# Modulos Documentation > AI Governance Platform Documentation ## Table of Contents ### Get Started - [Introduction](/guide/introduction.md): Modulos is an AI governance platform for compliance, risk management, and audit readiness across EU AI Act, ISO 42001, NIST AI RMF, and more. - [Quickstart](/guide/quickstart.md): Step-by-step quickstart — create your first Modulos project, complete a Control, attach Evidence, and export an audit snapshot in 5 minutes. - [First Steps](/guide/first-steps.md): Configure your organization and first project so Scout and risk quantification work from day one. - [Core Concepts](/guide/core-concepts.md): Core building blocks of Modulos — organizations, projects, frameworks, Controls, Evidence, risk quantification, runtime inspection, and AI agents. - [From Zero to Audit-Ready](/guide/from-zero-to-audit-ready.md): Go from zero documentation to an audit-ready snapshot, then keep it continuously current. - [How to Comply with AI Governance Frameworks — Step-by-Step Guides](/guide/how-to-comply.md): Step-by-step guides for complying with the major AI governance frameworks: ISO/IEC 42001, NIST AI RMF, EU AI Act. Structured as a sequence of actions, artifacts, and Evidence. - [Guided Paths](/guide/guided-paths.md): Step-by-step AI governance workflows organized by role (compliance lead, risk manager, auditor) and lifecycle stage (scope, implement, monitor, audit). #### How to Comply - [How to Comply with AI Governance Frameworks — Step-by-Step Guides](/guide/how-to-comply.md): Step-by-step guides for complying with the major AI governance frameworks: ISO/IEC 42001, NIST AI RMF, EU AI Act. Structured as a sequence of actions, artifacts, and Evidence. - [How to Comply with ISO 42001 — Step-by-Step Certification Guide](/guide/how-to-comply/iso-42001.md): Step-by-step guide to achieving ISO/IEC 42001:2023 certification: scope the AIMS, run a gap analysis, implement clauses 4–10 and Annex A, prepare for Stage 1 and Stage 2 audits. - [How to Comply with NIST AI RMF — Step-by-Step Adoption Guide](/guide/how-to-comply/nist-ai-rmf.md): Step-by-step guide to adopting the NIST AI Risk Management Framework 1.0: stand up Govern, build per-system Map profiles, define Measure signals, run Manage continuously. - [How to Comply with the EU AI Act — Step-by-Step Readiness Guide](/guide/how-to-comply/eu-ai-act.md): Step-by-step guide to EU AI Act compliance: identify your role, classify AI systems, build technical documentation, operate a QMS, conformity assessment, CE marking, and post-market monitoring. #### Guided Paths - [Guided Paths](/guide/guided-paths.md): Step-by-step AI governance workflows organized by role (compliance lead, risk manager, auditor) and lifecycle stage (scope, implement, monitor, audit). - [Compliance Lead Path](/guide/guided-paths/by-role/compliance-lead.md): Compliance lead path: run gap analysis, assign Control ownership, and achieve evidence-backed audit readiness in Modulos. - [Scope Phase](/guide/guided-paths/by-lifecycle/scope.md): Scoping phase: classify your AI system, select applicable frameworks, and define the governance boundary before implementation begins. ##### By Role - [Compliance Lead Path](/guide/guided-paths/by-role/compliance-lead.md): Compliance lead path: run gap analysis, assign Control ownership, and achieve evidence-backed audit readiness in Modulos. - [AI Product Owner Path](/guide/guided-paths/by-role/ai-product-owner.md): AI product owner guided path: document your AI system as an auditable project with scope, usage context, and governance Requirements in Modulos. - [Risk Manager Path](/guide/guided-paths/by-role/risk-manager.md): Risk manager guided path — set up risk quantification with shared taxonomy, explicit budgets, and repeatable monetary outputs across AI projects in Modulos. - [Engineer & Integrations Path](/guide/guided-paths/by-role/engineer-integrations.md): Engineer & integrations path — connect repositories, docs, tickets, and operational signals to ground governance in real artifacts. - [Internal Audit Path](/guide/guided-paths/by-role/internal-audit.md): Internal audit guided path: validate that governance work is traceable, evidence-backed, and consistent with your operating model in Modulos. - [Organization Admin Path](/guide/guided-paths/by-role/org-admin.md): Organization admin guided path: onboard users, assign roles, configure shared settings, and set up the access model for AI governance in Modulos. ##### By Lifecycle - [Scope Phase](/guide/guided-paths/by-lifecycle/scope.md): Scoping phase: classify your AI system, select applicable frameworks, and define the governance boundary before implementation begins. - [Implement Phase](/guide/guided-paths/by-lifecycle/implement.md): Implementation phase — assign Control ownership, collect Evidence, use AI agents to accelerate assessments, and close compliance gaps. - [Monitor Phase](/guide/guided-paths/by-lifecycle/monitor.md): Monitoring phase — schedule automated tests, track metric drift, and keep governance aligned with the live behavior of your AI systems. - [Audit Phase](/guide/guided-paths/by-lifecycle/audit.md): Audit phase: run internal readiness reviews, validate Evidence traceability, export the project PDF with supporting Evidence, and prepare for external certification. ### Platform - [Platform Overview](/platform/overview.md): How Modulos is organized — organizations, projects, governance workflows, risk management, runtime inspection, and integrations for AI compliance. - [Organization Overview](/platform/organizations/overview.md): The workspace boundary for people, shared policy, and defaults. - [Project Overview](/platform/projects/overview.md): Projects in Modulos define governance scope for an AI system — frameworks, Controls, Evidence, risk assessments, and audit-ready exports. - [Governance Operating Model](/platform/governance/operating-model.md): How frameworks, Requirements, Controls, Evidence, and reviews work together. - [Policy Center](/platform/policy-center/overview.md): How Policy Center fits into governance, who manages policies, and how the continuous review loop works. - [Risk Operating Model](/platform/risk/operating-model.md): Views, roles, and guardrails for running risk quantification in Modulos. - [Runtime Inspection Operating Model](/platform/runtime/operating-model.md): Continuous verification signals that connect runtime reality to governance. - [Integrations](/platform/integrations/overview.md): How integrations work in Modulos: project-level Sources for Runtime Inspection, user-level Scout Connectors (Google Drive, GitHub, Atlassian, Bitbucket), and API tokens for automation. - [AI Agents Overview](/platform/ai/overview.md): AI-assisted governance workflows in Modulos — Scout chat, Evidence extraction, Control assessment, and human-in-the-loop approvals. - [Vendor Overview](/platform/vendors/overview.md): Track third parties and vendor artifacts across your organization. #### Organizations - [Organization Overview](/platform/organizations/overview.md): The workspace boundary for people, shared policy, and defaults. - [Organization Settings](/platform/organizations/settings.md): Organization-wide defaults: currency, language, the organization profile Scout reads, and which Connector and Source integrations are enabled. - [User Management](/platform/organizations/user-management.md): Invite users, assign roles, and enforce separation of duties. - [Audit Trail](/platform/organizations/audit-trail.md): How notifications and per-object Comments and Logs create traceability, and what the organization's Audit Log tab does and does not record. #### Projects - [Project Overview](/platform/projects/overview.md): Projects in Modulos define governance scope for an AI system — frameworks, Controls, Evidence, risk assessments, and audit-ready exports. - [Create a Project](/platform/projects/create.md): Scope a project correctly so it stays audit-ready over time. - [Project Dashboard](/platform/projects/dashboard.md): How to interpret progress, status, and risk signals. - [Compliance Graph](/platform/projects/graph.md): Visual exploration of frameworks, Requirements, and Controls as an interactive node graph. - [Project Settings](/platform/projects/settings.md): Framework updates, EU AI Act classification, Sources, and users. #### Governance - [Governance Operating Model](/platform/governance/operating-model.md): How frameworks, Requirements, Controls, Evidence, and reviews work together. - [Frameworks in Modulos](/platform/governance/frameworks-in-modulos.md): Framework mapping, versions, and the unified Control framework. - [Requirements](/platform/governance/requirements.md): Requirements in Modulos — view framework obligations mapped to your project, track applicability, and link each Requirement to Controls. - [Controls](/platform/governance/controls.md): How to create, assign, and manage compliance Controls in Modulos, including mapping one Control to multiple framework Requirements. - [Evidence](/platform/governance/evidence.md): Attach Evidence to Controls in Modulos — upload documents, link test results, and build an auditable compliance trail. - [Assets & Documents](/platform/governance/assets-documents.md): Assets and documents in Modulos — register AI system assets, attach supporting documents, and link them to Controls and Evidence. - [Reviews & Statuses](/platform/governance/reviews-statuses.md): How statuses and reviews work in Modulos: Controls change status directly with a logged comment, Requirements are reviewed and fulfilled by their owners, and Assets use formal review requests. - [Reports & Exports](/platform/governance/reports-exports.md): Reports and exports in Modulos: generate the project snapshot PDF from the Dashboard, download Evidence and Asset files, and assemble an audit-ready bundle for auditors. #### Policy Center - [Policy Center](/platform/policy-center/overview.md): How Policy Center fits into governance, who manages policies, and how the continuous review loop works. - [Policy Management](/platform/policy-center/policy-management.md): Creating, managing, and searching policies in Policy Center. - [Policy Templates](/platform/policy-center/policy-templates.md): Create policies from a Modulos-maintained Templates Catalog, fill organization-specific placeholders, and run them through the normal approval lifecycle. - [Lifecycle & Approvals](/platform/policy-center/lifecycle.md): How policy versions move from draft to published, the approval workflow, archival, and renewal. #### Risk - [Risk Operating Model](/platform/risk/operating-model.md): Views, roles, and guardrails for running risk quantification in Modulos. - [Portfolio Overview](/platform/risk/portfolio-overview.md): Portfolio-level AI risk dashboard: track monetary risk exposure against organization appetite and category limits across all projects in your organization. - [Organization Taxonomy](/platform/risk/organization-taxonomy.md): Categories, risks, and threat vectors at the organization level. - [Project Risks](/platform/risk/project-risks.md): Project risks in