Skip to content

Compliance Intelligence API

692 frameworks, 13,700+ controls, and 819,000+ cross-framework mappings. REST API and MCP server for AI agents.

Add to Claude Desktop, Cursor, or any MCP client:

{ "mcpServers": { "compliance": { "url": "https://api.theartofservice.com/mcp" } } }

Popular Framework APIs

All 693 Framework APIs

CSA CCM v4 · 171 controlsISO 22313:2020 — Guidance on Business Continuity Management Systems · 145 controlsISO 39001:2012 — Road Traffic Safety Management · 145 controlsISO 41001:2018 — Facility Management Systems · 145 controlsISO 50001:2018 — Energy Management Systems · 145 controlsISO 56002 · 138 controlsASD Information Security Manual (ISM) · 136 controlsISO 37002:2021 — Whistleblowing Management Systems · 136 controlsNIST Privacy Framework 1.0 · 100 controlsDefence Security Principles Framework (DSPF) · 92 controlsProtective Security Policy Framework (PSPF) Release 2024 · 91 controlsWCAG 2.2 · 86 controlsUK Telecommunications (Security) Act 2021 · 76 controlsConnecticut Data Privacy Act (CTDPA) · 72 controlsISO/IEC 17025:2017 — General Requirements for Testing and Calibration Laboratories · 65 controlsEAR — Export Administration Regulations · 64 controlsFedRAMP Rev 5 · 64 controlsISO 15189:2022 — Medical Laboratories Requirements for Quality and Competence · 64 controlsPCI DSS v4.0 · 63 controlsRhode Island Data Transparency and Privacy Protection Act (RIDTPPA) · 63 controlsEU Digital Markets Act · 61 controlsBank Secrecy Act / Anti-Money Laundering (BSA/AML) · 60 controlsThe Leadership Challenge (Kouzes & Posner) · 60 controlsColorado Privacy Act (CPA) · 59 controlsWCO Authorised Economic Operator (AEO) Framework · 59 controls21 CFR Part 211 — Current Good Manufacturing Practice · 57 controlsAS9100D — Aerospace Quality Management System · 57 controlsASD Essential Eight Maturity Model · 57 controlsFull Range Leadership Model (Bass & Avolio) · 57 controlsISO/IEC 27003:2017 · 57 controlsHeifetz Adaptive Leadership Framework · 56 controlsNIS2 Directive Implementing Acts · 56 controlsTennessee Information Protection Act (TIPA) · 56 controlsWisconsin Data Privacy Act (SB 670) · 55 controlsAustralia Consumer Data Right — Banking (CDR) · 50 controlsEIOPA Guidelines on ICT Security and Governance (2020) · 50 controlsFTC Health Breach Notification Rule · 50 controlsCFTC System Safeguards (17 CFR 37, 38, 39, 49) · 49 controlsNAIC Insurance Data Security Model Law (MDL-668) · 49 controlsFlorida Digital Bill of Rights (FDBR) · 48 controlsUK Modern Slavery Act 2015 · 48 controlsUS EPA Safe Drinking Water Act (SDWA) — Cybersecurity Requirements · 48 controlsSSAE 18 — Attestation Standards (SOC Reporting) · 47 controlsTISAX — Trusted Information Security Assessment Exchange · 47 controlsGLI-33 — Gaming Laboratories International Event Wagering Systems · 46 controlsAustralia eSafety Commissioner — Online Safety Expectations for Industry · 45 controlsBotswana Data Protection Act (2024) · 45 controlsFAA Cybersecurity Framework for Aviation · 45 controlsISO 26262:2018 — Functional Safety for Road Vehicles · 45 controlsMontenegro Law on Personal Data Protection (2023) · 45 controlsNorth Macedonia Law on Personal Data Protection (2020) · 45 controlsNotifiable Data Breaches Scheme (Australia) · 45 controlsParaguay Law on Protection of Personal Data (Law No. 6534/2020) · 45 controlsHungary Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Info Act) · 44 controlsPortugal Law No. 58/2019 — Data Protection Implementation Act · 44 controlseIDAS 2.0 — EU Digital Identity Regulation · 44 controlsAPRA CPS 230 Operational Risk Management · 43 controlsEU Machinery Regulation (Regulation (EU) 2023/1230) · 43 controlsNIST AI 600-1 Generative AI Profile · 43 controlsSouth Korea Personal Information Protection Act (PIPA) · 43 controlsCISA ICS-CERT Advisories and Industrial Control