lead

ISO/IEC 42001 A.5.2–5.5 · AI system impact assessment

Runtime + attestation

Evidence: register rows · Owner: Risk owner

ISO/IEC 42001 A.6.2.4 · Verification & validation

Runtime + attestation

Evidence: eval runs · Owner: Product / ML owner

ISO/IEC 42001 A.6.2.5 · Deployment

Runtime + attestation

Evidence: enforcement decisions · Owner: Platform operator

ISO/IEC 42001 A.6.2.6 · Operation & monitoring

Runtime-evidenced

Evidence: enforcement decisions, blocked events · Owner: Platform operator

ISO/IEC 42001 A.6.2.8 · Recording of event logs

Runtime-evidenced

Evidence: run traces, enforcement decisions · Owner: Platform operator

ISO/IEC 42001 A.7.2–7.6 · Data for AI systems

Runtime + attestation

Evidence: redaction events · Owner: Security / DPO

ISO/IEC 42001 A.8.4 · Communication of incidents

Runtime + attestation

Evidence: blocked events · Owner: Risk owner / ops lead

ISO/IEC 42001 A.9.2–9.4 · Responsible use & intended use

Runtime + attestation

Evidence: approval-gate decisions, register rows · Owner: Product owner / AI governance lead

ISO/IEC 42001 A.10.2–10.4 · Third-party & customer relationships

Runtime + attestation

Evidence: provider attribution, run traces · Owner: Risk owner / procurement

Outside Norcaster's evidence scope

  • the management-system clauses (4–10): context, leadership, planning, support, performance evaluation, improvement
  • resources and competence (A.4)
  • information for interested parties (A.8.2–8.3, 8.5)
  • AI system requirements, design and development documentation (A.6.1, A.6.2.2–6.2.3, A.6.2.7)
  • development-time data acquisition and preparation for models the organisation does not train

ISO/IEC 42001 scopes an organisation's whole AI management system. Norcaster is an evidence source for the controls that operate at runtime; the management system is the organisation's.

GDPR

EU / EEA · Regulation · Controllers and processors of personal data · catalogue 2026.12 · Norcaster's own mapping — no external validation on record

Scope: personal data passing through AI systems routed through the Norcaster gateway — runtime evidence for the controller's data-protection programme, not the programme itself. Norcaster is a processor for the data it hosts.

A GDPR bundle is the evidence package for personal data passing through gatewayed AI systems in a review period — minimisation and redaction, security of processing, breach inputs, processor and transfer attribution, records of processing and DPIA inputs — mapped to the articles your DPO works from. It is not a compliance assessment or a DPIA; the controller determines compliance.

GDPR Art. 5(1)(a)–(b), 6 · Lawfulness & purpose limitation

Runtime + attestation

Evidence: register rows · Owner: DPO / product owner

GDPR Art. 5(1)(c), 25 · Data minimisation & protection by design

Runtime-evidenced

Evidence: redaction events · Owner: Security / DPO

GDPR Art. 5(1)(e) · Storage limitation

Requires attestation

Evidence: organisation's own records · Owner: DPO

GDPR Art. 9 · Special categories of personal data

Runtime + attestation

Evidence: redaction events, blocked events · Owner: DPO / product owner

GDPR Art. 22 · Automated decision-making & human intervention

Runtime + attestation

Evidence: approval-gate decisions · Owner: DPO / compliance lead

GDPR Art. 28 · Processors & sub-processors

Runtime + attestation

Evidence: provider attribution · Owner: DPO / procurement

GDPR Art. 30 · Records of processing activities

Runtime + attestation

Evidence: register rows · Owner: DPO

GDPR Art. 32 · Security of processing

Runtime-evidenced

Evidence: enforcement decisions, blocked events, redaction events · Owner: Security / DPO

GDPR Art. 33–34 · Personal data breach notification

Runtime + attestation

Evidence: blocked events · Owner: DPO / ops lead

GDPR Art. 35 · Data protection impact assessment

Runtime + attestation

Evidence: register rows · Owner: DPO / risk owner

GDPR Art. 44–49 · International transfers

Runtime + attestation

Evidence: provider attribution · Owner: DPO / procurement

Outside Norcaster's evidence scope

  • data subject rights handling (Art. 12–21) beyond Norcaster's own account endpoints
  • lawful bases, consent and legitimate-interest assessments (Art. 6–7)
  • processing activities outside gatewayed AI systems
  • DPO appointment and supervisory-authority relations (Art. 37–39)
  • the transfer mechanisms themselves (standard contractual clauses, adequacy decisions)

GDPR applies to the organisation's whole processing estate. Norcaster is an evidence source for the AI slice; the controller and its supervisory authority determine compliance.

HIPAA

US · Regulation (health) · Covered entities and business associates handling PHI · catalogue 2026.11 · Norcaster's own mapping — no external validation on record

Scope: protected health information passing through AI systems routed through the Norcaster gateway — runtime evidence for the covered entity's or business associate's HIPAA programme, not the programme itself.

A HIPAA bundle is the evidence package for PHI passing through gatewayed AI systems in a review period — audit controls, activity review, minimum-necessary redaction, transmission blocks, incident and business-associate inputs — mapped to the Security and Privacy Rule sections your security officer works from. It is not a compliance assessment or a business associate agreement.

