Frameworks, Standards, & Regulations

Simplify compliance and manage multiple frameworks, standards, and regulations within a unified governance platform. Whether you’re implementing a new framework, adapting to changing regulatory requirements, or managing compliance across the enterprise, SAI360 helps your organization maintain continuous compliance readiness.

Reduce the complexity of managing multiple compliance requirements with a connected approach to risks, controls, assessments, and evidence. Reuse controls across applicable frameworks to reduce duplicate work and maintain greater consistency across your compliance programs.

Access pre-mapped standards and controls to streamline compliance activities and keep requirements easier to manage as regulations evolve. SAI360 helps teams maintain visibility, strengthen accountability, and stay continuously prepared for audits, assessments, and regulatory reviews.

AICPA SOC 2

Developed by the AICPA, SOC 2 defines security standards for managing data and preventing unauthorized access to assets, essential for service organizations handling sensitive information.

APRA CPS230

The Australian Prudential Regulation Authority’s CPS230 standard ensures banks, insurers, and superannuation funds manage operational risk and protect the stability of Australia’s financial system.

COSO Principles

COSO Principles guide organizations to assess risks, strengthen internal controls, and maintain ethical, transparent processes based on established frameworks for enterprise risk management.

EU Artificial Intelligence (AI) Act

The EU AI Act establishes a unified, risk-based framework to regulate the development and use of AI, ensuring systems are safe, transparent, and aligned with fundamental rights.

EU Corporate Sustainability Due Diligence Directive (CSDDD)

The CSDDD requires companies to identify, address, and document human rights and environmental risks across global supply chains, with strict oversight of both direct and indirect suppliers.

EU Corporate Sustainability Reporting Directive (CSRD)

The CSRD expands corporate disclosure requirements across environmental, social, and governance (ESG) issues, mandating detailed reports on sustainability practices, human rights, and corporate accountability.

 EU Deforestation Regulation
(EUDR)

The EU Deforestation Regulation (EUDR) requires companies to prove their products are deforestation-free, legally sourced, and fully traceable across the entire supply chain.

EU Digital Operational Resilience Act (DORA)

DORA establishes EU-wide requirements for financial firms to strengthen digital operational resilience, safeguard against cyber threats, and ensure the continuity of critical services under stress.

EU Whistleblower Directive

Requires EU organizations to provide secure reporting channels and protect whistleblowers from retaliation when reporting breaches of Union law.

GDPR

The General Data Protection Regulation (GDPR) imposes strict requirements on how organizations collect, process, store, and protect personal data.

HIPAA

Health Insurance Portability and Accountability Act (HIPAA) sets strict requirements for how healthcare organizations protect and manage patient health information

ISO
27001

ISO/IEC 27001 sets a global standard for information security management systems, helping organizations protect the confidentiality, integrity, and availability of their corporate data.

NIST CMMC

The Cybersecurity Maturity Model Certification (CMMC) establishes cybersecurity standards for U.S. defense contractors to protect controlled unclassified information across the defense industrial base.

NIST CSF

The NIST Cybersecurity Framework (CSF) provides structured guidance for managing cybersecurity risks, focusing on identification, protection, detection, response, and recovery activities across organizations.

NIST SP 800-53

NIST SP 800-53 outlines comprehensive security and privacy controls to protect federal information systems and support risk management across a range of industries.

NIST SP 800-66

NIST SP 800-66 offers a framework for HIPAA-covered entities to secure electronic protected health information (ePHI) and comply with regulatory health data protections.

SEC Climate Disclosures Rule

The SEC Climate Disclosure Rule requires U.S. companies to publicly report climate-related risks, greenhouse gas emissions, and the financial impacts of environmental factors on their business.

Sarbanes-Oxley Act (SOX)

The Sarbanes-Oxley Act enforces corporate financial transparency through strict recordkeeping, internal controls, and reporting practices to deter fraud and protect investors.

Turn your results into an action plan