Active public standards
Each page explains what the standard is, why it matters, and how Quick Policy helps teams draft and govern policies against it.
Browsing all 404 standards. Search by name, code or plain-English purpose.
ICAEW AAF 01/20 — Assurance Reports on Internal Controls
AAF 01/20 is the ICAEW assurance framework for reporting on the description, design and operating effectiveness of a service organisation’s internal controls (the UK analogue to ISAE 3402 / SOC 1). Used by accountancy and outsourcing firms to give user auditors assurance over controls relevant to user entities’ financial reporting.
Jurisdiction: UK
Lifecycle: Active
AAT Code of Professional Ethics
The AAT Code of Professional Ethics applies to AAT members and licensed members in practice. It mirrors the IESBA fundamental principles and conceptual framework and adds AAT-specific requirements on continuing professional development (CPD), professional indemnity insurance, client money, and complaints handling for AAT-licensed bookkeepers and accountants.
Jurisdiction: UK
Lifecycle: Active
ACCA Code of Ethics and Conduct
The ACCA Code of Ethics and Conduct binds ACCA members, affiliates and students worldwide. Like the ICAEW Code it adopts the IESBA five fundamental principles and the threats-and-safeguards conceptual framework, with specific provisions on professional appointments, conflicts of interest, fees, inducements, custody of client assets, and independence for assurance engagements.
Jurisdiction: UK
Lifecycle: Active
AEO + Trusted Trader Programs (EU + US C-TPAT + UK)
Authorized Economic Operator (AEO) is a globally-recognised customs trusted-trader status (WCO SAFE Framework). EU AEO certification (AEOC customs + AEOS security + AEOF full) under UCC Art 38. US Customs-Trade Partnership Against Terrorism (C-TPAT) + UK AEO (post-Brexit) provide similar benefits including reduced inspections, simplified procedures + mutual recognition with partner countries. Annual self-assessment + customs audit verification. Voluntary but increasingly contractually required by major customers.
Jurisdiction: GLOBAL
Lifecycle: Active
AICPA SSAE 21 — Statements on Standards for Attestation Engagements
AICPA Statements on Standards for Attestation Engagements (SSAE) are the standards for US attestation engagements (examinations, reviews + agreed-upon procedures) other than audits of historical financial statements. SSAE 21 consolidated + revised the framework. The most well-known SSAE-based engagements are SOC 1 (ICFR reports), SOC 2 (Trust Services Criteria), SOC 3 (general use SOC 2 summary). Audit firms applying SSAEs operate ISQM 1-aligned quality management.
Jurisdiction: US
Lifecycle: Active
EU Alternative Investment Fund Managers Directive (AIFMD)
AIFMD regulates managers of alternative investment funds (AIFs) marketed in the EU — hedge funds, private equity, real estate, infrastructure, venture capital. Imposes authorisation + ongoing requirements on AIFMs including organisational requirements, capital, conduct of business, delegation, valuation, depositary, leverage limits, transparency + reporting (Annex IV). AIFMD II (Dir 2024/927) amends the regime with substance + delegation requirements, liquidity-management tools for open-ended AIFs + new loan-origination AIF rules. Transposition deadline April 2026.
Jurisdiction: EU
Lifecycle: Active
ANSI/ASSP A10 — Construction + Demolition Safety
The ANSI/ASSP A10 series of voluntary consensus standards is the US construction industry's detailed companion to OSHA 29 CFR 1926 — covering pre-project + pre-task safety + health planning (A10.1), demolition (A10.6), tube + coupler scaffolding (A10.10), fall protection (A10.32), excavation (A10.12), steel erection (A10.13), explosives (A10.7) + many others. Voluntary but increasingly contractually required by owners + integrated into safety management systems. Frequently cited as recognised good practice in OSHA citations + enforcement.
