Active public standards
Each page explains what the standard is, why it matters, and how Quick Policy helps teams draft and govern policies against it.
Browsing all 404 standards. Search by name, code or plain-English purpose.
EU Price Marking + Omnibus Directives
EU Price Marking Directive 98/6/EC (as amended by Omnibus 2019/2161 in force 2022) requires clear + unambiguous + non-misleading price indication. Omnibus enhances "was / now" rules — reference price must be the lowest price applied in the 30 days prior + introduces additional rules on online consumer reviews + personalised pricing transparency. Implemented nationally; UK retained version applies.
Jurisdiction: EU
Lifecycle: Active
EU Package Travel Directive (EU) 2015/2302
EU Package Travel Directive 2015/2302 protects consumers buying package holidays + linked travel arrangements. Requires pre-contractual + contractual information, insolvency protection of consumer payments, performance liability + remedies for non-conforming travel services. UK retained version (Package Travel + Linked Travel Arrangements Regs 2018) applies in GB.
Jurisdiction: EU
Lifecycle: Active
EU REACH — Registration, Evaluation, Authorisation + Restriction of Chemicals
REACH is the EU regulation addressing the production + use of chemical substances + their potential impacts on human health + the environment. Requires manufacturers, importers + downstream users of chemicals to register substances >1 tonne/year, assess hazards + risks, apply for authorisation for substances of very high concern (SVHC) on the Candidate List + comply with restrictions in Annex XVII. Enforced by national authorities + ECHA; non-compliance can prevent EU market access.
Jurisdiction: EU
Lifecycle: Active
EU RoHS — Restriction of Hazardous Substances
The EU RoHS Directive restricts the use of 10 hazardous substances (lead, mercury, cadmium, hexavalent chromium, PBB, PBDE + four phthalates DEHP/BBP/DBP/DIBP) in electrical + electronic equipment placed on the EU market. Compliance demonstrated through a technical file + the EU Declaration of Conformity supporting CE marking. Annex III + IV exemptions for specific applications. Enforced by Member State market surveillance; non-compliant products can be withdrawn from market.
Jurisdiction: EU
Lifecycle: Active
EU Tachograph + Drivers' Hours Regulations
EU Regulation 561/2006 (Drivers' Hours) + Regulation 165/2014 (Tachographs), with significant amendments by the EU Mobility Package, set the rules on driving + rest times + tachograph use for commercial drivers in the EU + UK (retained post-Brexit, with national amendments). Limits: 9h daily driving (extended to 10h twice weekly), 56h weekly, 90h fortnightly + mandatory breaks + rest periods. Smart tachograph required for new vehicles. Penalties enforced through roadside checks + analyser systems.
Jurisdiction: EU
Lifecycle: Active
EU VAT Directive
The EU VAT Directive establishes the common system of value added tax across EU member states. Defines scope, place of supply rules, VAT rates, exemptions, deduction of input VAT, invoicing requirements + administrative obligations. Member states transpose into national law (with limited flexibility). The VAT in the Digital Age (ViDA) package, agreed 2024, introduces e-invoicing + digital reporting requirements progressively through 2030 + simplifies single-VAT registration + platform-economy treatment. Non-EU businesses making EU-taxable supplies face VAT obligations via OSS / IOSS schemes or local registration.
Jurisdiction: EU
Lifecycle: Active
EU WEEE 2012/19/EU — Waste EEE
The WEEE Directive 2012/19/EU establishes producer responsibility for the take-back, recycling + recovery of waste electrical + electronic equipment placed on the EU market. Producers must register with national WEEE registers, fund collection + treatment + report annually. WEEE marking + financial guarantees required. Member State implementation varies.
Jurisdiction: EU
Lifecycle: Active
Factor Analysis of Information Risk (FAIR)
FAIR is a quantitative information risk management framework standardised under The Open Group (Open FAIR). Defines a vocabulary + methodology for measuring loss-event frequency + magnitude in financial terms, enabling risk decisions to use the same units as other business decisions. Used by mature risk programmes to complement qualitative risk-matrix approaches.