Systems Security Guidelines · 42 controlsIceland Data Protection and Processing of Personal Data Act (Act No. 90/2018) · 42 controlsAML/CTF Act 2006 (Australia) · 41 controlsEU Anti-Money Laundering Directive (AMLD6 / Directive 2018/1673) · 41 controlsEU NIS2 Directive — Energy Sector Cybersecurity Requirements (Directive 2022/2555) · 41 controlsEuropean Accessibility Act (Directive (EU) 2019/882) · 41 controlsOntario Accessibility for Ontarians with Disabilities Act (AODA) — IASR Web Standard · 41 controlsPhilippines Cybercrime Prevention Act (RA 10175) · 41 controlsUS Gramm-Leach-Bliley Act (GLBA) — Higher Education Safeguards Rule · 41 controlsUS ITAR and EAR — Export Control and Data Security · 41 controlsUS SEC Digital Assets and Crypto Regulatory Framework · 41 controlsWashington My Health My Data Act (MHMD) · 41 controlsCISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 · 40 controlsCOBIT 2019 · 40 controlsEU Taxonomy Regulation · 40 controlsFATF 40 Recommendations · 40 controlsJordan Draft Personal Data Protection Law (2022) · 40 controlsTNFD Recommendations · 40 controlsAASB S2 Climate-related Disclosures · 39 controlsASEAN Data Management Framework · 39 controlsAustralian Energy Sector Cyber Security Framework (AESCSF) · 39 controlsC-TPAT — Customs-Trade Partnership Against Terrorism · 39 controlsCook Islands Electronic Transactions Act & Privacy Provisions (2003) · 39 controlsEU General Product Safety Regulation (GPSR, Regulation 2023/988) · 39 controlsEU Maritime Single Window Environment Regulation (EU 2019/1239) and EMSA Cybersecurity · 39 controlsEU Markets in Crypto-Assets Regulation (MiCA) · 39 controlsModern Slavery Act 2018 (Australia) · 39 controlsNRF Cybersecurity and Data Privacy Framework (National Retail Federation) · 39 controlsTelecommunications Sector Security Reforms (TSSR) · 39 controlsAS9100D:2016 — Quality Management Systems for Aviation, Space, and Defence · 38 controlsCIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) · 38 controlsEU Deforestation-Free Products Regulation (EUDR) · 38 controlsEU Seveso III Directive (Directive 2012/18/EU) · 38 controlsISO/IEC 27006:2024 · 38 controlsLatvia Personal Data Processing Law (Fizisko personu datu apstrades likums, 2018) · 38 controlsMiFID II / MiFIR · 38 controlsRwanda Law No. 058/2021 Relating to the Protection of Personal Data · 38 controlsUK Product Security and Telecommunications Infrastructure Act (PSTI) · 38 controlsUruguay Personal Data Protection Act (Law No. 18.331) · 38 controlsASD Strategies to Mitigate Cyber Security Incidents · 37 controlsEU Network Code on Cybersecurity for the Electricity Sector · 37 controlsEU Taxonomy Regulation (Regulation 2020/852) · 37 controlsISO 30414:2018 — Human Resource Management: Guidelines for Internal and External Human Capital Reporting · 37 controlsNHS Healthcare Leadership Model · 37 controlsOWASP DevSecOps Maturity Model (DSOMM) · 37 controlsDO-178C / ED-12C — Software Considerations in Airborne Systems · 36 controlsEU European Media Freedom Act (EMFA) · 36 controlsEU NIS2 Directive — Transport Sector Requirements · 36 controlsFTC GLBA Safeguards Rule (16 CFR Part 314) · 36 controlsUK Data Protection Act 2018 · 36 controlsVietnam Law on Cybersecurity (No. 24/2018/QH14) · 36 controlsDigital Economy Partnership Agreement (DEPA) · 35 controlsEU Markets in Crypto-Assets Regulation (MiCA, Regulation 2023/1114) · 35 controlsFinland Data Protection Act (Tietosuojalaki, 1050/2018) · 35 controlsISO 26000:2010 · 35 controlsNIST SP 800-171A Rev 3 — Assessing CUI Security Requirements · 35 controlsNYDFS Cybersecurity Regulation (23 NYCRR Part 500) · 35 controlsPoland Act on Personal Data Protection (Ustawa o ochronie danych osobowych, 2018) · 35 controlsSouth Korea Korea Internet Self-Governance Organisation (KISO) Code of Ethics · 35 controlsUS Americans with