SOC 2Security, availability, confidentiality
Trust services criteria turn on who had access to what, and whether someone owned it. Control ownership and access evidence accumulate as you operate rather than being assembled in the weeks before fieldwork.
ISO 27001:2022Annex A, including the 2022 additions
Annex A expects an asset inventory that is actually maintained, and the 2022 revision adds threat intelligence and cloud services. One record per asset, reconciled from fifteen sources, is what the statement of applicability is written against.
ISO 42001The AI management system standard
The AI management system standard asks for a model inventory with ownership and lifecycle. Providers, models, agents and keys are already tracked as assets here — with an owner, a purpose and a retirement date.
DPDP ActIndia — in force 13 May 2027
India’s data protection regime. The DPDP Rules 2025 (G.S.R. 846(E)) were notified on 13 November 2025, with full compliance due 13 May 2027. The question it forces is which model touched which personal data, under whose authority.
SEBI CSCRFCapital markets cyber resilience
The Cybersecurity and Cyber Resilience Framework asks regulated entities for measurable control posture across the estate — not a point-in-time report, which is why evidence has to collect itself.
RBI directionsIT governance and outsourcing
The IT governance and outsourcing directions already expect a defensible asset and access position from banks and NBFCs. AI arrived without one — holding standing credentials no joiner-mover-leaver process ever saw.
IRDAI guidelinesInformation and cybersecurity
Information and cybersecurity guidelines put the burden on demonstrable control ownership for every system touching policyholder data — including the ones adopted faster than they were reviewed.
EU AI ActRisk-tiered obligations per system
Obligations scale with the risk tier of each system, which presumes you can say what each system is for. A model inventory with a stated purpose per deployment is the precondition.
Cross-mapped across nineteen frameworks in total; the eight above are the ones we are asked about most, and a walkthrough confirms the rest against your own scope. Regulatory dates current as of 25 September 2026. Confirm exact clause mapping with your auditor — this is not legal advice.