Skip to main content
Document applicable AI laws and standards, required data protections, and strategies for compliance

Control activities

Typical evidence

Should include?

Identifying relevant regulations. For example, data protection laws. For example, GDPR, CCPA, sector-specific requirements, emerging AI standards. For example, EU AI Act.

Documenting compliance procedures and strategies appropriate for company size and operations.

Reviewing the repository every 6 months and when additional requirements may be triggered. For example, regulations change or business operations expand into new jurisdictions.

E012.1 Documentation: Regulatory compliance reviews

Compliance register, assessment memo or review tickets (e.g. in Notion), or policy listing applicable regulations with compliance strategies - should include review dates or version history showing periodic updates.

Typical location
Internal processes
Capabilities
Universal

Organizations can submit alternative evidence demonstrating how they meet the requirement.