Modulos — apply your organization's risk taxonomy to individual AI projects and quantify risk at the project level. - [Risk Quantification](/platform/risk/quantification.md): Turning risk threats into monetary expected loss. - [Quantification Methods](/platform/risk/quantification-methods.md): Reference for all monetary risk quantification methods in Modulos. - [Acting on Quantified Risk](/platform/risk/treatment.md): What to do in Modulos after quantifying a risk: compare exposure against risk limits, prioritize with the portfolio overview, implement mitigations as Controls with Evidence, and re-quantify to measure the change. #### Runtime Inspection - [Runtime Inspection Operating Model](/platform/runtime/operating-model.md): Continuous verification signals that connect runtime reality to governance. - [Tests & Schedules](/platform/runtime/tests-and-schedules.md): Define metric-based tests, assign ownership, and run them manually or on a schedule. - [Results & Remediation](/platform/runtime/results-and-remediation.md): Interpret outcomes, route failures to owners, and keep governance aligned with reality. #### Integrations - [Integrations](/platform/integrations/overview.md): How integrations work in Modulos: project-level Sources for Runtime Inspection, user-level Scout Connectors (Google Drive, GitHub, Atlassian, Bitbucket), and API tokens for automation. - [Sources](/platform/integrations/sources.md): Project-level service accounts for testing and automation. - [Scout Connectors](/platform/integrations/scout-connectors.md): Connect GitHub, Bitbucket, Google Drive, and Atlassian. - [API Tokens](/platform/integrations/api-tokens.md): API tokens in Modulos — create, rotate, and scope tokens for programmatic access to the Modulos API from CI pipelines and scripts. #### AI Agents - [AI Agents Overview](/platform/ai/overview.md): AI-assisted governance workflows in Modulos — Scout chat, Evidence extraction, Control assessment, and human-in-the-loop approvals. - [Scout](/platform/ai/scout.md): Scout is Modulos’ conversational assistant for governance, risk, and compliance work. - [Evidence Agent](/platform/ai/evidence-agent.md): Generate Evidence summaries and Control mapping suggestions. - [Control Assessment Agent](/platform/ai/control-assessment-agent.md): Generate structured Control readiness assessments from linked Evidence. - [Risk Agent](/platform/ai/risk-agent.md): How the Modulos Risk Agent quantifies a risk threat: the supervisor, investigator, auditor, and quantifier roles, the Fermi estimation they produce, and how to read and re-run the output. Use when quantifying risk threats with AI assistance. - [Human in the Loop](/platform/ai/human-in-the-loop.md): Human-in-the-loop oversight for Modulos AI agents — review, approve, or reject AI-generated assessments before they affect compliance status. #### Vendors - [Vendor Overview](/platform/vendors/overview.md): Track third parties and vendor artifacts across your organization. - [Vendor Records](/platform/vendors/vendor-records.md): Vendor records in Modulos — track third-party AI vendors, store due-diligence data, and link vendor risk to your governance projects. - [Vendor Documents](/platform/vendors/vendor-documents.md): Store vendor artifacts like DPAs and SOC reports in one place. ### Frameworks - [Frameworks Overview](/frameworks/overview.md): The AI and data governance frameworks Modulos supports: EU AI Act, ISO 42001, NIST AI RMF, GDPR, NIS2, DORA, OWASP, and more, with cross-framework control mapping. - [AI Governance Frameworks Comparison — EU AI Act, ISO 42001, NIST AI RMF, OWASP LLM](/frameworks/comparison.md): Side-by-side comparison of the major AI governance frameworks, AI compliance standards, and AI regulations: EU AI Act, ISO/IEC 42001, NIST AI RMF, OWASP Top 10 for LLM, GDPR, NIS2, DORA. Pick the right framework for your use case. - [AI Governance Framework Updates — EU AI Act, ISO 42001, NIST AI RMF News](/frameworks/updates.md): Ongoing updates on AI governance frameworks: EU AI Act phase-in dates, ISO 42001 amendments, NIST AI RMF profiles, OWASP Top 10 for LLM releases, and other framework news that affects AI compliance programs. - [EU AI Act — Regulation (EU) 2024/1689 Guide for AI Governance](/frameworks/eu-ai-act.md): Practical guide to the EU AI Act (Regulation (EU) 2024/1689): scope, prohibited practices (Art 5), high-risk classification (Art 6 + Annex I/III), Article 50 transparency, Chapter V GPAI, conformity assessment, post-market monitoring, and the Digital Omnibus on AI (Regulation (EU) 2026/1744) amendments, which defer the high-risk deadlines to 2 December 2027 / 2 August 2028. Anchored to OJ-published Article numbers, with common misreadings (the 'four-tier pyramid', 'limited risk', 'GenAI = high-risk') called out explicitly. - [ISO/IEC 42001:2023 — AI Management System Guide & Certification](/frameworks/iso-42001.md): Practical guide to ISO/IEC 42001:2023 — the world's first international AI management system (AIMS) standard. Covers scope and Statement of Applicability, Clauses 4–10, Annex A reference controls, the certification path, and how an ISO 42001 AIMS supports EU AI Act high-risk obligations. Modulos models the standard through the current, fully authored OFF-10/MFF-10 framework templates. - [IEEE 7003 — Algorithmic Bias Considerations](/frameworks/ieee-7003.md): Complete guide to IEEE Std 7003-2024, the IEEE Standard for Algorithmic Bias Considerations: a governance and process standard (not a fairness-metrics standard) for managing wanted and unwanted bias across the AI lifecycle, built around a through-life bias profile, and how Modulos operationalizes it as MFF-25 (app) and OFF-25 (org). Use to orient on the standard and route to the right topic page. - [NIST AI Risk Management Framework 1.0 (NIST AI RMF) — Complete Guide](/frameworks/nist-ai-rmf.md): Complete guide to the NIST AI Risk Management Framework 1.0 (AI RMF 1.0): the four core functions (Govern, Map, Measure, Manage), categories, subcategories, the AI RMF Playbook, Generative AI Profile, and how to operationalize NIST AI RMF in Modulos. - [GDPR — Regulation (EU) 2016/679 — Modulos Compliance Guide](/frameworks/gdpr.md): Primary-source overview of the GDPR (Regulation (EU) 2016/679) for AI systems processing personal data: scope (Articles 2 and 3), principles (Article 5), lawful basis (Article 6), rights including automated decisions (Articles 12–22), controller and processor obligations (Articles 24–32), breach notification (Articles 33–34), and DPIA (Article 35). Applied from 25 May 2018. - [NIS2 Directive (EU) 2022/2555 — Modulos Compliance Guide](/frameworks/nis2.md): Primary-source overview of the NIS2 Directive (EU) 2022/2555: scope, essential vs important entity classification, Article 21 cybersecurity measures, Article 23 reporting timelines, supervision, and how each obligation lands in Modulos. - [DORA — Regulation (EU) 2022/2554 — Modulos Compliance Guide](/frameworks/dora.md): Primary-source overview of the Digital Operational Resilience Act (Regulation (EU) 2022/2554, DORA): scope (Articles 1–2), ICT risk management framework (Articles 5–16), ICT-related incident reporting (Articles 17–23), digital operational resilience testing (Articles 24–27), ICT third-party risk (Articles 28–30), oversight of critical TPPs (Articles 31–44), information sharing (Article 45), and the eight Level 2 acts. Applies from 17 January 2025. - [Cyber Resilience Act (CRA) — Regulation (EU) 2024/2847 for Products with Digital Elements](/frameworks/cra.md): Complete guide to the EU Cyber Resilience Act (Regulation (EU) 2024/2847): which products are in scope, the Annex I essential cybersecurity requirements, vulnerability handling and SBOM, the support period, Article 14 reporting from 11 September 2026, economic-operator roles, and how Modulos operationalizes it as MFF-26 (application) and OFF-26 (organization). Use to orient on the framework and route to the right topic page. - [OWASP for AI Security — Top 10 for LLM and Agentic Applications](/frameworks/owasp.md): OWASP AI security hub: the Top 10 for Large Language Model Applications (2025) and the Top 10 for Agentic Applications. Use them together as your generative AI security and AI agent security baseline. - [UAE AI Ethics Principles & Guidelines — Practical Responsible AI Guide](/frameworks/uae-ai-ethics.md): Practical guide to the UAE AI Ethics Principles & Guidelines: the 8 principles (fairness, accountability, transparency, explainability, robustness/safety/security, human-centered, sustainability, privacy) and how to operationalize them in Modulos. - [UAE Consumer AI — CBUAE Guidance on AI and ML for Licensed Financial Institutions](/frameworks/uae-consumer-ai.md): Complete guide to the CBUAE Guidance Note on consumer protection and the responsible adoption and use of AI and ML by licensed financial institutions (23 February 2026): scope (onshore UAE LFIs), the governance-through-redress obligations, and how Modulos operationalizes it as MFF-21 (application-level) and OFF-21 (organization-level). Use to orient on the framework and route to the right topic page. - [UAE PDPL — Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data](/frameworks/uae-pdpl.md): Complete guide to the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021): who is in scope, the consent-first processing regime, data subject rights, breach reporting, DPIA, cross-border transfers, the pending Executive Regulation, and how Modulos operationalizes it as MFF-24 (application) and OFF-24 (organization). Use to orient on the framework and route to the right topic page. - [MAS FEAT — Fairness, Ethics, Accountability & Transparency (Practical Guide)](/frameworks/mas-feat.md): Practical guide to MAS FEAT for financial AI and data analytics: the FEAT principles, how to translate them into controls and testing, and how to operationalize FEAT in Modulos. - [FINMA AI Governance — Guidance 08/2024 on Governance and Risk Management When Using AI](/frameworks/finma-ai-governance.md): Complete guide to FINMA Guidance 08/2024 on governance and risk management when using artificial intelligence (18 December 2024): what the Swiss Financial Market Supervisory Authority observed across seven assessment areas, the proportionality principle, who is in scope, and how Modulos operationalizes it as OFF-22 (organization-level) and MFF-22 (application-level). Use to orient on the framework and route to the right topic page. - [Singapore IMDA Model AI Governance Framework for Agentic AI (v1.5) — Complete Guide](/frameworks/singapore-mgf-agentic.md): Complete guide to Singapore IMDA's Model AI Governance Framework for Agentic AI v1.5: the four dimensions (assess and bound risks, make humans meaningfully accountable, implement technical controls, enable end-user responsibility), the agentic risk taxonomy, and how Modulos operationalizes it as MFF-17 (application-level) and OFF-17 (organization-level). Use to orient on the framework and route to the right pillar page. - [Saudi AI Risk Management — SDAIA National AI Risk Management