Skip to main content
Standards

Standards-aware policy and compliance guidance

Browse active standards and frameworks that inform how Quick Policy baselines policy drafting and review.

Mapped standards (ISO, SOC 2, UK GDPR, and more)
Source-linked summaries
Policy-family guidance

Active public standards

Each page explains what the standard is, why it matters, and how Quick Policy helps teams draft and govern policies against it.

404 standards

Browsing all 404 standards. Search by name, code or plain-English purpose.

EU_OMNIBUS_PRICE_MARKING

EU Price Marking + Omnibus Directives

EU Price Marking Directive 98/6/EC (as amended by Omnibus 2019/2161 in force 2022) requires clear + unambiguous + non-misleading price indication. Omnibus enhances "was / now" rules — reference price must be the lowest price applied in the 30 days prior + introduces additional rules on online consumer reviews + personalised pricing transparency. Implemented nationally; UK retained version applies.

Jurisdiction: EU

Lifecycle: Active

EU_PACKAGE_TRAVEL_2015

EU Package Travel Directive (EU) 2015/2302

EU Package Travel Directive 2015/2302 protects consumers buying package holidays + linked travel arrangements. Requires pre-contractual + contractual information, insolvency protection of consumer payments, performance liability + remedies for non-conforming travel services. UK retained version (Package Travel + Linked Travel Arrangements Regs 2018) applies in GB.

Jurisdiction: EU

Lifecycle: Active

EU_REACH_1907_2006

EU REACH — Registration, Evaluation, Authorisation + Restriction of Chemicals

REACH is the EU regulation addressing the production + use of chemical substances + their potential impacts on human health + the environment. Requires manufacturers, importers + downstream users of chemicals to register substances >1 tonne/year, assess hazards + risks, apply for authorisation for substances of very high concern (SVHC) on the Candidate List + comply with restrictions in Annex XVII. Enforced by national authorities + ECHA; non-compliance can prevent EU market access.

Jurisdiction: EU

Lifecycle: Active

EU_ROHS_2011_65

EU RoHS — Restriction of Hazardous Substances

The EU RoHS Directive restricts the use of 10 hazardous substances (lead, mercury, cadmium, hexavalent chromium, PBB, PBDE + four phthalates DEHP/BBP/DBP/DIBP) in electrical + electronic equipment placed on the EU market. Compliance demonstrated through a technical file + the EU Declaration of Conformity supporting CE marking. Annex III + IV exemptions for specific applications. Enforced by Member State market surveillance; non-compliant products can be withdrawn from market.

Jurisdiction: EU

Lifecycle: Active

EU_TACHOGRAPH_DRIVERS_HOURS

EU Tachograph + Drivers' Hours Regulations

EU Regulation 561/2006 (Drivers' Hours) + Regulation 165/2014 (Tachographs), with significant amendments by the EU Mobility Package, set the rules on driving + rest times + tachograph use for commercial drivers in the EU + UK (retained post-Brexit, with national amendments). Limits: 9h daily driving (extended to 10h twice weekly), 56h weekly, 90h fortnightly + mandatory breaks + rest periods. Smart tachograph required for new vehicles. Penalties enforced through roadside checks + analyser systems.

Jurisdiction: EU

Lifecycle: Active

EU_VAT_2006_112

EU VAT Directive

The EU VAT Directive establishes the common system of value added tax across EU member states. Defines scope, place of supply rules, VAT rates, exemptions, deduction of input VAT, invoicing requirements + administrative obligations. Member states transpose into national law (with limited flexibility). The VAT in the Digital Age (ViDA) package, agreed 2024, introduces e-invoicing + digital reporting requirements progressively through 2030 + simplifies single-VAT registration + platform-economy treatment. Non-EU businesses making EU-taxable supplies face VAT obligations via OSS / IOSS schemes or local registration.

Jurisdiction: EU

Lifecycle: Active

EU_WEEE_2012_19

EU WEEE 2012/19/EU — Waste EEE

The WEEE Directive 2012/19/EU establishes producer responsibility for the take-back, recycling + recovery of waste electrical + electronic equipment placed on the EU market. Producers must register with national WEEE registers, fund collection + treatment + report annually. WEEE marking + financial guarantees required. Member State implementation varies.

Jurisdiction: EU

Lifecycle: Active

FAIR_V1

Factor Analysis of Information Risk (FAIR)

FAIR is a quantitative information risk management framework standardised under The Open Group (Open FAIR). Defines a vocabulary + methodology for measuring loss-event frequency + magnitude in financial terms, enabling risk decisions to use the same units as other business decisions. Used by mature risk programmes to complement qualitative risk-matrix approaches.

