Coverage

The regulations AIssure maps to.

AIssure is built for regulated finance, so it maps to the regimes that actually bind banks, asset managers and insurers — not a generic AI-ethics checklist. Coverage spans eight jurisdictions and the supervisory instruments within them, every finding traced to source.

The regulations AIssure maps to

Coverage spans eight jurisdictions — the UK, the EU, the US, Singapore, Hong Kong, Australia, South Africa and China — and the instruments within them that bind AI in financial services. The point of mapping to named regimes rather than an abstract ethics framework is defensibility: when a supervisor, a board or a counterparty asks how you govern AI, the answer is a cited trail to the primary provision, not a narrative.

Each regime below links to a factual explainer of what it requires and how AIssure maps to it, or to the primary source where the instrument speaks for itself. The grounding runs on a regulatory knowledge graph of 14,000+ provisions, and a fabricated citation is stripped before it ever reaches the report.

Regimes & standards

Regime Jurisdiction What it is
EU AI Act EU Regulation (EU) 2024/1689 — a risk-tiered regime for providers and deployers of AI, with prohibited-practice and general-purpose-AI obligations already in force.
PRA SS1/23 UK The PRA's model-risk management principles for banks, effective May 2024 — five principles spanning identification, governance, independent validation and mitigants.
FCA SYSC UK The FCA's Senior Management Arrangements, Systems and Controls sourcebook — systems and controls proportionate to the risk an activity carries.
DORA EU The EU's Digital Operational Resilience Act — ICT and operational-resilience requirements for financial entities and their critical technology providers.
POPIA South Africa South Africa's Protection of Personal Information Act — lawful processing of personal information, including automated decision-making.
ISO/IEC 42001 International The international management-system standard for AI — the framework an accredited certification body assesses for AI-management-system certification.
FAQ

Regulatory coverage — the questions we get.

What risk, compliance and procurement teams ask about which regimes AIssure maps to.

Which regulations does AIssure map to?

AIssure is built for regulated finance, so it maps to the instruments that actually bind banks, asset managers and insurers across eight jurisdictions — the UK, the EU, the US, Singapore, Hong Kong, Australia, South Africa and China. That includes the EU AI Act, the FCA's SYSC sourcebook, the PRA's SS1/23 model-risk principles, DORA, POPIA and the ISO/IEC 42001 management-system standard, rather than a generic AI-ethics checklist.

How does AIssure keep its regulatory coverage current?

Coverage lives on a regulatory knowledge graph of 14,000+ provisions across eight jurisdictions. Every finding an assessment produces links back to the primary provision it rests on, so the board pack reads as 'the regulation says', not 'the AI says' — and a fabricated citation is stripped before it reaches the page. When an instrument changes, the graph is versioned rather than re-remembered.

Does AIssure cover regulations outside financial services?

The framework is tuned for regulated finance, but several of the instruments it maps to are cross-cutting — the EU AI Act and ISO/IEC 42001 apply well beyond banking. What AIssure deliberately does not do is claim blanket coverage of every AI rule everywhere; it maps the supervisory instruments that bind the firms it serves, and cites them.

Is an AIssure assessment a substitute for legal advice?

No. AIssure produces a point-in-time, regulator-defensible assessment of how your firm governs its AI, with every finding traced to source. That is an evidence base a board, a supervisor or a certification body will accept — but it is an independent assessment, not legal advice, and it does not replace counsel on how a specific regulation applies to your firm.

Next step

Start with a thirty-minute read on your readiness.

A high-level, question-only session — 12 to 16 questions, no evidence to prepare — for an initial view of your AI governance maturity and readiness. It sets the scene for a full engagement: the audit platform deployed and evidence-based assessments run, self-serve or consultant-supported.