45 CFR §164.308(a)(1)(ii)(A)–(B) · Risk analysis & risk management

Runtime + attestation

Evidence: register rows · Owner: Security officer / risk owner

45 CFR §164.308(a)(1)(ii)(D) · Information system activity review

Runtime-evidenced

Evidence: enforcement decisions, blocked events · Owner: Security officer

45 CFR §164.308(a)(6) · Security incident procedures

Runtime + attestation

Evidence: blocked events · Owner: Security officer / ops lead

45 CFR §164.308(b), §164.314(a) · Business associate contracts

Runtime + attestation

Evidence: provider attribution · Owner: Privacy officer / procurement

45 CFR §164.312(a)(1) · Access control

Requires attestation

Evidence: organisation's own records · Owner: Security officer / IT admin

45 CFR §164.312(b) · Audit controls

Runtime-evidenced

Evidence: run traces, enforcement decisions · Owner: Platform operator

45 CFR §164.312(c)(1) · Integrity

Runtime + attestation

Evidence: run traces · Owner: Security officer

45 CFR §164.312(e)(1) · Transmission security

Runtime + attestation

Evidence: blocked events, redaction events · Owner: Security officer

45 CFR §164.502(b) · Minimum necessary

Runtime-evidenced

Evidence: redaction events · Owner: Privacy officer

Outside Norcaster's evidence scope

  • physical safeguards (§164.310)
  • workforce security, training and sanctions (§164.308(a)(3)–(5))
  • contingency planning (§164.308(a)(7))
  • the organisation's other systems that handle PHI
  • Privacy Rule notices, authorisations and individual rights (§164.520–164.528)

HIPAA applies to the whole covered entity or business associate. Norcaster is an evidence source for the AI slice; the entity and HHS OCR determine compliance.

PCI DSS

Global (payment brands) · Industry standard (v4.0) · Entities with a cardholder data environment · catalogue 2026.11 · Norcaster's own mapping — no external validation on record

Scope: account data passing through AI systems routed through the Norcaster gateway — runtime evidence for the AI slice of the entity's PCI DSS v4.0 assessment. Card-data detection is heuristic; the cardholder data environment boundary is the entity's.

A PCI DSS bundle is the evidence package for account data passing through gatewayed AI systems in a review period — card data stopped or masked before dispatch, logging and monitoring, scope inventory, third-party and incident inputs — mapped to the v4.0 requirements your assessor samples. It is not a Report on Compliance or a self-assessment questionnaire.

PCI DSS v4.0 Req. 3.3–3.4 · Protect stored account data

Runtime-evidenced

Evidence: redaction events, blocked events · Owner: Platform operator

PCI DSS v4.0 Req. 7 · Restrict access to system components & cardholder data

Requires attestation

Evidence: organisation's own records · Owner: Security / IT admin

PCI DSS v4.0 Req. 10 · Log & monitor all access

Runtime-evidenced

Evidence: run traces, enforcement decisions · Owner: Platform operator

PCI DSS v4.0 Req. 12.5 · Scope & inventory of system components

Runtime + attestation

Evidence: register rows · Owner: Compliance lead

PCI DSS v4.0 Req. 12.8 · Third-party service providers

Runtime + attestation

Evidence: provider attribution · Owner: Compliance lead / procurement

PCI DSS v4.0 Req. 12.10 · Incident response

Runtime + attestation

Evidence: blocked events · Owner: Security / ops lead

Outside Norcaster's evidence scope

  • network security controls and segmentation (Req. 1)
  • secure configurations and cryptography for the entity's own systems (Req. 2, 4)
  • malware and vulnerability management (Req. 5–6)
  • authentication and physical access (Req. 8–9)
  • security testing and penetration testing (Req. 11)
  • the Report on Compliance and self-assessment questionnaires

PCI DSS scopes the entity's whole cardholder data environment. Norcaster is an evidence source for the AI slice; a Qualified Security Assessor or the entity's self-assessment, and its acquirer, determine compliance.

Regional and sector profiles

Most regional AI law points at the frameworks above rather than inventing new evidence: Texas names NIST AI RMF, Japan and Australia publish ISO-shaped practice lists, Korea's high-impact duties mirror the EU AI Act's. So regional and sector regimes are handled as profiles — dated, reviewed notes that list the instruments in force, the framework views to open, and the duties the catalogue rows speak to, with what no stored signal covers stated next to each duty. Profiles never carry a status of their own; they are never a catalogue, because regional law moves too fast for versioned mappings. Facts marked unverified were not checked against a primary source at the last review and must be confirmed before you rely on them.

Americas

United States — Texas (TRAIGA)

Jurisdiction profile · applies to both · framework views: NIST AI RMF · last reviewed 2026-09-11

  • Texas Responsible Artificial Intelligence Governance Act (HB 149)In force from 2026-01-01 · Intent-based prohibited uses; disclosure in healthcare; Attorney General enforcement with a cure period; affirmative defense for substantial compliance with the current NIST AI RMF including the Generative AI Profile.
  • Do not develop or deploy AI for the prohibited purposes (manipulation toward self-harm or crime, unlawful discrimination, social scoring, certain biometric uses).

    Rows: NIST AI RMF · Security & resilience; NIST AI RMF · Post-deployment & third-party monitoring

    Not covered by stored evidence: Whether a use is prohibited is a legal determination; blocks and decisions evidence the control operating, not the classification.

  • Keep the NIST AI RMF alignment that the affirmative defense relies on documented and current.

    Rows: NIST AI RMF · AI policies & risk-management process; NIST AI RMF · Transparency & accountability; NIST AI RMF · Incident response & communication

  • Disclose AI interaction to consumers in healthcare services.

    Rows: NIST AI RMF · Context, intended purpose & risk tolerance

    Not covered by stored evidence: The disclosure happens in the entity's own product; the register records purpose, not the notice.