Disabilities Act (ADA) — Title III Digital Accessibility · 35 controlsUS OFAC Sanctions Compliance Framework · 35 controlsBrunei Personal Data Protection Order 2024 (PDPO) · 34 controlsEU Digital Services Act — Minors Protection Provisions (Regulation 2022/2065) · 34 controlsEstonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019) · 34 controlsFDA Quality Management System Regulation (QMSR) · 34 controlsGAMP 5 — Good Automated Manufacturing Practice · 34 controlsLuxembourg Law of 1 August 2018 on Data Protection (GDPR Implementation) · 34 controlsCambodia Sub-Decree on Personal Data Protection (Sub-Decree No. 134) · 33 controlsECSS Software Engineering Standards (ESA) · 33 controlsEU Pay Transparency Directive (Directive 2023/970) · 33 controlsEthiopia Personal Data Protection Proclamation (No. 1321/2024) · 33 controlsFBI CJIS Security Policy · 33 controlsISO/IEC 23894:2023 · 33 controlsJapan Act on Specified Commercial Transactions (ASCT) — Digital Services · 33 controlsLaos Law on Prevention and Combating Cybercrime (2015) · 33 controlsLebanon Electronic Transactions and Personal Data Protection Law (Law No. 81/2018) · 33 controlsMalta Data Protection Act (Cap. 586, 2018) · 33 controlsNetherlands GDPR Implementation Act (UAVG — Uitvoeringswet AVG, 2018) · 33 controlsSingapore Government Instruction Manual on ICT&SS Management (IM8) · 33 controlsANSSI Cybersecurity Framework · 32 controlsBSI IT-Grundschutz · 32 controlsBelgium CyberFundamentals · 32 controlsCDP (formerly Carbon Disclosure Project) · 32 controlsCISA Zero Trust Maturity Model · 32 controlsCyber Essentials Plus · 32 controlsDFARS 252.204-7012 — Safeguarding Covered Defense Information · 32 controlsDISA Security Technical Implementation Guides (STIGs) · 32 controlsDoD Zero Trust Reference Architecture · 32 controlsEU Product Liability Directive (Directive (EU) 2024/2853) · 32 controlsFISMA · 32 controlsFTC Safeguards Rule (16 CFR Part 314) · 32 controlsGhana Cybersecurity Act · 32 controlsISO/IEC 29147:2018 · 32 controlsNIST SP 800-171 · 32 controlsNIST SP 800-171A — Assessing CUI Security Requirements · 32 controlsNIST SP 800-172 · 32 controlsNIST SP 800-53A · 32 controlsSaudi NCA ECC · 32 controlsSouth Korea Credit Information Act · 32 controlsSpain ENS · 32 controlsSpain Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD) · 32 controlsZambia Data Protection Act (2021) · 32 controls21 CFR Part 58 — Good Laboratory Practice (GLP) · 31 controls3GPP Security · 31 controlsAICPA Privacy Management Framework (PMF) · 31 controlsAngola Personal Data Protection Law (Law No. 22/11) · 31 controlsBREEAM — Building Research Establishment Environmental Assessment Method · 31 controlsBSIMM · 31 controlsCOSO Internal Control — Integrated Framework (2013) · 31 controlsCalifornia IoT Security Law · 31 controlsCosta Rica Personal Data Protection Law (Law No. 8968) · 31 controlsCôte d'Ivoire Law on Personal Data Protection (Law No. 2013-450) · 31 controlsETSI EN 303 645 · 31 controlsEU Cyber Resilience Act · 31 controlsEU Platform Work Directive (Directive 2024/2831) · 31 controlsILO Nursing Personnel Convention C149 (1977) · 31 controlsISO 27002:2022 · 31 controlsISO 27043 · 31 controlsISO/SAE 21434 · 31 controlsMITRE ATT&CK · 31 controlsMITRE D3FEND · 31 controlsNIST AI Risk Management Framework (AI RMF 1.0) · 31 controlsNIST SP 800-115 · 31 controlsNIST SP 800-123 · 31 controlsNIST SP 800-128 · 31 controlsNIST SP 800-137 · 31 controlsNIST SP 800-150 · 31 controlsNIST SP 800-160 · 31 controlsNIST SP 800-161 · 31 controlsNIST SP 800-181 · 31 controlsNIST SP 800-183 · 31 controlsNIST SP 800-187 · 31 controlsNIST SP 800-207 · 31 controlsNIST SP 800-218 · 31 controlsNIST SP 800-61 · 31 controlsNIST SP 800-63 · 31 controlsNIST SP 800-88 · 31 controlsNIST SP 800-92 · 31 controlsOWASP ASVS · 31 controlsOWASP MASVS · 31 controlsOWASP SAMM · 31 