Framework catalog · 31 instruments · 16 jurisdictions

Every law, standard and instrument an audit can be scoped against.

All 31 instruments, grouped by what they govern - and what an audit covers against each.


A reviewer with greying hair, in a navy blazer, seated at a dark stone desk by a window in a warm, low-lit office, signing a printed page with further papers and a stoneware cup beside them. Illustrative materials
One engagement, scoped to the instruments that bind you
EU AI Act NIST AI RMF GDPR DORA SR 26-2 / OCC 2026-13

Our promise

“A catalog is a list. A scope is an answer.”

Typically three to six of these reach an organisation, not 31 — and you are quoted for those, with each further one a fraction of the first. Nothing is charged until you approve the scope.

Ask which of these apply
The case file

The catalog, in three chapters

31
Instruments Binding regulation, supervisory guidance, and the voluntary standards procurement asks about.
5
Families AI regulation, AI standards, model risk, privacy, and security & resilience.
16
Jurisdictions From the EU and the UK to the Gulf, Singapore, Canada and the US states.
5
Readiness assessments Certification schemes where the certificate is issued by an accredited body, not by us.
The List

Thirty-one instruments in five families, and they are not one kind of thing. Some of them are law that reaches you whether you have heard of them or not; some are what a supervisor arrives holding; some are voluntary until a customer makes one a condition of a signed contract.

The Overlap

A single AI system is routinely inside two or three of these at the same time, which cuts both ways. It means far more instruments reach you than you assumed - and it means the evidence written for one does most of the work for the next one, so the second costs a fraction of the first.

The Office

Our job is to settle which of them are actually yours. We inventory the systems, test each instrument against what they really do, fix your role under each of them, and hand you the shortlist — with the ones that do not reach you written down as excluded rather than left unmentioned.

Certification is issued by an accredited certification body, not by iDharma. We assess your readiness against the standard and prepare the evidence and gap list that body will ask you for.

Against the instruments that reach you - not against all 31 of them. Which ones those are is the first thing an engagement settles, and it is settled in writing before anything is charged.

How to read this catalog

Two kinds of engagement, and the difference matters.

Most entries here are audits. Some are schemes only an accredited body can certify.

Audit № 01
  • We assess you against the instrument - and we sign it
  • An independent review of what it actually requires of you
  • Ends in findings, evidence and a prioritised plan
  • The judgement is ours to make and ours to put a name to
26 of 31 entries · iDharma · Presented for assay
Readiness assessment № 02
  • We get you ready for someone else's audit
  • Certification schemes, where an accredited body certifies
  • We assemble the evidence, test the controls, list the gaps
  • The certificate is theirs to issue - and the card says so
5 of 31 entries · Marked on the card
Know what binds you

Not one kind of thing. Three kinds.

Binding

Law that reaches you anyway

Regulation applies because of what your systems do and where their output lands, not because you signed up to it. Most of this catalog is this kind: the EU AI Act, the state statutes, the privacy regimes. Nobody sends you a notice first, and not having heard of one has never been a defence to it.

Supervisory

What your regulator looks for

Model-risk guidance and supervisory expectations are not statutes, and they are examined against as though they were. SR 11-7, SS1/23, OSFI E-23: an examiner arrives holding the guideline and asks to see the validation. The consequence is the finding rather than the fine.

The catch

Standards nobody made you adopt

ISO/IEC 42001, SOC 2, NIST CSF: voluntary until a customer, an insurer or a tender makes one a condition of the deal. Then a scheme you never had to follow is holding up revenue - and the certificate comes from an accredited body, so the lead time is somebody else's calendar.

What most teams assume

“We’re certified, so we’re compliant.”

What the instruments say

A certificate covers its scheme. The law is separate.

It is the most common finding we write up.

  • Who it is for
  • AI product teams
  • SaaS & platform vendors
  • Banking & insurance
  • Legal & compliance
  • Regulated healthcare and HR tech
Overlap & consequence
A row of dark leather-bound volumes standing on a wooden shelf under a low warm light, one of them pulled forward and standing a little open, pale paper tabs marking several pages inside it: one instrument taken from a shelf of the ones that reach the same system.
01 One AI system is rarely inside one instrument. A hiring model in the EU sits under AI regulation and privacy law at the same time, and under a security scheme the moment a customer asks.
02

Typically three to six of these reach an organisation, not thirty-one - and it is almost never only the one that brought them here.

03

Overlap cuts in your favour too. Evidence written once for one instrument does most of the work for the next, so the second costs a fraction.

04

A certificate you hold covers its own scheme, at its own scope, on its own date. None of those three is the same as the law’s.