United States — Colorado (ADMT Act)

Jurisdiction profile · applies to both · framework views: NIST AI RMF, EU AI Act · last reviewed 2026-09-11

  • Automated Decision-Making Technology in Consequential Decisions Act (SB 26-189)Enacted, not yet in force from 2027-01-01 · Signed 14 May 2026; repeals and replaces SB 24-205. Removes the duty of care, impact assessments and the NIST/ISO presumption; substitutes disclosure duties, three-year record-keeping and a 60-day cure period.
  • Keep records of automated decision-making technology use for three years.

    Rows: EU AI Act · Decision / record-keeping; EU AI Act · Logging & traceability; NIST AI RMF · Transparency & accountability

    Not covered by stored evidence: Retention must be configured to at least three years; no retention signal reaches the map yet.

  • Disclose the use of automated decision-making technology in consequential decisions.

    Rows: NIST AI RMF · Context, intended purpose & risk tolerance

    Not covered by stored evidence: The disclosure is the entity's; the register records purpose and risk tier.

  • Respond to an Attorney General notice within the cure period.

    Rows: NIST AI RMF · Transparency & accountability; NIST AI RMF · Incident response & communication

United States — federal

Jurisdiction profile · applies to both · framework views: NIST AI RMF · last reviewed 2026-09-11

  • Executive Order 'Ensuring a National Policy Framework for Artificial Intelligence' and the AI Litigation Task ForceIn force from 2025-12-11 · Task Force from 10 January 2026 to challenge state AI laws; White House legislative recommendations on preemption in March 2026. State profiles are volatile as a result.
  • OMB memorandum M-25-21 (agency AI use and risk management)In force · not yet verified against a primary source · Binds federal agencies and shapes what their contractors are asked for.
  • Maintain an inventory of AI use cases and risk-management practices (agencies and their suppliers).

    Rows: NIST AI RMF · AI system inventory; NIST AI RMF · AI policies & risk-management process; NIST AI RMF · Post-deployment & third-party monitoring

United States — financial services (model risk, third-party risk, NYDFS)

Sector profile · applies to deployers · framework views: NIST AI RMF, DORA, SOC 2 (TSC) · last reviewed 2026-09-12

  • SR 11-7 / OCC Bulletin 2011-12 — Supervisory guidance on model risk managementIn force from 2011-04-04 · not yet verified against a primary source · Model inventory, validation, ongoing monitoring, change control; applied to AI/ML models by supervisors.
  • Interagency guidance on third-party relationships: risk managementIn force from 2023-06-06 · not yet verified against a primary source
  • NYDFS Cybersecurity Regulation (23 NYCRR Part 500), as amendedIn force from 2023-11-01 · not yet verified against a primary source · 72-hour incident notification; access, monitoring and third-party provisions.
  • Maintain a model inventory covering AI models and their third-party sources.

    Rows: NIST AI RMF · AI system inventory; DORA · Identification of ICT assets & dependencies; PCI DSS · Scope & inventory of system components

  • Ongoing monitoring and outcomes analysis of models in production.

    Rows: NIST AI RMF · Post-deployment & third-party monitoring; NIST AI RMF · Validity & reliability; DORA · Digital operational resilience testing

    Not covered by stored evidence: Validation methodology and independent review are the institution's; eval runs are the recorded inputs.

  • Change control for models and their governing policies.

    Rows: SOC 2 (TSC) · Change management; ISO/IEC 27001 · Change management

  • Third-party model and vendor risk, including concentration.

    Rows: NIST AI RMF · Third-party AI risk & components; DORA · Register of ICT third-party arrangements; DORA · ICT concentration risk

  • Incident notification within the NYDFS 72-hour window.

    Rows: SOC 2 (TSC) · Incident management; DORA · ICT-related incident management & classification

    Not covered by stored evidence: The notification is the entity's; blocked events, stops and failovers are the inputs.

United States — New York City (Local Law 144)

Jurisdiction profile · applies to deployers · framework views: NIST AI RMF · last reviewed 2026-09-12

  • NYC Local Law 144 — automated employment decision toolsIn force from 2023-07-05 · not yet verified against a primary source · Annual independent bias audit and candidate notices for automated employment decision tools.
  • Annual independent bias audit of the tool.

    Not covered by stored evidence: No fairness or bias metric is stored, so no row is tagged; the audit is the entity's and its auditor's.

  • Notice to candidates and employees that an automated tool is used.

    Rows: NIST AI RMF · Context, intended purpose & risk tolerance

    Not covered by stored evidence: The notice is the entity's; the register records purpose.

United States — California (CCPA/CPRA automated decision-making rules; AI auditor registry)

Jurisdiction profile · applies to deployers · framework views: NIST AI RMF, GDPR · last reviewed 2026-09-12

  • CPPA regulations on automated decision-making technology, risk assessments and cybersecurity auditsEnacted, not yet in force from 2027-01-01 · Approved by the Office of Administrative Law 23 Sep 2025. ADMT duties (pre-use notice, opt-out, access) for significant decisions from 1 Jan 2027; initial risk assessments due 31 Dec 2027 with submissions by 1 Apr 2028; annual cybersecurity audits phased 1 Apr 2028 / 2029 / 2030 by revenue.
  • SB 53 — Transparency in Frontier Artificial Intelligence ActIn force from 2026-01-01 · Signed 29 Sep 2025. Binds large frontier model developers (safety frameworks, transparency reports, critical-incident reporting), not deployers; out of scope for most customers.
  • AB 1405 — AI auditor registration (Government Operations Agency registry)Enacted, not yet in force from 2029-01-01 · Signed 9 Sep 2026. The registry must exist by 1 Jan 2029; from that date an unregistered person may not offer, sell or conduct a covered AI audit — an audit that a California statute requires an independent third party to perform. Registered auditors follow the AICPA Code of Professional Conduct and independence rules. It regulates the auditor, not the deployer; the deployer's evidence is what the auditor samples.
  • SB 813 — multistakeholder regulatory organisations; California AI Standards and Safety CommissionEnacted, not yet in force · Signed 9 Sep 2026. The Attorney General may designate private MROs for renewable 3-year terms to certify AI models and applications against risk-mitigation plans; certification is voluntary for developers and deployers. Designation process and dates follow the chaptered text — check before citing a date.
  • Risk assessment before using automated decision-making technology for significant decisions.