Jurisdiction: GLOBAL
Lifecycle: Active
US Foreign Account Tax Compliance Act (FATCA)
The US Foreign Account Tax Compliance Act (FATCA) requires foreign financial institutions (FFIs) to identify US account holders + report to IRS (or local tax authority under intergovernmental agreement / IGA), or face 30% withholding on certain US-source payments. Coexists with CRS — most non-US FIs apply both, with FATCA being US-specific. Withholding agent obligations for US payors making certain payments to foreign persons. CRS + FATCA reporting often combined operationally.
Jurisdiction: US
Lifecycle: Active
FATF Recommendation 16 — Virtual Asset Travel Rule
Financial Action Task Force (FATF) Recommendation 16 — the so-called "Travel Rule" — requires Virtual Asset Service Providers (VASPs) to obtain, hold + transmit required originator + beneficiary information for virtual asset transfers above $/€ 1,000. Implementation varies by jurisdiction: EU via Transfer of Funds Regulation (TFR) Reg 2023/1113 (no minimum threshold), US via FinCEN's $3,000 threshold, UK via Money Laundering Regulations 2017 (£1,000 threshold for crypto). VASPs must implement compliant infrastructure (e.g. TRP, Sumsub, Notabene, Veriscope) + perform sanctions screening on counterparties.
Jurisdiction: GLOBAL
Lifecycle: Active
UK FCA Consumer Duty (PRIN 12)
The UK FCA's Consumer Duty (PRIN 12 + PRIN 2A) is the outcomes-focused regulatory standard for retail consumer financial services. Three cross-cutting rules: (1) act in good faith; (2) avoid foreseeable harm; (3) enable + support customers to pursue their financial objectives. Four outcomes: products + services, price + value, consumer understanding, consumer support. Requires annual Board-approved Consumer Duty assessment + Champion role at Board level. Enforcement combines supervisory engagement, thematic reviews + enforcement action.
Jurisdiction: UK
Lifecycle: Active
FCA/PRA Operational Resilience and Conduct Profile
The FCA/PRA operational resilience regime requires UK regulated firms to identify Important Business Services (IBS), set impact tolerances, map dependencies, and demonstrate they can stay within tolerance through severe-but-plausible scenarios. The Senior Managers and Certification Regime (SMCR/SM&CR) layers personal accountability on top — the regulator can act directly against named senior managers when controls fail. Recent supervisory letters and enforcement actions have focused on outsourcing oversight, conduct around vulnerable customers, and resilience scenario testing that doesn’t reflect real third-party concentration risk.
Jurisdiction: UK
Lifecycle: Active
FDA 21 CFR Part 11 — Electronic Records / Signatures
FDA 21 CFR Part 11 establishes the criteria under which the FDA considers electronic records + electronic signatures to be trustworthy, reliable + equivalent to paper. Applies to records required by FDA predicate rules (e.g. 21 CFR Pt 210/211, Pt 312, Pt 314, Pt 820). Requires validation of systems, audit trails, electronic signature controls (unique IDs, two-component authentication, signature manifestations), access controls + system documentation. Predicate rule applicability + risk-based approach articulated in 2003 Scope and Application guidance. Failure to comply has resulted in FDA 483s, Warning Letters + consent decrees.
Jurisdiction: US
Lifecycle: Active
FDA 21 CFR Part 820 — Quality System Regulation (QSR)
FDA 21 CFR Part 820 is the Quality System Regulation (QSR) governing medical device manufacturers selling in the US — covering design controls, document controls, purchasing controls, production + process controls, CAPA, complaint handling, servicing, statistical techniques + management responsibility. The Quality Management System Regulation (QMSR) final rule (published Feb 2024, effective 2 Feb 2026) harmonises QSR with ISO 13485:2016 by incorporating the standard by reference, replacing many QSR-specific requirements but preserving FDA-specific records, labelling + complaint elements. Enforced through FDA inspections, 483s + Warning Letters.
