Active public standards
Each page explains what the standard is, why it matters, and how Quick Policy helps teams draft and govern policies against it.
Browsing all 404 standards. Search by name, code or plain-English purpose.
NFPA 101 — Life Safety Code
NFPA 101 (Life Safety Code) establishes minimum requirements for the design, operation + maintenance of buildings + structures for safety to life from fire + similar emergencies. Used alongside or in place of the IBC by certain jurisdictions + sectors (notably CMS-deemed healthcare facilities, which are required to comply with NFPA 101 to participate in Medicare). Covers occupancy classifications, means of egress, protection (fire-resistive construction, compartmentation, detection + alarm, automatic extinguishing), building service + fire protection equipment + operating features.
Jurisdiction: US
Lifecycle: Active
NFPA 70 — National Electrical Code (NEC)
The National Electrical Code (NEC), published by the National Fire Protection Association (NFPA 70), is the US benchmark for safe electrical design, installation + inspection. Adopted with amendments by all 50 states + many local jurisdictions. Covers wiring methods, conductors, branch circuits, feeders, services, overcurrent protection, grounding + bonding, special equipment + special conditions. Used by electrical designers, installers, AHJs (Authorities Having Jurisdiction) + insurers. The single most cited US electrical standard + a frequent subject of inspection findings.
Jurisdiction: US
Lifecycle: Active
NHS DCB0129 — Clinical Risk Management (Manufacturer)
DCB0129 is the NHS England clinical risk management standard for manufacturers of Health IT systems. Requires a documented Clinical Safety Management System overseen by a Clinical Safety Officer (CSO) — typically a registered clinician — to perform clinical risk analysis, define clinical risk controls + produce a Clinical Safety Case + Hazard Log per release. Compliance is a prerequisite for NHS England deployment + a core component of the DTAC assessment. Failure has resulted in patient-safety incidents + contractual rejection.
Jurisdiction: UK
Lifecycle: Active
NHS DCB0160 — Clinical Risk Management (Deploying Organisation)
DCB0160 is the companion to DCB0129 — applying to NHS organisations + others deploying Health IT systems. Mirrors DCB0129 with deployment-side responsibilities: deploying-organisation CSO, deployment-specific clinical risk analysis (configuration, integration, training, business processes), Clinical Safety Case + Hazard Log per deployment + transition. Required for NHS deployments + DTAC assessment.
Jurisdiction: UK
Lifecycle: Active
NHS Data Security and Protection Toolkit
The NHS Data Security and Protection Toolkit (DSPT) is the annual self-assessment every NHS organisation, NHS commissioned service, and supplier to NHS organisations must complete to evidence data-security and information-governance maturity. Failure to publish a satisfactory DSPT can block NHS contracts and procurement opportunities. The toolkit references the National Data Guardian standards, NIS regulations, UK GDPR, and ISO 27001, so DSPT readiness is usually evidenced from a broader ISMS rather than authored from scratch each year.
Jurisdiction: UK
Lifecycle: Active
NHS Digital Technology Assessment Criteria (DTAC)
DTAC is the NHS England assessment criteria for digital health technologies entering the NHS. Five domains: Clinical Safety (DCB0129), Data Protection (UK GDPR + Caldicott + DSPT), Technical Assurance (Cyber Essentials Plus + ISO 27001 / SOC 2), Interoperability (FHIR + SNOMED CT) + Usability + Accessibility (WCAG 2.1 AA). Plus core criteria covering company information + value proposition + MHRA registration where applicable. Most NHS procurements require DTAC completion + supplier evidence pack.
Jurisdiction: UK
Lifecycle: Active
NIS2 Obligations Profile
The EU NIS 2 Directive significantly expanded the scope of cybersecurity obligations across the EU — bringing in essential and important entities across energy, transport, banking, health, digital infrastructure, public administration, postal services, manufacturing of critical products, and more. National transposition gives competent authorities the power to impose fines (up to €10 million or 2% of global turnover for essential entities), suspend leadership, and require third-party audits. NIS 2 expects board-level accountability, supply-chain security obligations, and structured 24/72/30-day incident reporting cadences.
