Skip to main content
Kenvora AI Logo

Framework directory

Find the right path to compliance.

From healthcare assurance and enterprise security to AI governance, explore 61 frameworks and programs. Start with your customer requirements, your data, and the risks you need to manage.

One program. Connected evidence.

We map shared controls across obligations while keeping each framework’s scope, assessment requirements, and evidence expectations clear.

Discuss your requirements

Security & Trust

Security programs, assurance reports, and continuity for enterprise buyers.

SOC 1 Type 1 & Type 2

Identify controls relevant to customers’ financial reporting, document the system, and prepare evidence for an independent CPA examination.

Discuss SOC 1 Type 1 & Type 2 scope

SOC 3

Plan general-use assurance reporting on Trust Services Criteria with a CPA, and align the underlying evidence with your broader SOC program.

Discuss SOC 3 scope

ISO/IEC 27017

Clarify cloud provider and customer responsibilities, map cloud security controls, and collect evidence across shared infrastructure and service operations.

Explore assessment support

ISO/IEC 27018

Review protection of personally identifiable information in public cloud services, including processor responsibilities, customer commitments, and operational safeguards.

Discuss ISO/IEC 27018 scope

NIST CSF 2.0

Compare current and target cybersecurity profiles across Govern, Identify, Protect, Detect, Respond, and Recover to prioritize a practical improvement roadmap.

Explore assessment support

NIST SP 800-171

Trace controlled unclassified information through nonfederal systems, document safeguards, and align assessment preparation with the revision specified by your contract.

Explore assessment support

CSA STAR / CAIQ

Map cloud security practices to the Cloud Controls Matrix, prepare accurate CAIQ responses, and select the STAR assurance pathway your customers require.

Discuss CSA STAR / CAIQ scope

ISO 22301

Develop a business continuity management system using impact analysis, recovery strategies, exercises, and corrective actions to prepare for certification.

Explore assessment support

Healthcare & Life Sciences

Protect health information and prepare regulated systems for review.

HITRUST AI Security Assessment

Scope AI security risks, governance responsibilities, and technical safeguards alongside your existing HITRUST program, confirming the applicable assessment requirements.

Discuss HITRUST AI Security Assessment scope

HITECH

Review health data protection and breach-response responsibilities alongside HIPAA, including business associate arrangements and incident escalation procedures.

Discuss HITECH scope

21 CFR Part 11

Scope regulated electronic records and signatures, review access and audit trails, and organize validation evidence with the applicable predicate rules.

Discuss 21 CFR Part 11 scope

FDA AI/ML SaMD Guidance

Review AI-enabled medical software documentation, lifecycle controls, and change-management evidence with regulatory specialists for the intended product pathway.

Discuss FDA AI/ML SaMD Guidance scope

EHNAC

Identify the relevant healthcare accreditation program and organize policies, operational evidence, and remediation around its published criteria.

Discuss EHNAC scope

AI Governance

Make AI ownership, risk decisions, and lifecycle controls visible.

ISO/IEC 23894

Integrate AI-specific risk identification, analysis, evaluation, and treatment into existing enterprise risk processes and system lifecycle decisions.

Discuss ISO/IEC 23894 scope

Colorado AI Act

Assess applicability to AI use cases and prepare impact-assessment, notice, oversight, and risk-management workflows against current enacted requirements.

Discuss Colorado AI Act scope

Privacy & Data Protection

Connect data flows, individual rights, and accountable processing.

GDPR

Map personal data processing, review controller and processor roles, and operationalize records, rights requests, impact assessments, and transfer safeguards.

Explore assessment support

CCPA / CPRA

Review applicability, personal information flows, notices, rights-request processes, and service-provider contracts under California’s privacy framework.

Explore assessment support

US State Privacy Laws

Build a state-by-state applicability matrix and reusable request, notice, consent, and assessment workflows while retaining jurisdiction-specific requirements.

Discuss US State Privacy Laws scope

PIPEDA / Québec Law 25

Assess Canadian and Québec privacy obligations, including accountable processing, consent, impact assessments, breach workflows, and vendor arrangements.

Discuss PIPEDA / Québec Law 25 scope

Brazil LGPD

Map Brazilian personal data processing, identify legal bases and responsibilities, and organize individual-rights, security, and incident-response workflows.