Jurisdiction: US
Lifecycle: Active
FDA 21 CFR Part 210/211 — cGMP for Finished Pharmaceuticals
FDA 21 CFR Part 210 (general cGMP) + Part 211 (cGMP for finished pharmaceuticals) establish the minimum current Good Manufacturing Practice for pharmaceutical manufacturers — covering organisation + personnel, buildings + facilities, equipment, control of components + drug product containers, production + process controls, packaging + labelling, holding + distribution, laboratory controls, records + reports + returned/salvaged drug products. Failure results in FDA 483s, Warning Letters, import alerts + consent decrees. The reference standard for US pharmaceutical manufacturing.
Jurisdiction: US
Lifecycle: Active
FDA 21 CFR Part 50 + 56 — Human Subject Protection
FDA 21 CFR Part 50 (Protection of Human Subjects) + Part 56 (Institutional Review Boards) govern the protection of human subjects in FDA-regulated clinical investigations — operationalising the Belmont Report principles. Part 50 requires informed consent + (for emergency research) exception conditions; Part 56 requires IRB review + approval + continuing review. Aligned with the Common Rule (45 CFR §46 Subpart A) since the 2018 revisions, with FDA-specific differences (e.g., no broad consent option, expanded children's research provisions). Inspections by FDA BIMO program.
Jurisdiction: US
Lifecycle: Active
FDA 21 CFR Part 312 — IND Applications
FDA 21 CFR Part 312 governs Investigational New Drug (IND) applications — required before a drug can be shipped across state lines for clinical investigation. Covers commercial vs treatment vs investigator-sponsored INDs, content + format (Form FDA 1571), safety reporting (IND Safety Reports per §312.32 / 7- or 15-day timelines), clinical hold authorities, sponsor obligations + investigator obligations. Failure to comply has resulted in clinical holds + sponsor + investigator disqualification.
Jurisdiction: US
Lifecycle: Active
FDA Cybersecurity in Medical Devices guidance
FDA cybersecurity expectations for medical devices have been formalised through pre-market and post-market guidance, the Refuse-To-Accept (RTA) cybersecurity criteria under section 524B of the FD&C Act, and aligned international guidance (IMDRF). 510(k) and PMA submissions that don't include the required cybersecurity information are refused on receipt. Defensible programmes evidence secure development practices, a Software Bill of Materials (SBOM), vulnerability management, coordinated disclosure, and post-market monitoring — typically built on IEC 81001-5-1, IEC 62304, and ISO 14971.
Jurisdiction: US
Lifecycle: Active
FDA 21 CFR Part 314 — NDA Applications
FDA 21 CFR Part 314 governs New Drug Applications (NDAs) + Abbreviated New Drug Applications (ANDAs). Covers content + format requirements, FDA review timelines (PDUFA), supplements (post-approval changes), reporting (annual reports, NDA-Field Alert Reports, periodic adverse-drug-experience reports under §314.80), labelling + marketing materials. Companion provisions in Part 600 (biologics) + Part 601 (BLAs). Failure has resulted in approval delays, complete response letters + post-marketing requirements.
Jurisdiction: US
Lifecycle: Active
FedRAMP Moderate Baseline
FedRAMP Moderate is the standardised authorisation baseline for US federal civilian cloud services handling controlled unclassified information. Based on NIST SP 800-53 Rev 5 with FedRAMP-specific parameters and continuous monitoring obligations. Authorisation is granted by an Agency Sponsor or the Joint Authorization Board. Required for most federal SaaS contracts; commercial SaaS vendors increasingly pursue it to access government revenue.
Jurisdiction: US
Lifecycle: Active
Federal Reserve SR 11-7 — Model Risk Management
Federal Reserve + OCC Supervisory Letter SR 11-7 / OCC 2011-12 — Supervisory Guidance on Model Risk Management. The foundational US bank model-risk regulatory expectation framework, articulated for the largest BHCs but treated as the de-facto standard across the US banking + insurance industries + by FSB-watching supervisors globally. Defines model risk + the three pillars: model development, implementation + use; model validation; governance, policies + controls. Substantially extended by Federal Reserve SR 23-4 (interagency guidance on managing AI/ML in models).