Jurisdiction: EU
Lifecycle: Active
NIST SP 800-53
NIST Special Publication 800-53 Revision 5 is the US federal control catalogue — required for federal information systems under FISMA and the foundation for FedRAMP authorisation. Defence contractors, federal agencies, and public-sector suppliers reference it for control baselines (LOW/MODERATE/HIGH/PRIVACY) and tailoring. Rev 5 made significant updates around supply-chain risk management, privacy, and integration with the NIST Privacy Framework. Even non-government organisations use 800-53 to structure detailed control catalogues when ISO 27002 isn’t prescriptive enough.
Jurisdiction: GLOBAL
Lifecycle: Active
NIST SP 800-82 Rev. 3
NIST SP 800-82 Revision 3 is the US authoritative guide to operational-technology (OT) security — used by federal agencies, defence contractors, and critical-infrastructure operators as the OT-specific complement to NIST SP 800-53. Rev 3 expanded coverage to include cloud-connected OT, IoT in OT environments, and modern threat scenarios. Most useful when an organisation needs prescriptive OT guidance and 800-53 alone is too IT-focused to cover the realities of plant equipment.
Jurisdiction: GLOBAL
Lifecycle: Active
NIST AI RMF
The NIST AI Risk Management Framework is the most-cited public AI risk reference and is increasingly woven into US executive orders, federal procurement, and state legislation. Organised around four functions — Govern, Map, Measure, Manage — it asks teams to identify AI risks across the lifecycle, define metrics for both utility and harm, and document risk responses with named owners. It pairs naturally with ISO 42001 for certifiable AI management and with the EU AI Act for European market access. Use it to give engineers, legal, and risk a shared language for trustworthy AI.
Jurisdiction: GLOBAL
Lifecycle: Active
NIST Cybersecurity Framework
NIST Cybersecurity Framework 2.0 is the most widely adopted voluntary framework in the US and increasingly used as a board-level cybersecurity language globally. Built around six functions — Govern, Identify, Protect, Detect, Respond, Recover — it lets organisations describe maturity in plain English without committing to certification. Regulators, insurers, and customers reference CSF in expectations and questionnaires, so even teams not pursuing formal attestation use it to structure programmes, communicate to leadership, and crosswalk against ISO 27001, SOC 2, and sector standards. The 2.0 release added explicit governance and supply-chain treatment.
Jurisdiction: GLOBAL
Lifecycle: Active
NIST CSF + CISA Transport Sector Cybersecurity
The NIST Cybersecurity Framework 2.0 (CSF 2.0) provides voluntary guidance for managing cybersecurity risks across critical-infrastructure sectors including Transportation Systems. CISA Sector-Specific Plan for Transportation Systems + Maritime Transportation Security Act (MTSA) for ports overlay sectoral expectations. Used by FMCSA, FAA, FRA + TSA as a reference + by maritime + aviation operators for supply chain cyber due diligence.
Jurisdiction: US
Lifecycle: Active
NIST Computer Security Incident Handling Guide (SP 800-61 Rev 2)
Foundational NIST guide for incident response — defines the lifecycle (Preparation, Detection & Analysis, Containment, Eradication & Recovery, Post-Incident) used as the structural template by virtually every modern IR programme and referenced by SOC 2 CC7 + ISO 27001 A.5.24. NIST released a draft Rev 3 in 2024 — programmes should track for sign-off.
Jurisdiction: US
Lifecycle: Active
NIST Privacy Framework
The NIST Privacy Framework is the privacy counterpart to the Cybersecurity Framework — the same five-function structure (Identify-P, Govern-P, Control-P, Communicate-P, Protect-P) used to organise privacy risk activities. US regulators and procurement teams increasingly cite it in questionnaires, and it crosswalks cleanly to GDPR, CCPA/CPRA, and HIPAA so a single set of control statements can answer multiple jurisdictions. Useful for organisations that want privacy maturity without committing to ISO 27701 certification immediately.
Jurisdiction: GLOBAL
Lifecycle: Active
NIST Risk Management Framework (SP 800-37 Rev 2)
The NIST Risk Management Framework provides a structured 7-step process (Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor) for integrating security + privacy + supply-chain risk into the system development lifecycle. Required across US federal civilian agencies via FISMA and used as the assessment cadence backbone of FedRAMP authorisations.