Discuss Brazil LGPD scope

UK GDPR & DPA 2018

Review UK processing responsibilities, rights handling, impact assessments, and international transfer arrangements alongside your wider privacy program.

Discuss UK GDPR & DPA 2018 scope

EU–US Data Privacy Framework

Assess eligibility and commitments for the applicable self-certification program, and prepare privacy notices, dispute mechanisms, and ongoing verification processes.

Discuss EU–US Data Privacy Framework scope

FERPA

Review education records, authorized disclosures, access controls, and institutional or service-provider responsibilities for student information.

Discuss FERPA scope

Financial Services

Support payment security, financial controls, and operational resilience.

SOX IT General Controls

Document access, change-management, and IT operations controls that support financial reporting, with evidence aligned to the external auditor’s scope.

Discuss SOX IT General Controls scope

GLBA Safeguards Rule

Assess covered financial activities and strengthen the written information security program, risk assessment, service-provider oversight, and response planning.

Discuss GLBA Safeguards Rule scope

NYDFS Part 500

Review the covered entity’s cybersecurity program, governance, risk assessment, reporting processes, and evidence against applicable requirements and exemptions.

Discuss NYDFS Part 500 scope

EU DORA

Organize ICT risk management, resilience testing, incident reporting, and third-party arrangements for financial entities in the regulation’s scope.

Discuss EU DORA scope

FFIEC CAT Transition

The CAT was retired in August 2025. Map historical assessments to a current cybersecurity approach, such as NIST CSF, and preserve the rationale for transition.

Discuss FFIEC CAT Transition scope

Public Sector & Defense

Prepare systems and evidence for government procurement requirements.

FedRAMP

Define the cloud service boundary and applicable pathway, assess control and evidence gaps, and plan independent assessment and ongoing monitoring preparation.

Explore assessment support

TX-RAMP

Determine the Texas cloud-service assessment scope and risk level, organize required security documentation, and plan maintenance of program obligations.

Discuss TX-RAMP scope

FISMA

Support system categorization, control selection, assessment preparation, and continuous monitoring within the federal agency’s risk-management process.

Discuss FISMA scope

CJIS Security Policy

Map criminal justice information flows, personnel and access safeguards, and service-provider responsibilities to the applicable agency requirements.

Discuss CJIS Security Policy scope

IRS Publication 1075

Identify federal tax information handling, assess safeguarding responsibilities, and prepare system, personnel, and operational evidence for agency review.

Discuss IRS Publication 1075 scope

Global & Sector-Specific

Address regional and industry assurance requested by your buyers.

TISAX

Define automotive information-security assessment objectives, scope locations and information handling, and prepare evidence for the selected assessment level.

Discuss TISAX scope

BSI C5

Prepare cloud control documentation and operating evidence for a C5 examination, including customer responsibilities and service-specific assurance requirements.

Discuss BSI C5 scope

IRAP

Scope the system and relevant Australian government security controls, prepare an evidence package, and coordinate assessment with an endorsed IRAP assessor.

Discuss IRAP scope

Spain ENS

Determine the applicable system category, map security measures, and prepare governance and operational evidence for the required conformity process.

Discuss Spain ENS scope

Cyber Essentials / Plus

Review foundational technical safeguards, define the assessment boundary, and prepare for the appropriate UK certification pathway and verification requirements.

Discuss Cyber Essentials / Plus scope

Singapore MAS TRM

Assess technology risk governance, system security, resilience, and third-party oversight against applicable Monetary Authority of Singapore expectations.

Discuss Singapore MAS TRM scope

Saudi SAMA CSF / NCA ECC

Identify the applicable Saudi sector and national cybersecurity requirements, map control ownership, and prepare implementation and operating evidence.

Discuss Saudi SAMA CSF / NCA ECC scope

UAE Information Assurance

Review applicable UAE information assurance requirements, define the organizational and system scope, and prioritize governance and technical control gaps.

Discuss UAE Information Assurance scope

ISO/IEC 20000-1

Build a service management system with service planning, incident and change processes, performance reviews, and independent certification preparation.

Discuss ISO/IEC 20000-1 scope

Programs include laws, control frameworks, attestations, and certifications. The required pathway depends on your scope and customer obligations. Formal reports, certifications, and authorizations are issued by the relevant independent bodies or authorities.

Compliance Frameworks: Healthcare, Security & AI | Kenvora AI