HomeKnowledge Hub › Standards & Frameworks

Knowledge Hub

Privacy standards & frameworks

The international standards and recognised frameworks most relevant to privacy governance, assurance and AI. Curated to the essentials and growing — with links to the authoritative source for each.

Privacy-specific standards & frameworks
ReferenceWhat it isSource
ISO/IEC 27701Privacy Information Management System (PIMS) — extends ISO 27001 to privacy. The leading certifiable privacy standard.iso.org
ISO/IEC 29100Privacy framework — terminology and principles for protecting PII.iso.org
NIST Privacy FrameworkVoluntary US framework for managing privacy risk; maps to the NIST CSF.nist.gov
BS 10012British Standard for a personal information management system, aligned to UK GDPR.bsigroup.com
Security & cloud standards
ReferenceWhat it isSource
ISO/IEC 27001Information Security Management System (ISMS) — the foundational certifiable security standard.iso.org
ISO/IEC 27002Information security controls — implementation guidance for 27001.iso.org
ISO/IEC 27018Code of practice for protecting PII in public clouds acting as processors.iso.org
SOC 2 (AICPA TSC)Trust Services Criteria — assurance reporting on security, availability, confidentiality & privacy.aicpa-cima.com
NIST SP 800-53Security & privacy controls for information systems and organisations.csrc.nist.gov
CSA CCM / STARCloud Security Alliance Cloud Controls Matrix and STAR assurance programme.cloudsecurityalliance.org
PCI DSSPayment Card Industry Data Security Standard for cardholder data.pcisecuritystandards.org
AI governance
ReferenceWhat it isSource
ISO/IEC 42001AI Management System (AIMS) — the first certifiable AI governance standard.iso.org
NIST AI RMFAI Risk Management Framework for trustworthy AI.nist.gov
EU AI ActRegulation (EU) 2024/1689 — risk-based regulation of AI systems.eur-lex.europa.eu
Risk, governance & resilience
ReferenceWhat it isSource
ISO 31000Risk management — principles and guidelines.iso.org
ISO 22301Business continuity management systems.iso.org
NIST CSF 2.0Cybersecurity Framework — govern, identify, protect, detect, respond, recover.nist.gov
COBITISACA framework for governance and management of enterprise IT.isaca.org
This directory is curated to the essentials and expanding. Suggest a standard we should add — get in touch.