Prototype — this is a working draft, shared for feedback and discussion. Not a finished, certified, or officially adopted framework. Scope — not intended for use as, or in the development of, a regulated medical device.
Home / Governance & Risk
Coverage Matrix

For each source: what it actually says, how many artifacts cite it, and which ones. A narrow count isn't automatically a gap — ISO/IEC 22989 is a terminology standard, so it's correctly cited only where AI vocabulary alignment matters, not everywhere.

EU Artificial Intelligence Act (EU AI Act)
Regulation (EU) 2024/1689
26 artifacts
Risk-tiered EU regulation for AI systems — bans certain practices outright (Art. 5), and imposes graduated requirements (risk management, data governance, transparency, human oversight, conformity assessment) scaled to how high-risk a system is.
Cited by: Business Case & Project Charter, Compliance Analysis, Data Assessment Report, Data Dictionary & Feature Specification, Solution Design Document, Model Development Report, Model Card, System Test Protocol, Sample Test Scripts, Model Validation Report, Test Summary Report, Deployment & Hypercare Plan, AI/Model Monitoring Plan, Periodic Review Report, Change Control Form, Master Regulatory Crosswalk, AI Governance Board Charter, AI System Audit Checklist, Bias Testing & Prevention Developer Guide, AI Incident Report, Conformity Assessment, Retirement & Decommissioning Plan, Instructions for Use, Quality Management System, Fundamental Rights Impact Assessment, AI Application & Model Inventory
General Data Protection Regulation (GDPR)
Regulation (EU) 2016/679
10 artifacts
EU's data protection law — governs the lawful basis for processing personal data, data subject rights (access, erasure, portability), and requires safeguards like data minimization and impact assessments for high-risk processing.
Cited by: Business Case & Project Charter, Compliance Analysis, Data Assessment Report, Solution Design Document, System Test Protocol, Master Regulatory Crosswalk, AI System Audit Checklist, Vendor / Third-Party AI Due Diligence, Retirement & Decommissioning Plan, Fundamental Rights Impact Assessment
Health Insurance Portability and Accountability Act (HIPAA) Security Rule
45 CFR Parts 160 & 164
8 artifacts
US law protecting health information — requires administrative, physical, and technical safeguards for any system that creates, stores, or transmits protected health information (PHI).
Cited by: Business Case & Project Charter, Compliance Analysis, Data Assessment Report, Solution Design Document, System Test Protocol, Master Regulatory Crosswalk, AI System Audit Checklist, Vendor / Third-Party AI Due Diligence
Title 21 Code of Federal Regulations Part 11 (21 CFR Part 11)
Electronic Records; Electronic Signatures
9 artifacts
FDA regulation on electronic records and signatures — requires validated systems, audit trails, and secure electronic signatures for records used in FDA-regulated (pharma/GxP) processes.
Cited by: Business Case & Project Charter, Compliance Analysis, Data Assessment Report, Solution Design Document, IQ/OQ/PQ Qualification Protocol, Periodic Review Report, Change Control Form, Master Regulatory Crosswalk, AI System Audit Checklist
International Organization for Standardization / International Electrotechnical Commission 42001:2023 (ISO/IEC 42001)
AI Management System
10 artifacts
The first certifiable management-system standard for AI — defines how an organization establishes, implements, and continually improves an AI Management System (structured like ISO 27001, but for AI).
Cited by: Business Case & Project Charter, Compliance Analysis, Data Assessment Report, Data Dictionary & Feature Specification, Solution Design Document, Master Regulatory Crosswalk, AI Governance Board Charter, AI System Audit Checklist, Quality Management System, AI Application & Model Inventory
International Organization for Standardization / International Electrotechnical Commission 22989:2022 (ISO/IEC 22989)
AI Concepts & Terminology
2 artifacts
Defines standardized AI vocabulary and concepts — not a compliance requirement itself, but the shared terminology foundation that ISO 42001 and other AI standards are built on.
Cited by: Compliance Analysis, Master Regulatory Crosswalk
National Institute of Standards and Technology (NIST) AI Risk Management Framework (AI RMF) 1.0
AI Risk Management Framework
5 artifacts