Jurisdiction: US
Lifecycle: Active
NIST SP 800-171 Rev 3
NIST SP 800-171 Rev 3 specifies the security requirements US federal contractors must implement to protect Controlled Unclassified Information (CUI) on non-federal systems. Revision 3, published 2024, restructured the requirements into 17 families with stronger expectations for system architecture, supply chain risk, and ongoing assessment. Mandatory in DoD contracts via DFARS 252.204-7012 and is the technical foundation for CMMC Level 2 assessment.
Jurisdiction: US
Lifecycle: Active
NIST SP 800-82 — ICS Security
NIST SP 800-82 Rev 3 (Guide to Operational Technology Security) provides guidance on securing operational technology (OT) — industrial control systems (ICS), SCADA, distributed control systems (DCS), programmable logic controllers (PLCs) + industrial IoT. Updates the previous "ICS Security" guidance to reflect convergence of IT + OT + new ransomware threats targeting utilities + manufacturing. Aligned with NIST CSF + SP 800-53 + IEC 62443 + provides risk-based control selection for OT environments. Widely referenced by NERC CIP, TSA Pipeline directives + CISA guidance.
Jurisdiction: GLOBAL
Lifecycle: Active
NIST Secure Software Development Framework (SSDF)
NIST SP 800-218 — the Secure Software Development Framework — distils secure software practices into four groups (Prepare, Protect, Produce, Respond) covering 19 practices and 42 tasks. Referenced by US Executive Order 14028 as the baseline for software supplied to the federal government, increasingly cited by enterprise procurement and used as the structural backbone for SBOM and vulnerability-disclosure programmes.
Jurisdiction: US
Lifecycle: Active
NIST SP 800-207 Zero Trust Architecture
NIST SP 800-207 defines Zero Trust Architecture (ZTA) — the security model where no implicit trust is granted by network location, and every request is continuously verified. The publication describes seven tenets, deployment patterns, and component roles (policy engine, policy administrator, policy enforcement point). Cited by US federal Zero-Trust strategy (OMB M-22-09) and increasingly by enterprise architecture teams as the reference model.
Jurisdiction: US
Lifecycle: Active
NY DFS Cybersecurity Regulation (23 NYCRR 500)
New York State Department of Financial Services Cybersecurity Regulation (23 NYCRR 500) is the cyber regulation covering any entity authorised by NYDFS — banks, insurers, mortgage companies, money transmitters, crypto-asset businesses. The November 2023 Second Amendment introduced Class A company tier (≥ $20m revenue + ≥ 2,000 employees + materially impactful) with enhanced obligations, expanded Board oversight + governance requirements, ransomware reporting (within 24 hours of payment), independent audits + risk assessments. CISO must report to Board annually. Multi-factor authentication is now generally mandatory.
Jurisdiction: US-NY
Lifecycle: Active
OECD Common Reporting Standard (CRS)
The Common Reporting Standard (CRS) is the OECD framework for the automatic exchange of financial account information between jurisdictions to combat offshore tax evasion. Financial institutions in CRS-participating jurisdictions (120+ now signed) must identify reportable accounts via due diligence + report annually to local tax authority who exchanges with the account holder's residence jurisdiction. CRS 2.0 (March 2023) extends scope to include crypto-assets via the Crypto-Asset Reporting Framework (CARF), with implementation from 2026.
Jurisdiction: GLOBAL
Lifecycle: Active
OECD/G20 Pillar Two — Global Minimum Tax
OECD/G20 Inclusive Framework Pillar Two introduces a 15% global minimum effective tax rate for multinational enterprises with consolidated revenue ≥ €750m. Three interlocking rules: Income Inclusion Rule (IIR) — parent jurisdiction tops-up to 15% on low-taxed subsidiaries; Undertaxed Payments Rule (UTPR) — allocates additional top-up tax to other jurisdictions; Subject to Tax Rule (STTR) — treaty-based source-state top-up for certain payments. Transposed via EU Pillar Two Directive (2022/2523) + national laws in 30+ jurisdictions (UK, EU member states, South Korea, Japan, Canada, Australia, etc.) for FY beginning after 31 Dec 2023.