Jurisdiction: US
Lifecycle: Active
AS9100D / EN 9100 — Aerospace QMS
AS9100D is the global aerospace industry QMS standard, built on ISO 9001 with aerospace-specific requirements covering configuration management, risk-based product safety, counterfeit parts prevention, FAI (First Article Inspection) + supplier control. Required across aerospace + defence supply chains globally. EN 9100 + JISQ 9100 are the European + Japanese equivalents. Certification via IAQG-accredited bodies under the OASIS database.
Jurisdiction: GLOBAL
Lifecycle: Active
ASC Aquaculture Standards
Aquaculture Stewardship Council certification for responsibly farmed seafood. Species standards (salmon, shrimp, tilapia, pangasius, bivalves, seabass/seabream, etc.) cover environmental + social criteria. Joint ASC-MSC Seaweed Standard covers cultivated seaweeds.
Jurisdiction: GLOBAL
Lifecycle: Active
Basel III / Endgame "Basel IV"
Basel III is the Basel Committee on Banking Supervision's comprehensive set of reform measures developed in response to the 2007-09 financial crisis. The post-crisis reforms finalised in December 2017 (often called "Basel IV" or the Basel III Endgame) introduced revised credit + operational + market risk frameworks + an aggregate output floor. Implementation is phased through 2025-2028 across jurisdictions. Transposed into EU law via CRR / CRD (CRR3 + CRD VI), into UK rules via PRA Rulebook Implementation Phase 1 (effective 1 January 2026 in UK), into US via OCC/Fed/FDIC capital rules. Mandatory for all internationally-active banks; broad applicability to other licensed banks through national implementation.
Jurisdiction: GLOBAL
Lifecycle: Active
BRCGS Global Standard for Food Safety Issue 9
BRCGS Global Standard for Food Safety Issue 9 is a GFSI-benchmarked food safety + quality scheme widely required by UK + EU retailers + global brand owners. Covers senior management commitment, food safety plan (HACCP), food safety + quality management system, site standards, product control, process control, personnel + food fraud + defence. Audited by accredited certification bodies on a tiered grade system (AA+/AA/A/B/C/D).
Jurisdiction: GLOBAL
Lifecycle: Active
BREEAM — Building Research Establishment Environmental Assessment Method
BREEAM is the UK + international sustainability assessment method for buildings, administered by BRE. Rates buildings across 9 categories with ratings Pass / Good / Very Good / Excellent / Outstanding. Used widely in UK + Europe (mandatory in some public sector procurement) + frequently in pre-let / leasing requirements for grade-A commercial space. Companion schemes for refurbishment, in-use + communities.
Jurisdiction: UK
Lifecycle: Active
US Bank Secrecy Act + FinCEN Regulations
The US Bank Secrecy Act (BSA) is the principal federal anti-money-laundering law, administered by FinCEN. Requires US financial institutions (including banks, broker-dealers, money services businesses, casinos, mutual funds + certain non-bank residential mortgage lenders) to operate AML programmes, file Suspicious Activity Reports (SARs) + Currency Transaction Reports (CTRs), conduct customer due diligence (CDD/EDD) + identify beneficial ownership. The AML Act of 2020 significantly modernised the regime; the Corporate Transparency Act 2021 introduced beneficial-ownership reporting to FinCEN.
Jurisdiction: US
Lifecycle: Active
BSI Cloud Computing Compliance Criteria Catalogue (C5)
BSI C5 is the German Federal Office for Information Security (BSI) catalogue of minimum cloud-security requirements. Required by German federal procurement, increasingly required by German enterprise. The 2020 revision added 17 criteria reflecting cloud-specific evolution. Assessed via ISAE 3000 attestation that maps closely to SOC 2 reporting structure — many cloud providers obtain C5 + SOC 2 together.