    Rows: GDPR · Data protection impact assessment; NIST AI RMF · Context, intended purpose & risk tolerance

    Not covered by stored evidence: The assessment is the business's; register fields are the inputs.

  • Pre-use notice and opt-out or human-review mechanism for consumers.

    Rows: NIST AI RMF · Supersede, disengage or deactivate; GDPR · Automated decision-making & human intervention

    Not covered by stored evidence: Approval gates evidence a human-review mechanism on gatewayed decisions; the consumer-facing notice and opt-out are the business's.

  • Where a California statute requires an independent third-party audit of an AI system, use a registered AI auditor from 1 January 2029 (AB 1405) and give the auditor auditable evidence of the system's operation.

    Rows: NIST AI RMF · Transparency & accountability; NIST AI RMF · Post-deployment & third-party monitoring; NIST AI RMF · AI system inventory

    Not covered by stored evidence: The audit, the choice of a registered auditor and the auditor's independence are the business's and the auditor's; Norcaster's decision records, traces, register extract and framework-scoped bundles are the evidence an auditor samples, never the audit.

United States — Illinois (AI in employment)

Jurisdiction profile · applies to deployers · framework views: NIST AI RMF · last reviewed 2026-09-12

  • Illinois HB 3773 — amendments to the Human Rights Act on AI in employment decisionsIn force from 2026-01-01 · not yet verified against a primary source · Notice to employees and applicants; no use of AI that has a discriminatory effect. Verify effective date before customer-facing use.
  • Notify employees and applicants when AI is used in employment decisions.

    Rows: NIST AI RMF · Context, intended purpose & risk tolerance

    Not covered by stored evidence: The notice is the employer's.

  • Keep records of AI use in employment decisions.

    Rows: NIST AI RMF · Transparency & accountability; EU AI Act · Decision / record-keeping

Canada (privacy, Quebec Law 25, OSFI E-23)

Jurisdiction profile · applies to both · framework views: NIST AI RMF, ISO/IEC 42001 · last reviewed 2026-09-12

  • PIPEDA and Quebec Law 25 (automated decision transparency)In force from 2023-09-22 · not yet verified against a primary source · Law 25 requires informing individuals of decisions based exclusively on automated processing and offering review.
  • OSFI Guideline E-23 — Model Risk Management (federally regulated financial institutions)Enacted, not yet in force from 2027-05-01 · Final guideline published 11 September 2025; applies to all models regardless of source, including AI/ML.
  • Enterprise model inventory and lifecycle governance for AI/ML models (E-23).

    Rows: NIST AI RMF · AI system inventory; ISO/IEC 42001 · AI system impact assessment; ISO/IEC 42001 · Deployment

  • Inform individuals of exclusively automated decisions and offer human review (Law 25).

    Rows: NIST AI RMF · Supersede, disengage or deactivate

    Not covered by stored evidence: The notice and review process are the organisation's; approval gates evidence the mechanism.

  • Monitor third-party models as part of regular model monitoring.

    Rows: NIST AI RMF · Third-party AI risk & components; NIST AI RMF · Post-deployment & third-party monitoring

Brazil (LGPD, AI bill)

Jurisdiction profile · applies to both · framework views: GDPR, ISO/IEC 42001 · last reviewed 2026-09-12

  • Lei Geral de Proteção de Dados (LGPD)In force from 2020-09-18 · not yet verified against a primary source · Art. 20 right to review of decisions taken solely by automated processing.
  • AI bill (PL 2338/2023)Proposed · not yet verified against a primary source · Passed the Senate in December 2024; Chamber of Deputies pending — verify status before customer-facing use.
  • Data minimisation and security of personal data in AI processing.

    Rows: GDPR · Data minimisation & protection by design; GDPR · Security of processing

  • Right to review of solely automated decisions (LGPD Art. 20).

    Rows: GDPR · Automated decision-making & human intervention

  • Records of processing and processor arrangements.

    Rows: GDPR · Records of processing activities; GDPR · Processors & sub-processors

Asia-Pacific

South Korea (AI Basic Act)

Jurisdiction profile · applies to both · framework views: ISO/IEC 42001, EU AI Act · last reviewed 2026-09-11

  • Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust (AI Basic Act) and Enforcement DecreeIn force from 2026-01-22 · High-impact AI duties (risk management, impact assessment, human oversight, documentation, user notice), generative-AI labeling, domestic representative for foreign providers; administrative fines deferred for at least a year except in cases of serious harm.
  • Risk management and impact assessment for high-impact AI.

    Rows: EU AI Act · Risk management; ISO/IEC 42001 · AI system impact assessment; EU AI Act · AI system inventory

  • Human oversight of high-impact AI.

    Rows: EU AI Act · Human oversight; NIST AI RMF · Supersede, disengage or deactivate

  • Documentation and explanation of high-impact AI operation.

    Rows: EU AI Act · Technical documentation; ISO/IEC 42001 · Recording of event logs

  • User notice for high-impact and generative AI; labeling of generative outputs.

    Not covered by stored evidence: No labeling or notice signal is stored; these are the deployer's product duties.

  • Domestic representative for foreign operators above the threshold.

    Not covered by stored evidence: Corporate obligation with no runtime evidence.

