Skip to main content
Standards

Standards-aware policy and compliance guidance

Browse active standards and frameworks that inform how Quick Policy baselines policy drafting and review.

Mapped standards (ISO, SOC 2, UK GDPR, and more)
Source-linked summaries
Policy-family guidance

Active public standards

Each page explains what the standard is, why it matters, and how Quick Policy helps teams draft and govern policies against it.

404 standards

Browsing all 404 standards. Search by name, code or plain-English purpose.

IMO_ISPS_CODE

IMO ISPS Code — Ship + Port Facility Security

The International Ship and Port Facility Security (ISPS) Code (SOLAS Chapter XI-2) sets requirements for the security of ships + port facilities. Risk-based with security levels (1-3). Requires Ship Security Officer (SSO), Company Security Officer (CSO), Port Facility Security Officer (PFSO), Ship Security Plan (SSP), Port Facility Security Plan (PFSP) + International Ship Security Certificate (ISSC). Established post-9/11. Audited by RSO / flag State; ports administered by Contracting Government Designated Authority.

Jurisdiction: GLOBAL

Lifecycle: Active

IMO_MARPOL

IMO MARPOL — Prevention of Pollution from Ships

The International Convention for the Prevention of Pollution from Ships, 1973/1978 (MARPOL) is the principal international convention covering prevention of pollution of the marine environment by ships. Six annexes cover oil (Annex I), noxious liquid substances in bulk (Annex II), packaged harmful substances (Annex III), sewage (Annex IV), garbage (Annex V) + air pollution (Annex VI, including IMO 2020 sulphur cap + EEXI + CII + GHG measures). Companion: London Convention/Protocol for dumping. Flag State + Port State Control enforcement.

Jurisdiction: GLOBAL

Lifecycle: Active

IMO_MLC_2006

ILO Maritime Labour Convention 2006

The Maritime Labour Convention 2006 (MLC, 2006), known as the "seafarers' bill of rights", sets minimum employment + living + working conditions for seafarers. Comprehensive coverage: minimum age (16-18), medical fitness, qualifications, recruitment + placement, employment agreements, wages, hours of work + rest, leave, repatriation, accommodation, food, medical care, social security, health + safety + accident prevention + complaint procedures. Port State Control inspections + Maritime Labour Certificate (MLC) + Declaration of Maritime Labour Compliance (DMLC) for >500 GT.

Jurisdiction: GLOBAL

Lifecycle: Active

IMO_SOLAS

IMO SOLAS — Safety of Life at Sea

The International Convention for the Safety of Life at Sea, 1974 (SOLAS) is the most important international maritime safety treaty. Sets minimum safety standards for the construction, equipment + operation of merchant ships. Companion conventions: MARPOL (pollution), STCW (seafarer training), MLC (labour). Flag States enforce SOLAS via Port State Control + Recognised Organisations (Class Societies). Amendments adopted regularly via IMO MSC + MEPC. Modern enforcement includes ISM Code + ISPS Code as SOLAS chapters.

Jurisdiction: GLOBAL

Lifecycle: Active

IMO_STCW

IMO STCW — Seafarer Training + Certification

The International Convention on Standards of Training, Certification and Watchkeeping for Seafarers, 1978 (STCW) sets the qualifications + training of masters, officers + watch personnel on seagoing vessels. STCW Code Parts A (mandatory) + B (guidance). Manila Amendments 2010 introduced mandatory hours of rest, security awareness training + revised competence standards. Flag State certification + Recognised Organisation training centres. Companion: STCW-F for fishing vessel personnel.

Jurisdiction: GLOBAL

Lifecycle: Active

INVESTMENT_ADVISERS_ACT_1940

US Investment Advisers Act of 1940

The US federal statute regulating investment advisers — investment professionals advising on securities for compensation. Imposes fiduciary duty to clients, registration with SEC (≥ $110m AUM) or state authorities (smaller), Form ADV disclosure, code of ethics, compliance program (Rule 206(4)-7), recordkeeping (Rule 204-2), custody (Rule 206(4)-2), proxy voting (Rule 206(4)-6), marketing (Rule 206(4)-1 — "Marketing Rule"). SEC OCIE / Division of Examinations conducts ongoing examinations.

