ReguNav

Frameworks

13 frameworks shipped in V1 — every one declared as a dictionary so a single classification engine, evidence matcher, and obligation tracker work across all of them. New frameworks land monthly.

EU AI Act

(EU) 2024/1689EUofficial ↗

Risk-classified AI systems · Annex III high-risk · GPAI · post-market monitoring · serious-incident reporting · FRIA · transparency Art 50/53

ISO/IEC 42001:2023

First AI Management SystemGlobalofficial ↗

AIMS structure · risk treatment · impact assessment · operational planning · supplier requirements · monitoring + measurement · improvement

ISO/IEC 27001:2022

Information Security MSGlobalofficial ↗

Annex A controls (93) · ISMS scope · risk treatment · management review · continual improvement · Annex SL aligned

ISO/IEC 27701:2019

Privacy MS extension to 27001Globalofficial ↗

PII processor + controller · 6.x extension to ISO 27001 · privacy by design · data subject rights

GDPR

(EU) 2016/679EU/EEAofficial ↗

Lawful basis · Art 22 automated decisions · Art 25 by-design · Art 28 processors · Art 35 DPIA · Art 32 security · breach notification

HIPAA

Security & Privacy RulesUSofficial ↗

Administrative · physical · technical safeguards · BA agreements · breach notification · individual rights · accounting of disclosures

SOC 2 Type II

AICPA Trust Services CriteriaUS/Globalofficial ↗

CC1-CC9 · A1 availability · C1 confidentiality · PI1 processing integrity · P1-P8 privacy · 12-month observation period

SOC 1 Type II

ICFR-relevant controlsUS/Globalofficial ↗

Controls relevant to financial reporting at user entities · 6-12 month testing · ISAE 3402 alignment

PCI DSS 4.0.1

Payment Card IndustryGlobalofficial ↗

12 requirements · cardholder-data protection · network segmentation · access control · vulnerability management · monitoring

NIST AI RMF 1.0

AI risk-management frameworkUS/Globalofficial ↗

Govern · Map · Measure · Manage · trustworthy AI characteristics · profiles for use cases

NIST CSF 2.0

Cybersecurity frameworkUS/Globalofficial ↗

Govern · Identify · Protect · Detect · Respond · Recover · 6 functions · Implementation Tiers · Profiles

DORA

(EU) 2022/2554EU/EEAofficial ↗

ICT risk management · ICT incident reporting · digital operational resilience testing · ICT third-party risk · information sharing

CCPA / CPRA

California privacy lawUSofficial ↗

Consumer rights · sensitive personal info · service-provider obligations · automated decision-making opt-out · risk assessments

Custom frameworks

On the Enterprise plan, bring us any regulation, standard, or internal control catalog and we'll model it as a dictionary entry within 30 days. Includes clauses, controls, evidence types, and crosswalks to the 13 built-in frameworks.

Request a framework →