AICVS is EU AI Act-first, but many teams also need ISO/IEC 42001, SOC 2, ISO 27001, DORA, NIS2, or GDPR views. This page explains what each framework usually asks for and which records AICVS can help organise.
The same AI system record can support several reviews. A system owner, risk classification, vendor file, monitoring record, or incident route should not be rebuilt for every framework. AICVS keeps those records connected, then lets teams export the view they need.
For AI system role, risk tier, high-risk evidence, Annex IV inputs, oversight, monitoring, and incident readiness.
For AI management system governance, objectives, policy, risk treatment, controls, and continuous review records.
For security, availability, confidentiality, processing integrity, privacy, and AI-specific change evidence.
For information security controls that intersect with AI systems, suppliers, access, logging, and secure development.
For operational resilience where AI or SaaS providers support important financial-sector ICT services.
For cybersecurity and privacy records that often sit beside AI governance, including DPIA and incident hand-off.
Product-focused AI regulation for organisations that provide, deploy, import, distribute, or use AI systems in the EU market.
An AI management system standard for governance, policy, risk, objectives, responsibilities, and improvement.
A service organisation assurance framework often used by SaaS buyers to assess trust service criteria.
An information security management standard that often provides the security foundation for AI governance.
EU financial-sector rules for digital operational resilience, ICT risk, incidents, testing, and third-party dependencies.
NIS2 and GDPR are not AI-only frameworks, but they shape many AI governance records involving cybersecurity, personal data, DPIA, and incident handling.
AICVS is designed so the same record can be reused. A vendor file can support EU AI Act provider diligence, SOC 2 supplier review, ISO 27001 supplier controls, and DORA dependency context when relevant.
Choose EU AI Act, ISO 42001, SOC 2, ISO 27001, DORA, NIS2, or GDPR context without turning every review into the same oversized report.
Start readiness checkLast reviewed: 7 August 2026. Next review due 7 November 2026, or sooner if the Commission publishes new guidance. Checked against Regulation (EU) 2024/1689 as published in OJ L of 12.07.2024, the AI Omnibus (in force 27 July 2026), and the Commission's Article 50 transparency guidelines (20 July 2026).
Primary sources: EUR-Lex 2024/1689 · AI Omnibus · Art. 50 guidelines · Commission compliance checker
This is a plain-English summary for planning, not legal advice, and the official text governs. If anything here has gone out of date, please tell us at hello@aicvs.io — we would rather be corrected than confidently wrong.