Singapore (IMDA frameworks, AI Verify, PDPA, MAS)

Jurisdiction profile · applies to both · framework views: ISO/IEC 42001, NIST AI RMF, DORA · last reviewed 2026-09-11

  • IMDA Model AI Governance Framework (2020) and Model AI Governance Framework for Generative AI (2024)Voluntary
  • IMDA Model AI Governance Framework for Agentic AIVoluntary from 2026-05-20 · v1.0 January 2026, v1.5 20 May 2026: bound risks, meaningful human accountability, technical controls and processes, end-user responsibility.
  • AI Verify testing framework and toolkitVoluntary
  • Personal Data Protection Act (PDPA)In force · not yet verified against a primary source
  • MAS Technology Risk Management Guidelines and FEAT principles (financial institutions)In force · not yet verified against a primary source · Sector guidance; verify current edition before customer-facing use.
  • Bound agentic risks with technical controls and per-action decisions.

    Rows: NIST AI RMF · Security & resilience; NIST AI RMF · Supersede, disengage or deactivate; EU AI Act · Human oversight

  • Meaningful human accountability for AI systems.

    Rows: ISO/IEC 42001 · Roles & responsibilities; ISO/IEC 42001 · Responsible use & intended use

  • Testing and assurance (AI Verify process checks and technical tests).

    Rows: ISO/IEC 42001 · Verification & validation; NIST AI RMF · Validity & reliability

  • PDPA data minimisation and protection.

    Rows: GDPR · Data minimisation & protection by design; GDPR · Security of processing

  • MAS third-party and incident management for financial institutions.

    Rows: DORA · Register of ICT third-party arrangements; DORA · ICT-related incident management & classification

Japan (AI Promotion Act, METI/MIC guidelines, APPI)

Jurisdiction profile · applies to both · framework views: ISO/IEC 42001 · last reviewed 2026-09-11

  • Act on Promotion of Research and Development, and Utilization of AI-related Technology (AI Promotion Act)In force from 2025-09-01 · Most provisions from 4 June 2025; no penalties, no mandatory duties; AI Basic Plan revised by Cabinet decision on 14 July 2026.
  • METI/MIC AI Guidelines for Business v1.2Voluntary from 2026-03-31
  • Act on the Protection of Personal Information (APPI)In force · not yet verified against a primary source
  • Safety, transparency and accountability practices under the AI Guidelines for Business.

    Rows: ISO/IEC 42001 · AI policy; ISO/IEC 42001 · Recording of event logs; NIST AI RMF · Transparency & accountability

  • APPI minimisation and security of personal data.

    Rows: GDPR · Data minimisation & protection by design; GDPR · Security of processing

Australia (National AI Plan, Guidance for AI Adoption, Privacy Act, APRA)

Jurisdiction profile · applies to both · framework views: ISO/IEC 42001, DORA · last reviewed 2026-09-11

  • National AI Plan and the Guidance for AI Adoption (six essential practices)Voluntary from 2025-12-01 · Mandatory guardrails for high-risk AI were shelved; the Voluntary AI Safety Standard's ten guardrails fold into six practices: decide accountability, understand impacts, measure and manage risks, share information, test and monitor, maintain human control.
  • Privacy Act 1988 and 2024 amendments (automated-decision transparency)Enacted, not yet in force from 2026-12-10 · not yet verified against a primary source · Verify the commencement date of the automated-decision transparency obligations.
  • APRA CPS 230 Operational Risk Management and CPS 234 Information Security (regulated entities)In force from 2025-07-01 · not yet verified against a primary source · Sector; material service provider and incident duties.
  • Decide accountability and understand impacts.

    Rows: ISO/IEC 42001 · Roles & responsibilities; ISO/IEC 42001 · AI system impact assessment

  • Measure and manage risks; test and monitor.

    Rows: NIST AI RMF · AI policies & risk-management process; ISO/IEC 42001 · Verification & validation; ISO/IEC 42001 · Operation & monitoring

  • Maintain human control.

    Rows: NIST AI RMF · Supersede, disengage or deactivate; EU AI Act · Human oversight

  • Share information about AI use with affected people.

    Not covered by stored evidence: Disclosure is the organisation's product duty; no stored signal.

  • CPS 230 material service providers and incident management (APRA-regulated entities).

    Rows: DORA · Register of ICT third-party arrangements; DORA · ICT-related incident management & classification

India (AI Governance Guidelines, DPDP, deepfake rules)

Jurisdiction profile · applies to both · framework views: GDPR, ISO/IEC 42001 · last reviewed 2026-09-11

  • MeitY India AI Governance GuidelinesVoluntary from 2025-11-01 · Principles-based; self-certification and sandboxes rather than a standalone AI Act.
  • Digital Personal Data Protection Act 2023 and DPDP RulesIn force from 2025-11-01 · Consent, purpose limitation, minimisation, security safeguards, breach notification; phased obligations — verify the current phase.
  • IT Rules amendments on synthetically generated information (labeling and provenance)In force · Binds intermediaries; verify applicability to enterprise deployers.
  • DPDP minimisation, security safeguards and breach notification.

    Rows: GDPR · Data minimisation & protection by design; GDPR · Security of processing; GDPR · Personal data breach notification

  • Accountability and governance under the AI Governance Guidelines.

    Rows: ISO/IEC 42001 · Roles & responsibilities; ISO/IEC 42001 · AI policy

  • Labeling and provenance of synthetically generated content.

    Not covered by stored evidence: No labeling signal is stored; product duty.