Jurisdiction: GLOBAL

Lifecycle: Active

US_FATCA_2010

US Foreign Account Tax Compliance Act (FATCA)

The US Foreign Account Tax Compliance Act (FATCA) requires foreign financial institutions (FFIs) to identify US account holders + report to IRS (or local tax authority under intergovernmental agreement / IGA), or face 30% withholding on certain US-source payments. Coexists with CRS — most non-US FIs apply both, with FATCA being US-specific. Withholding agent obligations for US payors making certain payments to foreign persons. CRS + FATCA reporting often combined operationally.

Jurisdiction: US

Lifecycle: Active

FATF_TRAVEL_RULE

FATF Recommendation 16 — Virtual Asset Travel Rule

Financial Action Task Force (FATF) Recommendation 16 — the so-called "Travel Rule" — requires Virtual Asset Service Providers (VASPs) to obtain, hold + transmit required originator + beneficiary information for virtual asset transfers above $/€ 1,000. Implementation varies by jurisdiction: EU via Transfer of Funds Regulation (TFR) Reg 2023/1113 (no minimum threshold), US via FinCEN's $3,000 threshold, UK via Money Laundering Regulations 2017 (£1,000 threshold for crypto). VASPs must implement compliant infrastructure (e.g. TRP, Sumsub, Notabene, Veriscope) + perform sanctions screening on counterparties.

Jurisdiction: GLOBAL

Lifecycle: Active

CONSUMER_DUTY_2023

UK FCA Consumer Duty (PRIN 12)

The UK FCA's Consumer Duty (PRIN 12 + PRIN 2A) is the outcomes-focused regulatory standard for retail consumer financial services. Three cross-cutting rules: (1) act in good faith; (2) avoid foreseeable harm; (3) enable + support customers to pursue their financial objectives. Four outcomes: products + services, price + value, consumer understanding, consumer support. Requires annual Board-approved Consumer Duty assessment + Champion role at Board level. Enforcement combines supervisory engagement, thematic reviews + enforcement action.

Jurisdiction: UK

Lifecycle: Active

FCA_PRA_RESILIENCE_PROFILE_2025

FCA/PRA Operational Resilience and Conduct Profile

The FCA/PRA operational resilience regime requires UK regulated firms to identify Important Business Services (IBS), set impact tolerances, map dependencies, and demonstrate they can stay within tolerance through severe-but-plausible scenarios. The Senior Managers and Certification Regime (SMCR/SM&CR) layers personal accountability on top — the regulator can act directly against named senior managers when controls fail. Recent supervisory letters and enforcement actions have focused on outsourcing oversight, conduct around vulnerable customers, and resilience scenario testing that doesn’t reflect real third-party concentration risk.

Jurisdiction: UK

Lifecycle: Active

FDA_21_CFR_PART_11

FDA 21 CFR Part 11 — Electronic Records / Signatures

FDA 21 CFR Part 11 establishes the criteria under which the FDA considers electronic records + electronic signatures to be trustworthy, reliable + equivalent to paper. Applies to records required by FDA predicate rules (e.g. 21 CFR Pt 210/211, Pt 312, Pt 314, Pt 820). Requires validation of systems, audit trails, electronic signature controls (unique IDs, two-component authentication, signature manifestations), access controls + system documentation. Predicate rule applicability + risk-based approach articulated in 2003 Scope and Application guidance. Failure to comply has resulted in FDA 483s, Warning Letters + consent decrees.

Jurisdiction: US

Lifecycle: Active

FDA_21_CFR_PART_820

FDA 21 CFR Part 820 — Quality System Regulation (QSR)

FDA 21 CFR Part 820 is the Quality System Regulation (QSR) governing medical device manufacturers selling in the US — covering design controls, document controls, purchasing controls, production + process controls, CAPA, complaint handling, servicing, statistical techniques + management responsibility. The Quality Management System Regulation (QMSR) final rule (published Feb 2024, effective 2 Feb 2026) harmonises QSR with ISO 13485:2016 by incorporating the standard by reference, replacing many QSR-specific requirements but preserving FDA-specific records, labelling + complaint elements. Enforced through FDA inspections, 483s + Warning Letters.