Jurisdiction: US

Lifecycle: Active

IRC_CURRENT

IRC — International Residential Code

The International Residential Code (IRC), published by ICC, is the model code for the construction of one + two-family dwellings + townhouses up to 3 storeys in the US. Provides a single, comprehensive code combining building, plumbing, mechanical, electrical (via NEC reference), fuel gas + energy (via IECC reference) provisions for low-rise residential construction. Adopted with amendments by most US jurisdictions. IRC scope ends + IBC begins for buildings >3 storeys or non-conforming residential types.

Jurisdiction: US

Lifecycle: Active

ISA_CURRENT

International Standards on Auditing (ISA)

International Standards on Auditing (ISAs) are the global standards for the audit of historical financial statements, published by the International Auditing + Assurance Standards Board (IAASB). Adopted by 130+ jurisdictions either directly or via national equivalents. Cover the audit lifecycle from engagement acceptance, planning, risk assessment, evidence gathering, conclusions, reporting + group audit considerations. Closely related to ISRE (reviews), ISAE (assurance engagements) + ISRS (related services). Audit firms applying ISAs operate ISQM 1 + 2 quality management.

Jurisdiction: GLOBAL

Lifecycle: Active

ISO_13485_2016

ISO 13485:2016

ISO 13485 is the international quality management system standard for medical-device manufacturers — required by most regulators (FDA, MHRA, EMA, PMDA, NMPA) as evidence that a manufacturer can consistently meet customer and regulatory requirements applicable to medical devices. Notified body audits drive certification cycles; loss or suspension of an ISO 13485 certificate can stop CE marking and market access. Sustained operation requires design-control discipline, supplier oversight, post-market surveillance, and CAPA closure that the auditor can trace end-to-end.

Jurisdiction: GLOBAL

Lifecycle: Active

ISO_14001_2015

ISO 14001

ISO 14001:2015 is the international standard for environmental management systems (EMS). Certifiable. Increasingly required by enterprise procurement + supply-chain due diligence. Provides the management-system structure for environmental impact identification, lifecycle thinking, and continuous improvement. Pairs naturally with ISO 9001 + ISO 45001 for integrated management.

Jurisdiction: GLOBAL

Lifecycle: Active

ISO_14971_2019

ISO 14971:2019 — Medical Device Risk Management

ISO 14971:2019 specifies the process for medical device manufacturers to identify hazards + estimate, evaluate, control + monitor risks across the device lifecycle. Required by EU MDR + IVDR + FDA QMSR (via ISO 13485 incorporation) + every major regulator. Drives the Risk Management Plan, Risk Management File, hazard analysis (top-down + bottom-up), risk-benefit analysis + post-production information feedback. The A11:2021 amendment aligns the standard with EU MDR/IVDR risk-benefit + risk-control language. Failure to maintain a current RMF is the most common notified-body audit finding.

Jurisdiction: GLOBAL

Lifecycle: Active

ISO_19650_1_2018

ISO 19650-1:2018

ISO 19650-1 is the foundational standard for information management using BIM (Building Information Modelling) over the whole asset life cycle. Required on most UK public-sector construction projects and increasingly cited in private-sector procurement, it sets the concepts and principles that the rest of the 19650 series builds on. Use it to align project-information delivery with appointing-party requirements and to evidence BIM-mature processes during contract bids.

Jurisdiction: GLOBAL

Lifecycle: Active

ISO_19650_2_2018

ISO 19650-2:2018

ISO 19650-2 specifies the information-management process during the delivery phase of capital projects using BIM. Contractors, designers, and consultants on construction projects must evidence Common Data Environment (CDE) workflows, information-exchange milestones, BEP and EIR alignment, and named information-management responsibilities. Public-sector and major-infrastructure procurement increasingly require 19650-2 alignment as a precondition for bid.

Jurisdiction: GLOBAL

Lifecycle: Active

ISO_19650_3_2020

ISO 19650-3:2020

ISO 19650-3 covers the information-management process during the operational phase of assets — once the building or infrastructure is in use. Owner/operators, facilities managers, and asset-management teams use it to keep BIM-derived information current through changes, maintenance, and refurbishment. Increasingly required for public-sector asset operators and for projects that need to demonstrate whole-life information management beyond handover.

