The regulations AIssure maps to.
AIssure is built for regulated finance, so it maps to the regimes that actually bind banks, asset managers and insurers — not a generic AI-ethics checklist. Coverage spans eight jurisdictions and the supervisory instruments within them, every finding traced to source.
The regulations AIssure maps to
Coverage spans eight jurisdictions — the UK, the EU, the US, Singapore, Hong Kong, Australia, South Africa and China — and the instruments within them that bind AI in financial services. The point of mapping to named regimes rather than an abstract ethics framework is defensibility: when a supervisor, a board or a counterparty asks how you govern AI, the answer is a cited trail to the primary provision, not a narrative.
Each regime below links to a factual explainer of what it requires and how AIssure maps to it, or to the primary source where the instrument speaks for itself. The grounding runs on a regulatory knowledge graph of 14,000+ provisions, and a fabricated citation is stripped before it ever reaches the report.
Regimes & standards
| Regime | Jurisdiction | What it is |
|---|---|---|
| EU AI Act | EU | Regulation (EU) 2024/1689 — a risk-tiered regime for providers and deployers of AI, with prohibited-practice and general-purpose-AI obligations already in force. |
| PRA SS1/23 | UK | The PRA's model-risk management principles for banks, effective May 2024 — five principles spanning identification, governance, independent validation and mitigants. |
| FCA SYSC | UK | The FCA's Senior Management Arrangements, Systems and Controls sourcebook — systems and controls proportionate to the risk an activity carries. |
| DORA | EU | The EU's Digital Operational Resilience Act — ICT and operational-resilience requirements for financial entities and their critical technology providers. |
| POPIA | South Africa | South Africa's Protection of Personal Information Act — lawful processing of personal information, including automated decision-making. |
| ISO/IEC 42001 | International | The international management-system standard for AI — the framework an accredited certification body assesses for AI-management-system certification. |
Regime explainers.
Factual guides to each instrument — what it requires, what already binds, and how AIssure maps your AI to it.
EU AI Act
Regulation (EU) 2024/1689 — risk-tiered obligations for providers and deployers.
→ UKPRA SS1/23
The five model-risk principles UK banks govern their models against.
→ InternationalISO/IEC 42001
The AI management-system standard behind a certification-ready assessment.
→ EUDORA
Digital operational resilience for financial entities and their ICT providers.
→ South AfricaPOPIA
Lawful processing of personal information, including automated decisions.
→ The moatThe regulatory knowledge graph
How the citation trail is built, versioned and verified across eight jurisdictions.
→Regulatory coverage — the questions we get.
What risk, compliance and procurement teams ask about which regimes AIssure maps to.
Which regulations does AIssure map to?
AIssure is built for regulated finance, so it maps to the instruments that actually bind banks, asset managers and insurers across eight jurisdictions — the UK, the EU, the US, Singapore, Hong Kong, Australia, South Africa and China. That includes the EU AI Act, the FCA's SYSC sourcebook, the PRA's SS1/23 model-risk principles, DORA, POPIA and the ISO/IEC 42001 management-system standard, rather than a generic AI-ethics checklist.
How does AIssure keep its regulatory coverage current?
Coverage lives on a regulatory knowledge graph of 14,000+ provisions across eight jurisdictions. Every finding an assessment produces links back to the primary provision it rests on, so the board pack reads as 'the regulation says', not 'the AI says' — and a fabricated citation is stripped before it reaches the page. When an instrument changes, the graph is versioned rather than re-remembered.
Does AIssure cover regulations outside financial services?
The framework is tuned for regulated finance, but several of the instruments it maps to are cross-cutting — the EU AI Act and ISO/IEC 42001 apply well beyond banking. What AIssure deliberately does not do is claim blanket coverage of every AI rule everywhere; it maps the supervisory instruments that bind the firms it serves, and cites them.
Is an AIssure assessment a substitute for legal advice?
No. AIssure produces a point-in-time, regulator-defensible assessment of how your firm governs its AI, with every finding traced to source. That is an evidence base a board, a supervisor or a certification body will accept — but it is an independent assessment, not legal advice, and it does not replace counsel on how a specific regulation applies to your firm.
Start with a thirty-minute read on your readiness.
A high-level, question-only session — 12 to 16 questions, no evidence to prepare — for an initial view of your AI governance maturity and readiness. It sets the scene for a full engagement: the audit platform deployed and evidence-based assessments run, self-serve or consultant-supported.