Jurisdiction: DE
Lifecycle: Active
CCPA/CPRA Obligations Profile
The California Consumer Privacy Act, expanded by the CPRA, gives California residents specific rights over their personal information — including access, deletion, correction, and the right to limit use of sensitive personal information. The California Privacy Protection Agency (CPPA) now enforces directly, in addition to the state Attorney General, and has signalled aggressive action against businesses that fail to honour opt-outs, ignore Global Privacy Control signals, or mishandle sensitive personal information. Statutory damages of $100–$750 per consumer per breach add up fast in class actions. Even non-California companies above the size thresholds are typically in scope.
Jurisdiction: US_CA
Lifecycle: Active
42 CFR Part 2 — SUD Patient Records
42 CFR Part 2 governs the confidentiality of substance use disorder (SUD) patient records held by federally-assisted Part 2 programs. Stricter than HIPAA — historically required patient consent for nearly every disclosure (including treatment, payment + operations), with severe penalties for re-disclosure. The 2024 Final Rule (effective Feb 2026) harmonised Part 2 more closely with HIPAA — single patient consent for TPO is now permitted, breach notification aligned with HIPAA, civil + criminal penalties strengthened. Continues to require segregation of Part 2 records in EHRs, special handling for legal process, and the iconic re-disclosure prohibition notice.
Jurisdiction: US
Lifecycle: Active
CIS Controls v8.1
CIS Controls v8.1 (2024) consolidates 18 prioritised cybersecurity safeguards spanning identity, asset, vulnerability, account, data, and incident response domains. Maintained by the Center for Internet Security as a free, prescriptive baseline used by SMBs and as a procurement filter by enterprise + public-sector buyers. Implementation Group (IG) 1 covers essential hygiene; IG2 and IG3 add depth for higher-impact environments.
Jurisdiction: GLOBAL
Lifecycle: Active
Cybersecurity Maturity Model Certification 2.0
CMMC 2.0 is the US Department of Defense's tiered cybersecurity certification programme for contractors and subcontractors handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). Level 1 (self-assessment) covers basic FCI safeguards; Level 2 (NIST SP 800-171-aligned) is required for CUI; Level 3 (NIST SP 800-172) for the most sensitive contracts. Final rule effective 2024; phased flow-down to contracts began 2025.
Jurisdiction: US
Lifecycle: Active
CMS Hospital Conditions of Participation
CMS Conditions of Participation (CoP, 42 CFR Part 482) are the federal health + safety regulations hospitals must meet to participate in Medicare + Medicaid. Cover governing body, patients' rights, QAPI, medical staff, nursing services, medical records, pharmaceutical services, infection prevention, EMTALA + discharge planning. Enforced through CMS surveys + deemed-status accreditation (Joint Commission, DNV, AAAHC). Failure to meet a Condition can result in termination of provider agreement.
Jurisdiction: US
Lifecycle: Active
COBIT 2019
COBIT 2019 (ISACA) is an IT governance + management framework providing 40 governance + management objectives across 5 domains. Used by enterprise IT governance functions and audit teams to structure IT governance, risk + control activities. Often paired with ITIL 4 (service management) and ISO 27001 (security management) for integrated IT governance.
Jurisdiction: GLOBAL
Lifecycle: Active
Codex Alimentarius General Principles of Food Hygiene + HACCP
FAO/WHO Codex Alimentarius General Principles of Food Hygiene (CXC 1-1969) including the HACCP annex. The foundation for most national food safety regulations + industry standards globally.
Jurisdiction: GLOBAL
Lifecycle: Active
Codex HACCP — Hazard Analysis + Critical Control Points
Codex Alimentarius HACCP (CXC 1-1969) is the global reference for food-safety management. Seven principles: conduct hazard analysis, determine CCPs, establish critical limits, monitoring, corrective actions, verification + record-keeping. The foundational framework underlying virtually every national food-safety regime — including FSMA in the US, FSA in the UK + EU regulations.