The 60-second check

Three questions. Then you’ll know where to look.

No email, no signup. Families, not a named shortlist.

0 of 3

Where it lands -

Where the output lands, not where you are. Most of the AI regulation in this catalog is triggered by a system being placed on a market or its result being used there, whatever the company’s address.

What it decides -

The use decides it, not the technology. A simple model making a decision about a person carries more instruments than a sophisticated one doing nothing of the kind.

What you hold -

A certificate rarely covers what people think. It covers its own scheme, at the scope it was scoped to, on the date it was issued - and it says nothing about the law.

The calendar

Four moments, and two have already passed.

Most of this catalog has been in force for years. Two of these are live obligations today and two are still ahead, so they cannot be planned as one deadline.

  1. The standing set

    In force already

    Privacy law, model-risk guidance and the security schemes have applied for years. Most of this catalog is here.

  2. The AI wave

    Since 2025-26

    Prohibitions, transparency duties and the first US state AI statutes are live obligations today, not future ones.

  3. The heavy tier

    Through 2027

    The EU high-risk regime and the deferred state acts land here, and their documentation has the longest lead time.

  4. Flagged, not guessed

    Still moving

    Several entries have dates that are still being amended. Each page says so on its face rather than picking one.

The trap

Teams read a catalog as a list of future work and plan for the newest date on it. Most of what reaches them already applies - the privacy regime, the security scheme in the contract, the model-risk guideline the examiner arrives holding. The new instrument is rarely the urgent one.

Requirement & coverage

What you arrive asking, what we ship

12 questions, and the artefact that answers each one. Paired, so every promise on this page can be checked against the question beside it.

Which instruments reach you By what your systems do, and where the output lands
A written shortlist of the instruments in scope for you, with the reasoning for each one recorded.
Which role you hold Provider, deployer, processor - and often more than one
Your role settled per system per instrument, so a vendor's compliance is never mistaken for yours.
Who the instrument binds The scope test, in plain terms rather than in its own
The test applied to your facts, with the line drawn where the instrument draws it and not further.
What it actually requires The obligations as things that have to be true
Each requirement stated as a condition you either meet or do not, mapped to the clause it comes from.
Where it overlaps One system is routinely inside two or three of these
A map of which duties are satisfied once and which have to be met separately under each instrument.
What evidence is examined What an assessor asks to see, before they ask for it
The evidence list per instrument, and a note against each item saying whether you hold it today.
Where the dates stand In force, phasing in, or still being amended
The dates that bind you, with the ones still moving flagged as moving rather than quietly picked.
Audit or readiness Who is allowed to issue the certificate at the end
Stated before you buy: whether we can give you the finding, or prepare you for the body that does.
What a certificate covers Its own scheme, at its own scope, on its own date
What each certificate you already hold discharges, and which obligations it leaves entirely open.
Which gaps matter first Ranked by consequence, not by ease of fixing
A remediation shortlist ordered by what happens to the people affected if the gap stays open.
What it costs to cover Per instrument, flat, before you commit to anything
The fee for each instrument in scope, quoted against the scope you approved and never metered.
What happens next year On modification, and on the next instrument
A re-read against your known baseline, so the second engagement is not the first one done again.
The engagement

Your AI estate, read against the list

From one instrument to the handful that actually reach you.

  1. Scope

    Which instruments actually reach you, and in which role under each.

  2. Assess

    Your systems read against what each one requires, evidence by evidence.

  3. Report and re-read

    You see the draft first. Then findings, gaps and a plan - each dated.

Ask which of these apply
An auditor in a charcoal trouser suit and cream blouse, with dark hair pinned back, standing against a warm pale wall and pointing into the open space alongside.
The shortlist is what you are buying.
Struck in your favour

Why teams bring the whole list to iDharma

Genuinely independent

We build, resell and operate no AI systems of our own, and take no fee tied to what we find.

Scoped, not sold

You are quoted for the instruments that reach you. Nobody here is sold thirty-one of anything.

One engagement, end to end

Overlapping instruments read together in one scope, so no duty falls between two vendors.

The split stated up front

Where a certificate is somebody else's to issue, the page says so before you spend a fee.

Four marks, struck on every report.

Deliverables

What you get

Concrete artefacts, each with a name and a format - you know what lands before you buy.

Scope determination

The whole assessment in one document: every instrument in this catalog tested against what your systems actually do, the ones that reach you listed with the reasoning recorded, your own role settled under each, the overlaps between them marked, and the ones that do not reach you written down as excluded rather than left unmentioned.