controlsOpenSSF Scorecard · 31 controlsPTES · 31 controlsSIG (Shared Assessments) · 31 controlsSLSA · 31 controlsSSDF (NIST) · 31 controlsSingapore Payment Services Act 2019 (PSA) — Digital Payment Token Provisions · 31 controlsUK PSTI Act · 31 controlsUNECE WP.29 R155 · 31 controlsUNECE WP.29 R156 · 31 controlsVoluntary Principles on Security and Human Rights (VPs) · 31 controlsAfrican Union Malabo Convention · 30 controlsCanada's Anti-Spam Legislation (CASL) · 30 controlsChina Personal Information Protection Law (PIPL) · 30 controlsEN 301 549 — ICT Accessibility Requirements · 30 controlsEU Digital Services Act · 30 controlsIEC 62304:2015 Medical Device Software Lifecycle Processes · 30 controlsKuwait Data Privacy Protection Regulation (KDPPR, 2021 — CMA Directive) · 30 controlsPakistan Personal Data Protection Bill 2023 · 30 controlsRussia Federal Law on Personal Data (152-FZ) · 30 controlsSQF Code Edition 9 — Safe Quality Food · 30 controlsSecurity of Critical Infrastructure Act 2018 (SOCI) · 30 controlsUK Online Safety Act 2023 · 30 controlsAPPI · 29 controlsArgentina PDPA · 29 controlsBahrain PDPL · 29 controlsBosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011) · 29 controlsCCPA/CPRA · 29 controlsCOPPA · 29 controlsChile DPL · 29 controlsChile Personal Data Protection Law (Law No. 21.719) · 29 controlsChina PIPL · 29 controlsColombia Habeas Data Law · 29 controlsColorado Privacy Act · 29 controlsConnecticut DPA · 29 controlsDelaware Personal Data Privacy Act · 29 controlsDominican Republic DPL · 29 controlsEN 301 549 v3.2.1 — Accessibility Requirements for ICT Products and Services · 29 controlsEcuador LOPDP · 29 controlsFERPA · 29 controlsICN Leadership for Change Programme · 29 controlsISO 27701 · 29 controlsIceland DPA · 29 controlsIndia DPDP Act · 29 controlsIndiana Consumer Data Protection Act · 29 controlsIndonesia PDP Law · 29 controlsIowa Consumer Data Protection Act · 29 controlsJamaica DPA · 29 controlsKentucky Consumer Data Protection Act · 29 controlsKenya DPA · 29 controlsLGPD · 29 controlsLiechtenstein DPA · 29 controlsMalaysia PDPA 2010 · 29 controlsMaryland Online Data Privacy Act · 29 controlsMauritius DPA · 29 controlsMexico LFPDPPP · 29 controlsMinnesota Consumer Data Privacy Act · 29 controlsMontana Consumer Data Privacy Act · 29 controlsNIST SP 800-122 · 29 controlsNebraska Data Privacy Act · 29 controlsNew Hampshire Privacy Act · 29 controlsNew Jersey Data Privacy Act · 29 controlsNew Zealand Privacy Act · 29 controlsNigeria NDPR · 29 controlsNorway PDPA · 29 controlsOregon Consumer Privacy Act · 29 controlsPDPA Singapore · 29 controlsPDPA Thailand · 29 controlsPIPEDA · 29 controlsPOPIA · 29 controlsPanama Law on Personal Data Protection (Law No. 81 of 2019) · 29 controlsPeru DPL · 29 controlsPhilippines DPA · 29 controlsPrivacy Act 1988 (Australia) · 29 controlsQatar DPL · 29 controlsRomania Law No. 190/2018 on Data Protection Measures (GDPR Implementation) · 29 controlsRwanda DPL · 29 controlsSaudi Arabia PDPL · 29 controlsSerbia Law on Personal Data Protection (2018) · 29 controlsSouth Korea PIPA · 29 controlsSwitzerland FADP · 29 controlsTaiwan PDPA · 29 controlsTennessee IPA · 29 controlsTexas Data Privacy Act · 29 controlsTurkey KVKK · 29 controlsUAE PDPL · 29 controlsUK Construction (Design and Management) Regulations 2015 (CDM 2015) · 29 controlsUK Gambling Commission — Cyber Resilience Requirements · 29 controlsUruguay DPL · 29 controlsUtah Consumer Privacy Act · 29 controlsVietnam PDPD · 29 controlsVirginia CDPA · 29 controls3GPP 5G Security Architecture (TS 33.501) · 28 controlsAlbania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014) · 28 controlsAutomotive SPICE (ASPICE) v4.0 — Process Assessment Model · 28 controlsBRCGS Global Standard for Food Safety Issue 9 · 28 controlsCayman Islands Data Protection Act 2017 (DPA) · 28 