Framework](/frameworks/saudi-ai-risk-management.md): Complete guide to Saudi Arabia's National AI Risk Management Framework (SDAIA-P145, April 2026): the four reference pillars, the five-stage risk cycle with the 4x4 likelihood-impact matrix, who it applies to, and how Modulos operationalizes it as MFF-23 (app) and OFF-23 (org). Use to orient on the framework and route to the right topic page. - [Microsoft Supplier DPR (SSPA) — Data Protection Requirements Guide](/frameworks/microsoft-supplier-dpr.md): Practical guide to Microsoft Supplier Data Protection Requirements (DPR) under SSPA: what’s in scope, how assurance works, and how to manage evidence and review cadence in Modulos. #### Comparison - [AI Governance Frameworks Comparison — EU AI Act, ISO 42001, NIST AI RMF, OWASP LLM](/frameworks/comparison.md): Side-by-side comparison of the major AI governance frameworks, AI compliance standards, and AI regulations: EU AI Act, ISO/IEC 42001, NIST AI RMF, OWASP Top 10 for LLM, GDPR, NIS2, DORA. Pick the right framework for your use case. - [Control Overlap Across AI Governance Frameworks](/frameworks/comparison/control-overlap.md): How much do AI governance frameworks overlap at the Control level? An interactive matrix of shared Controls across the Modulos framework library, covering EU AI Act, ISO 42001, NIST AI RMF, ISO 27001, NIS2, DORA, GDPR and more. Use it to see how much of a new framework your existing program already covers. - [NIST AI RMF vs EU AI Act — Side-by-Side Comparison for AI Governance](/frameworks/comparison/nist-ai-rmf-vs-eu-ai-act.md): Side-by-side of the voluntary NIST AI Risk Management Framework 1.0 and the binding EU AI Act (Regulation (EU) 2024/1689): scope, status, risk logic, mapping of the AI RMF Core (Govern/Map/Measure/Manage) to AI Act provider obligations, and how the two combine in practice. - [ISO 42001 vs NIST AI RMF — Side-by-Side Comparison for AI Governance](/frameworks/comparison/iso-42001-vs-nist-ai-rmf.md): Detailed comparison of ISO/IEC 42001:2023 and the NIST AI Risk Management Framework 1.0: scope, structure, certification, risk methodology, and how the two frameworks combine in practice. - [ISO 42001 vs ISO 27001 — The Standards-Stack Comparison for AI and Information Security](/frameworks/comparison/iso-42001-vs-iso-27001.md): Side-by-side of ISO/IEC 42001:2023 (AI Management System) and ISO/IEC 27001:2022 (Information Security Management System): scope, structure, Annex A overlap, integration pattern, and how the two combine in practice. - [EN 18286 vs ISO/IEC 42001 — Regulatory QMS vs Certifiable AI Management System](/frameworks/comparison/en-18286-vs-iso-42001.md): Side-by-side of EN 18286:2026 (quality management system for EU AI Act regulatory purposes, presumption of conformity once OJ-cited) and ISO/IEC 42001:2023 (certifiable AI management system standard): purpose, legal effect, structure, the Annex C correspondence, and why the overlap is smaller than the similar clause skeletons suggest, with the quantified Modulos template intersection. Use to answer whether you need one, the other, or both. - [EU AI Act vs DORA — Comparison for AI in EU Financial Services](/frameworks/comparison/eu-ai-act-vs-dora.md): How the EU AI Act and DORA (Digital Operational Resilience Act, Regulation (EU) 2022/2554) interact for AI systems in EU financial services: scope, roles, ICT risk, third-party requirements, incident reporting, and how to comply with both at the same time. - [EU AI Act vs GDPR — Comparison for AI Systems Processing Personal Data](/frameworks/comparison/eu-ai-act-vs-gdpr.md): How the EU AI Act and GDPR interact for AI systems that process personal data: scope, roles, risk logic, documentation duties, fines, and how to comply with both at the same time. - [NIS2 vs DORA — Side-by-Side Comparison for EU Cybersecurity and Operational Resilience](/frameworks/comparison/nis2-vs-dora.md): Side-by-side comparison of NIS2 (Directive (EU) 2022/2555) and DORA (Regulation (EU) 2022/2554): scope, the sector-specific Union legal act interaction under NIS2 Article 4 / DORA Article 1(2), incident-reporting coordination, supervisory regimes, and how to operate both in parallel in Modulos. - [Singapore MGF for Agentic AI vs OWASP Top 10 for Agentic Applications — Governance and Security, Side by Side](/frameworks/comparison/singapore-mgf-vs-owasp-agentic.md): How Singapore IMDA's Model AI Governance Framework for Agentic AI and the OWASP Top 10 for Agentic Applications relate: one is a governance framework, the other a security-risk taxonomy. Includes a crosswalk mapping each ASI risk to the MGF dimension that governs it, and how to run both in Modulos. #### EU AI Act - [EU AI Act — Regulation (EU) 2024/1689 Guide for AI Governance](/frameworks/eu-ai-act.md): Practical guide to the EU AI Act (Regulation (EU) 2024/1689): scope, prohibited practices (Art 5), high-risk classification (Art 6 + Annex I/III), Article 50 transparency, Chapter V GPAI, conformity assessment, post-market monitoring, and the Digital Omnibus on AI (Regulation (EU) 2026/1744) amendments, which defer the high-risk deadlines to 2 December 2027 / 2 August 2028. Anchored to OJ-published Article numbers, with common misreadings (the 'four-tier pyramid', 'limited risk', 'GenAI = high-risk') called out explicitly. - [EU AI Act — Article 5 Prohibited Practices and Article 50 Transparency Obligations](/frameworks/eu-ai-act/prohibited-practices-and-transparency.md): Article 5 prohibited AI practices and Article 50 transparency duties in the EU AI Act (Regulation (EU) 2024/1689): the eight categorical bans, the four transparency-by-deployment duties, how they interact with high-risk classification, the Digital Omnibus on AI (Regulation (EU) 2026/1744) NCII/CSAM prohibition (new Article 5(1)(ba)/(bb), applicable 2 December 2026), and Modulos rollout. - [EU AI Act — High-Risk AI Systems (Article 6, Annex I/III, Articles 8–15)](/frameworks/eu-ai-act/high-risk-ai-systems.md): How the EU AI Act classifies high-risk AI systems under Article 6 (Annex I products and Annex III standalone use cases) and what Articles 8–15 require: risk-management system, data governance, technical documentation, record-keeping, transparency to deployers, human oversight, accuracy and robustness, plus the Article 27 fundamental-rights impact assessment for deployers. - [EU AI Act — Roles and Responsibilities (Articles 3, 16, 22, 23, 24, 25, 26, 27)](/frameworks/eu-ai-act/roles-and-responsibilities.md): How the EU AI Act assigns obligations by legal role under Article 3 — provider, deployer, importer, distributor, authorized representative — and what Articles 16, 22, 23, 24, 26 and 27 require of each. Includes Article 25 'accidental provider' rules where a deployer or distributor substantially modifies a high-risk AI system, and the Article 27 fundamental-rights impact assessment for public-sector deployers. - [EU AI Act — Conformity Assessment and CE Marking (Articles 43, 44, 47, 48, 49)](/frameworks/eu-ai-act/conformity-assessment-and-ce-marking.md): The EU AI Act conformity-assessment routes for high-risk AI systems under Article 43, including Annex VI internal control and Annex VII notified-body assessment, the Article 47 EU declaration of conformity, the Article 48 CE marking, the Article 44 certificates regime, and Article 49 EU-database registration. Includes the Annex I sectoral conformity-assessment integration path. - [EU AI Act — General-Purpose AI Models (Chapter V, Articles 51–56)](/frameworks/eu-ai-act/general-purpose-ai-models.md): How Chapter V of the EU AI Act regulates general-purpose AI models at the model level (not the system level): the Article 51 systemic-risk threshold of 10²⁵ FLOPs, Article 53 provider obligations, Article 54 authorized representatives, Article 55 additional obligations for systemic-risk GPAI, and Article 56 Codes of Practice. AI Office supervisory role and how Chapter V interacts with the Article 6 system-level regime. - [EU AI Act — Post-Market Monitoring and Serious Incidents (Articles 72, 73)](/frameworks/eu-ai-act/post-market-monitoring.md): Article 72 post-market monitoring plan and Article 73 serious-incident reporting under the EU AI Act, with explicit distinction from Article 33 GDPR personal-data breach notification. Definitions, event-specific deadlines (15 days; 10 days for death; 2 days for widespread infringement or critical-infrastructure disruption), and Modulos evidence patterns. - [EU AI Act — Commission Guidance Overview](/frameworks/eu-ai-act/commission-guidance.md): Index of the European Commission's interpretive guidance on Regulation (EU) 2024/1689 (AI Act): definition of an AI system (Article 3(1), final), prohibited practices (Article 5, final), the draft high-risk classification guidelines (Article 6, consultation closed 23 July 2026), the transparency obligations (Article 50, content approved 20 July 2026), and the GPAI-model scope guidelines (Chapter V, final). Soft law, not binding. The Regulation text and any CJEU interpretation prevail. - [EU AI Act Harmonized Standards — Presumption of Conformity and the JTC 21 Pipeline](/frameworks/eu-ai-act/harmonized-standards.md): How harmonized standards confer EU AI Act presumption of conformity under Article 40, the CEN/CLC JTC 21 standards pipeline, and the current status of EN 18286 and the remaining prEN drafts. Use to check which AI Act standards are final and what presumption they carry. - [Operationalizing the EU AI Act in Modulos — OFF-1, MFF-1, Evidence Patterns](/frameworks/eu-ai-act/operationalizing-in-modulos.md): How to roll out the EU AI Act in Modulos using the OFF-1 (organization) and MFF-1 (AI application) framework templates, scope role tagging and risk classification, and run requirements with readiness signals and owner-attested fulfillment evidence. Covers Articles 4a, 5, 6, 8–15, 17, 22, 26, 27, 43, 47, 48, 49, 50, 51–56, 72, 73 — where each lives in Modulos. ##### Commission guidance - [EU AI Act — Commission Guidance Overview](/frameworks/eu-ai-act/commission-guidance.md): Index of the European Commission's interpretive guidance on Regulation (EU) 2024/1689 (AI Act): definition of an AI system (Article 3(1), final), prohibited practices (Article 5, final), the draft high-risk classification guidelines (Article 6, consultation closed 23 July 2026), the transparency obligations (Article 50, content approved 20 July 2026), and the GPAI-model scope guidelines (Chapter V, final). Soft law, not binding. The Regulation text and any CJEU interpretation prevail. - [Commission Guidance on the AI System Definition (Article 3(1) EU AI Act)](/frameworks/eu-ai-act/commission-guidance/definition.md): Commission interpretive guidance (C(2025) 5053 final, 29 July 2025) on the Article 3(1) AI system definition — the seven elements, the carve-outs from Recital 12 and paragraphs (41)–(51) of the guideline, and the interaction with downstream classification under Articles 5, 6 and 50. Soft law, not binding; CJEU and the Regulation prevail. - [Commission Guidance on Prohibited AI Practices (Article 5 EU AI Act)](/frameworks/eu-ai-act/commission-guidance/prohibited.md): Commission