This matrix is intended to help organisations quickly determine the role each regulation or standard plays in the AI security programme.
| Source | Status | AI? | What the Organisation Must Demonstrate | Recommended Owner |
|---|---|---|---|---|
| AI Act | Mandatory | Yes | AI literacy, transparency, risk classification, operator role, controls, and documentation. | CAISO + legal + owner |
| GDPR | Mandatory | Conditional | Lawful processing, purpose limitation, minimisation, DPIA, privacy by design. | DPO + owner |
| NIS2 | Conditional | Indirectly | Management decisions, risk measures, incident process, supplier control. | CISO + management |
| Regulation (EU) 2024/2690 | Conditional | Indirectly | Technical cloud / data centre / MSP security requirements where in scope. | CISO / CTO |
| CRA | Conditional | Yes | Secure product development, vulnerability management, updates, market conformity. | CTO + product leads |
| DORA | Sectoral | Indirectly | Digital operational resilience, third-party ICT risk, continuity. | Risk function + CISO |
| ISO/IEC 27001 | Voluntary / evidentiary | Indirectly | ISMS, policy, risk, controls, audit. | CISO |
| ISO/IEC 42001 | Voluntary / evidentiary | Yes | AIMS, AI governance, responsibilities, continual improvement. | CAISO |
| ISO/IEC 23894 | Voluntary / evidentiary | Yes | AI risk management methodology. | CAISO |
| ISO/IEC 38507 | Voluntary / evidentiary | Yes | Governance model for leadership. | Management / CAISO |
| ISO/IEC 42005 | Voluntary / evidentiary | Yes | AI impact assessment methodology. | CAISO + DPO + owner |