Jurisdiction: GLOBAL

Lifecycle: Active

ISO_19650_4_2022

ISO 19650-4:2022

ISO 19650-4 sets information-exchange requirements between parties on BIM-enabled construction projects — defining how information is requested, produced, reviewed, and accepted. Use it to remove ambiguity from BEP/EIR negotiations and to give auditors and clients defensible evidence that information exchanges meet contractual requirements.

Jurisdiction: GLOBAL

Lifecycle: Active

ISO_19650_5_2020

ISO 19650-5:2020

ISO 19650-5 specifies the security-minded approach to information management for construction projects and operational assets — the BIM-specific security standard increasingly required on critical infrastructure (defence, energy, transport, government estates). It defines sensitivity-aware information classification, security triage, and the security-minded common data environment.

Jurisdiction: GLOBAL

Lifecycle: Active

ISO_19650_6_2025

ISO 19650-6:2025

ISO 19650-6 (Health and Safety information requirements) extends the 19650 series with explicit health and safety information management — turning the Construction Design and Management (CDM) duties and Building Safety Act 2022 information requirements into BIM-aligned workflows. Required reading for designers, contractors, and principal designers on UK high-risk building projects.

Jurisdiction: GLOBAL

Lifecycle: Active

ISO_19650_BIM

ISO 19650 — BIM Information Management

ISO 19650 is the international standard for the management of information using Building Information Modelling (BIM) across the lifecycle of the built asset. Parts 1-5 cover concepts, delivery phase, operational phase, information exchange + security-minded approach. UK adoption via the UK BIM Framework. Required by the UK Construction Playbook for public sector + increasingly contractually required in private sector. Drives EIR / BEP / common data environment / federation strategy.

Jurisdiction: GLOBAL

Lifecycle: Active

ISO_SAE_21434_2021

ISO/SAE 21434

ISO/SAE 21434 is the cybersecurity engineering lifecycle standard for road vehicles — required reading for OEMs, Tier 1, and Tier 2 automotive suppliers under UNECE R155 type-approval. It covers cybersecurity governance, threat analysis and risk assessment (TARA), product development, production, operations, decommissioning, and post-production cyber-security responsibilities. Customer audits from OEMs are now routine, and supplier disqualification follows quickly when a Tier 1 cannot demonstrate a documented CSMS, defensible TARA outputs, and a vulnerability-handling process that actually closes loops back into engineering.

Jurisdiction: GLOBAL

Lifecycle: Active

ISO_22000_2018

ISO 22000:2018 — Food Safety Management Systems

ISO 22000:2018 specifies requirements for a food safety management system across the food chain. Combines HACCP principles with the PDCA + risk-based thinking of ISO management systems. Used by global food manufacturers + the GFSI-benchmarked schemes (FSSC 22000, BRCGS, IFS, SQF) build on it or align with it.

Jurisdiction: GLOBAL

Lifecycle: Active

ISO_22301_2019

ISO 22301

ISO/IEC 22301 is the international standard for business continuity management systems (BCMS). It is referenced by financial regulators (FCA/PRA, DORA), public-sector procurement, and large-enterprise vendor questionnaires as evidence that an organisation can survive disruption — cyber incidents, supplier failures, pandemics, supply-chain shocks. Auditors look for a current Business Impact Analysis, defined RTO/RPO per critical service, exercised continuity and recovery plans, and evidence the BCMS feeds back into actual operational change. Strong BCMS programmes also satisfy operational resilience expectations under DORA and FCA rules.

Jurisdiction: GLOBAL

Lifecycle: Active

ISO_IEC_22989_2022

ISO/IEC 22989

ISO/IEC 22989 establishes the international vocabulary and taxonomy for artificial intelligence — the agreed-language foundation other ISO AI standards (42001, 23053, 23894, 42005, 38507) build on. Use it to make sure governance, legal, and engineering teams describe AI systems consistently in policies, risk registers, model documentation, and customer-facing assurance artefacts. Underrated in marketing but critical when an enterprise buyer asks where you draw the line between "AI", "machine learning", and "automation".