Jurisdiction: US

Lifecycle: Active

FDA_21_CFR_PART_210_211

FDA 21 CFR Part 210/211 — cGMP for Finished Pharmaceuticals

FDA 21 CFR Part 210 (general cGMP) + Part 211 (cGMP for finished pharmaceuticals) establish the minimum current Good Manufacturing Practice for pharmaceutical manufacturers — covering organisation + personnel, buildings + facilities, equipment, control of components + drug product containers, production + process controls, packaging + labelling, holding + distribution, laboratory controls, records + reports + returned/salvaged drug products. Failure results in FDA 483s, Warning Letters, import alerts + consent decrees. The reference standard for US pharmaceutical manufacturing.

Jurisdiction: US

Lifecycle: Active

FDA_21_CFR_PART_50_56

FDA 21 CFR Part 50 + 56 — Human Subject Protection

FDA 21 CFR Part 50 (Protection of Human Subjects) + Part 56 (Institutional Review Boards) govern the protection of human subjects in FDA-regulated clinical investigations — operationalising the Belmont Report principles. Part 50 requires informed consent + (for emergency research) exception conditions; Part 56 requires IRB review + approval + continuing review. Aligned with the Common Rule (45 CFR §46 Subpart A) since the 2018 revisions, with FDA-specific differences (e.g., no broad consent option, expanded children's research provisions). Inspections by FDA BIMO program.

Jurisdiction: US

Lifecycle: Active

FDA_21_CFR_PART_312

FDA 21 CFR Part 312 — IND Applications

FDA 21 CFR Part 312 governs Investigational New Drug (IND) applications — required before a drug can be shipped across state lines for clinical investigation. Covers commercial vs treatment vs investigator-sponsored INDs, content + format (Form FDA 1571), safety reporting (IND Safety Reports per §312.32 / 7- or 15-day timelines), clinical hold authorities, sponsor obligations + investigator obligations. Failure to comply has resulted in clinical holds + sponsor + investigator disqualification.

Jurisdiction: US

Lifecycle: Active

FDA_CYBERSECURITY_MEDICAL_DEVICES_CURRENT

FDA Cybersecurity in Medical Devices guidance

FDA cybersecurity expectations for medical devices have been formalised through pre-market and post-market guidance, the Refuse-To-Accept (RTA) cybersecurity criteria under section 524B of the FD&C Act, and aligned international guidance (IMDRF). 510(k) and PMA submissions that don't include the required cybersecurity information are refused on receipt. Defensible programmes evidence secure development practices, a Software Bill of Materials (SBOM), vulnerability management, coordinated disclosure, and post-market monitoring — typically built on IEC 81001-5-1, IEC 62304, and ISO 14971.

Jurisdiction: US

Lifecycle: Active

FDA_21_CFR_PART_314

FDA 21 CFR Part 314 — NDA Applications

FDA 21 CFR Part 314 governs New Drug Applications (NDAs) + Abbreviated New Drug Applications (ANDAs). Covers content + format requirements, FDA review timelines (PDUFA), supplements (post-approval changes), reporting (annual reports, NDA-Field Alert Reports, periodic adverse-drug-experience reports under §314.80), labelling + marketing materials. Companion provisions in Part 600 (biologics) + Part 601 (BLAs). Failure has resulted in approval delays, complete response letters + post-marketing requirements.

Jurisdiction: US

Lifecycle: Active

FEDRAMP_MODERATE_2024

FedRAMP Moderate Baseline

FedRAMP Moderate is the standardised authorisation baseline for US federal civilian cloud services handling controlled unclassified information. Based on NIST SP 800-53 Rev 5 with FedRAMP-specific parameters and continuous monitoring obligations. Authorisation is granted by an Agency Sponsor or the Joint Authorization Board. Required for most federal SaaS contracts; commercial SaaS vendors increasingly pursue it to access government revenue.

Jurisdiction: US

Lifecycle: Active

SR_11_7_MRM

Federal Reserve SR 11-7 — Model Risk Management

Federal Reserve + OCC Supervisory Letter SR 11-7 / OCC 2011-12 — Supervisory Guidance on Model Risk Management. The foundational US bank model-risk regulatory expectation framework, articulated for the largest BHCs but treated as the de-facto standard across the US banking + insurance industries + by FSB-watching supervisors globally. Defines model risk + the three pillars: model development, implementation + use; model validation; governance, policies + controls. Substantially extended by Federal Reserve SR 23-4 (interagency guidance on managing AI/ML in models).