Jurisdiction: GLOBAL
Lifecycle: Active
OECD Transfer Pricing Guidelines for MNEs
The OECD Transfer Pricing Guidelines provide guidance on the application of the arm's-length principle for international transfer pricing between associated enterprises. The 2022 consolidation incorporates BEPS Actions 8-10 + 13 reforms including value-creation alignment + Country-by-Country Reporting (CbCR). Heavily relied upon by most OECD + many non-OECD tax administrations + by MNE tax functions for documentation, planning + dispute resolution. CbCR template + master file / local file documentation requirements have been adopted by 110+ jurisdictions.
Jurisdiction: GLOBAL
Lifecycle: Active
US OFAC Sanctions Programs
The US Treasury Office of Foreign Assets Control (OFAC) administers economic + trade sanctions programs against targeted foreign countries + regimes, terrorists, international narcotics traffickers + other threats to US national security. All US persons (citizens, residents, entities, foreign branches of US entities) must comply. Penalties include criminal + civil sanctions reaching tens of millions of dollars per violation; secondary sanctions can apply to non-US entities. Maintains the Specially Designated Nationals (SDN) List + sanctioned-country programs (Russia, Iran, North Korea, Cuba, Venezuela, etc.). Strict liability — no intent required for many violations.
Jurisdiction: US
Lifecycle: Active
ONC 21st Century Cures Act + USCDI v4
The 21st Century Cures Act (2016) + ONC Final Rule (2020) require certified Health IT to support FHIR-based APIs + prohibit information blocking by healthcare providers, EHR vendors + HINs/HIEs. USCDI (United States Core Data for Interoperability) defines the minimum standardised data classes + elements; USCDI v4 (effective 2026) adds classes for SDOH, mental health + facility info. Penalties for vendors include certification removal; for providers + HINs/HIEs, civil money penalties up to $1M per violation. Drives FHIR + SMART on FHIR adoption + Information Blocking exception analysis.
Jurisdiction: US
Lifecycle: Active
US OSHA 29 CFR 1910 — General Industry Standards
OSHA 29 CFR Part 1910 covers general-industry occupational safety + health standards in the US. Frequently applies to construction-adjacent operations (fixed-site maintenance, fabrication, MEP installation in occupied facilities) + the construction supply chain (prefab manufacturing, scaffolding manufacturing, equipment maintenance). Key topics include walking + working surfaces, exit routes, occupational health + environmental control, hazardous materials, PPE, general environmental controls, medical + first aid, fire protection, materials handling + storage, machinery + machine guarding, hand + portable powered tools, welding, electrical (Subpart S) + commercial diving.
Jurisdiction: US
Lifecycle: Active
US OSHA 29 CFR 1926 — Construction Industry Standards
OSHA 29 CFR Part 1926 is the federal occupational safety + health regulatory regime for the US construction industry — covering general safety, occupational health, PPE, fire protection, materials handling, hand + power tools, welding + cutting, electrical, scaffolds, fall protection, cranes + derricks, motor vehicles, excavations, concrete + masonry, steel erection, demolition, blasting, power transmission + distribution, stairways + ladders, and toxic + hazardous substances. Enforced by OSHA via inspections + citations + civil penalties; willful or repeated violations can result in criminal prosecution. The single most important US regulatory framework for construction safety.
Jurisdiction: US
Lifecycle: Active
OSHA Focus Four — Construction Fatal Hazards
The OSHA Focus Four are the four leading causes of construction fatalities in the US: Falls, Electrocutions, Struck-By + Caught-In/Between. Collectively they account for ~60% of US construction deaths. The Focus Four anchors OSHA's 10-Hour + 30-Hour Construction Outreach Training. Not a regulatory standard per se but a structured framework derived from OSHA 29 CFR 1926 subparts M, K + V, Q + various Caught-In provisions.
Jurisdiction: US
Lifecycle: Active
US OSHA Hospitality + Food Retail Standards
OSHA 29 CFR §1910 applies to US hospitality + food retail — Bloodborne Pathogens (1910.1030) for staff handling injuries, HazCom (1910.1200) for cleaning chemicals, walking + working surfaces (1910 Subpart D), exit routes (Subpart E) + emergency action plans. Heat illness prevention + ergonomics increasingly emphasised. Enforced by OSHA + state plan equivalents.