A voluntary US framework organized around four functions — Govern, Map, Measure, Manage — for identifying and managing AI risk across a system's lifecycle.
Cited by: Business Case & Project Charter, Solution Design Document, Master Regulatory Crosswalk, AI Governance Board Charter, AI System Audit Checklist
Organisation for Economic Co-operation and Development (OECD) AI Principles
Foundational trustworthy-AI principles
2 artifacts
The first intergovernmental AI policy principles (2019) — establishes high-level values (human rights, transparency, robustness, accountability) that later binding regulations, including the EU AI Act, were substantially built on.
Cited by: Compliance Analysis, Master Regulatory Crosswalk
Open Web Application Security Project (OWASP) LLM Top 10
OWASP Gen AI Security Project
4 artifacts
The most common security vulnerabilities specific to large language model applications — prompt injection, insecure output handling, training-data poisoning, and similar LLM-specific risks.
Cited by: Solution Design Document, System Test Protocol, Sample Test Scripts, AI System Audit Checklist
Open Web Application Security Project (OWASP) Agentic Top 10 (2026)
OWASP Gen AI Security Project
4 artifacts
Emerging security risks specific to autonomous multi-agent AI systems — agent goal hijacking, tool misuse, unsafe inter-agent communication, and cascading agent failures.
Cited by: Solution Design Document, System Test Protocol, Sample Test Scripts, AI System Audit Checklist
Open Web Application Security Project (OWASP) ML Security Top 10
OWASP Foundation
2 artifacts
Security risks specific to traditional machine learning systems — data poisoning, model theft/extraction, adversarial evasion attacks, and ML supply-chain risks.
Cited by: Data Assessment Report, Data Dictionary & Feature Specification
Good Automated Manufacturing Practice (GAMP) 5 (2nd Ed.)
ISPE — Risk-Based GxP Computerized Systems
1 artifact
A pharma-industry framework for validating computerized systems using a risk-based approach — ensures GxP systems are tested proportionate to risk, not uniformly over-tested.
Cited by: IQ/OQ/PQ Qualification Protocol
Good Automated Manufacturing Practice (GAMP) Guide: AI
ISPE — GAMP 5 extended to AI-enabled GxP systems
1 artifact
Extends GAMP 5's risk-based validation approach specifically to AI/ML-enabled systems used in GxP-regulated environments.
Cited by: IQ/OQ/PQ Qualification Protocol
Model Cards for Model Reporting
Mitchell et al., 2019
2 artifacts
Academic paper (Mitchell et al., 2019) proposing a standardized short document that accompanies a trained model — its intended use, performance across subgroups, and known limitations.
Cited by: Model Card, System Card
Datasheets for Datasets
Gebru et al., 2021
4 artifacts
Academic paper (Gebru et al., 2021) proposing standardized documentation for datasets — how they were collected, their composition, and appropriate vs. inappropriate downstream uses.
Cited by: Data Assessment Report, Data Dictionary & Feature Specification, Model Development Report, Model Card
AI Governance Committee Guide
Trustible, 2026
1 artifact
Practitioner guidance on structuring an internal AI governance body — roles, escalation paths, and decision rights for an AI Governance Board.
Cited by: AI Governance Board Charter
AI Governance Best Practices Guide
Cogitx, 2026
1 artifact
Practitioner guidance on operationalizing AI governance day-to-day — similar in scope to the Trustible guide, from a different practitioner source.
Cited by: AI Governance Board Charter
MITRE ATLAS
The MITRE Corporation
2 artifacts
Adversarial tactics/techniques knowledge base for AI systems — not a compliance requirement itself, but the reference catalog used to structure red-teaming and threat-modeling test coverage against documented real-world attacks.
Cited by: System Test Protocol, Statistical & Technical Methods Reference
NIST AI RMF Agentic Profile
Cloud Security Alliance Labs, 2026
1 artifact
Extends NIST AI RMF's Measure and Manage functions to autonomous multi-agent systems. An industry whitepaper filling a gap NIST itself has acknowledged — not yet a finished NIST publication.
Cited by: AI/Model Monitoring Plan
EU AI Act — Clause-Level Detail

The EU AI Act is the most complex source cited across this playbook. This table goes one level deeper than the matrix above: for each of the 18 Articles already addressed somewhere in the playbook, what it requires and the exact section that addresses it.