Jurisdiction: US

Lifecycle: Active

FFIEC_AIO_2021

FFIEC Architecture, Infrastructure, and Operations booklet

The FFIEC Architecture, Infrastructure, and Operations (AIO) Booklet covers examiner expectations for IT operations management at US financial institutions — IT change management, system development life cycle, capacity management, data centre operations, cloud, end-user computing, and resilience. Examiners use it alongside the Information Security Booklet, and findings flow into the same supervisory escalation paths. A defensible programme demonstrates documented architecture decisions, formal change management, capacity forecasting, and outsourced-services oversight.

Jurisdiction: US

Lifecycle: Active

FFIEC_INFORMATION_SECURITY_CURRENT

FFIEC Information Security booklet

The FFIEC Information Security Booklet is the binding examination reference US bank, savings, and credit union examiners use during cybersecurity reviews. It expects governance, risk identification, mitigating-controls, monitoring, and assurance activities — all evidenced through policies, board reporting, and operational records. FFIEC findings escalate quickly into supervisory letters, MRA/MRIA action plans, and consent orders, so US financial institutions treat the booklet as the de facto standard even though it isn’t certifiable.

Jurisdiction: US

Lifecycle: Active

FORM_PF_2024

SEC Form PF + 2024 Amendments

Form PF is the SEC + CFTC Private Fund Adviser reporting form filed by SEC-registered investment advisers managing one or more private funds with at least $150m AUM. The February 2024 amendments expanded current + quarterly reporting requirements for large hedge fund advisers + private equity advisers to FSOC. The March 2024 amendments overhauled Section 5 (large private equity adviser reporting). Filings are confidential to SEC + FSOC; non-compliance penalties include censure + fines.

Jurisdiction: US

Lifecycle: Active

FRC_ETHICAL_STANDARD_2024

FRC Ethical Standard (Auditors)

The FRC Ethical Standard sets the integrity, objectivity and independence requirements for auditors and those providing assurance and related services in the UK. It covers the overarching principles, conflicts of interest, fees and remuneration, non-audit services, and the role of the Engagement Quality Control Reviewer (EQCR). Applies to firms registered to perform statutory audit; the 2024 revision tightened restrictions on non-audit services for public-interest entities.

Jurisdiction: UK

Lifecycle: Active

GDPR_PROFILE_2016_679

General Data Protection Regulation

EU/UK privacy and data protection requirements for personal data processing.

Jurisdiction: EU

Lifecycle: Active

GFSI_BRCGS_FOOD_V9

BRCGS Food Safety Standard v9 (GFSI-recognised)

GFSI-benchmarked food safety standard widely required by major retailers. Issue 9 covers senior management commitment, food safety plan (HACCP), food safety + quality management system, site standards, product control, process control, personnel + product authenticity. Certification covers a single site under unannounced or announced audit.

Jurisdiction: GLOBAL

Lifecycle: Active

GFSI_FSSC_22000_V6

FSSC 22000 v6 (GFSI-recognised)

GFSI-recognised food safety management certification combining ISO 22000 + PRP standards (e.g. ISO/TS 22002-1) + additional FSSC requirements. v6 strengthens food safety culture, food loss + waste, equipment management + food fraud/defence.

Jurisdiction: GLOBAL

Lifecycle: Active

GFSI_SQF_FOOD

SQF Food Safety Code (GFSI-recognised)

GFSI-recognised certification programme published by SQFI (a division of FMI). Covers HACCP-based food safety + quality across primary production, manufacturing, distribution + storage. Common in North American food supply chains; uses approved certification bodies + SQF Practitioners.

Jurisdiction: GLOBAL

Lifecycle: Active

GLBA_FTC_SAFEGUARDS_2023

US Gramm-Leach-Bliley Act + FTC Safeguards Rule (2023 amendments)

The Gramm-Leach-Bliley Act (Title V) is the US federal financial-privacy law. The 2023 amended FTC Safeguards Rule (effective 9 May 2023 for most provisions) substantially strengthened information security obligations for financial institutions under FTC jurisdiction (including auto dealers, payday lenders, mortgage brokers + many fintechs). Mandates a written Information Security Program with named CISO equivalent, risk assessment, MFA, encryption, regular pen-testing, incident response plan + Board reporting. The Safeguards Rule was further amended in 2023 to require notification of qualifying security events to FTC within 30 days.

Jurisdiction: US

Lifecycle: Active

GLOBALGAP_IFA_V6

GlobalG.A.P. Integrated Farm Assurance v6

Voluntary on-farm food safety + sustainability certification covering Fruit & Vegetables, Aquaculture, Livestock + Combinable Crops. Required by major retailers in EU, UK + increasingly elsewhere. v6 adds GRASP (workers' welfare) + SPRING (water stewardship) add-ons.