Jurisdiction: US
Lifecycle: Active
FFIEC Architecture, Infrastructure, and Operations booklet
The FFIEC Architecture, Infrastructure, and Operations (AIO) Booklet covers examiner expectations for IT operations management at US financial institutions — IT change management, system development life cycle, capacity management, data centre operations, cloud, end-user computing, and resilience. Examiners use it alongside the Information Security Booklet, and findings flow into the same supervisory escalation paths. A defensible programme demonstrates documented architecture decisions, formal change management, capacity forecasting, and outsourced-services oversight.
Jurisdiction: US
Lifecycle: Active
FFIEC Information Security booklet
The FFIEC Information Security Booklet is the binding examination reference US bank, savings, and credit union examiners use during cybersecurity reviews. It expects governance, risk identification, mitigating-controls, monitoring, and assurance activities — all evidenced through policies, board reporting, and operational records. FFIEC findings escalate quickly into supervisory letters, MRA/MRIA action plans, and consent orders, so US financial institutions treat the booklet as the de facto standard even though it isn’t certifiable.
Jurisdiction: US
Lifecycle: Active
SEC Form PF + 2024 Amendments
Form PF is the SEC + CFTC Private Fund Adviser reporting form filed by SEC-registered investment advisers managing one or more private funds with at least $150m AUM. The February 2024 amendments expanded current + quarterly reporting requirements for large hedge fund advisers + private equity advisers to FSOC. The March 2024 amendments overhauled Section 5 (large private equity adviser reporting). Filings are confidential to SEC + FSOC; non-compliance penalties include censure + fines.
Jurisdiction: US
Lifecycle: Active
FRC Ethical Standard (Auditors)
The FRC Ethical Standard sets the integrity, objectivity and independence requirements for auditors and those providing assurance and related services in the UK. It covers the overarching principles, conflicts of interest, fees and remuneration, non-audit services, and the role of the Engagement Quality Control Reviewer (EQCR). Applies to firms registered to perform statutory audit; the 2024 revision tightened restrictions on non-audit services for public-interest entities.
Jurisdiction: UK
Lifecycle: Active
General Data Protection Regulation
EU/UK privacy and data protection requirements for personal data processing.
Jurisdiction: EU
Lifecycle: Active
BRCGS Food Safety Standard v9 (GFSI-recognised)
GFSI-benchmarked food safety standard widely required by major retailers. Issue 9 covers senior management commitment, food safety plan (HACCP), food safety + quality management system, site standards, product control, process control, personnel + product authenticity. Certification covers a single site under unannounced or announced audit.
Jurisdiction: GLOBAL
Lifecycle: Active
FSSC 22000 v6 (GFSI-recognised)
GFSI-recognised food safety management certification combining ISO 22000 + PRP standards (e.g. ISO/TS 22002-1) + additional FSSC requirements. v6 strengthens food safety culture, food loss + waste, equipment management + food fraud/defence.
Jurisdiction: GLOBAL
Lifecycle: Active
SQF Food Safety Code (GFSI-recognised)
GFSI-recognised certification programme published by SQFI (a division of FMI). Covers HACCP-based food safety + quality across primary production, manufacturing, distribution + storage. Common in North American food supply chains; uses approved certification bodies + SQF Practitioners.
Jurisdiction: GLOBAL
Lifecycle: Active
US Gramm-Leach-Bliley Act + FTC Safeguards Rule (2023 amendments)
The Gramm-Leach-Bliley Act (Title V) is the US federal financial-privacy law. The 2023 amended FTC Safeguards Rule (effective 9 May 2023 for most provisions) substantially strengthened information security obligations for financial institutions under FTC jurisdiction (including auto dealers, payday lenders, mortgage brokers + many fintechs). Mandates a written Information Security Program with named CISO equivalent, risk assessment, MFA, encryption, regular pen-testing, incident response plan + Board reporting. The Safeguards Rule was further amended in 2023 to require notification of qualifying security events to FTC within 30 days.
Jurisdiction: US
Lifecycle: Active
GlobalG.A.P. Integrated Farm Assurance v6
Voluntary on-farm food safety + sustainability certification covering Fruit & Vegetables, Aquaculture, Livestock + Combinable Crops. Required by major retailers in EU, UK + increasingly elsewhere. v6 adds GRASP (workers' welfare) + SPRING (water stewardship) add-ons.
