Solutions · Compliance & Regulations

Every framework. Every region. Pre-mapped.

Safeguard ships pre-mapped control narratives and automated evidence pipelines for 7 regions and more than 60 frameworks — including the AI-specific regulations now landing across the EU, the US, Singapore, Korea, and India. This page is the encyclopedic map: every framework we cover, organised by region and by sector.

7
Regions
60+
Frameworks
AI-Specific
Regs included
Continuous
Evidence, not annual snapshots
Regional Coverage

Seven regions. One ledger.

Each card lists the frameworks we cover in that jurisdiction, the scope of each, and a direct link to the evidence packet shape we ship for it.

Region 01

North America

Federal cloud authorisation, DoD maturity, and state-level privacy.

FlagshipFedRAMP HIGH
Region 02

European Union

Privacy, operational resilience, AI obligations, and product cyber security.

FlagshipEU AI Act
Region 03

United Kingdom

Post-GDPR privacy plus national cyber assessment baselines.

  • UK GDPRUnited Kingdom general data protection regulation
    Evidence packet
  • NCSC Cyber Assessment Framework (CAF)national cyber baseline for essential services
    Evidence packet
  • PRA SS1/21operational resilience (banking)
    Evidence packet
  • FCA fintech / SYSC cyber rulesconduct rules for regulated firms
    Evidence packet
  • MOD JSP-440Ministry of Defence security policy
    Evidence packet
FlagshipNCSC CAF
Region 04

India

DPDP, sector regulators, and sovereign deployment readiness.

FlagshipDPDP Act, 2023
Region 05

Middle East

GCC national cyber controls plus emerging privacy laws.

FlagshipSaudi NCA ECC
Region 06

APAC

Privacy laws, banking technology risk, and AI assurance.

FlagshipSingapore MAS TRM
Region 07

Latin America & Africa

Privacy frameworks across Brazil, Mexico, and African data laws.

FlagshipBrazil LGPD
AI-Specific Regulations

AI regs overlap regions. We map them anyway.

Eight AI-specific regimes that we surface as standalone control sets in addition to their parent region — because most AI-touching products are now subject to two or three of them at once.

01

EU AI Act

high-risk AI obligations across the EU single market

02

US AI EO 14110

federal AI safety, transparency, and reporting

03

Singapore AI Verify

AI governance testing toolkit and attestations

04

UK AI Safety Institute alignment

frontier model evaluation baseline

05

Japan AI Governance Guidelines (METI)

voluntary corporate AI governance baseline

06

Korea AI Framework Act

AI system risk classification and obligations

07

China Generative AI Measures

model registration, content labelling, training data

08

India DPDP + draft AI Advisory framework

data fiduciary plus AI advisory layer

Sectoral Overlays

The regions are the map. Sectors are the overlays.

Four overlays where a single product is typically subject to two or three frameworks from different regions at the same time.

Finance

  • DORA + EU CRA
    operational resilience plus product cyber
  • MAS TRM + PRA SS1/21
    banking technology risk on both sides of Asia and the UK
  • RBI + SEBI CSCRF + IFSCA
    Indian banking, securities, and international financial services

Healthcare

  • HIPAA / HITECH
    protected health information across covered entities
  • EU MDR / IVDR
    medical device and in vitro diagnostic security obligations
  • Regional privacy overlays
    GDPR, DPDP, LGPD, POPIA where patient data crosses borders

Defence / Government

  • FedRAMP HIGH + CMMC L2/L3
    US federal cloud and DoD supplier maturity
  • MOD JSP-440
    UK Ministry of Defence security policy baseline
  • STQC + Saudi NCA OTCC
    sovereign certification and OT-grade national controls

Critical Infrastructure

  • NIS2 + EU CER Directive
    essential and critical entities across the EU
  • NIST SP 800-53 + 800-161
    federal information systems and supply-chain risk
  • Saudi NCA OTCC + UAE NESA
    OT and national assurance for operators of national importance
What "Covered" Means

Three things. Not just a list.

Most vendors put a logo grid on a marketing page and call it "coverage." Coverage here means three concrete things. Where a control requires human judgement — policy authoring, organisational scope, attestation of governance — we surface it as an open checklist gap, not a fake green check.

Pre-mapped control narratives

Every control in the framework is read, interpreted, and given a narrative that explains what Safeguard does for it, what the customer must still attest to, and where the gaps live.

Automated evidence collection

Scans, SBOMs, signed attestations, access logs, policy gate verdicts — all bound to controls and collected continuously, not in screenshot sprints before an audit.

Signed export per framework

One-click export in the format the regulator or auditor expects. Each artifact is signed; the auditor can verify without trusting Safeguard.

Coverage Pipeline

How a new region gets added.

Any framework not on this page is a 4–8 week add given the existing evidence pipeline. Here is what those weeks look like.

01

Customer Signal

A regulated buyer, a partner, or an internal review surfaces a framework that isn't yet on the map. We log the regulator, the jurisdiction, and the deadline.

02

Legal + Regulator Alignment

Counsel and the framework authors read the source text. Where the regulator publishes a control catalogue, we map clause-by-clause. Where it doesn't, we infer from guidance and precedent and flag the inference.

03

Control Narrative + Evidence Pipeline

Each control gets a written narrative plus an automated evidence binding to the underlying telemetry — scans, SBOMs, attestations, access logs, policy gates. Where a control needs human attestation, we ship it as a checklist gap rather than a fake check.

04

Release

The framework appears in the console, the export menu, and on this page. Any framework not yet listed is a 4–8 week add given the existing evidence pipeline — most of the work is narrative authoring, not engineering.

Headline Coverage

The shortlist. One row per region.

RegionFrameworks coveredFlagship frameworkEvidence packet
North America
13 mappedFedRAMP HIGHOpen
European Union
9 mappedEU AI ActOpen
United Kingdom
5 mappedNCSC CAFOpen
India
8 mappedDPDP Act, 2023Open
Middle East
10 mappedSaudi NCA ECCOpen
APAC
10 mappedSingapore MAS TRMOpen
Latin America & Africa
6 mappedBrazil LGPDOpen

Totals on this table refer to frameworks explicitly mapped in the console. Sectoral overlays and AI regimes are counted within their parent region as well as listed in their own sections above.

Talk to compliance.

Bring the frameworks you owe. We'll walk the map with you — region by region, control by control, evidence packet by evidence packet.