Jurisdiction: US
Lifecycle: Active
US OSHA Process Safety Management (29 CFR §1910.119)
OSHA Process Safety Management (PSM) 29 CFR §1910.119 establishes requirements for the management of hazards associated with processes using highly hazardous chemicals. Covers 14 elements: PHA, employee participation, PSI, operating procedures, training, contractor management, pre-startup safety review, mechanical integrity, hot work, MOC, incident investigation, emergency planning, compliance audits + trade secrets. Applies to facilities with listed chemicals above threshold quantities. Enforced by OSHA + EPA RMP companion.
Jurisdiction: US
Lifecycle: Active
OWASP Application Security Verification Standard v4.0.3
OWASP ASVS v4.0.3 is the application security verification reference used by developers, security testers, and procurement teams. Defines three verification levels — L1 (opportunistic), L2 (standard), L3 (advanced) — across 14 control families. Increasingly cited in enterprise procurement security questionnaires as the minimum bar for SaaS application security.
Jurisdiction: GLOBAL
Lifecycle: Active
OWASP Mobile Application Security Verification Standard v2
OWASP MASVS v2 is the mobile-specific equivalent of ASVS — eight control families covering storage, cryptography, authentication, network communication, platform interaction, code quality, resilience, and privacy. Adopted as the security baseline for mobile-app submissions to NowSecure, OWASP MASTG, and increasingly by enterprise mobile-app security testing programmes.
Jurisdiction: GLOBAL
Lifecycle: Active
Passivhaus — Ultra-Low-Energy Building Standard
Passivhaus (Passive House) is a voluntary, certifiable ultra-low-energy building standard developed by the Passivhaus Institut. Sets strict performance targets for space heating + cooling demand (<=15 kWh/m²/yr), airtightness (<=0.6 ach@50Pa) + total primary energy. Achieved through a fabric-first approach: super-insulation, airtight envelope, thermal-bridge-free design, MVHR + appropriate glazing. Certification via independent Passivhaus Certifier using PHPP energy model + on-site verification. Gaining traction in UK + US + EU as low-energy benchmark; pairs well with EnerPHit retrofit standard.
Jurisdiction: GLOBAL
Lifecycle: Active
PCAOB Auditing Standards
PCAOB Auditing Standards are required for audits of US public companies + SEC-registered broker-dealers, administered by the Public Company Accounting Oversight Board (PCAOB). Substantially overlap with IAASB ISAs but with US-specific requirements. The PCAOB published transformative new AS 1000 (general responsibilities of the auditor in conducting an audit) + revised AS 2310 (auditor's use of confirmation) in 2024. Auditors of public companies must register with PCAOB + are subject to inspection.
Jurisdiction: US
Lifecycle: Active
PCI DSS
PCI DSS 4.0.1 is the global standard every business that stores, processes, or transmits cardholder data must meet, enforced by the card brands through acquiring banks. Non-compliance triggers monthly fines from acquirers, increased per-transaction fees, contractual termination, and — after a breach — forensic costs, brand-mandated penalties, and class actions. Version 4.0.1 hardens authentication, expands scoping to in-scope service providers, and requires defined responsibility matrices between merchants and providers. Quick Policy maps the 12 requirements to policies, evidence, and SAQ alignment so attestation prep stops being a quarterly fire drill.
Jurisdiction: GLOBAL
Lifecycle: Active
PCI DSS — Hospitality Card Handling
PCI DSS v4.0.1 applies to hospitality businesses processing payment cards — restaurants, hotels, takeaways. Scope is typically SAQ B-IP / B / D depending on payment channel. Risk-based controls covering cardholder data environment, network security, encryption, vulnerability management + access control. Frequent breach source via integrated POS systems + Wi-Fi.