Jurisdiction: GLOBAL
Lifecycle: Active
GS1 Standards — Barcodes + Identifiers
GS1 is the global standards organisation for supply chain identification + barcoding. Standards include GS1 GTIN (Global Trade Item Number), barcode formats (UPC, EAN, ITF-14, DataMatrix), 2D barcodes including QR + GS1 Digital Link, GS1 Standards for EPCIS (event tracking) + GS1 SmartLabel. Used by virtually all retail supply chains for product identification + inventory + recall + traceability. Adopted in EU Digital Product Passport + retail Web3 use cases.
Jurisdiction: GLOBAL
Lifecycle: Active
GSMA Security Standards + Specifications
The GSMA (GSM Association) develops global mobile network security specifications including the Network Security Assurance Framework, FS.31 Baseline Security Controls, Signalling Security (FS.07) + SS7 / Diameter / GTP security guidelines. Used by mobile network operators + equipment vendors. Pairs with NESAS (Network Equipment Security Assurance Scheme) for product certification. Increasingly mandated by national regulators (e.g. UK Ofcom, BEREC) as supplementary security baselines.
Jurisdiction: GLOBAL
Lifecycle: Active
HEDIS — Healthcare Effectiveness Data and Information Set
HEDIS is the NCQA performance measurement set used by 90%+ of US health plans to measure care quality + service. ~90 measures across 6 domains (effectiveness of care, access/availability, experience of care, utilisation/risk-adjusted utilisation, health plan descriptive info, electronic clinical data systems). Audited annually by NCQA-certified HEDIS Compliance Auditors. Drives CMS Medicare Advantage Star Ratings + state Medicaid plan oversight + accreditation. NCQA publishes the technical specifications + annual update cycle.
Jurisdiction: US
Lifecycle: Active
HIPAA Security and Privacy Profile
HIPAA governs how covered entities (healthcare providers, plans, clearinghouses) and their business associates handle protected health information (PHI). The Office for Civil Rights (HHS OCR) enforces the Privacy, Security, and Breach Notification Rules with penalties up to $2.1 million per violation category per year. Right-of-access enforcement and ransomware-driven breach disclosures have driven recent OCR settlements. A defensible programme proves administrative, physical, and technical safeguards under §164.308–§164.312, plus a current risk analysis, workforce training records, and 60-day breach notification readiness.
Jurisdiction: US
Lifecycle: Active
HIPAA Transactions + Code Sets (X12)
HIPAA Transactions + Code Sets (TCS) standardise electronic administrative + financial transactions across US health care — 837 (claims), 835 (remittance), 834 (enrolment), 270/271 (eligibility), 276/277 (claim status), 278 (prior authorisation), 820 (premium payment). ASC X12 5010A1 is the current version. Code sets: ICD-10-CM (diagnoses), ICD-10-PCS (inpatient procedures), CPT/HCPCS (outpatient procedures), NDC (drugs), CDT (dental). Required for all HIPAA-covered electronic transactions. Operating Rules (CAQH CORE) add consistency + connectivity.
Jurisdiction: US
Lifecycle: Active
HITECH Act 2009
The US Health Information Technology for Economic and Clinical Health Act (HITECH) of 2009 strengthened HIPAA — extending Privacy + Security Rule obligations to Business Associates directly, raising civil money penalties to a tiered structure (up to $1.5M per violation category per year), introducing the Breach Notification Rule (notify affected individuals + HHS + sometimes media within 60 days), and incentivising EHR adoption via Meaningful Use. The 2013 Omnibus Rule operationalised most provisions. Enforcement by HHS Office for Civil Rights (OCR) is via resolution agreements + corrective action plans + civil money penalties.
Jurisdiction: US
Lifecycle: Active
HITRUST CSF v11
HITRUST CSF v11 is a certifiable security + privacy framework primarily used in US healthcare. It harmonises HIPAA, HITECH, NIST 800-53, ISO 27001, PCI DSS, and 40+ other authoritative sources into a single auditable framework with three certification levels (e1, i1, r2) reflecting depth + assurance. The r2 ("Risk-based, 2-year") certification is the gold standard demanded by US payers + large hospital systems.