controlsCustoms-Trade Partnership Against Terrorism (C-TPAT) · 28 controlsEU Chips Act (Regulation (EU) 2023/1781) · 28 controlsEU Critical Raw Materials Act (Regulation (EU) 2024/1252) · 28 controlsFiji Data Protection Bill (2020) · 28 controlsGHG Protocol · 28 controlsGeorgia Law on Personal Data Protection (2012) · 28 controlsOECD/G20 Principles of Corporate Governance · 28 controlsOman Personal Data Protection Law (Royal Decree 6/2022) · 28 controlsSingapore Payment Services Act (PSA) — Digital Payment Token Regulation · 28 controlsSouth Korea Cloud Security Assurance Program (CSAP) · 28 controlsWCO SAFE Framework of Standards to Secure and Facilitate Global Trade (2021) · 28 controlsZimbabwe Data Protection Act (2021) · 28 controlsEU Digital Services Act — Online Gaming Platform Requirements · 27 controlsEU PSD3 and Payment Services Regulation (Proposed) · 27 controlsEgypt Personal Data Protection Law (Law No. 151 of 2020) · 27 controlsFFIEC Cybersecurity Assessment Tool (CAT) · 27 controlsGoleman Emotional Intelligence Leadership Framework · 27 controlsILO Tripartite Declaration of Principles concerning Multinational Enterprises (MNE Declaration) · 27 controlsISO/IEC 27011:2024 · 27 controlsITAR — International Traffic in Arms Regulations · 27 controlsPeru Personal Data Protection Law (Law No. 29733) · 27 controlsSSAE 18 SOC 1 — Report on Controls at a Service Organisation (ICFR) · 27 controlsUAE Virtual Asset Regulatory Authority (VARA) Regulations · 27 controlsUzbekistan Law on Personal Data (No. ZRU-547) · 27 controlsAustralia Online Safety Act 2021 · 26 controlsBasel III International Banking Framework · 26 controlsDenmark Data Protection Act (Databeskyttelsesloven, 2018) · 26 controlsEBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04) · 26 controlsEU SFDR (Sustainable Finance Disclosure Regulation) · 26 controlsExtractive Industries Transparency Initiative (EITI) Standard (2023) · 26 controlsIATA Operational Safety Audit (IOSA) Standards Manual · 26 controlsISO 37000:2021 — Governance of Organizations · 26 controlsISO/IEC 27014:2020 · 26 controlsJamaica Data Protection Act 2020 · 26 controlsMauritius Data Protection Act 2017 · 26 controlsOCC Heightened Standards (12 CFR Part 30, Appendix D) · 26 controlsQatar Personal Data Privacy Protection Law (Law No. 13 of 2016) · 26 controlsUK Security and Emergency Measures Direction (SEMD) — Water Industry · 26 controlsUganda Data Protection and Privacy Act (2019) · 26 controlsVermont Artificial Intelligence and Consumer Data Act (AICDA) · 26 controlsWELL Building Standard v2 (International WELL Building Institute) · 26 controlsAICPA SOC 1 · 25 controlsAICPA SOC 3 · 25 controlsAPRA CPS 234 · 25 controlsAWS Well-Architected Security Pillar · 25 controlsAWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) · 25 controlsAustralia AI Ethics Framework · 25 controlsAustralia NHMRC National Statement on Ethical Conduct in Human Research · 25 controlsAzure Security Benchmark · 25 controlsBCBS 239 · 25 controlsBrazil AI Framework · 25 controlsC5 (Germany) · 25 controlsCAIQ (CSA) · 25 controlsCDP Corporate Questionnaire · 25 controlsCWE Top 25 Most Dangerous Software Weaknesses (2024) · 25 controlsChina AI Regulations · 25 controlsConsumer Data Right (CDR) Framework (Australia) · 25 controlsDORA · 25 controlsECB TIBER-EU · 25 controlsESA ECSS-E-ST-40C — Space Software Engineering Standard · 25 controlsESRB Privacy Certified Programme · 25 controlsEU European Health Data Space (EHDS) · 25 controlsFFIEC IT Examination Handbook · 25 controlsGLBA · 25 controlsHKMA SPM · 25 controlsIATF 16949:2016 — Quality Management System for Automotive Production · 25 controlsIEEE 7000 · 25 controlsISMAP (Japan) · 25 controlsISO 27017 · 25 controlsISO 27018 · 25 controlsISO 8000 — Data Quality · 25 controlsISO/IEC 27010:2015 · 25 controlsItaly Personal Data Protection