Jurisdiction: GLOBAL

Lifecycle: Active

GS1_BARCODE_STANDARDS

GS1 Standards — Barcodes + Identifiers

GS1 is the global standards organisation for supply chain identification + barcoding. Standards include GS1 GTIN (Global Trade Item Number), barcode formats (UPC, EAN, ITF-14, DataMatrix), 2D barcodes including QR + GS1 Digital Link, GS1 Standards for EPCIS (event tracking) + GS1 SmartLabel. Used by virtually all retail supply chains for product identification + inventory + recall + traceability. Adopted in EU Digital Product Passport + retail Web3 use cases.

Jurisdiction: GLOBAL

Lifecycle: Active

GLOBAL_GSMA_NETWORK_SECURITY

GSMA Security Standards + Specifications

The GSMA (GSM Association) develops global mobile network security specifications including the Network Security Assurance Framework, FS.31 Baseline Security Controls, Signalling Security (FS.07) + SS7 / Diameter / GTP security guidelines. Used by mobile network operators + equipment vendors. Pairs with NESAS (Network Equipment Security Assurance Scheme) for product certification. Increasingly mandated by national regulators (e.g. UK Ofcom, BEREC) as supplementary security baselines.

Jurisdiction: GLOBAL

Lifecycle: Active

HEDIS_CURRENT

HEDIS — Healthcare Effectiveness Data and Information Set

HEDIS is the NCQA performance measurement set used by 90%+ of US health plans to measure care quality + service. ~90 measures across 6 domains (effectiveness of care, access/availability, experience of care, utilisation/risk-adjusted utilisation, health plan descriptive info, electronic clinical data systems). Audited annually by NCQA-certified HEDIS Compliance Auditors. Drives CMS Medicare Advantage Star Ratings + state Medicaid plan oversight + accreditation. NCQA publishes the technical specifications + annual update cycle.

Jurisdiction: US

Lifecycle: Active

HIPAA_PROFILE_2013

HIPAA Security and Privacy Profile

HIPAA governs how covered entities (healthcare providers, plans, clearinghouses) and their business associates handle protected health information (PHI). The Office for Civil Rights (HHS OCR) enforces the Privacy, Security, and Breach Notification Rules with penalties up to $2.1 million per violation category per year. Right-of-access enforcement and ransomware-driven breach disclosures have driven recent OCR settlements. A defensible programme proves administrative, physical, and technical safeguards under §164.308–§164.312, plus a current risk analysis, workforce training records, and 60-day breach notification readiness.

Jurisdiction: US

Lifecycle: Active

HIPAA_TCS_X12

HIPAA Transactions + Code Sets (X12)

HIPAA Transactions + Code Sets (TCS) standardise electronic administrative + financial transactions across US health care — 837 (claims), 835 (remittance), 834 (enrolment), 270/271 (eligibility), 276/277 (claim status), 278 (prior authorisation), 820 (premium payment). ASC X12 5010A1 is the current version. Code sets: ICD-10-CM (diagnoses), ICD-10-PCS (inpatient procedures), CPT/HCPCS (outpatient procedures), NDC (drugs), CDT (dental). Required for all HIPAA-covered electronic transactions. Operating Rules (CAQH CORE) add consistency + connectivity.

Jurisdiction: US

Lifecycle: Active

HITECH_2009

HITECH Act 2009

The US Health Information Technology for Economic and Clinical Health Act (HITECH) of 2009 strengthened HIPAA — extending Privacy + Security Rule obligations to Business Associates directly, raising civil money penalties to a tiered structure (up to $1.5M per violation category per year), introducing the Breach Notification Rule (notify affected individuals + HHS + sometimes media within 60 days), and incentivising EHR adoption via Meaningful Use. The 2013 Omnibus Rule operationalised most provisions. Enforcement by HHS Office for Civil Rights (OCR) is via resolution agreements + corrective action plans + civil money penalties.

Jurisdiction: US

Lifecycle: Active

HITRUST_CSF_V11_2024

HITRUST CSF v11

HITRUST CSF v11 is a certifiable security + privacy framework primarily used in US healthcare. It harmonises HIPAA, HITECH, NIST 800-53, ISO 27001, PCI DSS, and 40+ other authoritative sources into a single auditable framework with three certification levels (e1, i1, r2) reflecting depth + assurance. The r2 ("Risk-based, 2-year") certification is the gold standard demanded by US payers + large hospital systems.

