Skip to content

Frameworks Overview

Modulos supports compliance across multiple AI governance frameworks. Each framework page in this section explains the regulation's scope, its key requirements, and exactly how Modulos maps controls to help you achieve and maintain compliance.

The frameworks below span AI-specific regulations (EU AI Act, ISO/IEC 42001, NIST AI RMF, the CCPA ADMT Regulations, Colorado SB 26-189, NYC Local Law 144), data protection and cybersecurity rules (GDPR, NIS2, DORA, the Cyber Resilience Act, ISO 27001, ISO 27701, UAE PDPL), AI security standards (OWASP Top 10 for LLM and Agentic applications), and regional or corporate governance requirements (UAE AI Ethics, MAS FEAT, Microsoft Supplier DPR).

Not sure which framework applies to you?

See the AI governance frameworks comparison for a side-by-side view of EU AI Act, ISO/IEC 42001, NIST AI RMF, OWASP Top 10 for LLM, GDPR, NIS2, and DORA — and when to use each.

How frameworks work in Modulos

Modulos treats frameworks as structured collections of requirements — the specific obligations your organization must satisfy. You address requirements by implementing controls: documented policies, processes, or technical measures that prove compliance.

Naming update

Framework and requirement names no longer carry the " (app)" / " (org)" suffixes — a framework's scope (application vs organization) comes from the project type it is attached to.

The key advantage of Modulos is cross-framework mapping:

  • One control, multiple frameworks — A single control can satisfy requirements from several frameworks at once. For example, a model documentation control may cover EU AI Act Article 11, ISO 42001 Annex A.5, and NIST AI RMF Map 1.1 simultaneously.
  • Framework versioning — Modulos tracks framework versions and notifies you when regulatory updates affect your projects, so you can assess impact before deadlines.
  • Coverage indicators — Each framework page shows which requirements Modulos helps you address, making gap analysis straightforward.

Cross-framework efficiency

When a control satisfies requirements from multiple frameworks, you implement once and get coverage everywhere. Organizations typically reduce compliance effort by 40–60% compared to managing each framework independently.

Control overlap across AI governance frameworks measures this across the whole framework library, with the shared Controls for every pair.

AI-specific frameworks

EU AI Act
EU AI ActAug 2026

European Union regulation on artificial intelligence systems.

Regulation: EU
EN 18286 QMS
EN 18286 QMS

Quality management system standard for EU AI Act regulatory purposes.

Standard: CEN/CENELEC
ISO/IEC 42001
ISO/IEC 42001

AI management system standard for responsible AI governance.

Standard: ISO
IEEE 7003
IEEE 7003

IEEE standard for algorithmic bias considerations across the AI lifecycle.

Standard: IEEE
NIST AI RMF
NIST AI RMF

Risk management framework for trustworthy AI systems.

Framework: NIST
Colorado SB 26-189
Colorado SB 26-189Jan 2027

Colorado law for covered ADMT that materially influences consequential decisions: developer documentation, deployer notices, post-adverse-outcome correction and commercially reasonable human review, records, and relative-fault allocation.

Regulation: Colorado
CCPA ADMT Regulations
CCPA ADMT RegulationsJan 2027

California Privacy Protection Agency regulations on automated decisionmaking technology under the CCPA: Pre-use Notice, opt-out with conditional exceptions, access to ADMT, risk assessments with Agency submissions, and service-provider and supplier duties.

Regulation: California
NYC Local Law 144
NYC Local Law 144

New York City law on automated employment decision tools: independent bias audits, public results, advance candidate and employee notices, and data disclosures.

Regulation: New York City
OWASP Top 10 for LLM
OWASP Top 10 for LLM

Security risks for large language model applications.

Standard: OWASP
OWASP Top 10 for Agentic
OWASP Top 10 for Agentic

Security risks for agentic AI applications and autonomous workflows.

Standard: OWASP
UAE AI Ethics
UAE AI Ethics

AI ethics principles and guidelines for the UAE.

Regulation: UAE
UAE Consumer AI
UAE Consumer AI

CBUAE guidance on consumer protection and responsible AI/ML use by licensed financial institutions.

Regulation: UAE
MAS FEAT
MAS FEAT

Fairness, Ethics, Accountability and Transparency for financial AI.

Regulation: Singapore
FINMA AI Governance
FINMA AI Governance

FINMA guidance on governance and risk management when using AI, for supervised Swiss financial institutions.

Regulation: Switzerland
Singapore MGF for Agentic AI
Singapore MGF for Agentic AI

IMDA best-practice governance framework for agentic AI systems.

Framework: Singapore
Saudi AI Risk Management
Saudi AI Risk Management

SDAIA's national methodology for identifying, assessing, treating, and monitoring AI risks.

Framework: Saudi Arabia

Data protection and security

Vendor and supply chain


Disclaimer

The content on our website is provided "as is;" no representations are made that the content is up-to-date, complete or error-free. Further, the information provided on this website does not, and is not intended to, constitute legal advice; instead, all information, content, and materials available on this site are for general informational purposes only.

Readers of this website should contact a legal expert to obtain advice with respect to any particular legal matter. Only your individual legal expert can provide assurances that the generalized information contained herein – and your interpretation of it – is applicable or appropriate to your particular situation.

This website contains links to other third-party websites. Such links are only for the convenience of the reader, user or browser; Modulos AG does not recommend or endorse the contents of third-party sites.