Jurisdiction: GLOBAL
Lifecycle: Active
HL7 FHIR R5 — Fast Healthcare Interoperability Resources
HL7 FHIR (Fast Healthcare Interoperability Resources) is the modern interoperability standard for exchanging healthcare information electronically. R5 (released 2023) is the latest "normative" version, building on R4 (the foundation for most national programs). FHIR resources (Patient, Observation, Condition, Encounter, MedicationRequest, etc.) + RESTful API + SMART on FHIR (OAuth 2.0 + OpenID Connect) underpin US ONC Cures Act + EHR Common Health Data Set (USCDI v4), UK NHS Federated Data Platform + EU European Health Data Space (EHDS). Implementation Guides (US Core, UK Core, IPS, Da Vinci, CARIN) tailor FHIR to national + use-case contexts.
Jurisdiction: GLOBAL
Lifecycle: Active
IATA Dangerous Goods Regulations
The IATA Dangerous Goods Regulations (DGR) are the global reference for the safe transport of dangerous goods by air. Operationalise the ICAO Technical Instructions (TI) with practical guidance for shippers, carriers + ground handlers. Annual revision. Cover classification, packaging, marking + labelling, documentation + training. Training every 24 months mandatory for all involved in DG by air. Used by airlines, freight forwarders + ground service providers worldwide.
Jurisdiction: GLOBAL
Lifecycle: Active
IATF 16949:2016 — Automotive QMS
IATF 16949:2016 is the global automotive industry quality management system standard, defining QMS requirements for automotive production + relevant service part organisations. Built on ISO 9001 with sector-specific customer + IATF-specific requirements. Required by virtually every OEM in automotive supply chains. Audited by IATF-certified bodies.
Jurisdiction: GLOBAL
Lifecycle: Active
IBC — International Building Code
The International Building Code (IBC), published by the International Code Council (ICC), is a model building code adopted with state + local amendments across nearly all US jurisdictions. Sets minimum requirements for the design + construction of new + existing buildings — structural, fire-resistive construction, means of egress, accessibility (referencing ICC A117.1), interior finishes, plumbing (via IPC), mechanical (via IMC), electrical (via NEC). Used together with the IRC (residential), IFC (fire), IPC, IMC, IECC + IGCC for a coherent US building regulatory baseline.
Jurisdiction: US
Lifecycle: Active
ICAEW Code of Ethics
The ICAEW Code of Ethics applies to all ICAEW members, firms and students. It is built on the five fundamental principles — integrity, objectivity, professional competence and due care, confidentiality, and professional behaviour — and the conceptual framework for identifying, evaluating and addressing threats (self-interest, self-review, advocacy, familiarity, intimidation). It incorporates the independence requirements for audit and assurance engagements (Parts 4A/4B aligned to the IESBA Code and the FRC Ethical Standard).
Jurisdiction: UK
Lifecycle: Active
ICH GCP E6(R3) — Good Clinical Practice
ICH E6(R3) Good Clinical Practice (GCP) is the international ethical + scientific quality standard for the design, conduct, recording + reporting of trials involving human subjects. R3 (finalised 2025) modernises R2 — risk-proportionate quality management, increased emphasis on data integrity in decentralised trials, sponsor + investigator responsibilities clarified, expanded trial protocol + investigator brochure requirements. Adopted by FDA + EMA + MHRA + PMDA + China NMPA via national implementation. Inspections by regulators result in 483s, Statements of Non-Compliance + suspension of trials.
Jurisdiction: GLOBAL
Lifecycle: Active
ICH Q9/Q10 — Quality Risk Management + PQS
ICH Q9(R1) Quality Risk Management + Q10 Pharmaceutical Quality System are the foundation of modern pharmaceutical quality. Q9 establishes a systematic approach to risk management across the product lifecycle (assessment, control, communication, review) using tools like FMEA, HACCP + fault-tree. Q10 describes a PQS based on ICH Q8 + Q9 — process performance + product quality monitoring, CAPA, change management, management review. Adopted by FDA + EMA + MHRA + PMDA + Health Canada into national cGMP frameworks. Q9(R1) revision (2023) added subjectivity-management + hazard-identification clarifications.