Jurisdiction: GLOBAL
Lifecycle: Active
ICD-10-CM / SNOMED CT / LOINC — Clinical Coding Standards
The three core clinical-coding standards used in modern healthcare: ICD-10-CM (US morbidity classification, annually updated by CMS + NCHS), SNOMED CT (comprehensive clinical terminology, distributed under SNOMED International / NHS), LOINC (laboratory + clinical observations, distributed by Regenstrief Institute). Together they enable problem lists, diagnoses, lab results + procedure coding for billing, public health reporting, clinical decision support + research. USCDI v4 + FHIR Implementation Guides specify which terminology is required per data class.
Jurisdiction: GLOBAL
Lifecycle: Active
COSO Enterprise Risk Management — Integrating with Strategy + Performance
COSO ERM 2017 is the enterprise risk management reference framework used by US public companies, financial-services firms, and increasingly enterprise CFO + CRO offices globally. Integrates risk management with strategy and performance through 20 principles across 5 components. Heavily referenced by SOX + SEC risk-management commentary; the de-facto framework for ERM committee structure.
Jurisdiction: US
Lifecycle: Active
CQC Fundamental Standards
The Care Quality Commission (CQC) Fundamental Standards are the regulations all CQC-registered providers in England must meet — covering person-centred care, dignity + respect, consent, safe care + treatment, safeguarding, nutrition + hydration, premises + equipment, complaints, good governance, staffing, fit + proper persons, and duty of candour. Breach can result in registration conditions, prosecution + closure. The single assessment framework (effective from 2023) replaces previous KLOEs with quality statements + ratings: Outstanding / Good / Requires Improvement / Inadequate.
Jurisdiction: UK
Lifecycle: Active
EU Capital Requirements Regulation + Directive (CRR + CRD)
The EU's transposition of Basel III into binding regulation (CRR) + member-state-transposed directive (CRD). CRR3 + CRD VI were adopted in 2024 to complete Basel III + add the 2017 Basel "Endgame" reforms — revised credit risk standardised approach, operational risk + output floor. Applies to EU credit institutions + investment firms (with separate prudential regime IFR/IFD for smaller investment firms). Enforcement: ECB (Single Supervisory Mechanism) for significant institutions + national competent authorities for others. Key obligations: capital ratios + buffers, LCR, NSFR, leverage ratio, large exposures, governance + remuneration, public disclosure (Pillar 3).
Jurisdiction: EU
Lifecycle: Active
CSA Cloud Controls Matrix v4
CSA Cloud Controls Matrix v4 is the Cloud Security Alliance's cloud-specific control framework — 197 controls across 17 domains, mapped to ISO 27001, ISO 27017, NIST 800-53, PCI DSS, and others. Forms the assessment criteria for CSA STAR Level 1 (self-assessment) + Level 2 (third-party certification) and is increasingly required by enterprise cloud procurement.
Jurisdiction: GLOBAL
Lifecycle: Active
Cyber Essentials
Cyber Essentials and Cyber Essentials Plus are the UK government-backed cybersecurity certifications administered by the IASME consortium and required for many public-sector contracts. Cyber Essentials is self-assessed across five technical control areas (firewalls, secure configuration, user access control, malware protection, security update management); Cyber Essentials Plus adds independent technical testing. The 2023 update tightened expectations around cloud services, MFA on internet-facing services, and bring-your-own-device. Certification is annual and is the fastest credible signal to UK buyers that baseline cyber hygiene is in place.
Jurisdiction: UK
Lifecycle: Active
DICOM — Digital Imaging and Communications in Medicine
DICOM is the international standard for medical imaging + related metadata, used in nearly all radiology, cardiology + oncology imaging worldwide. Covers data structure (Information Object Definitions), services (Storage, Query/Retrieve, Modality Worklist, Print), network protocol (DICOM upper layer over TCP/IP) + media exchange. DICOMweb (RESTful DICOM) modernises access. Tightly integrated with HL7 + IHE Profiles (XDS-I, Scheduled Workflow, etc.). Compliance is operational rather than certified, but interoperability with PACS / VNA / RIS is the practical test.