Jurisdiction: GLOBAL

Lifecycle: Active

HL7_FHIR_R5

HL7 FHIR R5 — Fast Healthcare Interoperability Resources

HL7 FHIR (Fast Healthcare Interoperability Resources) is the modern interoperability standard for exchanging healthcare information electronically. R5 (released 2023) is the latest "normative" version, building on R4 (the foundation for most national programs). FHIR resources (Patient, Observation, Condition, Encounter, MedicationRequest, etc.) + RESTful API + SMART on FHIR (OAuth 2.0 + OpenID Connect) underpin US ONC Cures Act + EHR Common Health Data Set (USCDI v4), UK NHS Federated Data Platform + EU European Health Data Space (EHDS). Implementation Guides (US Core, UK Core, IPS, Da Vinci, CARIN) tailor FHIR to national + use-case contexts.

Jurisdiction: GLOBAL

Lifecycle: Active

IATA_DGR

IATA Dangerous Goods Regulations

The IATA Dangerous Goods Regulations (DGR) are the global reference for the safe transport of dangerous goods by air. Operationalise the ICAO Technical Instructions (TI) with practical guidance for shippers, carriers + ground handlers. Annual revision. Cover classification, packaging, marking + labelling, documentation + training. Training every 24 months mandatory for all involved in DG by air. Used by airlines, freight forwarders + ground service providers worldwide.

Jurisdiction: GLOBAL

Lifecycle: Active

IATF_16949_2016

IATF 16949:2016 — Automotive QMS

IATF 16949:2016 is the global automotive industry quality management system standard, defining QMS requirements for automotive production + relevant service part organisations. Built on ISO 9001 with sector-specific customer + IATF-specific requirements. Required by virtually every OEM in automotive supply chains. Audited by IATF-certified bodies.

Jurisdiction: GLOBAL

Lifecycle: Active

IBC_CURRENT

IBC — International Building Code

The International Building Code (IBC), published by the International Code Council (ICC), is a model building code adopted with state + local amendments across nearly all US jurisdictions. Sets minimum requirements for the design + construction of new + existing buildings — structural, fire-resistive construction, means of egress, accessibility (referencing ICC A117.1), interior finishes, plumbing (via IPC), mechanical (via IMC), electrical (via NEC). Used together with the IRC (residential), IFC (fire), IPC, IMC, IECC + IGCC for a coherent US building regulatory baseline.

Jurisdiction: US

Lifecycle: Active

ICAEW_CODE_OF_ETHICS

ICAEW Code of Ethics

The ICAEW Code of Ethics applies to all ICAEW members, firms and students. It is built on the five fundamental principles — integrity, objectivity, professional competence and due care, confidentiality, and professional behaviour — and the conceptual framework for identifying, evaluating and addressing threats (self-interest, self-review, advocacy, familiarity, intimidation). It incorporates the independence requirements for audit and assurance engagements (Parts 4A/4B aligned to the IESBA Code and the FRC Ethical Standard).

Jurisdiction: UK

Lifecycle: Active

ICH_GCP_E6_R3

ICH GCP E6(R3) — Good Clinical Practice

ICH E6(R3) Good Clinical Practice (GCP) is the international ethical + scientific quality standard for the design, conduct, recording + reporting of trials involving human subjects. R3 (finalised 2025) modernises R2 — risk-proportionate quality management, increased emphasis on data integrity in decentralised trials, sponsor + investigator responsibilities clarified, expanded trial protocol + investigator brochure requirements. Adopted by FDA + EMA + MHRA + PMDA + China NMPA via national implementation. Inspections by regulators result in 483s, Statements of Non-Compliance + suspension of trials.

Jurisdiction: GLOBAL

Lifecycle: Active

ICH_Q9_Q10

ICH Q9/Q10 — Quality Risk Management + PQS

ICH Q9(R1) Quality Risk Management + Q10 Pharmaceutical Quality System are the foundation of modern pharmaceutical quality. Q9 establishes a systematic approach to risk management across the product lifecycle (assessment, control, communication, review) using tools like FMEA, HACCP + fault-tree. Q10 describes a PQS based on ICH Q8 + Q9 — process performance + product quality monitoring, CAPA, change management, management review. Adopted by FDA + EMA + MHRA + PMDA + Health Canada into national cGMP frameworks. Q9(R1) revision (2023) added subjectivity-management + hazard-identification clarifications.

