Supported Compliance Frameworks
ISMS Copilot injects verified knowledge for more than 90 compliance frameworks and regulations, so answers are grounded in real requirements, not AI guessing.
Contenido en inglés
ISMS Copilot provides specialized AI assistance grounded in a maintained framework knowledge registry, currently covering more than 90 frameworks and regulations across information security, privacy, AI governance, and sector rules. When you mention a supported framework in your questions, the system automatically detects it and injects verified framework knowledge before the AI responds.
The registry grows continuously. New frameworks are announced in the in-app Product Changelog, which is always more current than any static list.
What is covered
A non-exhaustive tour by family:
- Core management-system standards: ISO 27001:2022, ISO 27002, ISO 42001:2023 (AI), ISO 27701 (privacy), ISO 27017 / ISO 27018 (cloud), ISO 22301 (business continuity), ISO 9001 (quality), ISO 19011 (auditing)
- Attestations and certifications: SOC 2 (Trust Services Criteria), TISAX (VDA ISA), HDS (French health data hosting), SecNumCloud, BSI C5, ENS (Spain), PCI DSS
- EU regulation: GDPR, the EU AI Act, DORA, and NIS 2, including national transpositions for most EU member states (Germany, France, Italy, Belgium, the Nordics, and many more)
- Privacy laws worldwide: CCPA, UK GDPR and the UK Data Protection Act 2018, Swiss FADP, Canada PIPEDA and Quebec Law 25, Australia Privacy Act, India DPDPA, and other national regimes
- US frameworks: HIPAA, NIST CSF, NIST 800-53, NIST 800-171, NIST AI RMF, NIST Privacy Framework, FedRAMP, CMMC, CIS Controls v8
- National and sector schemes: BSI IT-Grundschutz, Cyber Essentials (UK), CyberFundamentals (Belgium), BIO2 and NEN 7510 (Netherlands), Swiss ICT minimum standard, FINMA guidance, Indian sector rules (RBI, SEBI, IRDAI, CERT-In), and more
If a framework matters to your work and you do not see it reflected in answers, ask the assistant directly; it will tell you honestly whether dedicated knowledge is loaded for it.
When you mention a supported framework in your questions, ISMS Copilot automatically detects it and loads relevant knowledge before answering. This prevents hallucinations and ensures responses are grounded in actual framework requirements, not AI guessing.
How Framework Knowledge Injection Works
Dynamic framework knowledge injection dramatically reduces AI hallucinations:
- You ask a question mentioning a framework (e.g., "What is ISO 27001 control A.5.9?")
- The system detects the framework mention
- Verified framework knowledge is loaded and provided to the AI
- The AI responds based on provided facts, not memory or guessing
For best results, mention the specific framework and version in your questions. For example: "Generate an access control policy for ISO 27001:2022 Annex A control 5.15" instead of just "Generate an access control policy."
What You Can Do
For any supported framework, you can:
- Ask specific questions about controls, requirements, or implementation guidance
- Generate framework-aligned policies and procedures
- Perform gap analysis by uploading existing documentation
- Create risk assessments mapped to framework requirements
- Get audit preparation guidance
- Map controls between different frameworks
Related Resources
- FAQ - Common questions about framework support
- Understanding AI Hallucinations - How framework knowledge injection prevents errors
- Product Changelog (in-app) - New framework announcements