Code (Legislative Decree No. 196/2003, amended 2018) · 25 controlsJapan AI Guidelines · 25 controlsMAS TRM · 25 controlsMTCS (Singapore) · 25 controlsNIST SP 800-144 · 25 controlsNIST SP 800-145 · 25 controlsNIST SP 800-146 · 25 controlsNIST SP 800-190 · 25 controlsNRC 10 CFR 73.54 — Nuclear Facility Cybersecurity · 25 controlsOECD AI Principles · 25 controlsOSFI B-13 · 25 controlsOpen Banking Security · 25 controlsPCI P2PE · 25 controlsPCI SSF · 25 controlsPSD2 SCA · 25 controlsSASB Standards (ISSB Integrated) · 25 controlsSWIFT CSCF · 25 controlsSWIFT CSP · 25 controlsSingapore AI Governance Framework · 25 controlsSingapore Protection from Online Falsehoods and Manipulation Act (POFMA, 2019) · 25 controlsTanzania Personal Data Protection Act (Draft) · 25 controlsUK AI Regulation Framework · 25 controlsUK Bribery Act 2010 · 25 controlsUNESCO Recommendation on the Ethics of AI · 25 controlsAPEC Cross-Border Privacy Rules (CBPR) System · 24 controlsAPI 1164 · 24 controlsBIMCO Cyber Security · 24 controlsBrazil Open Finance (Resolução Conjunta No. 1/2020) · 24 controlsC2M2 · 24 controlsCanada Artificial Intelligence and Data Act (AIDA) · 24 controlsCanada ITSG-33 — IT Security Risk Management · 24 controlsCzech Republic Act on Personal Data Processing (Act No. 110/2019 Sb.) · 24 controlsDO-326A · 24 controlsEDM Council DCAM — Data Management Capability Assessment Model · 24 controlsFCC Customer Proprietary Network Information (CPNI) and Data Breach Rules (47 CFR 64.2001-2011) · 24 controlsFDA 21 CFR Part 11 · 24 controlsHKMA Cyber Resilience Assessment Framework (C-RAF) · 24 controlsIAIS Insurance Core Principles (ICPs) · 24 controlsIEC 62443 · 24 controlsIEEE 1686 · 24 controlsISO 13485 · 24 controlsISO 27019 · 24 controlsISO 27799 · 24 controlsISO/IEC 27004:2016 · 24 controlsISO/IEC 27400:2022 · 24 controlsISO/IEC 38500:2024 — Governance of IT · 24 controlsIllinois Biometric Information Privacy Act (BIPA) · 24 controlsKenya Data Protection Act 2019 · 24 controlsMARS-E · 24 controlsMDS2 (Medical Device) · 24 controlsNIST SP 1800-32 · 24 controlsNIST SP 800-66 · 24 controlsNevada Gaming Control Board Cybersecurity Requirements · 24 controlsNew Zealand Information Security Manual (NZISM) · 24 controlsPAS 1192-5:2015 — Security-Minded Approach to BIM and Digital Built Environments · 24 controlsSenegal Law on Personal Data Protection (Law No. 2008-12) · 24 controlsSenge Fifth Discipline — Learning Organization · 24 controlsTSA Pipeline Security · 24 controlsTunisia Organic Law on Personal Data Protection (Law No. 2004-63) · 24 controlsTurkey Personal Data Protection Law (KVKK — Law No. 6698) · 24 controlsUK Building Safety Act 2022 · 24 controlsUK GDPR (UK General Data Protection Regulation) · 24 controlsUS Executive Order 14028 — Improving the Nation's Cybersecurity · 24 controlsWHO Global Competency Model · 24 controlsArmenia Law on Protection of Personal Data (2015) · 23 controlsBarbados Data Protection Act 2019 · 23 controlsChina Cybersecurity Law (CSL) · 23 controlsEU Better Internet for Kids (BIK+) Strategy · 23 controlsEU GMP Annex 11 — Computerised Systems · 23 controlsEU In Vitro Diagnostic Medical Devices Regulation (IVDR) · 23 controlsGreece Law 4624/2019 — Hellenic Data Protection Authority (HDPA) Implementation Act · 23 controlsICAO Annex 17 — Aviation Security (AVSEC) · 23 controlsISO 9001 · 23 controlsISO/IEC 29134:2023 · 23 controlsLithuania Law on Legal Protection of Personal Data (2018) · 23 controlsMorocco Data Protection Law (09-08) · 23 controlsNIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205) · 23 controlsSASB Standards · 23 controlsSolvency II · 23 controlsTEFCA — Trusted Exchange Framework and Common Agreement · 23 controlsTrinidad and Tobago Data Protection Act 2011 · 23 controlsUK ONR Cyber Security and Information Assurance (CSIA) for Nuclear Facilities · 