Jurisdiction: GLOBAL

Lifecycle: Active

ISO_IEC_23053_2022

ISO/IEC 23053

ISO/IEC 23053 defines the standard framework for describing AI systems that use machine learning — components, data lifecycle, model lifecycle, deployment, and monitoring. It gives organisations a shared structure for documenting ML systems so governance, model risk management, and audit teams can review them without bespoke templates per use case. Most useful when paired with ISO 42001 governance and ISO 23894 risk management to evidence end-to-end AI accountability.

Jurisdiction: GLOBAL

Lifecycle: Active

ISO_IEC_23894_2023

ISO/IEC 23894

ISO/IEC 23894 is the international guidance standard for AI risk management — sitting between the generic ISO 31000 risk-management framework and the certifiable ISO 42001 AI management system. It walks through how to identify, assess, treat, and monitor AI-specific risks across the lifecycle, with explicit treatment of fairness, robustness, transparency, and harm. Use it when ISO 42001 says "manage AI risk" and your team needs a defensible method to actually do that.

Jurisdiction: GLOBAL

Lifecycle: Active

ISO_IEC_27001_2022

ISO/IEC 27001

Information Security Management System (ISMS) controls and governance requirements.

Jurisdiction: GLOBAL

Lifecycle: Active

ISO_IEC_27002_2022

ISO/IEC 27002

ISO/IEC 27002 is the implementation companion to ISO/IEC 27001 — the practical control catalogue auditors and consultants reach for when they need to translate ISMS requirements into operational policies and procedures. The 2022 revision restructured the catalogue into 93 controls across four themes (organisational, people, physical, technological) and introduced attribute-based filtering by control type, security property, cybersecurity concept, operational capability, and security domain. Use it as the source of truth for control statements that align with 27001 certification or with internal security programmes that aren’t pursuing certification.

Jurisdiction: GLOBAL

Lifecycle: Active

ISO_IEC_27005_2022

ISO/IEC 27005

ISO/IEC 27005:2022 provides guidance on information security risk management within the context of an ISO 27001 ISMS. The 2022 revision aligned with ISO 31000 risk-management terminology and re-anchored the process around organisational context, risk identification, analysis, evaluation, and treatment. The reference companion auditors expect to see ISO 27001-aligned risk programmes follow.

Jurisdiction: GLOBAL

Lifecycle: Active

ISO_IEC_27017_2015

ISO/IEC 27017

ISO/IEC 27017 is the cloud-services extension to ISO 27001/27002 — the standard cloud service providers and cloud service customers both use to define shared security responsibilities. Enterprise procurement teams increasingly ask cloud-native vendors for ISO 27017 alignment or certification on top of ISO 27001, and the standard fills the gap between generic ISMS controls and the specific roles each side plays in a cloud deployment (capacity management, virtual-image hardening, multi-tenancy isolation, administrative access).

Jurisdiction: GLOBAL

Lifecycle: Active

ISO_IEC_27018_2019

ISO/IEC 27018

ISO/IEC 27018 is the privacy-in-cloud standard for processors handling personally identifiable information (PII) in public-cloud services. Major CSPs certify against it as evidence of GDPR-aligned data-handling commitments to customers; downstream SaaS vendors that hold PII on behalf of clients use it to demonstrate processor accountability without re-litigating every clause of GDPR. It complements ISO 27001 + 27701 and is one of the most commonly referenced standards in B2B SaaS vendor diligence.

Jurisdiction: GLOBAL

Lifecycle: Active

ISO_IEC_27032_2023

ISO/IEC 27032

ISO/IEC 27032:2023 provides guidance on internet security — the intersection of information, network, and application security. The 2023 revision broadened scope to include supply-chain dependencies, cloud services, and IoT, and is often cited alongside ISO 27001 for organisations wanting a cyber-specific complement to general ISMS controls.