ArticleWhat It Actually RequiresArtifactExact Section / Question
Art. 5 Prohibits 8 specific AI practices outright (social scoring, exploiting vulnerabilities, subliminal manipulation, real-time public biometric ID for law enforcement, workplace/education emotion recognition, sensitive-attribute biometric categorization, untargeted facial scraping, predictive policing) — no risk tier or mitigation applies; these cannot be built. Compliance Analysis Section 8, “Step One — Prohibited Practices Screen” (hard-stop callout before classification)
Art. 6 / Annex III Defines which AI systems count as High-Risk by naming 9 specific use-case categories (medical devices, vehicles, recruitment/HR, education, essential services, critical infrastructure, law enforcement, migration/justice, biometrics). Compliance Analysis Section 8, Axis 2 (EU AI Act Risk Tier) — Annex III category checklist note under the High-Risk checkbox
Art. 9 Requires a continuous, iterative risk management system across the AI system's lifecycle — not a one-time assessment. AI Risk Register / AI Solutions FMEA Both artifacts (ongoing use); confirmed as a genuine system, not just artifacts existing, in QMS Section 4 (“Risk Management System”)
Art. 10 Requires data governance covering acquisition, quality, representativeness, bias examination, and data-gap documentation for training/validation/test data. Data Assessment Report Sections 2–3 (Data Quality Assessment; Data Representativeness & Early Bias Screening)
Art. 11 / Annex IV Requires comprehensive technical documentation covering system description, development process, risk management, monitoring, and standards applied — compiled before market placement. Conformity Assessment Section 2, “Technical Documentation Compilation (Annex IV)” — element-by-element checklist
Art. 12 Requires the system to automatically log events across its lifetime, enabling traceability and post-market monitoring. Instructions for Use Section 7, “System Lifetime, Maintenance & Logging”
Art. 13 Requires the system to be accompanied by instructions for use covering intended purpose, performance characteristics, known limitations, and interpretation guidance for the deployer. Instructions for Use Whole document (Sections 1–4 specifically); Solution Design Section 5 addresses this at design time
Art. 14 Requires human oversight measures be designed in — the ability for a human to understand, monitor, and intervene in or override the system's operation. Instructions for Use Section 5, “Human Oversight Measures” + “Deactivation & Restriction Controls”; Solution Design Section 5
Art. 15 Requires an appropriate level of accuracy, robustness, and cybersecurity, consistently maintained throughout the lifecycle. System Test Protocol / Model Validation Report System Test Protocol Section 5, “Test Types & Coverage” (AI/Model Verification row); Model Validation Report (whole document)
Art. 17 Requires a Provider-level Quality Management System covering compliance strategy, design control, data management, risk management, post-market monitoring, incident reporting, record-keeping, and accountability. Quality Management System Whole document — an index confirming the above artifacts function as one system, not 11 disconnected ones
Art. 27 Requires certain Deployers (public bodies, public-service providers, or credit/insurance risk-assessment use cases) to assess a specific deployment's impact on fundamental rights before use. Fundamental Rights Impact Assessment Whole document — explicitly Deployer-side, with an applicability gate before Section 1
Art. 43 Defines the conformity assessment procedure a High-Risk system must undergo before market placement (internal control, or third-party/notified body, depending on category). Conformity Assessment Section 1, “Scope & Applicability”; Section 3, “Conformity Assessment Outcome”
Art. 47 Requires a formal Declaration of Conformity be issued and retained once conformity assessment is complete. Conformity Assessment Section 4, “Declaration of Conformity”
Art. 49 Requires High-Risk systems be registered in the EU public database before being placed on the market. Conformity Assessment; AI Application & Model Inventory Section 3 (registration referenced as part of the conformity outcome); AI App & Model Inventory References & Sources block (registration duty cited as basis for the internal register)
Art. 71 Establishes and requires the Commission to set up and maintain the EU database that Art. 49 registrations are entered into — the database itself, not the registration duty. AI Application & Model Inventory References & Sources block — cited as the database Art. 49 registration feeds; this artifact is the internal register that precedes external submission
Art. 50 Requires end-user-facing disclosure when a person interacts with generative AI, and labeling/watermarking of AI-generated synthetic content (with a stricter rule for deepfake-like content). Solution Design Document Section 5, “EU AI Act Art. 50 — Generative AI Disclosure” block
Art. 72 Requires Providers to actively collect and analyze post-market performance data as an operating system, not just a design intention. AI/Model Monitoring Plan Section 5, “Hypercare-to-Steady-State Cadence Step-Down”; confirmed as a real system (not just a plan) in QMS Section 5
Art. 73 Requires serious incidents be reported to the relevant market surveillance authority within a defined timeframe. AI Incident Report Reportability test (whole document); QMS Section 6, “Serious Incident Reporting Procedures” confirms the org-level process around it
Other Regulations — Clause-Level Detail