23 controlsUNICEF Policy Guidance on AI for Children (2021) · 23 controlsWHO Global Strategy on Digital Health 2020-2025 · 23 controls3GPP Security Architecture (TS 33.501 — 5G Security) · 22 controlsASIC Cyber Resilience Good Practices · 22 controlsASIS SPC.1-2009 — Organizational Resilience Standard · 22 controlsAged Care Quality Standards (Australia) · 22 controlsAustralia My Health Records Act 2012 · 22 controlsEU AI Liability Directive · 22 controlsEU Cyber Solidarity Act (Regulation (EU) 2025/38) · 22 controlsEU ePrivacy Directive (2002/58/EC) · 22 controlsFATF Recommendation 16 — Virtual Asset Travel Rule · 22 controlsFIDO2 and W3C WebAuthn Standard · 22 controlsGhana Data Protection Act 2012 (Act 843) · 22 controlsIACS Unified Requirements E26/E27 — Cyber Resilience of Ships and On-Board Systems · 22 controlsIAEA Nuclear Security Series — Computer Security at Nuclear Facilities (NSS-17-T Rev 1) · 22 controlsICH E6(R2) Good Clinical Practice — Data Integrity and Electronic Systems · 22 controlsIFRS 17 — Insurance Contracts · 22 controlsISO 14064 — Greenhouse Gas Accounting and Verification (Parts 1-3) · 22 controlsISO/IEC 23837 — Security Requirements for Quantum Key Distribution · 22 controlsISO/IEC 27031:2011 · 22 controlsISO/IEC 27557:2022 — Organisational Privacy Risk Management · 22 controlsISO/IEC 30111:2019 · 22 controlsIndia CERT-In Cyber Security Directions 2022 · 22 controlsPCI PIN Security · 22 controlsScience Based Targets initiative (SBTi) Corporate Standard · 22 controlsCCSDS 350.0-G-3 — Space Communications Security (Consultative Committee for Space Data Systems) · 21 controlsCISA Secure by Design Principles · 21 controlsColombia Data Protection Law (Law 1581 of 2012 — SIC Oversight) · 21 controlsDAMA-DMBOK2 — Data Management Body of Knowledge (2nd Edition) · 21 controlsEU Audiovisual Media Services Directive (AVMSD, Directive 2018/1808) · 21 controlsEU Carbon Border Adjustment Mechanism (CBAM) · 21 controlsISO 19650 — Organisation and Digitisation of Information about Buildings and Civil Engineering Works (BIM) · 21 controlsISO 28001:2007 Supply Chain Security Management · 21 controlsISO 37000:2021 · 21 controlsISO/IEC 29115:2023 — Entity Authentication Assurance Framework · 21 controlsKazakhstan Law on Personal Data and Their Protection (No. 94-V) · 21 controlsMARS-E — Minimum Acceptable Risk Standards for Exchanges · 21 controlsMyanmar Cybersecurity Law (2023) · 21 controlsNIST SP 800-82 Rev 3 — Guide to OT Security · 21 controlsNigeria Data Protection Act 2023 (NDPA) · 21 controlsOECD Guidelines for Multinational Enterprises on Responsible Business Conduct (2023 Update) · 21 controlsOnline Safety Act 2021 (Australia) · 21 controlsScience Based Targets Initiative (SBTi) — Net-Zero Standard · 21 controlsUK Defence Standard 05-138 — Cyber Security for Defence Suppliers · 21 controlsUK Open Banking Standard · 21 controlsUS Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements · 21 controlsUS NRC 10 CFR 73.54 — Cyber Security for Nuclear Power Plants · 21 controlsUkraine Law on Personal Data Protection (Law No. 2297-VI) · 21 controlsCNCF Cloud Native Security (Cloud Native Computing Foundation) · 20 controlsCOSO ERM · 20 controlsCOSO Enterprise Risk Management (ERM) Framework (2017) · 20 controlsColorado AI Act (SB 24-205) · 20 controlsEU Data Act · 20 controlsEU Medical Devices Regulation (MDR 2017/745) · 20 controlsEU Taxonomy for Sustainable Activities (Regulation 2020/852) · 20 controlsEU Union Customs Code (UCC) — Data Protection and Security Provisions (Regulation 952/2013) · 20 controlsFlorida Digital Bill of Rights (SB 262) · 20 controlsHITECH Act · 20 controlsIEC 60601-1 — Medical Electrical Equipment Safety · 20 controlsISO 22301 · 20 controlsISO 22316 · 20 controlsISO 22317 · 20 controlsISO 22318 · 20 controlsISO 22320:2018 · 20 controlsISO 27005 · 20 