Jurisdiction: GLOBAL
Lifecycle: Active
EU Insurance Distribution Directive (IDD)
The EU Insurance Distribution Directive governs the design, distribution + servicing of insurance products + the conduct of insurance intermediaries. Replaced the prior Insurance Mediation Directive. Key features: product oversight + governance (POG), Insurance Product Information Document (IPID) for non-life, demands + needs test for all insurance distribution, conflict-of-interest management, training + competence requirements, conduct of business rules + cross-selling restrictions. National competent authorities supervise; transposed via national law in each member state.
Jurisdiction: EU
Lifecycle: Active
IEC 62304:2006 — Medical Device Software Lifecycle
IEC 62304 specifies lifecycle requirements for the development + maintenance of medical device software (SaMD + embedded). Drives software safety classification (Class A / B / C based on harm potential), software development planning, requirements analysis, architectural design, unit implementation + integration, system testing, release + post-release maintenance + problem resolution. SOUP (Software of Unknown Provenance) — including OSS — must be identified, risk-assessed + maintained. Required by EU MDR + IVDR + FDA via 510(k) software documentation guidance + ISO 13485 incorporation.
Jurisdiction: GLOBAL
Lifecycle: Active
IEC 62304:2006 + A1:2015
IEC 62304 is the international standard for medical-device software life-cycle processes — required by FDA premarket submissions, EU MDR/IVDR technical files, and most other regulators worldwide. It defines software safety classification (Class A/B/C), development processes, maintenance, configuration management, and problem resolution. The 2015 amendment tightened expectations around legacy software and SOUP (Software of Unknown Provenance). Used with ISO 13485 (QMS), ISO 14971 (risk), and IEC 81001-5-1 (cybersecurity) for full medical-software regulatory readiness.
Jurisdiction: GLOBAL
Lifecycle: Active
IEC 62366-1:2015 — Medical Device Usability Engineering
IEC 62366-1 specifies the application of usability engineering to medical devices to mitigate use-related risks. Drives the Use Specification, identification of hazardous use scenarios, formative + summative evaluation, and the Usability Engineering File (UEF). Required by EU MDR + IVDR + FDA via Human Factors Engineering guidance. Failure to perform summative evaluation on the production-equivalent device is a common notified-body finding + FDA 510(k) deficiency.
Jurisdiction: GLOBAL
Lifecycle: Active
IEC 62443 — Industrial Automation + Control Systems Security
IEC 62443 (formerly ISA-99) is the leading international cybersecurity standard for Industrial Automation and Control Systems (IACS). Multi-part series covering general concepts, policies + procedures, system requirements + component requirements. Risk-based zone + conduit model + Security Levels (SL 1-4). Used by OT product vendors (62443-4-1/4-2) + asset owners (62443-2-1/3-2/3-3). Increasingly required in OT procurement; certifiable by IECEE. NIST SP 800-82 + ENISA + national CSIRTs align with 62443.
Jurisdiction: GLOBAL
Lifecycle: Active
IEC 62443-3-2 profile
IEC 62443-3-2 specifies the security risk assessment methodology for industrial automation and control systems (IACS) — zones, conduits, and security-level target identification. Asset owners, integrators, and product suppliers use it to produce defensible zoning decisions, residual-risk acceptance, and design-time security requirements ahead of build. Customer audits and insurer questionnaires for OT environments increasingly call out 3-2 explicitly.
Jurisdiction: GLOBAL
Lifecycle: Active
IEC 62443-3-3 profile
IEC 62443-3-3 defines the system security requirements and security levels (SL-1 through SL-4) for IACS — what a fully designed industrial control system must satisfy at each security level. Use it to specify procurement requirements, design-review acceptance criteria, and operational compliance for the systems running plants, pipelines, energy, water, and transport infrastructure.
Jurisdiction: GLOBAL
Lifecycle: Active
IEC 62443-4-1 profile
IEC 62443-4-1 sets the secure product-development lifecycle requirements for IACS product suppliers — covering security requirements management, secure design, secure implementation, verification and validation, defect management, and product end-of-life. Customers in critical infrastructure increasingly require 4-1 certification or alignment as a precondition for procurement.