Same treatment, extended to GDPR, HIPAA, NIST AI RMF, and ISO/IEC 42001.

Known Gap — Not Glossed Over

NIST AI RMF's Manage function isn't explicitly cited anywhere in this playbook yet. The AI Risk Register and Quality Management System (Section 4) cover the underlying substance — prioritizing and acting on identified risks — but neither names the Manage function directly. This surfaced while compiling this page, and is left visible rather than quietly patched over. See the highlighted row below.

RegulationClauseWhat It Actually RequiresArtifactExact Section / Question
GDPR Art. 6 Requires a valid lawful basis (consent, contract, legitimate interest, etc.) before personal data can be processed. Compliance Analysis Section 5, “Data Privacy Deep-Dive”
GDPR Art. 9 Imposes a stricter basis requirement for special-category data — health, biometric, and other sensitive personal data. Compliance Analysis Section 5, “Data Privacy Deep-Dive”
GDPR Art. 32 Requires appropriate technical and organizational security measures proportionate to the risk of processing. System Test Protocol / AI System Audit Checklist System Test Protocol Section 5 (Security test type)
GDPR Art. 35 Requires a Data Protection Impact Assessment before processing likely to result in high risk to individuals. Compliance Analysis / Business Case & Charter Compliance Analysis Section 5; Business Case & Charter Section 5 (DPIA trigger question)
HIPAA §164.312 Security Rule technical safeguards — access control, unique user identification, audit controls, encryption. Solution Design Document Section 6, “Security & Privacy by Design”
HIPAA Minimum Necessary Standard Limits use/disclosure of protected health information to the minimum needed for the intended purpose. Data Assessment Report Section 4, “Privacy & Sensitive Data Mapping”
NIST AI RMF Govern Establishes organizational culture, risk tolerance, and accountability structures for AI risk management. Business Case & Charter / AI System Audit Checklist Business Case & Charter, EU AI Act/NIST framework tag (risk tolerance ownership question)
NIST AI RMF Map Identifies system context, boundaries, and potential impacts before risk can be meaningfully measured. Solution Design Document / System Test Protocol Solution Design Section 7 (system boundaries question); Threat Modeling (System Test Protocol)
NIST AI RMF Measure Analyzes, assesses, and tracks identified risks using appropriate methods. System Test Protocol Red Teaming and Computer Vision robustness rows, Section 5
NIST AI RMF Manage Prioritizes and acts on risks based on the Measure function's findings; the follow-through step. Not currently an explicit citation anywhere — the AI Risk Register and QMS Section 4 cover this in substance but don't cite the Manage function by name. A real, honest gap.
ISO/IEC 42001 Annex A.2 / A.3 Requires defined organizational roles, responsibilities, and leadership commitment to the AI Management System. AI System Audit Checklist / Business Case & Charter AI System Audit Checklist; Business Case & Charter (AIMS scope question)
ISO/IEC 42001 Annex A.6 Requires life-cycle controls across an AI system's design, development, and deployment stages. Solution Design Document Section 8, framework tag (Annex A.6 life-cycle design controls question)
ISO/IEC 42001 Annex A.7 Requires documented data governance — provenance, quality, and category classification for AI system data. Data Assessment Report / AI System Audit Checklist Data Assessment Report, framework tag; AI System Audit Checklist
ISO/IEC 42001 Clause 9.1 Requires ongoing performance evaluation of the AI Management System — monitoring, measurement, and analysis. AI System Audit Checklist Performance evaluation section (Clause 9.1 citation)