Jurisdiction: GLOBAL

Lifecycle: Active

ISO_IEC_27036_2021

ISO/IEC 27036

ISO/IEC 27036 (multi-part) provides guidance on information security for supplier relationships. Part 1 covers overview + concepts, Part 2 requirements, Part 3 specifics for ICT supply chain, Part 4 cloud-service customer + provider relationships. The standard supplier-risk reference for ISO 27001-aligned programmes; pairs with ISO 27017 for cloud-specific shared-responsibility.

Jurisdiction: GLOBAL

Lifecycle: Active

ISO_IEC_27701_2019

ISO/IEC 27701

ISO/IEC 27701 extends ISO/IEC 27001 with privacy controls — turning a security management system into a privacy information management system (PIMS). It is increasingly used to evidence GDPR Article 24/25 accountability, demonstrate controller/processor responsibilities, and earn third-party assurance for international transfers. Certification (or alignment) is a fast way for B2B vendors to answer privacy diligence questionnaires without writing custom evidence for every prospect. The standard maps cleanly to GDPR articles so privacy teams stop maintaining parallel control sets.

Jurisdiction: GLOBAL

Lifecycle: Active

ISO_28000_2007

ISO 28000

ISO 28000 is the management-system standard for supply-chain security — covering risk identification, controls, and continual improvement for organisations whose operations depend on physical and logical supply chains. Increasingly referenced in critical-infrastructure procurement, customs and trade-facilitation programmes (AEO, C-TPAT), and as a complement to ISO 22301 business continuity. The 2022 revision aligned its structure with other management-system standards for easier integration.

Jurisdiction: GLOBAL

Lifecycle: Active

ISO_28000_SUPPLY_CHAIN

ISO 28000 — Security Management for Supply Chain

ISO 28000:2022 specifies requirements for a security management system, including aspects relevant to the supply chain. Applicable to organisations of all sizes that wish to establish, implement, maintain + improve a security management system. Aligned with ISO 9001 + 14001 + 45001 + 27001 in High-Level Structure. Used by logistics operators, warehousing + cross-border supply chains to evidence supply chain security to customers + customs authorities. Pairs with TAPA FSR + AEO programs.

Jurisdiction: GLOBAL

Lifecycle: Active

ISO_31000_2018

ISO 31000

ISO 31000:2018 is the international principles-and-guidelines standard for risk management — the conceptual backbone behind sector-specific risk standards (ISO 27005 for ISMS, ISO 22301 for BCM, ISO 23894 for AI). The 2018 revision sharpened the principles to 8 and emphasised integration of risk management into governance. Not certifiable but heavily referenced by certification standards.

Jurisdiction: GLOBAL

Lifecycle: Active

ISO_37301_2021

ISO 37301

ISO 37301:2021 specifies requirements + guidance for compliance management systems (CMS). Certifiable. Designed to be applicable across industries + regulatory domains. The reference standard for organisations wanting a unifying management-system approach to compliance — popular with multinational + regulated firms that already operate ISO 27001 / 9001 / 45001 management systems.

Jurisdiction: GLOBAL

Lifecycle: Active

ISO_IEC_38507_2022

ISO/IEC 38507

ISO/IEC 38507 sets governance guidance for the use of AI by organisations — written for boards, executive teams, and accountable owners rather than technical staff. It connects AI use to corporate governance, fiduciary duty, and stakeholder accountability, making it the natural reference for board-level AI policy, risk-appetite statements, and committee charters. Use it alongside ISO 42001 (operational) and ISO 23894 (risk) to give directors the language they need to ask the right questions.

Jurisdiction: GLOBAL

Lifecycle: Active

ISO_41001_FM

ISO 41001:2018 Facility Management Systems

ISO management system standard for Facility Management. Specifies requirements for an FM management system covering demand + supply organisation, service delivery, integration of people, place, process + technology. Certifiable.

Jurisdiction: GLOBAL

Lifecycle: Active

ISO_IEC_42001_2023

ISO/IEC 42001

ISO/IEC 42001 is the first certifiable management system standard for artificial intelligence — the AI-era counterpart to ISO 27001. It requires named AI governance, lifecycle risk assessment, transparency commitments, and continuous monitoring across every AI use case the business operates or relies on. Procurement teams at regulated buyers (banks, healthcare, public sector) have started to ask for ISO 42001 alignment or roadmap before they accept AI-enabled products, and EU AI Act enforcement makes documented AI management non-optional. Quick Policy seeds the governance, risk, and monitoring policies the standard demands.