Jurisdiction: GLOBAL

Lifecycle: Active

IDD_2016_97

EU Insurance Distribution Directive (IDD)

The EU Insurance Distribution Directive governs the design, distribution + servicing of insurance products + the conduct of insurance intermediaries. Replaced the prior Insurance Mediation Directive. Key features: product oversight + governance (POG), Insurance Product Information Document (IPID) for non-life, demands + needs test for all insurance distribution, conflict-of-interest management, training + competence requirements, conduct of business rules + cross-selling restrictions. National competent authorities supervise; transposed via national law in each member state.

Jurisdiction: EU

Lifecycle: Active

IEC_62304_2006

IEC 62304:2006 — Medical Device Software Lifecycle

IEC 62304 specifies lifecycle requirements for the development + maintenance of medical device software (SaMD + embedded). Drives software safety classification (Class A / B / C based on harm potential), software development planning, requirements analysis, architectural design, unit implementation + integration, system testing, release + post-release maintenance + problem resolution. SOUP (Software of Unknown Provenance) — including OSS — must be identified, risk-assessed + maintained. Required by EU MDR + IVDR + FDA via 510(k) software documentation guidance + ISO 13485 incorporation.

Jurisdiction: GLOBAL

Lifecycle: Active

IEC_62304_2006_A1_2015

IEC 62304:2006 + A1:2015

IEC 62304 is the international standard for medical-device software life-cycle processes — required by FDA premarket submissions, EU MDR/IVDR technical files, and most other regulators worldwide. It defines software safety classification (Class A/B/C), development processes, maintenance, configuration management, and problem resolution. The 2015 amendment tightened expectations around legacy software and SOUP (Software of Unknown Provenance). Used with ISO 13485 (QMS), ISO 14971 (risk), and IEC 81001-5-1 (cybersecurity) for full medical-software regulatory readiness.

Jurisdiction: GLOBAL

Lifecycle: Active

IEC_62366_1_2015

IEC 62366-1:2015 — Medical Device Usability Engineering

IEC 62366-1 specifies the application of usability engineering to medical devices to mitigate use-related risks. Drives the Use Specification, identification of hazardous use scenarios, formative + summative evaluation, and the Usability Engineering File (UEF). Required by EU MDR + IVDR + FDA via Human Factors Engineering guidance. Failure to perform summative evaluation on the production-equivalent device is a common notified-body finding + FDA 510(k) deficiency.

Jurisdiction: GLOBAL

Lifecycle: Active

IEC_62443

IEC 62443 — Industrial Automation + Control Systems Security

IEC 62443 (formerly ISA-99) is the leading international cybersecurity standard for Industrial Automation and Control Systems (IACS). Multi-part series covering general concepts, policies + procedures, system requirements + component requirements. Risk-based zone + conduit model + Security Levels (SL 1-4). Used by OT product vendors (62443-4-1/4-2) + asset owners (62443-2-1/3-2/3-3). Increasingly required in OT procurement; certifiable by IECEE. NIST SP 800-82 + ENISA + national CSIRTs align with 62443.

Jurisdiction: GLOBAL

Lifecycle: Active

IEC_62443_3_2_PROFILE_2025

IEC 62443-3-2 profile

IEC 62443-3-2 specifies the security risk assessment methodology for industrial automation and control systems (IACS) — zones, conduits, and security-level target identification. Asset owners, integrators, and product suppliers use it to produce defensible zoning decisions, residual-risk acceptance, and design-time security requirements ahead of build. Customer audits and insurer questionnaires for OT environments increasingly call out 3-2 explicitly.

Jurisdiction: GLOBAL

Lifecycle: Active

IEC_62443_3_3_PROFILE_2025

IEC 62443-3-3 profile

IEC 62443-3-3 defines the system security requirements and security levels (SL-1 through SL-4) for IACS — what a fully designed industrial control system must satisfy at each security level. Use it to specify procurement requirements, design-review acceptance criteria, and operational compliance for the systems running plants, pipelines, energy, water, and transport infrastructure.

Jurisdiction: GLOBAL

Lifecycle: Active

IEC_62443_4_1_PROFILE_2025

IEC 62443-4-1 profile

IEC 62443-4-1 sets the secure product-development lifecycle requirements for IACS product suppliers — covering security requirements management, secure design, secure implementation, verification and validation, defect management, and product end-of-life. Customers in critical infrastructure increasingly require 4-1 certification or alignment as a precondition for procurement.

Jurisdiction: GLOBAL

Lifecycle: Active

IEC_62443_4_2_PROFILE_2025

IEC 62443-4-2 profile

IEC 62443-4-2 defines the technical security requirements for IACS components — devices, embedded systems, network components, software applications, and host devices. Product suppliers, system integrators, and asset owners use it to evidence component-level security capabilities aligned to the security levels (SL-C 1-4) the system architecture requires.