Jurisdiction: GLOBAL
Lifecycle: Active
DORA Obligations Profile
The EU Digital Operational Resilience Act (DORA) is the binding ICT resilience regime for banks, insurers, investment firms, payment institutions, crypto-asset providers, and a long list of critical ICT third parties from 17 January 2025. National competent authorities (NCAs) and the ESAs can fine, issue enforcement actions, and require corrective action plans. Defensible compliance proves an ICT risk-management framework, a current third-party register at contract-level, structured incident reporting on regulator timelines, threat-led penetration testing for critical entities, and resilience testing across important business services — not just the IT estate.
Jurisdiction: EU
Lifecycle: Active
EU 5G Security Toolbox
The EU 5G Security Toolbox is a coordinated EU approach to securing 5G networks. Recommends strategic + technical risk-mitigation measures including supplier risk assessment, multi-vendor strategies, restricting high-risk vendors from core + sensitive parts of networks + mitigating dependencies. Implemented through national + sector regulations. Pairs with UK Telecommunications Security Act + national equivalents.
Jurisdiction: EU
Lifecycle: Active
ADR — European Agreement on Dangerous Goods by Road
ADR (Accord européen relatif au transport international des marchandises Dangereuses par Route) is the European agreement on the international carriage of dangerous goods by road. Classifies hazardous substances + sets requirements for packaging, marking + labelling, vehicles, tank construction, training (DGSA), documentation + security. Updated biennially. Implemented across 50+ countries including UK + EU. Companion modes: RID (rail), ADN (inland waterways), IMDG Code (sea), ICAO TI / IATA DGR (air). DGSA appointment required for in-scope companies.
Jurisdiction: EU
Lifecycle: Active
EU AI Act
EU Regulation 2024/1689 (the AI Act) is the first comprehensive AI law — a risk-tiered regulation reaching anyone who places an AI system on the EU market, puts one into service in the EU, or whose output is used in the EU. Penalties reach €35 million or 7% of global turnover for prohibited-practice violations; €15 million or 3% for high-risk non-compliance. Obligations land in waves: prohibited practices and AI literacy from February 2025; general-purpose AI model rules from August 2025; full high-risk system obligations from August 2026. High-risk systems (Annex III: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice, democratic processes) require a registered AI system, risk-management process, data-governance evidence, technical documentation, logging, human oversight, accuracy/robustness/cybersecurity testing, and a quality-management system. Quick Policy seeds the AI governance, AI risk, transparency, and human-oversight policies the Act requires and links them to ISO 42001 + 42005 for a defensible audit trail.
Jurisdiction: EU
Lifecycle: Active
EU ATEX 2014/34/EU — Equipment for Explosive Atmospheres
The ATEX Equipment Directive 2014/34/EU sets requirements for equipment + protective systems intended for use in potentially explosive atmospheres placed on the EU market. Companion to ATEX Workplace Directive 1999/92/EC. Equipment categorised by Group (I mining, II surface) + Category (1/2/3 reflecting protection level). CE marking + Ex marking + DoC required. Notified body involvement increases with category. Aligned with IEC 60079 series.
Jurisdiction: EU
Lifecycle: Active
EU Audiovisual Media Services Directive
The EU Audiovisual Media Services Directive (AVMSD) regulates television broadcasting + on-demand audiovisual media services (VOD) + video-sharing platforms (VSPs) across EU Member States. Covers protection of minors, commercial communications, European works promotion (30% quota for VOD), accessibility + advertising restrictions. National regulatory authorities (e.g. Ofcom (formerly), CNIL, AGCOM) implement nationally. Implemented in UK as Audiovisual Media Services Regulations (retained post-Brexit).
Jurisdiction: EU
Lifecycle: Active
EU Battery Regulation 2023/1542
The EU Battery Regulation 2023/1542 replaced the Battery Directive 2006/66/EC. Covers all battery categories — portable, EV, industrial, LMT (light means of transport), SLI. Imposes carbon footprint, recycled content, due diligence, performance + durability, removability + replaceability + labelling requirements. Phased implementation 2024-2030+. Strong supply-chain due-diligence requirements for cobalt, lithium, nickel + natural graphite.