Hong Kong (PCPD AI framework, PDPO, HKMA)

Jurisdiction profile · applies to both · framework views: ISO/IEC 42001, GDPR · last reviewed 2026-09-12

  • PCPD Artificial Intelligence: Model Personal Data Protection FrameworkVoluntary from 2024-06-11 · not yet verified against a primary source
  • Personal Data (Privacy) Ordinance (PDPO)In force · not yet verified against a primary source
  • HKMA guidance on generative AI in bankingVoluntary · not yet verified against a primary source · Sector; verify the current circular before customer-facing use.
  • PDPO data minimisation and security.

    Rows: GDPR · Data minimisation & protection by design; GDPR · Security of processing

  • AI governance, risk assessment and human oversight under the PCPD framework.

    Rows: ISO/IEC 42001 · AI policy; ISO/IEC 42001 · AI system impact assessment; NIST AI RMF · Supersede, disengage or deactivate

  • Third-party model risk for banks.

    Rows: NIST AI RMF · Third-party AI risk & components

Europe, Middle East & Africa

United Kingdom (UK GDPR, ICO, FCA/PRA)

Jurisdiction profile · applies to both · framework views: GDPR, ISO/IEC 27001, DORA · last reviewed 2026-09-12

  • UK GDPR and Data Protection Act 2018, with ICO guidance on AI and data protectionIn force · not yet verified against a primary source
  • Pro-innovation AI regulation principles (sector regulators)Voluntary · not yet verified against a primary source
  • PRA SS1/23 Model risk management principles for banksIn force from 2024-05-17 · not yet verified against a primary source · Sector; verify current version.
  • Operational resilience and critical third parties regime (FCA/PRA/Bank of England)In force · not yet verified against a primary source · Sector; verify the critical third parties regime commencement.
  • UK GDPR minimisation, security, records and automated-decision safeguards.

    Rows: GDPR · Data minimisation & protection by design; GDPR · Security of processing; GDPR · Records of processing activities; GDPR · Automated decision-making & human intervention

  • Model risk management for banks (inventory, validation, monitoring).

    Rows: NIST AI RMF · AI system inventory; NIST AI RMF · Validity & reliability; NIST AI RMF · Post-deployment & third-party monitoring

  • Operational resilience and third-party dependencies.

    Rows: DORA · Response & recovery; DORA · Register of ICT third-party arrangements; ISO/IEC 27001 · Supplier relationships & cloud services

European Union — NIS2 (essential and important entities)

Sector profile · applies to deployers · framework views: ISO/IEC 27001, DORA · last reviewed 2026-09-12

  • Directive (EU) 2022/2555 (NIS2), Article 21 cybersecurity risk-management measures, as transposed nationallyIn force from 2024-10-17 · not yet verified against a primary source · Transposition deadline; national laws vary — verify the member state's transposition and the entity's classification.
  • Incident handling, and early-warning (24h) and notification (72h) reporting.

    Rows: ISO/IEC 27001 · Information security incident management; DORA · ICT-related incident management & classification

    Not covered by stored evidence: The reporting is the entity's; blocked events, stops and failovers are the inputs.

  • Supply chain security including direct suppliers and service providers.

    Rows: ISO/IEC 27001 · Supplier relationships & cloud services; DORA · Register of ICT third-party arrangements

  • Logging, monitoring and access control.

    Rows: ISO/IEC 27001 · Logging; ISO/IEC 27001 · Monitoring activities; ISO/IEC 27001 · Access control & identity

Applicability and interpretation of regional law are determined by your counsel. Profiles are product mappings maintained by Norcaster, dated on review, and never legal advice.

Crosswalk: one record, many rows

The same stored record backs rows in several frameworks at once — an enforcement decision is EU AI Act record-keeping evidence, SOC 2 processing-integrity evidence and ISO/IEC 27001 logging evidence in one write. The crosswalk groups every row of every framework by the record it rests on, so a reviewer working from one framework can find the citation in another, and the Obligations Map shows an "also satisfies" line on each row. Each theme also names the external targets security teams bring — CSA AI Controls Matrix domains, OWASP Top 10 for LLM Applications categories, MITRE ATLAS techniques — as crosswalk notes, never as catalogues; identifiers marked unverified must be confirmed against the published matrices before you rely on them.

Decision records & logging

One decision record per gatewayed request with policy version and actor, plus run traces on the hash-chained ledger — exportable and verifiable offline.

  • EU AI Act: Logging & traceability; Decision / record-keeping
  • SOC 2 (TSC): Processing integrity (AI calls)
  • NIST AI RMF: Transparency & accountability
  • ISO/IEC 27001: Logging
  • ISO/IEC 42001: Recording of event logs
  • HIPAA: Audit controls; Integrity
  • PCI DSS: Log & monitor all access

External targets: CSA AI Controls Matrix v1.1 (July 2026) — Logging and Monitoring

Monitoring & detection

Requests evaluated and stopped before dispatch; adversarial-input detections stored with violation codes; unapproved models and out-of-region providers refused.

  • SOC 2 (TSC): Monitoring & anomaly detection
  • DORA: Protection, prevention & detection
  • NIST AI RMF: Post-deployment & third-party monitoring; Security & resilience
  • ISO/IEC 27001: Monitoring activities
  • ISO/IEC 42001: Operation & monitoring
  • GDPR: Security of processing
  • HIPAA: Information system activity review

External targets: CSA AI Controls Matrix v1.1 (July 2026) — Threat and Vulnerability Management, Model Security · OWASP Top 10 for LLM Applications (2025) — LLM01 Prompt Injection, LLM07 System Prompt Leakage, LLM10 Unbounded Consumption · MITRE ATLAS — AML.T0051 LLM Prompt Injection, AML.T0054 LLM Jailbreak

Data minimisation, masking & leakage prevention

Redaction events with category, action and policy version — sensitive data masked or stopped before it reaches a provider; masked metadata stored, never bodies.