Jurisdiction: GLOBAL
Lifecycle: Active
IEC 62443-4-2 profile
IEC 62443-4-2 defines the technical security requirements for IACS components — devices, embedded systems, network components, software applications, and host devices. Product suppliers, system integrators, and asset owners use it to evidence component-level security capabilities aligned to the security levels (SL-C 1-4) the system architecture requires.
Jurisdiction: GLOBAL
Lifecycle: Active
IEC 62443 Profile
IEC 62443 is the international standards family for industrial automation and control system (IACS) cybersecurity — adopted across manufacturing, energy, water, transport, and process industries. It defines security levels, zones-and-conduits architecture, component-level requirements, and product-development practices. Customer audits from large industrial buyers, NIS2 sector overlays, and insurer questionnaires increasingly reference 62443 explicitly. A defensible programme demonstrates segmentation evidence, secure-by-design controls in product development, vulnerability handling that doesn’t freeze plants, and a service-provider model that survives long equipment lifecycles.
Jurisdiction: GLOBAL
Lifecycle: Active
IEC 81001-5-1:2021
IEC 81001-5-1 specifies the cybersecurity activities required across the lifecycle of health software and health IT systems — required by FDA premarket cybersecurity guidance, EU MDCG cybersecurity guidance, and increasingly by NHS DTAC and DSPT reviewers. Manufacturers must evidence a secure development process, threat modelling, vulnerability handling, post-market monitoring, and end-of-support communications. The standard sits beside IEC 62304 (software lifecycle) and ISO 14971 (risk) to cover medical-device cybersecurity end-to-end.
Jurisdiction: GLOBAL
Lifecycle: Active
International Financial Reporting Standards (IFRS)
International Financial Reporting Standards published by the IFRS Foundation + International Accounting Standards Board (IASB). The global accounting framework adopted (or substantially converged) by 168+ jurisdictions including the EU, UK (FRS 101 incorporates), Canada, Australia, India + most other major economies (notable holdout: US). Key standards include IFRS 15 (Revenue), IFRS 16 (Leases), IFRS 17 (Insurance Contracts — see separate reference), IFRS 9 (Financial Instruments), IFRS 13 (Fair Value), IAS 12 (Income Taxes), IAS 21 (FX), IAS 36 (Impairment), IAS 38 (Intangibles).
Jurisdiction: GLOBAL
Lifecycle: Active
IFRS 17 Insurance Contracts
IFRS 17 replaced IFRS 4 as the IASB's accounting standard for insurance contracts. Introduces a current measurement model (General Measurement Model — GMM) with Variable Fee Approach (VFA) for direct participating contracts + Premium Allocation Approach (PAA) simplification for short-duration contracts. Requires presentation of insurance revenue + insurance service expense separately from investment + financing components. Required by IFRS-reporting insurers including most EU + UK + Canadian + Australian insurance groups. US insurers continue under US GAAP (LDTI for long-duration contracts).
Jurisdiction: GLOBAL
Lifecycle: Active
IMDG Code — Dangerous Goods at Sea
The International Maritime Dangerous Goods (IMDG) Code is the international standard for the safe transport of packaged dangerous goods by sea. Adopted under SOLAS Chapter VII; mandatory since 2004. Classifies + sets packaging, marking, labelling, stowage, segregation + documentation requirements for 9 classes of dangerous goods + marine pollutants. Biennial amendments. Training every 3 years for shore-based personnel. Companion to IATA DGR (air), ADR (road), RID (rail), ADN (inland waterways).
Jurisdiction: GLOBAL
Lifecycle: Active
IMO ISM Code — Safety Management
The International Safety Management (ISM) Code (SOLAS Chapter IX) sets an international standard for the safe management + operation of ships + for pollution prevention. Requires shipping companies to establish a Safety Management System (SMS) + obtain a Document of Compliance (DOC) for the company + a Safety Management Certificate (SMC) for each ship. Designated Person Ashore (DPA) acts as the link between company + ship. Audits by flag State / Recognised Organisation every 30 months. Failure can result in DOC withdrawal + ship detention.
Jurisdiction: GLOBAL
Lifecycle: Active