Jurisdiction: EU
Lifecycle: Active
EU CPR — Construction Products Regulation (EU) 305/2011
The EU Construction Products Regulation 305/2011 (CPR) establishes harmonised conditions for the marketing of construction products in the EU. Requires the CE marking of products covered by a harmonised European standard (hEN) or European Assessment Document (EAD), based on a manufacturer's Declaration of Performance (DoP). Sets out 7 basic requirements for construction works. UK has implemented a UKCA-marking parallel regime post-Brexit. 2024 CPR reform — Regulation (EU) 2024/3110 — modernises the framework.
Jurisdiction: EU
Lifecycle: Active
EU Corporate Sustainability Due Diligence Directive
The EU CSDDD obliges large EU + non-EU companies to identify, prevent + mitigate adverse human rights + environmental impacts in their operations + value chains. In-scope: EU companies >1,000 employees + €450m turnover; non-EU companies with €450m EU turnover. Phased implementation 2027-2029. Civil liability + Member State enforcement; transition plans for climate. Companion to CSRD reporting.
Jurisdiction: EU
Lifecycle: Active
EU CSRD + ESRS — Corporate Sustainability Reporting
The EU Corporate Sustainability Reporting Directive (CSRD) Directive (EU) 2022/2464 + the European Sustainability Reporting Standards (ESRS) adopted by EFRAG significantly expand sustainability reporting for in-scope EU companies + non-EU companies with EU activities. Phased application from 2024 for large public companies + extending to large + listed SMEs by 2027. Mandatory double-materiality assessment + assurance by auditor / independent assurance provider. Companion: SFDR for financial market participants.
Jurisdiction: EU
Lifecycle: Active
EU Digital Markets Act (DMA)
The EU Digital Markets Act (Regulation (EU) 2022/1925) sets rules for "gatekeepers" — large digital platforms providing core platform services. Imposes obligations + prohibitions to ensure contestable + fair digital markets including interoperability, data portability, anti-self-preferencing + transparent app stores. Enforced by EU Commission. Fines up to 10% global turnover (20% for repeats). Indirectly affects retail through marketplace + advertising rules.
Jurisdiction: EU
Lifecycle: Active
EU Digital Services Act (DSA)
The EU Digital Services Act (Regulation (EU) 2022/2065) regulates online intermediaries + platforms. Imposes obligations including transparent content moderation, transparent advertising, recommender system transparency, risk assessments (for Very Large Online Platforms (VLOPs) + Very Large Online Search Engines (VLOSEs)) + Trusted Flaggers. Online marketplaces face additional KYC of business users. Enforced by Member State Digital Services Coordinators + EU Commission. Fines up to 6% global turnover.
Jurisdiction: EU
Lifecycle: Active
EU EASA Aircrew + Air Operations + Maintenance
The European Union Aviation Safety Agency oversees civil aviation safety across EU Member States + EASA-participating states. Implementing Regulations cover Aircrew (Part-FCL), Air Operations (Part-ORO, Part-CAT, Part-SPO), Continuing Airworthiness (Part-M, Part-145), Initial Airworthiness (Part-21) + Aerodromes (Part-ADR). National Aviation Authorities (NAAs) implement EASA regulations. AOC (Air Operator Certificate) + Continuing Airworthiness Management Organisation (CAMO) approvals. UK post-Brexit operates a parallel CAA regime largely aligned with EASA.
Jurisdiction: EU
Lifecycle: Active
EU European Electronic Communications Code
The European Electronic Communications Code (EECC) is the foundational EU regulatory framework for electronic communications networks + services + associated facilities. Covers market regulation, spectrum, end-user rights (transparency, contract information, switching, fault repair), universal service + security of networks + services. National Regulatory Authorities (NRAs e.g. ComReg, BNetzA) implement. UK retained pre-Brexit equivalent via Communications Act 2003 + General Conditions.