Workbook

Instrument register

Every system against every instrument that reaches it, with its role, its status and its owner, in a workbook your team can keep current.

Diagram

Overlap map

Which duties are satisfied once across several instruments and which have to be met separately under each, drawn rather than asserted.

Templates

Evidence index

What each instrument in scope asks to see, broken into its sections, showing what you already hold, what is thin, and what is missing.

Memo

Exclusion memo

Which instruments were tested and found not to reach you, and why each call was made - the written record standing behind a shorter scope.

Ranked

Remediation shortlist

Where the gaps sit, what to do first, and why each one is where it is. Ranked by consequence to the people affected, not by ease of fixing.

Memo

Certificate coverage read

What the certificates and attestations you already hold actually discharge, at what scope and to what date, and which obligations they leave open.

Format & fee

Real numbers, upfront.

Scope
Set by the instruments, not by us
Priced
Per instrument, flat — 31 of 31 published
Together
Each further instrument 40% of its own fee, in the same scope

The instruments fixed the scope, not us, so each fee is flat - nothing is charged until you approve it.

Ask what yours would cost
Per instrument · Flat $6,500–25,000 each
  • Scope determination for every instrument
  • Instrument register and overlap map
  • Each further instrument at 40% in the same scope
  • Re-audit after a change at 65% of the band
  • Annual renewal at 85%, locked
On every framework page

Four things every entry has to answer

Thirty-one pages, one shape. Each of these is settled on the page before you spend a call asking for it.

Who it binds,
exactly

The scope test in plain terms: whether the instrument reaches you at all, and in which role it does. Most pages in this catalog settle that inside one short paragraph.

What it requires,
listed

The obligations set out as things that have to be true, each mapped to the clause it comes from - so a finding against it can be checked rather than simply trusted.

What we examine,
named

The evidence an engagement asks for and the findings it lands on. Named on the page before you buy, so what arrives at the end is what the page said would arrive.

Where it stands,
dated

Which dates are in force, which are phasing in, and which are still being amended - the moving ones flagged as moving rather than quietly resolved in our favour.

Four answers, on all 31 pages. Not four out of four on the ones we like.

FAQ

Plain answers

Coverage, the readiness split, and what a scope costs.

Ask about yours
Ours is not on this list. Now what?

Ask. The method does not change with the instrument - these are the ones we are asked for most often, not the limit of what an engagement can be scoped against.

How many of these are actually going to reach us?

For most organisations it is between three and six, not thirty-one - and it is almost never only the one they arrived worrying about. Scoping settles it before anything is charged.

Why do some entries say readiness assessment instead of audit?

Because only an accredited body can issue those certificates. Against a certification scheme we prepare the evidence and the gap list; the certificate is somebody else's to sign, and the card says so before you buy.

Do we have to cover all of them at once?

No, and almost nobody should. An engagement is scoped against the instruments that actually reach you - typically three to six - and the overlap between them makes the second much cheaper than the first.

How long does one take?

Two to four weeks from hand-over for a single instrument, and a multi-instrument scope is longer but not proportionally - the overlap does most of the work. Scope is agreed before anything is charged.

Get started

Not sure which of these apply to you?

That is the first thing a scoping call settles - tell us what your AI does and where, and we come back within one business day.

What we need from you

Nothing you do not already have. Most of this is a folder someone can assemble in an afternoon, and we name every document first, in writing, before you commit.

  1. Which AI systems you build or use, and what each decides
  2. Where they operate, and where their output is used
  3. Any documentation - model cards, contracts, DPIAs
  4. Any certificates or attestations you already hold
  5. Whether an instrument has already been named to you

What happens next

  1. You send the five items we need.
  2. We come back with the instruments that reach you.
  3. Nothing is charged until you approve the scope.
Tell us about your AI
Sources & standing

What this catalog is, and what it is not

Where the entries come from, what the copy is worth, and where it stops - stated, not assumed.

Why these 31

  • The ones clients ask us for, not a survey
  • Each with a page behind it, or it is not listed
Instruments
31 in 5 families
Jurisdictions
16

What it means

  • These pages describe what each instrument requires and what an engagement covers against it. They are scoping guidance, not legal advice, and no professional relationship arises from reading them.
  • iDharma works alongside your counsel, not in place of them. Where a scope question is arguable, our reports say so rather than the convenient thing.

Scope & limitation

  • Yours not listed? Ask. The method does not change with the instrument.
  • This is the index. The reading of each instrument is on its own page, not here.
  • Use it to start a scoping conversation, not as your final word on coverage.

An instrument missing, or an entry out of date?

Tell us

From Insights

Before you pick one