interpretive guidance (C(2025) 5052 final, 29 July 2025) on Article 5 prohibited AI practices: Article 5(1)(a)–(h) per-prohibition reading, the Article 5(2)–(7) real-time RBI authorization regime, and interaction with Article 50 transparency duties. Soft law, not binding; CJEU and the Regulation prevail. - [Commission Draft Guidance on High-Risk AI Classification (Article 6 EU AI Act)](/frameworks/eu-ai-act/commission-guidance/high-risk-classification.md): Draft Commission guidance on Article 6 high-risk classification under the EU AI Act: Article 6(1) Annex I product-safety route, Article 6(2) Annex III standalone route, and the Article 6(3) filter mechanism with its profiling override. Soft law; draft guidelines published for stakeholder consultation, which closed on 23 July 2026; text may change before adoption. CJEU and the Regulation prevail. - [Commission Draft Worked Examples — High-Risk AI Classification](/frameworks/eu-ai-act/commission-guidance/high-risk-examples.md): Illustrative worked examples paraphrased from the Commission's draft Annex I and Annex III classification guidelines (May 2026, consultation closed 23 July 2026) — biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice. Soft law, draft; text may change; CJEU and the Regulation prevail. - [Commission Guidance on Article 50 Transparency Obligations (EU AI Act)](/frameworks/eu-ai-act/commission-guidance/transparency.md): Commission interpretive guidance (C(2026) 5054, content approved 20 July 2026) on the Article 50 transparency obligations: interactive-AI disclosure (50(1)), synthetic-content marking and detection (50(2)), emotion-recognition and biometric-categorization notification (50(3)), deepfake and public-interest-text labeling (50(4)), and the horizontal timing, clarity and accessibility rule (50(5)). Non-binding; the Regulation and CJEU prevail. Article 50 applies from 2 August 2026. - [Commission Guidance on General-Purpose AI Models (Scope of Obligations)](/frameworks/eu-ai-act/commission-guidance/gpai-models.md): Commission interpretive guidance (C(2025) 7719 final, 19 Nov 2025) on GPAI-model scope under the EU AI Act: the indicative 10²³ FLOP criterion, the one-third-compute downstream-modifier rule, training-compute estimation, lifecycle, and the 2 August 2026 AI Office enforcement-powers date. Soft law, not binding. ##### Harmonized standards - [EU AI Act Harmonized Standards — Presumption of Conformity and the JTC 21 Pipeline](/frameworks/eu-ai-act/harmonized-standards.md): How harmonized standards confer EU AI Act presumption of conformity under Article 40, the CEN/CLC JTC 21 standards pipeline, and the current status of EN 18286 and the remaining prEN drafts. Use to check which AI Act standards are final and what presumption they carry. - [EN 18286 Quality Management System for EU AI Act](/frameworks/eu-ai-act/harmonized-standards/en-18286.md): Guide to EN 18286:2026, the CEN/CENELEC quality management system standard for EU AI Act regulatory purposes: approval status, clause structure, exactly what Annex ZA covers (Articles 17(1) and 11(1) first sentence), what changed from the prEN draft, and how Modulos models it as OFF-19 and MFF-19. Use to orient on the standard before operationalizing it. ###### EN 18286 QMS - [EN 18286 Quality Management System for EU AI Act](/frameworks/eu-ai-act/harmonized-standards/en-18286.md): Guide to EN 18286:2026, the CEN/CENELEC quality management system standard for EU AI Act regulatory purposes: approval status, clause structure, exactly what Annex ZA covers (Articles 17(1) and 11(1) first sentence), what changed from the prEN draft, and how Modulos models it as OFF-19 and MFF-19. Use to orient on the standard before operationalizing it. - [EN 18286 Annex ZA — Full Coverage Table and Presumption of Conformity](/frameworks/eu-ai-act/harmonized-standards/en-18286/annex-za-and-presumption.md): Row-by-row rendering of EN 18286:2026 Annex ZA Table ZA.1: which EU AI Act provisions the standard covers (Article 17(1) points (a) to (m), Article 11(1) first sentence), each row's clauses and conditions, what is expressly not covered, and which Modulos Requirements own each row. Use to answer whether a specific AI Act provision gets presumption of conformity from EN 18286. - [EN 18286 QMS Clauses — Clauses 4–7 and 10 (Organization Layer)](/frameworks/eu-ai-act/harmonized-standards/en-18286/the-qms-clauses.md): Clause-by-clause guide to the organization layer of EN 18286:2026: establishing the QMS, identifying regulatory requirements, the strategy for regulatory compliance, documented information, leadership, planning, support, and management review, with the Modulos OFF-19 Requirements and Controls that carry each clause. Use when implementing or auditing the QMS itself. - [EN 18286 Lifecycle and Operations — Clause 8 and Clauses 9.1–9.5 (Application Layer)](/frameworks/eu-ai-act/harmonized-standards/en-18286/lifecycle-and-operations.md): Clause-by-clause guide to the per-AI-system layer of EN 18286:2026: life cycle processes, risk management, design and development, verification and validation with the reproducibility conditions, data management, retirement, identification and traceability, continuous learning, product documentation, market placement, support services, supply chain, modifications, and post-market monitoring, with the Modulos MFF-19 Requirements. Use when implementing the standard for a specific AI system. - [EN 18286 Serious Incidents and Non-Compliance — Clauses 9.6 and 9.7](/frameworks/eu-ai-act/harmonized-standards/en-18286/incidents-and-non-compliance.md): Operational guide to EN 18286:2026 clauses 9.6 and 9.7: the causal-link trigger and 2/10/15-day serious-incident reporting deadlines, deployer reporting and use suspension, non-compliance detection, the bring-into-compliance / withdraw / disable / recall menu, the AI-system-presenting-a-risk threshold, and market-surveillance notification, with the Modulos ORF-420/ORF-421 mapping. Use during incident response or when building the procedures beforehand. - [Operationalizing EN 18286 in Modulos — OFF-19 and MFF-19 Implementation Playbook](/frameworks/eu-ai-act/harmonized-standards/en-18286/operationalizing-in-modulos.md): How to implement EN 18286:2026 in Modulos: the OFF-19 organization / MFF-19 application split, the clause-to-Requirement map, the reused EU AI Act and ISO 42001 Control estate plus the EN-specific overlays, and what the 1.0.26 template upgrade changed. Use when rolling out the QMS standard in Modulos. #### ISO Standards - [ISO/IEC 42001:2023 — AI Management System Guide & Certification](/frameworks/iso-42001.md): Practical guide to ISO/IEC 42001:2023 — the world's first international AI management system (AIMS) standard. Covers scope and Statement of Applicability, Clauses 4–10, Annex A reference controls, the certification path, and how an ISO 42001 AIMS supports EU AI Act high-risk obligations. Modulos models the standard through the current, fully authored OFF-10/MFF-10 framework templates. - [ISO/IEC 27001:2022 — Information Security Management System (ISMS) Guide](/frameworks/iso-27001.md): Practical guide to ISO/IEC 27001:2022 (ISMS): Annex SL Clauses 4–10, normative Annex A controls, certification process (Stage 1, Stage 2, surveillance, recertification), the Statement of Applicability, and how to operationalize the ISMS in Modulos including IMS integration with ISO 42001 and ISO 27701. - [ISO/IEC 27701 — Privacy Information Management System (PIMS) Guide](/frameworks/iso-27701.md): Practical guide to ISO/IEC 27701 (PIMS): how the privacy management system extends an ISO 27001 ISMS, the Clauses 4–10 Annex SL backbone, the Annex A privacy controls (Table A.1 controllers, Table A.2 processors, Table A.3 both roles), and how the PIMS supports GDPR operational compliance. ##### ISO/IEC 42001 - [ISO/IEC 42001:2023 — AI Management System Guide & Certification](/frameworks/iso-42001.md): Practical guide to ISO/IEC 42001:2023 — the world's first international AI management system (AIMS) standard. Covers scope and Statement of Applicability, Clauses 4–10, Annex A reference controls, the certification path, and how an ISO 42001 AIMS supports EU AI Act high-risk obligations. Modulos models the standard through the current, fully authored OFF-10/MFF-10 framework templates. - [ISO/IEC 42001:2023 Scope, Statement of Applicability and Certification](/frameworks/iso-42001/scope-and-certification.md): How to define the AIMS scope under Clause 4.3, build a Statement of Applicability for Annex A reference controls, and prepare for the accredited ISO 42001 certification audit — Stage 1, Stage 2, surveillance, recertification. - [ISO/IEC 42001:2023 Clauses 4–10 — Practical Implementation Guide](/frameworks/iso-42001/clauses-4-10.md): Implementation guide for ISO/IEC 42001:2023 Clauses 4–10 (Context → Improvement): the Annex SL backbone with AIMS-specific additions in Clauses 5.2 AI policy, 6.1.2 AI risk assessment, 6.1.3 AI risk treatment and 6.1.4 AI system impact assessment. What to implement, what evidence looks like, common pitfalls, and the Modulos requirement-code mapping — including the shared Clauses 4–10 control set and harmonized cross-references across ISO 27001/27701/42001. - [ISO/IEC 42001:2023 Annexes A–D — Reference Controls and Informative Guidance](/frameworks/iso-42001/annexes-a-d.md): How to use the four ISO/IEC 42001:2023 annexes: Annex A reference controls (informative), Annex B implementation guidance, Annex C potential objectives and risk sources, Annex D using the AIMS across domains. Includes the Statement of Applicability pattern, the Modulos requirement-code mapping, and the fully authored Annex A control set including the added Annex A.10.4 Customers control. - [Operationalizing ISO/IEC 42001:2023 in Modulos — AIMS Playbook](/frameworks/iso-42001/operationalizing-in-modulos.md): Implementation playbook for ISO/IEC 42001:2023 in Modulos using the OFF-10/MFF-10 framework templates. Project structure, evidence patterns, IMS integration with ISO 27001/27701 (one shared Clauses 4–10 control set and harmonized cross-references), and the Statement of Applicability. ##### ISO/IEC 27001 - [ISO/IEC 27001:2022 — Information Security Management System (ISMS) Guide](/frameworks/iso-27001.md): Practical guide to ISO/IEC 27001:2022 (ISMS): Annex SL Clauses 4–10, normative Annex A controls, certification process (Stage 1, Stage 2, surveillance, recertification), the Statement of Applicability, and how to operationalize the ISMS in Modulos including IMS integration with ISO 42001 and ISO 27701. - [ISO/IEC 27001:2022 ISMS Foundations — Scope, SoA, and Certification](/frameworks/iso-27001/isms-foundations.md): ISO/IEC 27001:2022 ISMS foundations: how to write the Clause 4.3 ISMS scope statement, build the mandatory Statement of Applicability under Clause 6.1.3 d, and prepare for the Stage 1 / Stage 2 / surveillance / recertification cycle by an accredited certification body. - [ISO/IEC 27001:2022 Clauses 4–10 — Practical ISMS Implementation Guide](/frameworks/iso-27001/clauses-4-10.md): Implementation