Jurisdiction: EU
Lifecycle: Active
EU EMC 2014/30/EU — Electromagnetic Compatibility
The Electromagnetic Compatibility Directive 2014/30/EU sets essential requirements for equipment to not generate excessive electromagnetic disturbance + to function in its intended electromagnetic environment. Applies to most electrical + electronic equipment placed on the EU market alongside LVD. Self-certification via technical file + DoC supporting CE marking. Harmonised standards EN 55032, EN 61000 series, EN 55035.
Jurisdiction: EU
Lifecycle: Active
EU Ecodesign for Sustainable Products Regulation
The Ecodesign for Sustainable Products Regulation (ESPR) (EU) 2024/1781 expands the Ecodesign Directive 2009/125/EC. Sets a framework to apply ecodesign + circular requirements to virtually all physical products placed on the EU market (initial focus: textiles, iron + steel, furniture, tyres, chemicals, paint). Introduces the Digital Product Passport (DPP), prohibits destruction of unsold consumer goods + sets ecodesign requirements through delegated acts. Phased implementation.
Jurisdiction: EU
Lifecycle: Active
EU F-Gas Regulation 517/2014
EU Regulation 517/2014 (F-Gas Regulation) controls fluorinated greenhouse gases used in refrigeration, air conditioning, heat pumps + fire protection. Imposes a phase-down quota system on HFC placement on the EU market, leak-check obligations, record-keeping, recovery + destruction obligations + training + certification of technicians + companies. Revised by Regulation (EU) 2024/573 — accelerated HFC phase-down to net-zero by 2050. UK retained equivalent regime post-Brexit.
Jurisdiction: EU
Lifecycle: Active
EU Food Information to Consumers Regulation 1169/2011
EU FIC Regulation 1169/2011 sets mandatory food information rules for the EU — covering allergen declaration (14 listed allergens), nutrition labelling, country of origin, durability date + readability. UK Natasha's Law (Food Information Amendment 2019) extends allergen labelling to prepacked-for-direct-sale (PPDS) food + is widely referenced as a model elsewhere.
Jurisdiction: EU
Lifecycle: Active
EU Regulation (EC) 852/2004 on the Hygiene of Foodstuffs
EU regulation setting general hygiene requirements for all food business operators, including HACCP principles, food premises + equipment, water, waste, personal hygiene + training. Annex I covers primary production; Annex II covers processing.
Jurisdiction: EU
Lifecycle: Active
EU General Food Law Regulation (EC) 178/2002
Foundation EU food regulation establishing general principles + requirements of food law, the European Food Safety Authority + procedures in matters of food safety. Imposes traceability (Article 18), the precautionary principle, withdrawal/recall (Article 19) + responsibility of food + feed business operators.
Jurisdiction: EU
Lifecycle: Active
EU General Food Law Regulation 178/2002
EU Regulation 178/2002 is the foundational EU food law — establishing food safety principles, the European Food Safety Authority (EFSA), the Rapid Alert System for Food + Feed (RASFF) + the precautionary principle. Imposes traceability + withdrawal / recall obligations on all food businesses. Companion regulations cover hygiene (852/2004), official controls (625/2017) + food information to consumers (1169/2011).
Jurisdiction: EU
Lifecycle: Active
EU General Product Safety Regulation 2023/988
EU Regulation 2023/988 (General Product Safety Regulation — GPSR) replaces the General Product Safety Directive 2001/95/EC from December 2024. Imposes safety + traceability + recall obligations on producers, importers, distributors + online marketplaces. Internal Production Control + risk assessment required. Mandatory online product safety information + corrective action public notifications. Companion: Market Surveillance Regulation 2019/1020 + product-specific safety laws.