Jurisdiction: GLOBAL

Lifecycle: Active

ISO_IEC_42005_2025

ISO/IEC 42005

ISO/IEC 42005 provides guidance for conducting AI system impact assessments — covering both expected benefits and the social, ethical, and rights-related risks of an AI use case. It is the structured method that lets an organisation make a defensible go/no-go decision on a use case before resources are committed, and the artefact procurement reviewers and regulators increasingly ask to see for high-impact AI. Use it to satisfy ISO 42001 Clause 8.4 impact-assessment requirements and to align with EU AI Act fundamental-rights impact assessment expectations.

Jurisdiction: GLOBAL

Lifecycle: Active

ISO_45001_2018

ISO 45001

ISO 45001:2018 is the international standard for occupational health + safety management systems (OHSMS). Certifiable. Replaced OHSAS 18001 as the global benchmark. Required by major construction / manufacturing / energy procurement and useful for any organisation with workplace safety risks. Pairs naturally with ISO 9001 + ISO 14001 for integrated management.

Jurisdiction: GLOBAL

Lifecycle: Active

ISO_50001_2018

ISO 50001:2018 — Energy Management Systems

ISO 50001:2018 specifies requirements for establishing, implementing, maintaining + improving an energy management system (EnMS). Enables organisations to achieve continual improvement in energy performance, energy efficiency, energy use + consumption. Pairs well with ISO 14001 + ISO 45001 + ISO 9001 in integrated management systems. Certifiable through accredited bodies. Used to evidence energy reduction in TCFD / CSRD reporting.

Jurisdiction: GLOBAL

Lifecycle: Active

ISO_IEC_5338_2025

ISO/IEC 5338

ISO/IEC 5338 specifies AI system lifecycle processes — extending ISO/IEC 12207 (software lifecycle) and 15288 (systems lifecycle) to cover AI-specific concerns from concept through retirement. Engineering, MLOps, and quality teams use it to define gated lifecycle stages, validation criteria, and handoff artefacts. Pair with ISO 42001 governance to evidence "managed AI lifecycle" claims to auditors and procurement reviewers in regulated sectors.

Jurisdiction: GLOBAL

Lifecycle: Active

ISO_55000_ASSET_MGMT

ISO 55000 — Asset Management

ISO 55000 (Asset Management — Overview, principles + terminology), ISO 55001 (requirements) + ISO 55002 (guidance) provide the international framework for managing physical + intangible assets across their lifecycle. Widely adopted by utilities, transport + heavy industry to demonstrate that critical infrastructure investment + maintenance is risk-informed + value-aligned. Pairs with PAS 55-equivalent (predecessor) + RIIO price control submissions in UK.

Jurisdiction: GLOBAL

Lifecycle: Active

ISO_9001_2015

ISO 9001

ISO 9001:2015 is the international standard for quality management systems (QMS). Certifiable. Provides the management-system structure that other ISO management standards mirror (the "Annex SL" structure). Common pre-requisite for manufacturing + professional-services procurement and frequently mandated in regulated sectors. ISO 9001:2026 is in development.

Jurisdiction: GLOBAL

Lifecycle: Active

ISO_TR_24971_2020

ISO/TR 24971:2020

ISO/TR 24971 is the technical-report companion to ISO 14971 — practical guidance on applying medical-device risk management in the way notified bodies and FDA reviewers expect. Cited heavily in technical files because it bridges the abstract requirements of 14971 with the day-to-day decisions risk teams have to document for an audit. Essential reading alongside 14971 for any medical device team building or maintaining a regulator-ready risk file.

Jurisdiction: GLOBAL

Lifecycle: Active

ISQM_1_2_2022

ISQM 1 + ISQM 2 + ISA 220 (Revised) — Quality Management

ISQM 1 (firm-level quality management), ISQM 2 (engagement quality reviews) + ISA 220 Revised (engagement-level quality management) form the IAASB's revised quality management framework for audit firms applying ISAs. Effective 15 December 2022, ISQM 1 replaced ISQC 1 with a risk-based + proactive system requiring quality objectives, risk assessment, response design + monitoring + remediation. Annual evaluation of the firm's system of quality management by leadership.