guide for ISO/IEC 27001:2022 Clauses 4–10 (Context → Improvement): the Annex SL backbone with ISMS-specific risk language in 6.1.2 and 6.1.3, including the mandatory Statement of Applicability under Clause 6.1.3 d. What to implement, what evidence looks like, common pitfalls, the 2024 climate-change amendment to Clause 4.1, and the Modulos requirement-code mapping. - [ISO/IEC 27001:2022 Annex A — 93 Controls in Four Themes](/frameworks/iso-27001/annex-a.md): ISO/IEC 27001:2022 Annex A controls reference: 93 controls organized into four themes (5 Organizational, 6 People, 7 Physical, 8 Technological). How to use Annex A in the Statement of Applicability, what changed from the 2013 edition, and how Modulos tracks the 93 controls — as first-class controls under four theme requirements on the app-level MFF-9 template, and as the SoA on the org-level OFF-9 template. - [Operationalizing ISO/IEC 27001:2022 in Modulos — ISMS Playbook](/frameworks/iso-27001/operationalizing-in-modulos.md): Implementation playbook for ISO/IEC 27001:2022 in Modulos using the OFF-9 (org, 28 ORF) and MFF-9 (app, 6 MRF) framework templates. Project structure, the 93 Annex A controls tracked as first-class controls on MFF-9, the mandatory Statement of Applicability under Clause 6.1.3 d, IMS integration with ISO 42001 and 27701. - [ISO/IEC 27001 Integration with AI Governance — 42001 + EU AI Act](/frameworks/iso-27001/integration-with-ai-governance.md): How to operate ISO/IEC 27001:2022 alongside ISO/IEC 42001:2023 (AIMS) and the EU AI Act. The shared Annex SL backbone, control reuse patterns, evidence linking across frameworks, and how the ISMS becomes the security backbone for AI governance in Modulos. ##### ISO/IEC 27701 - [ISO/IEC 27701 — Privacy Information Management System (PIMS) Guide](/frameworks/iso-27701.md): Practical guide to ISO/IEC 27701 (PIMS): how the privacy management system extends an ISO 27001 ISMS, the Clauses 4–10 Annex SL backbone, the Annex A privacy controls (Table A.1 controllers, Table A.2 processors, Table A.3 both roles), and how the PIMS supports GDPR operational compliance. - [ISO/IEC 27701 PIMS Foundations — Scope, Controller / Processor Roles, Certification](/frameworks/iso-27701/pims-foundations.md): PIMS foundations under ISO/IEC 27701:2025: how to write the Clause 4.3 scope statement, determine PII controller / processor / joint-controller roles, apply the relevant Annex A control tables (A.1 controllers, A.2 processors, A.3 both), and prepare for the Stage 1 / Stage 2 / surveillance / recertification cycle. - [ISO/IEC 27701 Clauses 4–10 — Practical PIMS Implementation Guide](/frameworks/iso-27701/clauses-4-10.md): Implementation guide for ISO/IEC 27701 Clauses 4–10 (Context → Improvement): the Annex SL backbone with PIMS-specific privacy risk language in 6.1.2 and 6.1.3, role determination under 4.1, and how the PIMS produces operational evidence for GDPR compliance. - [ISO/IEC 27701 Annexes — Annex A Control Tables (A.1 Controllers, A.2 Processors, A.3 Both), Annex D GDPR Mapping](/frameworks/iso-27701/annexes.md): ISO/IEC 27701 annex structure: Annex A privacy controls in three role-based tables (Table A.1 PII controllers, Table A.2 PII processors, Table A.3 both roles), Annex B implementation guidance, Annex D informative GDPR mapping. How the controller / processor / joint-controller role drives table selection and how Modulos models each table as a first-class MFF-13 requirement. - [Operationalizing ISO/IEC 27701 in Modulos — PIMS Playbook](/frameworks/iso-27701/operationalizing-in-modulos.md): Implementation playbook for ISO/IEC 27701:2025 (PIMS) in Modulos using the OFF-12 (org, 28 ORF) and MFF-13 (app, 5 MRF) framework templates. Project structure, controller / processor / joint-controller role determination, the Annex A control tables (A.1 / A.2 / A.3) as first-class MFF-13 requirements, IMS integration with ISO 27001 and 42001, and GDPR evidence reuse. - [ISO/IEC 27701 and GDPR — Integration Guide for AI Governance](/frameworks/iso-27701/integration-with-gdpr.md): How ISO/IEC 27701:2025 (PIMS) operationalizes GDPR obligations: controller / processor / joint-controller mapping, the Annex A control tables (A.1 / A.2 / A.3), Article 35 DPIA inside the Clause 6.1.2 risk method, Annex D mapping, and evidence reuse in Modulos using OFF-12 + MFF-13. #### IEEE 7003 - [IEEE 7003 — Algorithmic Bias Considerations](/frameworks/ieee-7003.md): Complete guide to IEEE Std 7003-2024, the IEEE Standard for Algorithmic Bias Considerations: a governance and process standard (not a fairness-metrics standard) for managing wanted and unwanted bias across the AI lifecycle, built around a through-life bias profile, and how Modulos operationalizes it as MFF-25 (app) and OFF-25 (org). Use to orient on the standard and route to the right topic page. - [Bias Requirements and the Bias Profile — IEEE 7003](/frameworks/ieee-7003/bias-requirements-and-the-bias-profile.md): The IEEE 7003 setup activity (Clause 4) and the through-life bias profile (Clause 5): establishing how an AI system considers bias in its context, separating wanted from unwanted bias, the values statement and boundaries of acceptability, the accountability structure, and the version-preserving profile that records every bias decision. Maps to MRF-440 and MRF-441. Read first to set the footing for the rest of the standard. - [Stakeholders and Data Representation — IEEE 7003](/frameworks/ieee-7003/stakeholders-and-data-representation.md): IEEE 7003 stakeholder identification (Clause 6) and data representation (Clause 7): distinguishing impacted from influencing stakeholders and their attributes, identifying protected attributes with rationale, documenting dataset provenance and collection-condition metadata and proxies, and mapping data to impacted-stakeholder attributes with imbalance analysis. Maps to MRF-442, MRF-443, and MRF-444. - [Risk, Evaluation, and Monitoring — IEEE 7003](/frameworks/ieee-7003/risk-evaluation-and-monitoring.md): IEEE 7003 risk and impact assessment (Clause 8), design and output bias evaluation (Clause 9.2), and ongoing evaluation and drift monitoring (Clause 9.3): dual risk inventories with accountable sign-off, an evaluation record across testing and mitigation and UI/UX, and a context-specific monitored-item program that catches data, concept, and system drift. Maps to MRF-445, MRF-446, and MRF-447. - [Operationalizing IEEE 7003 in Modulos — OFF-25 and MFF-25 Playbook](/frameworks/ieee-7003/operationalizing-in-modulos.md): A practical playbook to implement IEEE Std 7003-2024 in Modulos: the org/app project split (OFF-25 organization, MFF-25 per-system), the requirement-to-clause mapping across all 11 requirements, the 10 new controls versus the reused shared controls, a foundation-first rollout sequence, how conformance works, and the readiness-plus-attestation evidence model. Use when setting up IEEE 7003 in Modulos. #### NIST AI RMF - [NIST AI Risk Management Framework 1.0 (NIST AI RMF) — Complete Guide](/frameworks/nist-ai-rmf.md): Complete guide to the NIST AI Risk Management Framework 1.0 (AI RMF 1.0): the four core functions (Govern, Map, Measure, Manage), categories, subcategories, the AI RMF Playbook, Generative AI Profile, and how to operationalize NIST AI RMF in Modulos. - [NIST AI RMF Govern Function — Official Categories, Subcategories, and Operationalization](/frameworks/nist-ai-rmf/govern.md): The Govern function of the official NIST AI Risk Management Framework 1.0: its six categories (GOVERN 1 through GOVERN 6), all 19 subcategories with the official NIST AI RMF Playbook statements, and how to operationalize Govern outcomes in an enterprise AI governance program. - [NIST AI RMF Map Function — Categories, Subcategories, and Operationalization](/frameworks/nist-ai-rmf/map.md): The Map function of the official NIST AI Risk Management Framework 1.0 (NIST AI 100-1): its five categories (MAP 1 through MAP 5), all 18 subcategories with verbatim NIST 100-1 statements, and how to operationalize Map outcomes in an enterprise AI governance program. - [NIST AI RMF Measure Function — Categories, Subcategories, and Operationalization](/frameworks/nist-ai-rmf/measure.md): The Measure function of the official NIST AI Risk Management Framework 1.0 (NIST AI 100-1): its four categories (MEASURE 1 through MEASURE 4), all 22 subcategories with verbatim NIST 100-1 statements, and how to operationalize Measure outcomes in an enterprise AI governance program. - [NIST AI RMF Manage Function — Categories, Subcategories, and Operationalization](/frameworks/nist-ai-rmf/manage.md): The Manage function of the official NIST AI Risk Management Framework 1.0 (NIST AI 100-1): its four categories (MANAGE 1 through MANAGE 4), all 13 subcategories with verbatim NIST 100-1 statements, and how to operationalize Manage outcomes in an enterprise AI governance program. - [NIST AI RMF Generative AI Profile (NIST AI 600-1) — 12 Official Risk Categories and Operationalization](/frameworks/nist-ai-rmf/generative-ai-profile.md): The official NIST Generative AI Profile (NIST AI 600-1, July 2024): the 12 risk categories unique to or exacerbated by generative AI (CBRN, confabulation, data privacy, harmful bias, information integrity, and more), each with verbatim NIST definitions and how to operationalize them in an enterprise AI governance program. - [NIST AI RMF Trustworthy AI Characteristics (NIST AI 100-1) — The 7 Official Characteristics and Operationalization](/frameworks/nist-ai-rmf/trustworthy-ai.md): The 7 characteristics of trustworthy AI from the official NIST AI Risk Management Framework 1.0 (NIST AI 100-1, §3): valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed. - [Operationalizing NIST AI RMF in Modulos — Implementation Playbook](/frameworks/nist-ai-rmf/operationalizing-in-modulos.md): A practical playbook to implement NIST AI RMF in Modulos using projects, requirements, controls, evidence, testing, risk treatment, and review cadence to create continuous trustworthy AI governance. #### GDPR (EU) - [GDPR — Regulation (EU) 2016/679 — Modulos Compliance Guide](/frameworks/gdpr.md): Primary-source overview of the GDPR (Regulation (EU) 2016/679) for AI systems processing personal data: scope (Articles 2 and 3), principles (Article 5), lawful basis (Article 6), rights including automated decisions (Articles 12–22), controller and processor obligations (Articles 24–32), breach notification (Articles 33–34), and DPIA (Article 35). Applied from 25 May 2018. - [GDPR Scope and Applicability — Articles 1, 2, 3, 4](/frameworks/gdpr/scope-and-applicability.md): GDPR (Regulation (EU) 2016/679) scope explained: Article 1 subject matter, Article 2 material scope (with its exclusions for purely personal activities and law-enforcement processing covered by Directive (EU) 2016/680), Article 3 territorial scope (establishment, offering goods or services, behavior monitoring), and Article 4 key definitions. - [GDPR Principles, Rights, and Lawful Basis — Articles 5, 6, 9, 12–22](/frameworks/gdpr/key-principles-and-obligations.md): GDPR Articles 5–22 explained for AI systems: Article 5(1)(a)–(f) six principles + Article 5(2) accountability quoted verbatim, Article 6(1)(a)–(f) lawful basis, Article 9 special categories, Articles 12–22 data subject rights, with Article 22 (automated individual decision-making, including profiling) the most legally consequential GDPR provision for AI. - [GDPR Controller Obligations and Breach Notification — Articles 24–37](/frameworks/gdpr/controller-obligations-and-breach-notification.md): GDPR Articles 24–37 explained: controller responsibility (Art 24), data protection by design and by default (Art 25), joint controllers (Art 26), processor contracts (Art 28), records of processing activities / RoPA (Art 30), security of processing (Art 32), personal-data breach notification (Art 33 — 72 hours), data subject communication (Art 34), data protection impact assessment / DPIA (Art 35), prior consultation (Art 36), and the data protection officer (Articles 37–39). - [Operationalizing GDPR in Modulos — OFF-11 and MFF-12 rollout](/frameworks/gdpr/operationalizing-in-modulos.md): Implementation playbook for GDPR (Regulation (EU) 2016/679) in Modulos: how to roll out OFF-11 (organization-level GDPR, 31 requirements ORF-225 to ORF-255) and MFF-12 (AI application, 10 requirements MRF-233 to MRF-242), sequence the principles + lawful basis + rights + obligations + DPIA + breach work, and assemble the supervisory-authority evidence package. #### NIS2 (EU) - [NIS2 Directive (EU) 2022/2555 — Modulos Compliance Guide](/frameworks/nis2.md): Primary-source overview of the NIS2 Directive (EU) 2022/2555: scope, essential vs important entity classification, Article 21 cybersecurity measures, Article 23 reporting timelines, supervision, and how each obligation lands in Modulos. - [NIS2 Scope and Applicability — Articles 2, 3, 4, 26](/frameworks/nis2/scope-and-applicability.md): How NIS2 scope is determined under Articles 2 (size-cap rule), 3 (essential vs important classification), 4 (sector-specific Union legal acts), and 26 (jurisdiction): Annex I / Annex II sectors, Implementing Regulation 2024/2690 sub-sectoral specification, and the scoping workflow in Modulos. - [NIS2 Cybersecurity Measures — Articles 20 and 21](/frameworks/nis2/cybersecurity-measures.md): NIS2 Article 21 cybersecurity risk-management measures explained: Article 21(1) framing obligation, Article 21(2) all-hazards chapeau and the ten Article 21(2)(a)–(j) categories quoted verbatim from EUR-Lex, Article 20 management-body duties, supply-chain risk assessment, corrective action, and how each measure lands in Modulos. - [NIS2 Incident Reporting and Communications — Article 23](/frameworks/nis2/incident-reporting-and-communications.md): NIS2 Article 23 incident reporting explained: significance test, staged timelines (24-hour early warning, 72-hour notification, intermediate report on request, one-month final report, progress report for ongoing incidents), the trust-service 24-hour derogation, and recipient communication duties — with the key reporting provisions (Article 23(1)–(4) and the trust-service derogation) quoted verbatim from EUR-Lex. - [Operationalizing NIS2 in Modulos — OFF-15 and MFF-15 rollout](/frameworks/nis2/operationalizing-in-modulos.md): Implementation playbook for the NIS2 Directive (EU) 2022/2555 in Modulos: how to roll out OFF-15 (organization-level NIS2) and MFF-15 (AI-service NIS2) framework templates, sequence Article 20 + 21 measures and the Article 23 reporting package, and assemble the supervisory evidence package. #### DORA (EU) - [DORA — Regulation (EU) 2022/2554 — Modulos Compliance Guide](/frameworks/dora.md): Primary-source overview of the Digital Operational Resilience Act (Regulation (EU) 2022/2554, DORA): scope (Articles 1–2), ICT risk management framework (Articles 5–16), ICT-related incident reporting (Articles 17–23), digital operational resilience testing (Articles 24–27), ICT third-party risk (Articles 28–30), oversight of critical TPPs (Articles 31–44), information sharing (Article 45), and the eight Level 2 acts. Applies from 17 January 2025. - [DORA Applicability and Governance — Articles 1, 2, 4, 5, 6, 16](/frameworks/dora/applicability-and-governance.md): DORA Articles 1 (subject matter), 2 (financial-entity scope), 4 (proportionality), 5 (governance and organization), 6 (ICT risk management framework), and 16 (simplified ICT risk management framework for specific entity types) — operationalized in Modulos OFF-16. - [DORA ICT Risk and Resilience Operations — Articles 7–23](/frameworks/dora/ict-risk-and-resilience-operations.md): DORA Articles 7–23 explained: the ICT risk management framework operationalization (Articles 7–14, 15 RTS), simplified framework (Article 16), ICT-related incident management process (Article 17), classification (Article 18), reporting (Article 19), Level 2 harmonization (Article 20), and operational / security payment-related incidents (Article 23) — with the cornerstone provisions (Articles 8(1), 17(1), 18(1), 19(1)) quoted verbatim from EUR-Lex. - [DORA Testing and Third-Party Risk — Articles 24–30](/frameworks/dora/testing-and-third-party-risk.md): DORA Articles 24–27 (digital operational resilience testing and threat-led penetration testing) and Articles 28–30 (ICT third-party risk management, register of information, contractual provisions, subcontracting). Operationalized in Modulos OFF-16 / MFF-16 with the relevant Level 2 acts (2024/1773, 2024/1774, 2024/2956, 2025/532, 2025/1190). - [DORA Information Sharing and Level 2 Acts — Article 45 + 8 Commission Regulations](/frameworks/dora/information-sharing-and-secondary-legislation.md): DORA Article 45 information-sharing arrangements and the eight Commission Delegated and Implementing Regulations that flesh out DORA's operative obligations: 2024/1772, 2024/1773, 2024/1774, 2024/2956, 2025/301, 2025/302, 2025/532, 2025/1190. Each with title, CELEX number, OJ pinpoint, and Article anchor. - [Operationalizing DORA in Modulos — OFF-16 and MFF-16 rollout](/frameworks/dora/operationalizing-in-modulos.md): Implementation playbook for DORA (Regulation (EU) 2022/2554) in Modulos: how to roll out OFF-16 (organization-level DORA) and MFF-16 (ICT system / AI application) framework templates, sequence the ICT risk management framework, the incident-reporting workflow, resilience testing and TLPT, the ICT third-party regime, and the Article 45 information-sharing duty. #### Cyber Resilience Act (EU) - [Cyber Resilience Act (CRA) — Regulation (EU) 2024/2847 for Products with Digital Elements](/frameworks/cra.md): Complete guide to the EU Cyber Resilience Act (Regulation (EU) 2024/2847): which products are in scope, the Annex I essential cybersecurity requirements, vulnerability handling and SBOM, the support period, Article 14 reporting from 11 September 2026, economic-operator roles, and how Modulos operationalizes it as MFF-26 (application) and OFF-26 (organization). Use to orient on the framework and route to the right topic page. - [CRA Scope, Classification, and Conformity — Product Boundary, Categories, CE Marking](/frameworks/cra/scope-classification-and-conformity.md): How the Cyber Resilience Act's scoping, product classification, and conformity machinery works in Modulos: the applicability decision and product boundary (MRF-450), important and critical categories with the Article 12 high-risk-AI interplay and conformity routes (MRF-451), technical documentation (MRF-473), the EU declaration and CE marking (MRF-474), and continuous conformity (MRF-475). - [CRA Risk Assessment and Annex I — The Thirteen Product-Security Properties](/frameworks/cra/risk-assessment-and-annex-i.md): How the Cyber Resilience Act's cybersecurity risk assessment (MRF-452) drives the risk-based application of the thirteen Annex I, Part I product-security properties (MRF-454–466) in Modulos, plus the overall secure-by-design outcome (MRF-453) and component and remote-solution assurance (MRF-467). - [CRA Vulnerability Handling and the Support Period — SBOM, Updates, User Information](/frameworks/cra/vulnerability-handling-and-support-period.md): How the Cyber Resilience Act's vulnerability-handling and lifecycle duties work in Modulos: the support-period determination and disclosure (MRF-468), the SBOM and vulnerability record with its three authority routes (MRF-469), security testing (MRF-470), remediation, update delivery, and advisories (MRF-471), and product identity and user information (MRF-472). - [CRA Reporting and Economic Operators — Article 14 Deadlines and Supply-Chain Roles](/frameworks/cra/reporting-and-economic-operators.md): The Cyber Resilience Act's organization-side duties in Modulos: role and applicability governance (ORF-468), the manufacturer's repeatable capabilities (ORF-469–475), the Article 14 reporting ladders for actively exploited vulnerabilities and severe incidents from 11 September 2026 (ORF-476), post-market corrective action and authority cooperation (ORF-477), compliance records and traceability (ORF-478), and the conditional authorized-representative, importer, distributor, and open-source steward roles (ORF-479–482). - [Operationalizing the CRA in Modulos — MFF-26 and OFF-26](/frameworks/cra/operationalizing-in-modulos.md): How to run the Cyber Resilience Act in Modulos: the MFF-26 (application) and OFF-26 (organization) project structure, the requirement mapping tables, the 22 new CRA controls, the control reuse with ISO 27001, NIS2, DORA, ISO 42001, and EN 18286, the three CRA tag categories, and the rollout sequence. Templates 1.0.28. #### OWASP for AI Security - [OWASP for AI Security — Top 10 for LLM and Agentic Applications](/frameworks/owasp.md): OWASP AI security hub: the Top 10 for Large Language Model Applications (2025) and the Top 10 for Agentic Applications. Use them together as your generative AI security and AI agent security baseline. - [OWASP Top 10 for Large Language Model Applications (2025) — Modulos Governance Guide](/frameworks/owasp-top-10-llm.md): Primary-source overview of the OWASP Top 10 for LLM Applications 2025 (LLM01:2025–LLM10:2025): independently authored definitions, governance implications, NIST AI RMF / ISO 42001 / EU AI Act cross-mappings, and how each risk lands in Modulos. - [OWASP Top 10 for Agentic Applications (2026) — Modulos Governance Guide](/frameworks/owasp-top-10-agentic.md): Primary-source overview of the OWASP Top 10 for Agentic Applications 2026 (ASI01–ASI10): independently authored definitions, governance implications, NIST AI RMF / ISO 42001 / EU AI Act cross-mappings, and how each agentic risk lands in Modulos. #### UAE AI Ethics - [UAE AI Ethics Principles & Guidelines — Practical Responsible AI Guide](/frameworks/uae-ai-ethics.md): Practical guide to the UAE AI Ethics Principles & Guidelines: the 8 principles (fairness, accountability, transparency, explainability, robustness/safety/security, human-centered, sustainability, privacy) and how to operationalize them in Modulos. - [UAE AI Ethics Principles — Practical Interpretation for AI Systems](/frameworks/uae-ai-ethics/principles.md): Practical interpretation of the UAE