The regulatory atlas — mapping obligations to controls
A Regulatory Field Guide · Companion to the GRC course

The Regulatory Atlas

The ten frameworks in the GRC database — what each one is, who it binds, what it demands, and what happens if you ignore it. From GDPR to the EU AI Act.

How to read this atlas

Law, standard, or framework — know which you're holding

Not everything here is a “law.” The distinction changes what non-compliance costs you, so it's the first thing to check on any entry:

Each entry is tagged by domain (colored), jurisdiction, instrument type, and the year it took effect. Here's the whole landscape, grouped by what it protects:

Financial & corporate
SOX — US financial reporting
01

General Data Protection Regulation

GDPR
PrivacyEuropean UnionLaw · Reg (EU) 2016/679In force 2018
What

The EU's comprehensive personal-data law. It governs how any organization collects, uses, stores, and shares personal data about people in the EU/EEA — and it applies even if your company sits outside Europe, as long as you handle Europeans' data (extraterritorial reach).

Who

Anyone processing EU residents' personal data. It splits roles into the controller (decides why/how data is used) and the processor (handles it on the controller's behalf). Larger operations must appoint a Data Protection Officer (DPO).

Requires
  • A lawful basis for every use of data (consent, contract, legal obligation, legitimate interests, etc.).
  • Core principles: purpose limitation, data minimization, accuracy, storage limitation, security, accountability.
  • Data-subject rights: access, correction, erasure (“right to be forgotten”), portability, objection, and a right not to be subject to solely automated decisions (Art. 22).
  • Breach notification to the regulator within 72 hours; a DPIA for high-risk processing.
Teeth

Fines up to €20 million or 4% of global annual turnover, whichever is higher.

Why it matters

It set the global template — most modern privacy laws copy it. For AI, Art. 22 (automated decisions) collides directly with the AI Act: an AI that auto-rejects a loan triggers both. You can't govern AI without GDPR in the room.

02

Sarbanes-Oxley Act

SOX
FinancialUnited StatesLaw · 2002Public companies
What

A US federal law passed after the Enron and WorldCom accounting scandals. Its aim: make corporate financial statements trustworthy by forcing strong internal controls and holding executives personally accountable for them.

Who

US publicly traded companies (and foreign firms listed on US exchanges), plus their auditors. It created the PCAOB to oversee those auditors.

Requires
  • Section 302: the CEO and CFO personally certify each financial report is accurate.
  • Section 404: management and the external auditor must assess and attest to Internal Control over Financial Reporting (ICFR) — the famous, expensive one.
  • Section 802: records-retention and anti-document-shredding rules.
  • Whistleblower protections; independent audit committees.
Teeth

Criminal: executives face fines and up to 20 years' imprisonment for willful false certification or fraud.

Why it matters

SOX is why “segregation of duties,” “journal-entry approval,” and “control testing” are everyday words in finance. It made internal control a board-level, legally-personal obligation — the mindset all of GRC inherited.

03

Health Insurance Portability & Accountability Act

HIPAA
Health privacyUnited StatesLaw · 1996PHI
What

The US law protecting Protected Health Information (PHI) — medical records and any health data that can identify a person. It sets national standards for keeping that information private and secure.

Who

Covered entities — health providers, health plans, and clearinghouses — and their business associates (vendors that touch PHI, e.g. a cloud host or a billing firm).

Requires
  • Privacy Rule: limits use/disclosure of PHI to the “minimum necessary.”
  • Security Rule: administrative, physical, and technical safeguards for electronic PHI (access controls, encryption, audit logs).
  • Breach Notification Rule: notify affected individuals (and, for large breaches, the media and regulator).
Teeth

Tiered civil penalties (up to ~$1.9M per violation category per year) and criminal penalties up to 10 years' imprisonment for knowing misuse.

Why it matters

The template for sector-specific data protection. Its “safeguards” trio (admin/physical/technical) is a clean way to teach that security isn't just technology — it's also people and process. Vital for any healthcare AI (e.g. the triage example in the main course).

04

ISO/IEC 27001:2022

ISO 27001
SecurityInternationalStandard (certifiable)2022 revision
What

The world's leading standard for an Information Security Management System (ISMS) — a documented, risk-based way of running security across the whole organization. Not a law: you get certified against it by an accredited auditor.