Jurisdiction: GLOBAL
Lifecycle: Active
PCI DSS for Retail
PCI DSS v4.0.1 applies to retail merchants processing payment cards. Scope is typically SAQ A (outsourced e-commerce), SAQ A-EP (e-commerce with redirect), SAQ B / B-IP (terminal-only), SAQ C / C-VT (basic payment apps) or SAQ D / D-Merchant (everything else). Risk-based controls covering cardholder data environment, network security, encryption, vulnerability management, access control, monitoring + testing + information security policy. P2PE + tokenisation reduce scope.
Jurisdiction: GLOBAL
Lifecycle: Active
Professional Conduct in Relation to Taxation (PCRT)
PCRT is the standard for tax work adopted by the seven leading UK accountancy and tax bodies (CIOT, ATT, ICAEW, ACCA, AAT, ICAS, STEP). It sets the fundamental principles plus five standards for tax planning — lawful, disclosure and transparency, advising on tax planning arrangements, professional judgement and appropriate documentation, and client-specific advice. Members must not create, encourage or promote tax planning that sets out to achieve results contrary to the clear intention of Parliament.
Jurisdiction: UK
Lifecycle: Active
Proceeds of Crime Act 2002 — Suspicious Activity Reports
The Proceeds of Crime Act 2002 creates the legal obligation for individuals in the regulated sector — including accountants — to report knowledge or suspicion of money laundering to the National Crime Agency via a Suspicious Activity Report (SAR), and the offences of failure to disclose and tipping off. Where a transaction may involve criminal property, a Defence Against Money Laundering (DAML) SAR may be required before proceeding.
Jurisdiction: UK
Lifecycle: Active
EU Payment Services Directive 2 (PSD2)
PSD2 is the EU regulatory framework for payment services + payment-service providers (banks, payment institutions, e-money institutions). Key features: Strong Customer Authentication (SCA) for electronic payments (in force 14 Sep 2019, extended for e-commerce to Dec 2020 + UK to Mar 2022), Open Banking (account information + payment initiation services with regulated TPP access), enhanced consumer protection (refund rights, complaint handling). PSD3 + Payment Services Regulation (PSR) proposals are progressing in EU legislative process to replace PSD2; expected adoption 2025-26.
Jurisdiction: EU
Lifecycle: Active
RBI Master Directions Profile
The Reserve Bank of India’s Master Directions are the binding rule-set for Indian banks, NBFCs, payment system operators, and increasingly for fintechs operating in the Indian financial system. They cover IT governance, cyber security, outsourcing, fraud risk management, customer protection, and incident reporting — with active RBI inspections, monetary penalties, and licence-impacting enforcement. The Master Direction on IT Governance (2023) and the Cyber Security Framework set explicit board accountability, control expectations, and detailed reporting timelines that Indian boards must be able to evidence end-to-end.
Jurisdiction: IN
Lifecycle: Active
US Reg E — Electronic Fund Transfer Act
Federal Reserve Regulation E (administered by CFPB) implements the Electronic Fund Transfer Act. Establishes consumer rights + protections for electronic fund transfers including ATM, POS, debit, ACH, P2P (e.g. Zelle / CashApp / Venmo). Key features: disclosure requirements at account opening, change-in-terms notice (typically 21 days), 60-day error-resolution + provisional credit, unauthorised-transfer liability tiering ($50/$500/unlimited based on reporting time), preauthorised transfer authorisation rules. CFPB has actively expanded Reg E enforcement to cover authorised-push-payment fraud reimbursement issues + P2P platforms.
Jurisdiction: US
Lifecycle: Active
RICS Valuation — Global Standards (Red Book)
RICS Valuation Global Standards (Red Book) incorporating International Valuation Standards. Mandatory for all RICS members carrying out written valuations. Sets out standards for terms of engagement, valuation bases, reporting + ethics.
Jurisdiction: GLOBAL
Lifecycle: Active
UK Senior Managers + Certification Regime (SM&CR)
The UK FCA + PRA Senior Managers + Certification Regime is the individual accountability framework for senior personnel of authorised financial services firms. Three tiers: (1) Senior Manager Functions (SMFs) — pre-approved by regulator with Statement of Responsibilities + Management Responsibilities Map; (2) Certification Regime — annual fit + proper assessment of staff who can cause significant harm; (3) Conduct Rules — individual conduct standards applying to nearly all staff. Replaces the prior Approved Persons regime. Senior Managers can be personally held accountable for misconduct in their area of responsibility.