AI Ethics Principles: how to translate each principle into controls, evidence, and monitoring signals for AI systems. - [Operationalizing UAE AI Ethics in Modulos](/frameworks/uae-ai-ethics/operationalizing-in-modulos.md): How to operationalize UAE AI Ethics with Modulos projects, requirements, controls, evidence, reviews, and testing to make principle-based governance auditable. #### UAE Consumer AI - [UAE Consumer AI — CBUAE Guidance on AI and ML for Licensed Financial Institutions](/frameworks/uae-consumer-ai.md): Complete guide to the CBUAE Guidance Note on consumer protection and the responsible adoption and use of AI and ML by licensed financial institutions (23 February 2026): scope (onshore UAE LFIs), the governance-through-redress obligations, and how Modulos operationalizes it as MFF-21 (application-level) and OFF-21 (organization-level). Use to orient on the framework and route to the right topic page. - [Scope and Governance — UAE Consumer AI (CBUAE)](/frameworks/uae-consumer-ai/scope-and-governance.md): The scope and governance foundation of the CBUAE Consumer AI guidance in Modulos: the onshore-LFI perimeter (DIFC/ADGM out of scope), board and senior-management accountability, the AI/ML inventory and risk-rating process, consumer-protection impact governance, the MMS-anchored model-governance requirement, and industry engagement. Maps to ORF-423–426, ORF-431, ORF-438, and MRF-397. Read to establish the OFF-21 foundation before the principle families. - [Fairness, Transparency, and Oversight — UAE Consumer AI (CBUAE)](/frameworks/uae-consumer-ai/fairness-transparency-and-oversight.md): The three consumer-protection principle families of the CBUAE Consumer AI guidance in Modulos: fairness and non-discrimination, transparency and explainability (including bilingual disclosure and opt-out), and human oversight and escalation (the three oversight models). Each is split across an org governance requirement and an app execution requirement. Maps to ORF-427–429 and MRF-399–401. Read to design the principle-level obligations after the governance foundation. - [Data, Models, Monitoring, and Remediation — UAE Consumer AI (CBUAE)](/frameworks/uae-consumer-ai/data-models-monitoring-and-remediation.md): The operational backbone of the CBUAE Consumer AI guidance in Modulos: data quality, privacy, and security (PDPL, in-country retention); model validation and the deployment boundary; logging and traceability; continuous monitoring, drift, and outcome review; incident, harm, and remediation response; and the proactive use of AI to detect fraud and financial crime. Maps to ORF-430/431/433/434/436/437 and MRF-397/398/402/403/404. - [Consumer Redress and Third-Party AI — UAE Consumer AI (CBUAE)](/frameworks/uae-consumer-ai/consumer-redress-and-third-party-ai.md): The conditional duties of the CBUAE Consumer AI guidance in Modulos: third-party and outsourced AI dependency governance and assurance (provider due diligence, contractual audit rights, inventory parity), and consumer human review, complaints, redress, and communication support (Article 8 of the Consumer Protection Regulation). Explains how applicability is recorded without a scoping questionnaire. Maps to ORF-432/435 and MRF-405/406. - [Operationalizing UAE Consumer AI in Modulos — OFF-21 and MFF-21 Implementation Playbook](/frameworks/uae-consumer-ai/operationalizing-in-modulos.md): A practical playbook to implement the CBUAE Consumer AI guidance in Modulos: the org/app project split (OFF-21 organization, MFF-21 per-use-case), the full requirement-to-pillar mapping across the 26 requirements, the baseline-vs-UAE-specific control library, the rollout sequence by requirement ID, and the readiness-plus-attestation evidence model. Use when setting up UAE Consumer AI governance in Modulos. #### UAE PDPL - [UAE PDPL — Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data](/frameworks/uae-pdpl.md): Complete guide to the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021): who is in scope, the consent-first processing regime, data subject rights, breach reporting, DPIA, cross-border transfers, the pending Executive Regulation, and how Modulos operationalizes it as MFF-24 (application) and OFF-24 (organization). Use to orient on the framework and route to the right topic page. - [Scope, Enforcement, and the Executive Regulation — UAE PDPL](/frameworks/uae-pdpl/scope-enforcement-and-the-executive-regulation.md): The perimeter and enforcement posture of the UAE PDPL (Federal Decree-Law No. 45 of 2021) in Modulos: Article 1 definitions, the Article 2 scope limbs and exclusions including the free-zone exclusion (DIFC and ADGM are the established examples), the Article 3 Bureau exemption power, complaints and grievances under Articles 24–25, the pending Article 26 penalties decision, and the Article 28–29 Executive Regulation timeline, mapped to ORF-456, ORF-463, and ORF-464. Read this first to establish which entities and processing the framework covers. - [Lawful Processing and Data Subject Rights — UAE PDPL](/frameworks/uae-pdpl/lawful-processing-and-data-subject-rights.md): The UAE PDPL's consent-default rule (Article 4), processing controls (Article 5), consent terms (Article 6), and data subject rights (Articles 13 to 19), mapped to Modulos requirements MRF-431, MRF-432, and MRF-434 to MRF-436 in the MFF-24 template. Read this page when defining lawful bases, consent capture, and rights handling for an application processing personal data under UAE federal law. - [Controllers, Processors, and the Data Protection Officer — UAE PDPL](/frameworks/uae-pdpl/controllers-processors-and-the-dpo.md): How the UAE PDPL's controller obligations (Article 7), processor obligations (Article 8), protection by design and by default, and the Data Protection Officer articles (Articles 10–12) are modeled in Modulos: ORF-457, ORF-458, ORF-460, and ORF-461 on the organization side and MRF-433 per AI application. Read to set up the controller/processor role split, the records of processing, and the DPO appointment determination. - [Security, Breaches, Impact Assessment, and Cross-Border Transfers — UAE PDPL](/frameworks/uae-pdpl/security-breaches-dpia-and-cross-border-transfers.md): Articles 9, 20, 21, 22 and 23 of the UAE Personal Data Protection Law in Modulos: the Article 20 security measures and risk-based evaluation, breach notification to the Bureau and data subjects (notification period pending the Executive Regulation), the Article 21 impact assessment, and the Article 22 and 23 cross-border transfer mechanisms, mapped to MRF-437, MRF-438, MRF-439, ORF-459, and ORF-462. Read when implementing security, breach, impact-assessment, and transfer duties under the PDPL. - [Operationalizing UAE PDPL in Modulos — OFF-24 and MFF-24 Playbook](/frameworks/uae-pdpl/operationalizing-in-modulos.md): A practical playbook to implement the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) in Modulos: the org/app project split (OFF-24 organization, MFF-24 per AI application), the full requirement-to-control mapping across all 18 requirements, the 59 reused versus 6 new controls, the Executive Regulation watch loop with the Article 29 regularisation clock, a scope-first rollout sequence, and the readiness-plus-attestation evidence model. Use when setting up UAE PDPL compliance in Modulos. #### MAS FEAT - [MAS FEAT — Fairness, Ethics, Accountability & Transparency (Practical Guide)](/frameworks/mas-feat.md): Practical guide to MAS FEAT for financial AI and data analytics: the FEAT principles, how to translate them into controls and testing, and how to operationalize FEAT in Modulos. - [MAS FEAT Principles — Practical Implementation for Financial AI](/frameworks/mas-feat/principles.md): Practical implementation lens for MAS FEAT: how to translate Fairness, Ethics, Accountability, and Transparency principles into controls, evidence, and continuous testing signals. - [Operationalizing MAS FEAT in Modulos](/frameworks/mas-feat/operationalizing-in-modulos.md): How to implement MAS FEAT in Modulos using requirements, controls, evidence, reviews, and testing to create an auditable responsible AI program. #### FINMA AI Governance - [FINMA AI Governance — Guidance 08/2024 on Governance and Risk Management When Using AI](/frameworks/finma-ai-governance.md): Complete guide to FINMA Guidance 08/2024 on governance and risk management when using artificial intelligence (18 December 2024): what the Swiss Financial Market Supervisory Authority observed across seven assessment areas, the proportionality principle, who is in scope, and how Modulos operationalizes it as OFF-22 (organization-level) and MFF-22 (application-level). Use to orient on the framework and route to the right topic page. - [Governance, Inventory and Risk Classification, and Data Quality — FINMA AI Governance](/frameworks/finma-ai-governance/governance-inventory-and-data-quality.md): The three foundational assessment areas of FINMA Guidance 08/2024 in Modulos: the proportionate AI governance framework, roles and accountabilities, competence and training, outsourcing and third-party AI oversight (§2.1); the centrally managed risk-classified AI inventory and per-application classification (§2.2); and institution-wide data-quality standards (§2.3). Maps to ORF-439/440/442/443/444/445 and MRF-407/412. Read to establish the OFF-22 foundation before testing and review. - [Testing and Ongoing Monitoring, Documentation, Explainability, and Independent Review — FINMA AI Governance](/frameworks/finma-ai-governance/testing-monitoring-documentation-and-review.md): The four evidentiary and operational assessment areas of FINMA Guidance 08/2024 in Modulos: tests and ongoing monitoring (§2.4), documentation (§2.5), explainability (§2.6), and independent review (§2.7). Maps to ORF-441, ORF-446, MRF-408, MRF-409, MRF-410, and MRF-411. This is where most evidence overlaps with existing ISO 42001, EU AI Act, and NIST AI RMF programs — the fastest reuse path. - [Operationalizing FINMA AI Governance in Modulos — OFF-22 and MFF-22 Playbook](/frameworks/finma-ai-governance/operationalizing-in-modulos.md): A practical playbook to implement FINMA Guidance 08/2024 in Modulos: the org/app project split (OFF-22 organization, MFF-22 per-use-case), the requirement-to-assessment-area mapping across all 14 requirements, the four FINMA-exclusive controls versus the 30 reused shared controls, a proportionality-ordered rollout sequence, and the readiness-plus-attestation evidence model. Use when setting up FINMA AI Governance in Modulos. #### Singapore MGF for Agentic AI - [Singapore IMDA Model AI Governance Framework for Agentic AI (v1.5) — Complete Guide](/frameworks/singapore-mgf-agentic.md): Complete guide to Singapore IMDA's Model AI Governance Framework for Agentic AI v1.5: the four dimensions (assess and bound risks, make humans meaningfully accountable, implement technical controls, enable end-user responsibility), the agentic risk taxonomy, and how Modulos operationalizes it as MFF-17 (application-level) and OFF-17 (organization-level). Use to orient on the framework