Who

Any organization, voluntarily — but very often required by customers as a condition of doing business, especially in B2B and cloud.

Requires
  • A working ISMS built on risk assessment and treatment.
  • Consideration of 93 controls in Annex A, grouped into four themes: Organizational, People, Physical, Technological.
  • Continual improvement (the Plan-Do-Check-Act cycle) and management review.
Teeth

No government fine — but you can fail or lose certification (via 3-year cycles with annual surveillance audits), which can cost you contracts.

Why it matters

It teaches the management-system idea: security isn't a one-time project but a governed, repeating cycle. That exact pattern is what the AI world is now copying (see AICM, and its real cousin ISO 42001).

05

Payment Card Industry Data Security Standard

PCI DSS
SecurityInternationalIndustry standard (contractual)v4.0
What

A security standard for anyone who stores, processes, or transmits credit-card data. It's set not by a government but by the card brands' council (the PCI SSC — Visa, Mastercard, Amex, etc.) and enforced through your contracts with banks and processors.

Who

Every merchant and service provider that handles cardholder data — from a corner shop to a global platform. Your transaction volume sets your validation level (a simple self-questionnaire vs. a full on-site audit).

Requires

12 requirements across 6 goals: build/maintain a secure network, protect stored cardholder data (encryption), manage vulnerabilities, enforce strong access control (incl. MFA), monitor and test networks, and maintain a security policy.

Teeth

Contractual fines from card brands, higher transaction fees, and — the real killer — losing your ability to accept card payments.

Why it matters

The clearest example that “compliance” isn't always “law.” A private contract can bind you just as hard as a statute. Great for teaching that the source of an obligation matters less than its consequences.

06

NIST Cybersecurity Framework

NIST CSF
SecurityUnited StatesVoluntary frameworkv2.0 (2024)
What

A voluntary, outcome-based framework from the US National Institute of Standards and Technology for organizing an entire cybersecurity program into a shared language. Not a checklist of controls — a map of outcomes to aim for.

Who

Originally for US critical infrastructure; now used worldwide, across every sector, because it's flexible and free.

Requires

Nothing mandatory — you self-adopt. It's built on six core functions (v2.0 added the first): Govern, Identify, Protect, Detect, Respond, Recover. Organizations rate their maturity in Tiers (1–4) and set target Profiles.

Teeth

None directly — but it's the de-facto benchmark regulators and courts point to when asking “was your security reasonable?”

Why it matters

Its six functions are a superb mental model for any risk domain, including AI. Note that v2.0 added Govern at the top — the whole field is realizing, as this course argues, that governance comes first.

07

California Consumer Privacy Act

CCPA / CPRA
PrivacyCalifornia, USLaw · 2018 (CPRA 2023)
What

California's landmark privacy law — the US's closest answer to GDPR — later strengthened by the CPRA amendment. It gives California residents control over the personal information businesses collect about them.

Who

For-profit businesses that handle Californians' data and meet a threshold (e.g. ~$25M+ revenue, or data on 100k+ consumers, or majority of revenue from selling data). Enforced by a dedicated agency, the CPPA.

Requires
  • Consumer rights to know, delete, correct, and opt out of the sale/sharing of their data.
  • A right to limit use of sensitive personal information.
  • Non-discrimination for exercising these rights.
Teeth

Civil penalties of $2,500 per violation, rising to $7,500 for intentional violations or those involving minors — multiplied across thousands of consumers.

Why it matters

Shows that privacy law is fragmenting by geography — a US company can face GDPR, CCPA, and a dozen other state laws at once. Managing that patchwork is a core GRC job, and AI training data makes it harder.

08

EU Artificial Intelligence Act

AI Act
AI governanceEuropean UnionLaw · Reg (EU) 2024/1689Phasing in 2025–2027
What

The world's first comprehensive AI law. It regulates AI by risk tier: the more potential for harm, the heavier the obligations — from an outright ban down to no rules at all.

Who

Providers (who build/place AI on the market) and deployers (who use it), anywhere in the world, if the AI's output is used in the EU. Extraterritorial, like GDPR.

Requires
  • Unacceptable riskbanned (social scoring, manipulative AI).
  • High risk (Annex III: credit, hiring, biometrics…) → full regime: risk management, data governance, human oversight, technical documentation, conformity assessment, and EU registration.
  • Limited risk (chatbots, deepfakes) → transparency only.
  • Minimal risk → no obligations. Separate rules cover general-purpose AI models.
Teeth

Up to €35M or 7% of global turnover (banned uses); €15M or 3% (most obligations); €7.5M or 1% (misinformation to regulators). High-risk duties apply from August 2026.