  • EU AI Act: Data minimisation / PII redaction
  • SOC 2 (TSC): Confidentiality
  • NIST AI RMF: Privacy
  • ISO/IEC 27001: Data masking & data leakage prevention; Privacy & protection of PII
  • ISO/IEC 42001: Data for AI systems
  • GDPR: Data minimisation & protection by design; Special categories of personal data
  • HIPAA: Minimum necessary; Transmission security
  • PCI DSS: Protect stored account data

External targets: CSA AI Controls Matrix v1.1 (July 2026) — Data Security and Privacy Lifecycle Management · OWASP Top 10 for LLM Applications (2025) — LLM02 Sensitive Information Disclosure · MITRE ATLAS — AML.T0057 LLM Data Leakage

Boundary enforcement & policy versions

Policies enforced at the request boundary, each decision stamped with the policy version in force; lifecycle and policy changes in the change history.

  • SOC 2 (TSC): System boundaries & transmission; Change management
  • DORA: Governance & ICT risk-management framework
  • NIST AI RMF: AI policies & risk-management process
  • ISO/IEC 27001: Change management
  • ISO/IEC 42001: AI policy; Deployment

External targets: CSA AI Controls Matrix v1.1 (July 2026) — Change Control and Configuration Management · OWASP Top 10 for LLM Applications (2025) — LLM05 Improper Output Handling

Incident inputs & recovery

Blocked events with timestamps, audited deployment stops and resumes, provider failover events — the raw inputs for incident classification, response and reporting.

  • EU AI Act: Incidents & flags
  • SOC 2 (TSC): Incident management; Availability
  • DORA: ICT-related incident management & classification; Response & recovery
  • NIST AI RMF: Incident response & communication
  • ISO/IEC 27001: Information security incident management
  • ISO/IEC 42001: Communication of incidents
  • GDPR: Personal data breach notification
  • HIPAA: Security incident procedures
  • PCI DSS: Incident response

External targets: CSA AI Controls Matrix v1.1 (July 2026) — Security Incident Management, E-Discovery and Cloud Forensics

Third-party & provider attribution

Which provider and model served each call, with approval state, residency tag and failover events — the inputs to supplier, processor and concentration duties.

  • EU AI Act: Provider / model identification
  • SOC 2 (TSC): Risk assessment & vendor management
  • DORA: Register of ICT third-party arrangements; ICT concentration risk; Key contractual provisions
  • NIST AI RMF: Third-party AI risk & components
  • ISO/IEC 27001: Supplier relationships & cloud services
  • ISO/IEC 42001: Third-party & customer relationships
  • GDPR: Processors & sub-processors; International transfers
  • HIPAA: Business associate contracts
  • PCI DSS: Third-party service providers

External targets: CSA AI Controls Matrix v1.1 (July 2026) — Supply Chain Management, Transparency and Accountability · OWASP Top 10 for LLM Applications (2025) — LLM03 Supply Chain

Human oversight & disengagement

Approval-gate decisions on gatewayed actions and audited stop/resume — the mechanisms to intervene in, supersede or deactivate an AI system.

  • EU AI Act: Human oversight
  • NIST AI RMF: Supersede, disengage or deactivate
  • ISO/IEC 42001: Responsible use & intended use
  • GDPR: Automated decision-making & human intervention

External targets: OWASP Top 10 for LLM Applications (2025) — LLM06 Excessive Agency

Inventory, context & impact assessment

Register rows with purpose, risk tier, data classification and accountable owner; the coverage statement of how many registered systems are gatewayed.

  • EU AI Act: AI system inventory; Records of processing (RoPA); Risk management; Gateway coverage / estate completeness
  • DORA: Identification of ICT assets & dependencies
  • NIST AI RMF: AI system inventory; Context, intended purpose & risk tolerance
  • ISO/IEC 42001: AI system impact assessment
  • GDPR: Lawfulness & purpose limitation; Records of processing activities; Data protection impact assessment
  • HIPAA: Risk analysis & risk management
  • PCI DSS: Scope & inventory of system components

External targets: CSA AI Controls Matrix v1.1 (July 2026) — Governance, Risk and Compliance

Testing & validation

Eval runs against in-scope deployments — status, pass rate and item results as the stored testing inputs; test design and review stay with the organisation.

  • EU AI Act: Accuracy / robustness
  • DORA: Digital operational resilience testing
  • NIST AI RMF: Validity & reliability
  • ISO/IEC 42001: Verification & validation

External targets: CSA AI Controls Matrix v1.1 (July 2026) — Model Security · OWASP Top 10 for LLM Applications (2025) — LLM09 Misinformation

Access control

RBAC, MFA and access-audit records exist server-side; until an access-events signal reaches the map these rows stay attested across every framework.

  • SOC 2 (TSC): Logical access controls
  • ISO/IEC 27001: Access control & identity
  • HIPAA: Access control
  • PCI DSS: Restrict access to system components & cardholder data

External targets: CSA AI Controls Matrix v1.1 (July 2026) — Identity and Access Management

Governance documentation & roles

Policies, roles and technical documentation the organisation holds; Norcaster records the inputs (register, policy manifests) but the documents are the organisation's.

  • EU AI Act: Technical documentation
  • ISO/IEC 27001: Information security policies & roles
  • ISO/IEC 42001: Roles & responsibilities

External targets: CSA AI Controls Matrix v1.1 (July 2026) — Governance, Risk and Compliance

Retention & storage limitation

Retention is configurable per organisation, but no retention signal reaches the map yet — attested everywhere it appears (see also the Colorado three-year record-keeping profile).