and route to the right pillar page. - [Agentic AI Components and Risks (MGF Section 1) — What the Framework Governs](/frameworks/singapore-mgf-agentic/agentic-ai-risks.md): The definitional and risk foundation of Singapore's MGF for Agentic AI: the eight core agent components, multi-agent design patterns, the action-space-versus-autonomy distinction, the four human-involvement levels, and the agentic risk taxonomy (erroneous, unauthorized, biased, data-breach, disruption, plus systemic and multi-agent risks). Read this before the four pillar pages. - [Assess and Bound the Risks Upfront (MGF Dimension 1) — Suitability, Limits, and Agent Identity](/frameworks/singapore-mgf-agentic/assess-and-bound-risks.md): Dimension 1 of Singapore's MGF for Agentic AI: deciding whether a use case is suitable for an agent via an impact-and-likelihood risk assessment, bounding agent authority by design (least privilege, deterministic over prompt, emergency revocation), agent identity and delegated authorization, threat modeling and taint tracing, the central agent catalog, and residual-risk acceptance. Read when scoping a new agent and when mapping the work to MRF-311/312 and ORF-390/391 in Modulos. - [Make Humans Meaningfully Accountable (MGF Dimension 2) — Responsibility Allocation and Human Oversight](/frameworks/singapore-mgf-agentic/human-accountability.md): Dimension 2 of Singapore's MGF for Agentic AI: allocating responsibility across the agentic value chain and internal teams, designing meaningful human oversight (approval checkpoints, anti-rubber-stamping metrics, automation-bias mitigation), red-teaming agents, and assessing third-party components. Read when you need to assign accountability for agent actions or evidence that human oversight is genuine. Maps to MRF-313, MRF-319, and ORF-389. - [Implement Technical Controls and Processes (MGF Dimension 3) — Build, Test, Deploy, and Govern Multi-Agent Systems](/frameworks/singapore-mgf-agentic/technical-controls.md): Dimension 3 of Singapore's MGF for Agentic AI: technical controls for the agentic components a plain LLM application lacks (planning, memory, tools, protocols), pre-deployment workflow and multi-agent testing, gradual rollout with continuous monitoring and change management, and governing multi-agent and cross-system interactions. Read when building and operating agents in Modulos under MRF-314/315/316/317. - [Enable End-User Responsibility (MGF Dimension 4) — Disclosure, Training, and Tradecraft Continuity](/frameworks/singapore-mgf-agentic/end-user-responsibility.md): Dimension 4 of Singapore's MGF for Agentic AI: disclosing agent identity, authority, data use and escalation at the point of interaction; training users who integrate agents into their work; and preserving manual fallback competence (tradecraft continuity) distinct from AI literacy. Read this when designing agent disclosure UX or planning user training and business-continuity drills. Maps to MRF-318 and ORF-392. - [Operationalizing the MGF for Agentic AI in Modulos — MFF-17 and OFF-17 Implementation Playbook](/frameworks/singapore-mgf-agentic/operationalizing-in-modulos.md): A practical playbook to implement Singapore's MGF for Agentic AI in Modulos: the org/app project split (OFF-17 organization, MFF-17 per-application), how the four dimensions map to the 13 requirements, the agentic control library, and the readiness-plus-attestation evidence loop. Use when setting up agentic AI governance in Modulos. #### Saudi AI Risk Management - [Saudi AI Risk Management — SDAIA National AI Risk Management Framework](/frameworks/saudi-ai-risk-management.md): Complete guide to Saudi Arabia's National AI Risk Management Framework (SDAIA-P145, April 2026): the four reference pillars, the five-stage risk cycle with the 4x4 likelihood-impact matrix, who it applies to, and how Modulos operationalizes it as MFF-23 (app) and OFF-23 (org). Use to orient on the framework and route to the right topic page. - [Reference Pillars and Context Scoping — Saudi AI Risk Management](/frameworks/saudi-ai-risk-management/reference-pillars-and-context.md): The four reference pillars of SDAIA's National AI Risk Management Framework (general principles and AI ethics, AI regulations, data regulations, sector regulations) and the context-and-scope stage: system description and use boundaries, data and I/O points, automation level and the human role, and lifecycle and change plan. Maps to ORF-449–452 and MRF-414–418. Read to establish the footing before risk identification. - [Risk Identification and Assessment — Saudi AI Risk Management](/frameworks/saudi-ai-risk-management/risk-identification-and-assessment.md): The identification and assessment stages of SDAIA's National AI Risk Management Framework in Modulos: the seven-category risk taxonomy with the semantic-coverage crosswalk option, causal characterization by source, intent, and timing, the four-level likelihood and impact scales with their named factors, the reserved catastrophic level, and the 4x4 matrix with bands. Maps to MRF-419–423. Read when building and scoring the risk register. - [Risk Treatment, Monitoring, and Incidents — Saudi AI Risk Management](/frameworks/saudi-ai-risk-management/risk-treatment-monitoring-and-incidents.md): The treatment and monitoring stages of SDAIA's National AI Risk Management Framework in Modulos: the four treatment strategies (avoidance, mitigation, transfer, acceptance), control design and implementation, residual-risk reassessment, the acceptance or escalation decision, continuous performance monitoring, periodic register reviews, and incident response with root-cause analysis. Maps to MRF-424–430. Read when treating scored risks and running live operation. - [Governance, Documentation Standards, and Capability — Saudi AI Risk Management](/frameworks/saudi-ai-risk-management/governance-documentation-and-capability.md): The organization-level foundations of SDAIA's National AI Risk Management Framework in Modulos: internal AI risk policies built on the five-stage methodology, risk governance with decision rights and an approved risk tolerance, organization-wide risk documentation standards, and awareness and capability development. Maps to ORF-448 and ORF-453–455. Read to stand up the OFF-23 machinery the per-system cycle consumes. - [Operationalizing Saudi AI Risk Management in Modulos — OFF-23 and MFF-23 Playbook](/frameworks/saudi-ai-risk-management/operationalizing-in-modulos.md): A practical playbook to implement SDAIA's National AI Risk Management Framework in Modulos: the org/app project split (OFF-23 organization, MFF-23 per-system), the requirement-to-activity mapping across all 25 requirements, the 20 new controls versus the reused shared controls, a foundation-first rollout sequence, and the readiness-plus-attestation evidence model. Use when setting up Saudi AI Risk Management in Modulos. #### Microsoft Supplier DPR - [Microsoft Supplier DPR (SSPA) — Data Protection Requirements Guide](/frameworks/microsoft-supplier-dpr.md): Practical guide to Microsoft Supplier Data Protection Requirements (DPR) under SSPA: what’s in scope, how assurance works, and how to manage evidence and review cadence in Modulos. - [Microsoft Supplier DPR Scope — What’s In Scope and How to Organize Evidence](/frameworks/microsoft-supplier-dpr/scope.md): How to scope Microsoft Supplier DPR work: data types, system boundaries, subprocessors, required evidence artifacts, and ownership so supplier assurance stays repeatable and review-ready. - [Microsoft Supplier DPR Evidence & Audits — How to Stay Review-Ready](/frameworks/microsoft-supplier-dpr/evidence-and-audits.md): Practical playbook for Microsoft Supplier DPR evidence and audits: what artifacts teams maintain, how to keep review cadence, and how to manage supplier assurance workflows in Modulos. ### Resources - [Glossary](/resources/glossary.md): Definitions of key AI governance terms used in Modulos — from compliance Controls and risk quantification to framework-specific terminology. - [Changelog](/resources/changelog.md): New features, improvements, and fixes in the Modulos platform. - [Modulos Client](/resources/modulos-client.md): Modulos Client Python SDK — upload Evidence from CI pipelines, push operational metrics for continuous testing, and automate governance workflows via API. - [Data Handling & Access](/resources/security-privacy.md): What Modulos stores, who can access it, and how integrations are scoped. - [Troubleshooting](/resources/troubleshooting.md): Troubleshooting guides for Modulos — fix common issues with access, integrations, runtime inspection, Evidence uploads, and exports. - [Support](/resources/support.md): Contact Modulos support, report issues, and find resources for troubleshooting your AI governance platform setup. #### Troubleshooting - [Troubleshooting](/resources/troubleshooting.md): Troubleshooting guides for Modulos — fix common issues with access, integrations, runtime inspection, Evidence uploads, and exports. - [Access & Permissions](/resources/troubleshooting/access-permissions.md): Fix missing tabs, forbidden errors, and role-related issues. - [Troubleshooting Integrations](/resources/troubleshooting/integrations.md): Fix common issues with Sources, Scout Connectors, and API tokens in Modulos — validation errors, sync failures, and permission problems. - [Runtime Inspection](/resources/troubleshooting/runtime.md): Fix missing metrics, failed tests, and schedule issues. - [Evidence & Exports](/resources/troubleshooting/evidence-exports.md): Fix Evidence upload issues and missing items in exports. ### Other - [NIST AI RMF Core Functions — page moved](/frameworks/nist-ai-rmf/core-functions-and-profiles.md): This page has moved. The four NIST AI RMF functions (Govern, Map, Measure, Manage) now have dedicated spokes. - [OWASP Top 10 for Agentic Applications — Mitigations and Testing (page moved)](/frameworks/owasp-top-10-agentic/mitigations-and-testing.md): This page has moved. OWASP Top 10 for Agentic Applications mitigation patterns and testing guidance are now folded into the consolidated framework page. - [OWASP Top 10 for Agentic Applications — Top Risks (page moved)](/frameworks/owasp-top-10-agentic/top-risks.md): This page has moved. The OWASP Top 10 for Agentic Applications (ASI01–ASI10) now lives on the consolidated framework page. - [OWASP Top 10 for LLM Applications — Mitigations and Testing (page moved)](/frameworks/owasp-top-10-llm/mitigations-and-testing.md): This page has moved. OWASP Top 10 for LLM Applications mitigation patterns and testing guidance are now folded into the consolidated framework page. - [OWASP Top 10 for LLM Applications — Top Risks (page moved)](/frameworks/owasp-top-10-llm/top-risks.md): This page has moved. The OWASP Top 10 for LLM Applications (LLM01:2025–LLM10:2025) now lives on the consolidated framework page. - [Runtime Inspection Sources](/platform/runtime/sources.md): Configure project-level service accounts (Sources) that connect Runtime Inspection pipelines and Scout to external systems like GitHub, Jira, and Google Drive.