Why it matters

This is the framework the whole GRC course orbits. Its risk-tier logic — do the governance work in proportion to the danger — is the model every organization now has to operationalize. Explored in depth in Module 04 of the main course.

09

AI Compliance Management

AICM
AI governanceInternationalManagement frameworkLifecycle
What

The discipline of keeping AI compliant over its whole lifecycle — not just at launch. Where the AI Act says what you must achieve, AICM is the how: the standing processes that make compliance repeatable and durable.

Who

Any organization operating AI systems it must keep compliant as models, data, and laws all change over time.

Requires
  • Risk classification of every system before build.
  • Standing conformity-assessment and documentation processes (not one-offs).
  • Post-market monitoring for drift and incidents.
  • Lifecycle tracking from development through decommissioning.
Reality check

“AICM” is this dataset's stand-in for a real practice area rather than a single named law. Its real-world cousins are ISO/IEC 42001:2023 (the AI management-system standard) and the NIST AI Risk Management Framework. Teach it as the management-system layer for AI.

Why it matters

It's what stops compliance from decaying. A model that passed its assessment at launch and silently drifted for six months is compliant on paper and dangerous in reality — the AICM lens is what catches that.

10

AI Ethics in the EU

AIEU
AI governanceEuropean UnionEthics guidelinesTrustworthy AI
What

The ethics layer above the law. Where the AI Act sets the legal floor, AIEU raises the bar to what is legitimate and trustworthy — the practices that keep public trust even where the law is silent.

Who

Anyone building AI that affects people, especially in high-stakes settings where “legal” isn't the same as “acceptable.”

Requires
  • Transparency & explainability — people can understand a decision.
  • Fairness & non-discrimination; human oversight & autonomy.
  • Accountability, robustness & safety, and protection of fundamental rights.
Reality check

Like AICM, “AIEU” represents a practice area, not one statute. Its real basis is the EU's Ethics Guidelines for Trustworthy AI (2019), whose seven requirements the list above mirrors. Many are now hard law inside the AI Act — ethics that graduated into obligation.

Why it matters

It's the reminder that governance isn't only about avoiding fines — it's about deserving trust. The gap between “legal” and “right” is exactly where reputations are made or lost.


One-screen summary

The ten at a glance

#FrameworkDomainWhereTypeWhat happens if you ignore it
1GDPRPrivacyEULawUp to €20M / 4% global turnover
2SOXFinancialUSLawExecutive fines + up to 20 yrs prison
3HIPAAHealth privacyUSLawCivil fines + up to 10 yrs prison
4ISO 27001SecurityIntlStandardLose certification → lose contracts
5PCI DSSSecurityIntlContractFines + lose card-processing ability
6NIST CSFSecurityUSVoluntaryNo fine, but the “reasonable security” benchmark
7CCPAPrivacyCaliforniaLaw$2,500–$7,500 per violation
8EU AI ActAIEULawUp to €35M / 7% global turnover
9AICMAIIntlFrameworkCompliance decays; drift goes uncaught
10AIEUAIEUGuidelinesLegal but untrusted; reputational harm

Three patterns worth pointing out to students

  • The consequence, not the label, is what binds you. A contract (PCI) or a lost certification (ISO) can hurt as much as a statute.
  • Privacy is fragmenting; AI is consolidating. Privacy splinters into GDPR + CCPA + dozens of state laws, while AI is being pulled into one horizontal law (the AI Act) plus its ethics and lifecycle layers.
  • Old frameworks still apply to AI. An AI system rarely triggers only the AI rules — GDPR, SOX, and HIPAA all come along for the ride. Govern the system, not the single law.

The Regulatory Atlas — a field guide to the ten frameworks in the GRC database, companion to the courses “GRC for Generative AI” and “The Seven Building Blocks of GRC.” Descriptions of real laws are simplified for teaching and are not legal advice; “AICM” and “AIEU” are the dataset's representations of real practice areas (ISO 42001 / NIST AI RMF; the EU Trustworthy-AI guidelines) rather than single named statutes. Penalty figures are indicative and subject to change.