Jurisdiction: GLOBAL

Lifecycle: Active

IEC_62443_PROFILE_2025

IEC 62443 Profile

IEC 62443 is the international standards family for industrial automation and control system (IACS) cybersecurity — adopted across manufacturing, energy, water, transport, and process industries. It defines security levels, zones-and-conduits architecture, component-level requirements, and product-development practices. Customer audits from large industrial buyers, NIS2 sector overlays, and insurer questionnaires increasingly reference 62443 explicitly. A defensible programme demonstrates segmentation evidence, secure-by-design controls in product development, vulnerability handling that doesn’t freeze plants, and a service-provider model that survives long equipment lifecycles.

Jurisdiction: GLOBAL

Lifecycle: Active

IEC_81001_5_1_2021

IEC 81001-5-1:2021

IEC 81001-5-1 specifies the cybersecurity activities required across the lifecycle of health software and health IT systems — required by FDA premarket cybersecurity guidance, EU MDCG cybersecurity guidance, and increasingly by NHS DTAC and DSPT reviewers. Manufacturers must evidence a secure development process, threat modelling, vulnerability handling, post-market monitoring, and end-of-support communications. The standard sits beside IEC 62304 (software lifecycle) and ISO 14971 (risk) to cover medical-device cybersecurity end-to-end.

Jurisdiction: GLOBAL

Lifecycle: Active

IFRS_CORE

International Financial Reporting Standards (IFRS)

International Financial Reporting Standards published by the IFRS Foundation + International Accounting Standards Board (IASB). The global accounting framework adopted (or substantially converged) by 168+ jurisdictions including the EU, UK (FRS 101 incorporates), Canada, Australia, India + most other major economies (notable holdout: US). Key standards include IFRS 15 (Revenue), IFRS 16 (Leases), IFRS 17 (Insurance Contracts — see separate reference), IFRS 9 (Financial Instruments), IFRS 13 (Fair Value), IAS 12 (Income Taxes), IAS 21 (FX), IAS 36 (Impairment), IAS 38 (Intangibles).

Jurisdiction: GLOBAL

Lifecycle: Active

IFRS_17_INSURANCE

IFRS 17 Insurance Contracts

IFRS 17 replaced IFRS 4 as the IASB's accounting standard for insurance contracts. Introduces a current measurement model (General Measurement Model — GMM) with Variable Fee Approach (VFA) for direct participating contracts + Premium Allocation Approach (PAA) simplification for short-duration contracts. Requires presentation of insurance revenue + insurance service expense separately from investment + financing components. Required by IFRS-reporting insurers including most EU + UK + Canadian + Australian insurance groups. US insurers continue under US GAAP (LDTI for long-duration contracts).

Jurisdiction: GLOBAL

Lifecycle: Active

IMDG_CODE

IMDG Code — Dangerous Goods at Sea

The International Maritime Dangerous Goods (IMDG) Code is the international standard for the safe transport of packaged dangerous goods by sea. Adopted under SOLAS Chapter VII; mandatory since 2004. Classifies + sets packaging, marking, labelling, stowage, segregation + documentation requirements for 9 classes of dangerous goods + marine pollutants. Biennial amendments. Training every 3 years for shore-based personnel. Companion to IATA DGR (air), ADR (road), RID (rail), ADN (inland waterways).

Jurisdiction: GLOBAL

Lifecycle: Active

IMO_ISM_CODE

IMO ISM Code — Safety Management

The International Safety Management (ISM) Code (SOLAS Chapter IX) sets an international standard for the safe management + operation of ships + for pollution prevention. Requires shipping companies to establish a Safety Management System (SMS) + obtain a Document of Compliance (DOC) for the company + a Safety Management Certificate (SMC) for each ship. Designated Person Ashore (DPA) acts as the link between company + ship. Audits by flag State / Recognised Organisation every 30 months. Failure can result in DOC withdrawal + ship detention.

Jurisdiction: GLOBAL

Lifecycle: Active

Review industries served

See how standards context shows up in sector-specific rollout and drafting guidance.

Read supporting articles

Explore long-form explainers, buyer guides, and roadmap content that supports these standards pages.

Validate platform fit

Compare the workflow, trust material, and rollout path before starting a free guided preview.

Need help baselining against specific standards?

Use Quick Policy to turn standards context into practical drafting, review, and evidence workflows.