  • GDPR: Storage limitation

CSA AI Controls Matrix v1.1 (July 2026): Domain names cited; control identifiers to be confirmed against the published matrix before customer-facing use. Not yet verified. OWASP Top 10 for LLM Applications (2025): Risk categories cited by number and title. Not yet verified. MITRE ATLAS: Technique identifiers to be confirmed against the current ATLAS release before customer-facing use. Not yet verified.

How a framework view becomes an audit bundle

Choose a framework when generating an audit bundle and the bundle carries that framework's catalogue version, a criterion-mapping section (which bundle sections back which row, with the evidence rows included and the attestation citation or its explicit gap), the scope statement, and an attestor-boundary sentence on the cover — for example that only a licensed CPA firm attests under SOC 2, that only an accredited certification body certifies against ISO/IEC 27001 or 42001, or that a supervisory authority determines GDPR compliance. Two appendices follow the evidence sections: the jurisdiction and sector profiles the organisation has enabled (each duty with the catalogue rows it cites and the bundle sections that back them, dated on review, never a status) and a crosswalk of every row in the chosen framework to its peers in the organisation's other in-scope views. CSV and PDF exports ship with the standalone verifier; JSON bundles embed the verification instructions.

Common questions

Which obligation frameworks can Norcaster project runtime evidence onto?

Nine framework views today, all generated from one obligations catalogue: the EU AI Act, SOC 2 Trust Services Criteria, DORA, NIST AI RMF (with the Generative AI Profile), ISO/IEC 27001:2022 Annex A, ISO/IEC 42001 Annex A, GDPR, HIPAA (Security and Privacy Rules) and PCI DSS v4.0. Each view maps the same stored records — decisions, redactions, blocks, approvals, provider attribution, eval runs — onto that framework's rows, tags every row runtime-evidenced, mixed, or requires-attestation, and states what stays outside Norcaster's evidence scope. Regional laws that point at these frameworks (for example Texas TRAIGA's reference to NIST AI RMF) are handled as notes, not as separate catalogues.

All framework views

What does "draft mapping" mean on a framework view?

It means Norcaster's reading of that framework against stored runtime evidence has not yet been walked row by row by an external reviewer — a certification body, an audit firm, a supervisor-facing compliance function, or a customer's DPO. The draft sentence is printed on the Obligations Map header and on every audit bundle for that framework until the walkthrough happens, and flipping it is a versioned catalogue change with a changelog entry naming who validated the mapping and when. As of September 2026 every view is Norcaster's own published mapping after an internal row-by-row review recorded in its walkthrough pack, and none has been validated by an external reviewer yet — a view says "validated by" only after that session.

Validation status per framework

Can Norcaster certify us against ISO/IEC 27001, ISO/IEC 42001, PCI DSS, or HIPAA?

No. Only an accredited certification body certifies against ISO/IEC 27001 or 42001; a Qualified Security Assessor, or the entity's own self-assessment and its acquirer, determine PCI DSS compliance; the covered entity or business associate and HHS OCR determine HIPAA compliance; a controller and its supervisory authority determine GDPR compliance. Norcaster produces the runtime evidence for the AI slice of each of those programmes, prints the boundary on every bundle cover, and never declares anyone compliant or certified.

Attestor boundaries per framework

Do you cover Texas, Colorado, Korea, Singapore, or my sector regulator?

As profiles, not as catalogues. A jurisdiction or sector profile lists the instruments that apply (with their status, effective date, and whether the fact was verified at the last review), the framework views worth opening, and the duties the existing catalogue rows speak to — with what no stored signal covers stated next to each duty. Today's profiles cover the US federal picture and Texas, Colorado, New York City, California and Illinois, US financial services (SR 11-7, third-party risk, NYDFS), Canada, Brazil, South Korea, Singapore, Japan, Australia, India, Hong Kong, the United Kingdom and NIS2. Regional law moves fast, so profiles are dated and reviewed rather than versioned like catalogues, and applicability is always your counsel's call.

Regional and sector profiles

Do you map to the CSA AI Controls Matrix, OWASP Top 10 for LLM Applications, or MITRE ATLAS?

As crosswalk targets, not as catalogues. The crosswalk groups every catalogue row across all nine frameworks by the stored record it rests on — decision records, monitoring and detection, minimisation and masking, boundary enforcement, incident inputs, third-party attribution, human oversight, inventory and context, testing, access control, governance documentation, retention — and each theme names the CSA AICM domains, OWASP LLM risk categories and ATLAS techniques security teams bring to the conversation. A reviewer working from ISO can find the SOC 2, DORA or GDPR row for the same evidence, and the map shows an 'also satisfies' line on every row. External control identifiers are marked unverified until confirmed against the published matrices.

The crosswalk

Does Norcaster replace Vanta, Drata, or Secureframe?

No — it complements them. A readiness platform covers the organization: laptops, people, policies, org-wide controls. It cannot see inside AI runtime traffic. Norcaster evidences that slice — the requests, redactions, policy decisions, and approvals on gatewayed AI traffic. Two different evidence surfaces, one audit; HR, endpoints, physical security, BCP, and org-wide vendor management remain readiness-platform territory, and Norcaster states that boundary in the product and in every SOC 2 bundle.

Working alongside readiness platforms

Capabilities described as of September 2026. Every framework mapping is Norcaster's own reading of the standard against stored runtime evidence; none has yet been validated by an external reviewer, and a view says “validated by” only after a recorded walkthrough. A mapping marked draft has not yet had Norcaster's own row-by-row review either. ISO and PCI DSS texts are licensed; rows cite control or requirement numbers with Norcaster's paraphrase only. Norcaster is not an auditor, a CPA firm, a certification body, a Qualified Security Assessor, or a law firm; this page is not an attestation, a certificate, an audit deliverable, or legal advice.