Jurisdiction: EU
Lifecycle: Active
EU IVDR — Regulation (EU) 2017/746
The EU In Vitro Diagnostic Regulation (IVDR) replaced the IVDD, applying since 26 May 2022. Risk-based classification (Class A / B / C / D) drives notified-body involvement for the vast majority of IVDs (vs ~10% under IVDD). Sets requirements on clinical evidence (scientific validity, analytical + clinical performance), performance evaluation reports, EUDAMED registration, UDI, and Person Responsible for Regulatory Compliance. Transitional provisions extended in 2024 (IVDR Amendment 2024/1860) for legacy IVDD devices.
Jurisdiction: EU
Lifecycle: Active
EU LVD 2014/35/EU — Low Voltage Directive
The Low Voltage Directive 2014/35/EU sets essential safety requirements for electrical equipment operating between 50-1000V AC + 75-1500V DC placed on the EU market. Self-certification via technical file + DoC supporting CE marking. Aligned with harmonised standards (EN IEC 62368 + others). One of the foundational CE-marking directives. Enforced by Member State market surveillance.
Jurisdiction: EU
Lifecycle: Active
EU Machinery Regulation 2023/1230
The EU Machinery Regulation 2023/1230 (effective 2027) replaces the Machinery Directive 2006/42/EC. Sets essential health + safety requirements for the design + construction of machinery placed on the EU market, plus requirements for CE marking, Technical File, Declaration of Conformity + (for Annex I "high-risk" machinery including AI-enabled) third-party assessment. AI-enabled machinery + cybersecurity addressed for the first time. Companion to LVD + EMC + RED.
Jurisdiction: EU
Lifecycle: Active
EU Mortgage Credit Directive 2014/17/EU
EU Directive regulating credit agreements for consumers relating to residential immovable property. Establishes harmonised pre-contractual information (ESIS), creditworthiness assessment, conduct of business rules + cooling-off / reflection period.
Jurisdiction: EU
Lifecycle: Active
EU MDR — Regulation (EU) 2017/745
The EU Medical Device Regulation (MDR) replaced the MDD + AIMDD, applying since 26 May 2021. Sets requirements for the placing on the market + putting into service of medical devices + their accessories in the EU. Drives notified-body conformity assessment, technical documentation (Annex II + III), clinical evaluation (Annex XIV), post-market surveillance (Annex III) + post-market clinical follow-up. EUDAMED registration + UDI assignment + Person Responsible for Regulatory Compliance (PRRC) required. Transitional provisions extended in 2023 (MDR Amendment 2023/607) for legacy MDD devices.
Jurisdiction: EU
Lifecycle: Active
EU Nitrates Directive 91/676/EEC
EU Directive protecting waters against pollution caused by nitrates from agricultural sources. Member States designate Nitrate Vulnerable Zones (NVZs) + adopt action programmes with manure storage + spreading limits.
Jurisdiction: EU
Lifecycle: Active
EU Organic Regulation (EU) 2018/848
EU regulation on organic production + labelling of organic products. Replaces 834/2007 from 2022. Covers crops, livestock, aquaculture, processed food, wine, yeast + seaweed. Mandates certification by control bodies + organic logo on labelled products.
Jurisdiction: EU
Lifecycle: Active
EU PED — Pressure Equipment Directive 2014/68/EU
The Pressure Equipment Directive 2014/68/EU establishes essential safety requirements for the design + manufacture of pressure equipment + assemblies placed on the EU market. Classifies equipment by category (I-IV) based on pressure, volume + fluid type with corresponding conformity assessment modules. Notified body involvement increases with category. CE marking + DoC required. Companion: SPVD 2014/29/EU for simple pressure vessels.
Jurisdiction: EU
Lifecycle: Active
EU Regulation (EC) 1107/2009 — Plant Protection Products
EU regulation on the placing of plant protection products (pesticides) on the market. Companion: Sustainable Use Directive 2009/128/EC + Maximum Residue Levels Regulation 396/2005. Establishes active substance approval + product authorisation.
Jurisdiction: EU
Lifecycle: Active