Jurisdiction: GLOBAL

Lifecycle: Active

ITIL_4_2019

ITIL 4

ITIL 4 (AXELOS / PeopleCert) is the leading IT service management (ITSM) framework. Reorganised the prior ITIL v3 process orientation into 34 management practices across the ITIL Service Value System. The reference framework for incident, change, problem, request, and asset management — increasingly aligned with DevOps + product-oriented delivery. Foundation + Specialist certifications are widely required for IT operations roles.

Jurisdiction: GLOBAL

Lifecycle: Active

JMLSG_GUIDANCE

JMLSG Anti-Money Laundering Guidance

Joint Money Laundering Steering Group guidance interprets the UK MLR 2017 for the financial sector and is HM Treasury–approved. While primarily for FCA-regulated firms, accountancy practices providing payment, trust or company-formation services use JMLSG Part II sectoral guidance to calibrate risk-based CDD and monitoring.

Jurisdiction: UK

Lifecycle: Active

JOINT_COMMISSION_HOSPITAL

The Joint Commission — Hospital Accreditation

The Joint Commission (TJC) is the largest CMS-deemed hospital accreditor in the US. Accreditation covers all chapters of the Comprehensive Accreditation Manual for Hospitals (CAMH) — National Patient Safety Goals, Provision of Care, Treatment + Services, Medication Management, Infection Prevention + Control, Performance Improvement, Leadership, Information Management, Environment of Care, Emergency Management, Human Resources + Record of Care. Triennial unannounced on-site surveys + intracycle Sentinel Event reporting. Loss of TJC accreditation often triggers CMS termination of provider agreement.

Jurisdiction: US

Lifecycle: Active

LEED_V4_1

LEED v4.1 — USGBC Sustainable Building Rating

LEED (Leadership in Energy and Environmental Design), administered by the US Green Building Council (USGBC), is the world's most widely-used green building rating system. LEED v4.1 covers Building Design + Construction (BD+C), Interior Design + Construction (ID+C), Building Operations + Maintenance (O+M), Neighborhood Development (ND), Homes + Cities + Communities. Project teams earn points across 9 credit categories for Certified / Silver / Gold / Platinum rating. Widely required in US owner + investor procurement.

Jurisdiction: GLOBAL

Lifecycle: Active

LLOYDS_MARKET_RULES

Lloyd's Market Rules — Performance Management + Conduct

Lloyd's of London is the world's specialist insurance + reinsurance marketplace. Lloyd's syndicates + managing agents must comply with FCA + PRA regulation plus Lloyd's-specific requirements: Lloyd's Minimum Standards (governance, risk, capital, conduct, operations + reporting) + Performance Management Supplement. Major changes during transformation (Future at Lloyd's) increasingly digitalise the market + impose tighter performance + conduct standards. Customer + claims focus + Consumer Duty alignment are critical.

Jurisdiction: UK

Lifecycle: Active

MHRA_GPVP

MHRA Good Pharmacovigilance Practice (GPvP)

MHRA Good Pharmacovigilance Practice (GPvP) governs the system Marketing Authorisation Holders use in the UK to monitor + report on the safety of medicinal products. Largely aligned with EU GVP modules — pharmacovigilance system master file (PSMF), QPPV (Qualified Person for Pharmacovigilance), ICSR reporting, PSURs / PBRERs, risk management plans, signal management + post-authorisation safety studies. MHRA inspectorate conducts routine + for-cause GPvP inspections with critical / major / minor finding grading. Failure has resulted in regulatory action + market withdrawals.

Jurisdiction: UK

Lifecycle: Active

MICA_EU_2023_1114

EU Markets in Crypto-Assets Regulation (MiCA)

MiCA is the EU regulatory framework for crypto-asset issuers + crypto-asset service providers (CASPs). Three categories of crypto-assets: e-money tokens (EMTs), asset-referenced tokens (ARTs) + other crypto-assets. Imposes white-paper requirements, authorisation + ongoing requirements on CASPs, governance + capital requirements, custody + segregation, market abuse + transparency. Provides EU passport rights once authorised in one member state. Title V on CASP services + Title VI on market abuse apply from 30 December 2024; stablecoin titles from 30 June 2024.