Jurisdiction: UK
Lifecycle: Active
SOC 2 Trust Services Criteria
Control criteria for security, availability, confidentiality, processing integrity, and privacy.
Jurisdiction: GLOBAL
Lifecycle: Active
EU Solvency II Directive
Solvency II is the EU regulatory framework for insurance + reinsurance undertakings. Three pillars: (1) quantitative capital requirements — Solvency Capital Requirement (SCR) + Minimum Capital Requirement (MCR), valuation of assets + liabilities; (2) qualitative governance + risk management including Own Risk + Solvency Assessment (ORSA); (3) disclosure + reporting including Solvency + Financial Condition Report (SFCR) + Regular Supervisory Report (RSR). The Solvency II Review 2024 introduced enhanced macroprudential tools, sustainability-risk integration + recovery + resolution provisions.
Jurisdiction: EU
Lifecycle: Active
Sarbanes-Oxley Act of 2002
The US Sarbanes-Oxley Act of 2002 (SOX) is the federal law that established sweeping corporate-governance + financial-reporting requirements for US public companies + their auditors. Section 302 requires CEO + CFO personal certification of quarterly + annual financial reports. Section 404 requires management + external auditor assessment of internal control over financial reporting (ICFR). Section 906 imposes criminal penalties for false certifications. Section 301 mandates whistleblower protections. Enforcement: SEC + PCAOB + DOJ. Penalties include criminal sanctions, financial penalties + executive disqualification. SOX is the de-facto framework behind US public company ICFR programmes + drives controls over journal entries, period-end close, account reconciliation + ITGCs.
Jurisdiction: US
Lifecycle: Active
SWIFT Customer Security Controls Framework
The SWIFT Customer Security Controls Framework (CSCF) is the mandatory control set every SWIFT-connected institution must self-attest against annually — covering secure environment, restricting access, detecting and responding to threats. Attestation results are visible to counterparties through the KYC Security Attestation (KYC-SA) service, so weak attestations directly affect bank relationships and correspondent banking access. Independent assessment cycles, expansion of advisory controls into mandatory, and tighter expectations around third-party connectivity make CSCF a moving target year-on-year.
Jurisdiction: GLOBAL
Lifecycle: Active
TAPA Facility Security Requirements
The Transported Asset Protection Association Facility Security Requirements (TAPA FSR) is the global industry-led security standard for secure transportation + storage of high-value goods. Three certification levels (A, B, C) covering physical security, procedural security + personnel security. Audited by accredited third parties. Widely required by major shippers + brand owners (technology, pharma, luxury) for warehousing + cross-docking + freight forwarding facilities. Companion: TAPA TSR (Trucking Security Requirements) + PSR (Parking Security).
Jurisdiction: GLOBAL
Lifecycle: Active
US TSA Aviation Security Regulations
The Transportation Security Administration regulates US civil aviation security under 49 CFR §§1540-1562. Aircraft operators (commercial), foreign air carriers, indirect air carriers (IAC), airport operators + general aviation operators must comply with Aircraft Operator Standard Security Program (AOSSP), airport-specific security programs + threat-based security directives. Cargo security via Known Shipper + Air Cargo Security Roadmap. Penalties up to $14k per violation + EO suspensions.
Jurisdiction: US
Lifecycle: Active
US TSA Pipeline Security Directive
The Transportation Security Administration Pipeline Security Directive series (post-Colonial Pipeline 2021) imposes mandatory cybersecurity requirements on critical US pipeline operators. SD02C requires cybersecurity implementation plans, mitigation measures (network segmentation, access controls, MFA, logging, anti-malware, patching), assessment + audit + incident reporting to CISA + TSA. Updated periodically; compliance enforced through civil penalties + criminal referral. Largely aligned with NIST CSF + NIST SP 800-82.
Jurisdiction: US
Lifecycle: Active
EU UCITS Directive
UCITS (Undertakings for Collective Investment in Transferable Securities) is the EU regulatory framework for retail-oriented mutual funds. UCITS funds can be marketed across the EU + globally with significant trust + brand recognition. Imposes investment restrictions (eligible assets, diversification, leverage limits), liquidity requirements, depositary safekeeping + oversight, transparency (KIID/KID under PRIIPs), risk + portfolio management requirements + management-company organisational rules.
