Compliance Intelligence
AI Compliance
Verified standards, privacy laws, and AI governance frameworks from official issuers. Brel does not assert that any vendor holds a certification unless a cited trust-center disclosure is present on that company profile.
12 compliance frameworks
AI governance
-
AI Act
European Union
The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) is the European Union’s horizontal regulatory framework for AI systems, establishing risk-based obligations for providers and deployers of AI, including prohibited practices and requirements for high-risk AI systems…
-
ISO 42001
ISO / IEC
ISO/IEC 42001 is an international standard for artificial intelligence management systems (AIMS). It specifies requirements for establishing, implementing, maintaining, and continually improving an AIMS within organizations that provide or use AI-based products or services.
-
NIST AI RMF
NIST (U.S. Department of Commerce)
The NIST Artificial Intelligence Risk Management Framework (AI RMF 1.0) is a voluntary framework to help organizations manage risks to people and organizations from AI systems across the AI lifecycle, organized around Govern, Map, Measure, and…
AI application security
-
OWASP Top 10 for LLM Applications
OWASP
The OWASP Top 10 for Large Language Model Applications is a community-maintained awareness document listing critical security risks for LLM-powered applications, such as prompt injection, insecure output handling, and training-data poisoning.
Health privacy
-
HIPAA
U.S. Department of Health & Human Services (HHS)
The Health Insurance Portability and Accountability Act (HIPAA) Privacy, Security, and Breach Notification Rules regulate protected health information (PHI) held by covered entities and their business associates in the United States.
Privacy law
-
CCPA / CPRA
State of California
The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), grants California residents privacy rights regarding personal information collected by covered businesses and imposes corresponding business obligations.
-
GDPR
European Union
The General Data Protection Regulation (Regulation (EU) 2016/679) is the EU’s primary data protection law governing processing of personal data relating to individuals in the EU/EEA, with extraterritorial reach in defined cases.
Security assurance
-
CSA STAR
Cloud Security Alliance
CSA STAR (Security, Trust, Assurance, and Risk) is the Cloud Security Alliance’s program for cloud security assurance, including self-assessment and third-party certification levels built around the Cloud Controls Matrix (CCM).
-
FedRAMP
U.S. General Services Administration (FedRAMP Program)
The Federal Risk and Authorization Management Program (FedRAMP) provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services used by U.S. federal agencies.
-
ISO/IEC 27001
ISO / IEC
ISO/IEC 27001 is an international standard specifying requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS).
-
PCI DSS
PCI Security Standards Council
The Payment Card Industry Data Security Standard (PCI DSS) is a set of security requirements for organizations that store, process, or transmit cardholder data, maintained by the PCI Security Standards Council.
-
SOC 2
AICPA
SOC 2 is an AICPA attestation framework for service organizations. Independent auditors report on controls related to Trust Services Criteria (security, availability, processing integrity, confidentiality, and/or privacy) over a defined period or point in time.
Integrations → · APIs & SDKs → · AI Glossary → · Industries →