Jurisdiction: EU

Lifecycle: Active

MIFID_II_2014_65

Markets in Financial Instruments Directive II + Regulation (MiFID II / MiFIR)

MiFID II + MiFIR establish the EU regulatory framework for investment firms + trading venues. Comprehensive scope: investor protection (suitability, appropriateness, best execution, product governance), market structure (organised trading facilities, systematic internalisers), market transparency (pre/post-trade), commodity derivative position limits, third-country firms regime. Enforcement: national competent authorities, coordinated by ESMA. UK applies retained UK MiFID II post-Brexit (with FCA divergences). MiFID II Review 2024 introduces consolidated tape + revisions to research unbundling + payment for order flow.

Jurisdiction: EU

Lifecycle: Active

MSC_FISHERIES_STANDARD

MSC Fisheries Standard v3.0

Marine Stewardship Council's certification standard for wild-capture fisheries — sustainable stocks, minimal environmental impact + effective management. Companion: MSC Chain of Custody Standard for supply chain traceability.

Jurisdiction: GLOBAL

Lifecycle: Active

HMRC_MTD_ITSA

Making Tax Digital for Income Tax Self Assessment

Making Tax Digital for Income Tax Self Assessment requires affected sole traders and landlords (and their agents) to keep digital records and submit quarterly updates plus a final declaration to HMRC using compatible software. Accountancy firms acting as tax agents must operate MTD-compliant digital record-keeping, agent authorisation, and submission processes.

Jurisdiction: UK

Lifecycle: Active

NAIC_MODEL_LAWS

NAIC Model Laws + Regulations

National Association of Insurance Commissioners (NAIC) Model Laws + Regulations form the basis of state-by-state US insurance regulation. Key models adopted in many states: Insurance Data Security Model Law (#668), Corporate Governance Annual Disclosure Model Act, Own Risk + Solvency Assessment (ORSA) Model Act, Credit for Reinsurance Model Law, Insurance Holding Company System Model Act. Each US insurer is regulated by its state of domicile + states where it transacts business; NAIC accreditation provides standardised supervision baseline.

Jurisdiction: US

Lifecycle: Active

NCQA_ACCREDITATION

NCQA Accreditation Programs

NCQA Accreditation programs benchmark + recognise quality across health plans, MBHOs, UM organisations, credentialing verification organisations + accountable care organisations. Health Plan Accreditation (HPA) is the most prevalent — driving CMS Star Ratings + state Medicaid contract requirements. Standards cover quality management + improvement, population health management, network management, utilisation management, credentialing + recredentialing, members' rights + responsibilities + member connections + Medicare-specific + Medicaid-specific modules. Surveyor-led on-site + virtual reviews on a 3-year cycle.

Jurisdiction: US

Lifecycle: Active

NERC_CIP

NERC Critical Infrastructure Protection (CIP)

NERC CIP Reliability Standards set cybersecurity + physical security requirements for the Bulk Electric System (BES) in North America. Mandatory + enforceable under the Federal Power Act. Cover BES Cyber Asset identification (CIP-002), security management controls, personnel + training (CIP-004), electronic + physical security perimeters (CIP-005/006), systems security management (CIP-007), incident reporting (CIP-008), recovery (CIP-009), configuration change management (CIP-010), information protection (CIP-011), supply chain risk (CIP-013) + physical security (CIP-014). Penalties up to $1.5M per day per violation.

Jurisdiction: US

Lifecycle: Active

Review industries served

See how standards context shows up in sector-specific rollout and drafting guidance.

Read supporting articles

Explore long-form explainers, buyer guides, and roadmap content that supports these standards pages.

Validate platform fit

Compare the workflow, trust material, and rollout path before starting a free guided preview.

Need help baselining against specific standards?

Use Quick Policy to turn standards context into practical drafting, review, and evidence workflows.

400+ compliance standards and frameworks (page 3) | Quick Policy