Jurisdiction: EU
Lifecycle: Active
UK Approved Documents B + M — Fire Safety + Accessibility
Approved Document B (Fire Safety) Volumes 1 + 2 + Approved Document M (Access to and use of buildings) are the practical guidance under the Building Regulations 2010 for fire safety + accessibility. Post-Grenfell, AD B has been substantially revised — ban on combustible materials in external walls of buildings >18m (2018), now >11m (2022).
Jurisdiction: UK
Lifecycle: Active
UK ASA CAP + BCAP Codes
The Committee of Advertising Practice (CAP) Code applies to non-broadcast advertising including online + social media + direct marketing. The BCAP Code applies to broadcast advertising. Both administered by the Advertising Standards Authority (ASA). Self-regulatory system supported by Ofcom backstop for broadcast + CMA backstop for non-broadcast misleading claims. Heavy emphasis on substantiation + honesty + responsibility (especially to children). Voluntary but de facto mandatory for advertisers + agencies.
Jurisdiction: UK
Lifecycle: Active
UK Academies Trust Handbook + ESFA Funding Rules
The Academies Trust Handbook (ATH) is the annual statutory governance + financial framework for academy trusts in England, issued by the ESFA (now part of DfE). Replaces the Academies Financial Handbook. Sets requirements for trust governance, financial management, internal control, related-party transactions, executive pay + audit. Companion to ESFA funding rules for the AGFS (Academy General Annual Grant) + capital funding. Audited annually by external auditors + occasionally by ESFA.
Jurisdiction: UK
Lifecycle: Active
UK Working Together to Improve School Attendance (Statutory)
Working Together to Improve School Attendance is the statutory guidance from DfE on improving attendance — now mandatory for schools + LAs from August 2024. Sets expectations for schools to have an attendance policy, designated senior leader for attendance, regular monitoring + tiered support / fines. Replaces previous guidance + introduces consistent national approach including fixed penalty notice thresholds.
Jurisdiction: UK
Lifecycle: Active
UK Animal Welfare Act 2006
UK primary legislation establishing duty of care on animal keepers — five welfare needs (suitable environment + diet, behaviour, companionship, protection from suffering). Sector-specific welfare codes cover livestock species.
Jurisdiction: UK
Lifecycle: Active
UK DfE Behaviour in Schools (Statutory Guidance)
DfE statutory guidance on managing behaviour in schools in England — establishing whole-school cultures, classroom + corridor practice, mobile phones, suspensions + permanent exclusions. Companion to Suspension and Permanent Exclusion guidance + Searching, Screening + Confiscation guidance. Inspected as part of Ofsted EIF Behaviour + Attitudes judgement.
Jurisdiction: UK
Lifecycle: Active
UK Bribery Act 2010 — Legal Sector Application
The UK Bribery Act 2010 applies to law firms with UK presence + creates the corporate offence of failing to prevent bribery (§7). Law firms must have adequate procedures including risk assessment, top-level commitment, due diligence on clients + agents, communication + monitoring + review. Legal sector has been highlighted by Ministry of Justice + SRA as higher-risk given cross-border + government client work.
Jurisdiction: UK
Lifecycle: Active
UK Building Safety Act 2022
The Building Safety Act 2022 (BSA) is the UK post-Grenfell legislative response. Establishes the Building Safety Regulator (BSR — part of HSE) with oversight of the building safety regime + competence framework for industry. For higher-risk buildings (HRBs — broadly buildings >=18m or >=7 storeys with >=2 residential units), introduces the gateway regime (Gateway 1 planning, Gateway 2 pre-construction, Gateway 3 completion), an Accountable Person, a Principal Accountable Person, a Building Safety Case + Safety Case Report, mandatory occurrence reporting + the residents engagement strategy. Tightens construction product regulation + extends limitation periods for defective premises claims to 30 years (retrospective) + 15 years (prospective).
Jurisdiction: UK
Lifecycle: Active