This matrix is intended to help organisations quickly determine the role each regulation or standard plays in the AI security programme.

Source Status AI? What the Organisation Must Demonstrate Recommended Owner
AI Act Mandatory Yes AI literacy, transparency, risk classification, operator role, controls, and documentation. CAISO + legal + owner
GDPR Mandatory Conditional Lawful processing, purpose limitation, minimisation, DPIA, privacy by design. DPO + owner
NIS2 Conditional Indirectly Management decisions, risk measures, incident process, supplier control. CISO + management
Regulation (EU) 2024/2690 Conditional Indirectly Technical cloud / data centre / MSP security requirements where in scope. CISO / CTO
CRA Conditional Yes Secure product development, vulnerability management, updates, market conformity. CTO + product leads
DORA Sectoral Indirectly Digital operational resilience, third-party ICT risk, continuity. Risk function + CISO
ISO/IEC 27001 Voluntary / evidentiary Indirectly ISMS, policy, risk, controls, audit. CISO
ISO/IEC 42001 Voluntary / evidentiary Yes AIMS, AI governance, responsibilities, continual improvement. CAISO
ISO/IEC 23894 Voluntary / evidentiary Yes AI risk management methodology. CAISO
ISO/IEC 38507 Voluntary / evidentiary Yes Governance model for leadership. Management / CAISO
ISO/IEC 42005 Voluntary / evidentiary Yes AI impact assessment methodology. CAISO + DPO + owner