controlsISO 31000 · 20 controlsISO/IEC 29100:2024 · 20 controlsLEADS in a Caring Environment · 20 controlsLEED v4.1 — Green Building Rating System (US Green Building Council) · 20 controlsNATO AQAP 2110 — Quality Assurance Requirements for Design, Development, and Production · 20 controlsNIST SP 800-30 · 20 controlsNIST SP 800-37 · 20 controlsNIST SP 800-39 · 20 controlsPCAOB AS 2201 — Audit of Internal Control Over Financial Reporting (ICFR) · 20 controlsPrivacy and Other Legislation Amendment Act 2024 (Australia) · 20 controlsRBI Cybersecurity Framework for Banks · 20 controlsSouth Korea ISMS-P · 20 controlsSpace ISAC (Information Sharing and Analysis Center) — Threat Framework · 20 controlsTonga Communications Act (2015) — Privacy & Data Protection · 20 controlsUK FCA/PRA Operational Resilience Framework · 20 controlsUN Guiding Principles on Business and Human Rights (UNGPs) · 20 controlsUS Automated Commercial Environment (ACE) — CBP Trade Data Requirements · 20 controlsUS Children's Online Privacy Protection Act (COPPA) and COPPA 2.0 Proposed Updates · 20 controlsUS Consumer Product Safety Commission (CPSC) — Connected Product Safety · 20 controlsUS Foreign Corrupt Practices Act (FCPA) · 20 controlsUS Section 508 — ICT Accessibility Standards (Revised 2017) · 20 controlsAPRA Prudential Standard CPS 234 — Information Security (Australia) · 19 controlsBS 65000:2014 — Guidance on Organizational Resilience · 19 controlsCroatia Act on Implementation of the GDPR (Official Gazette 42/2018) · 19 controlsDefence Industry Security Program (DISP) · 19 controlsEU Energy Performance of Buildings Directive (EPBD Recast, Directive 2024/1275) · 19 controlsISO 20000-1 · 19 controlsISO 20400:2017 — Sustainable Procurement · 19 controlsISO 22739:2024 — Blockchain and Distributed Ledger Technologies Vocabulary · 19 controlsISO 37301 · 19 controlsISO/IEC 27007:2020 · 19 controlsITIL 4 · 19 controlsJapan FSA Cybersecurity Guidelines for Financial Institutions · 19 controlsPrivacy by Design (PbD) — Seven Foundational Principles · 19 controlsSA8000:2014 — Social Accountability Standard · 19 controlsSANS Incident Handler's Handbook and PICERL Methodology · 19 controlsSwitzerland New Federal Act on Data Protection (nFADP/nDSG, 2023) · 19 controlsAuthorised Economic Operator (AEO) Programmes — Global Standards · 18 controlsBermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct · 18 controlsChina Data Security Law (DSL) · 18 controlsEASA Part-IS — Information Security in Aviation · 18 controlsEN 50126/50128/50129 — Railway RAMS and Safety · 18 controlsEU Code of Conduct for Research Data Management (GDPR Article 40) · 18 controlsEU Web Accessibility Directive (Directive 2016/2102) · 18 controlsGlobal Cross-Border Privacy Rules (Global CBPR) Forum · 18 controlsISO 19011 · 18 controlsISO 30401 · 18 controlsISO 37001 · 18 controlsISO 55001 · 18 controlsISO/IEC 25012:2008 — Data Quality Model · 18 controlsNIST Privacy Framework Version 1.0 · 18 controlsRFC 2350 — Expectations for Computer Security Incident Response (BCP 21) · 18 controlsSection 508 — ICT Accessibility (Revised) · 18 controlsSouth Africa Promotion of Access to Information Act (PAIA) · 18 controlsUK Age Appropriate Design Code (Children's Code) · 18 controlsUNCITRAL Model Law on Electronic Commerce (1996, updated 2005) · 18 controlsUSMCA Chapter 19 — Digital Trade (United States-Mexico-Canada Agreement) · 18 controlsW3C Verifiable Credentials (VC) Data Model 2.0 · 18 controlsASEAN Guide on AI Governance and Ethics · 17 controlsECB TIBER-EU Framework · 17 controlsEU Clinical Trials Regulation (CTR 536/2014) · 17 controlsEU Data Governance Act (DGA) · 17 controlsFIRST CSIRT Services Framework and Standards · 17 controlsICH E6(R3) — Good Clinical Practice · 17 controlsISO/IEC 27050 — Electronic Discovery (Parts 1-4) · 17 controlsISPE GAMP 5 — A Risk-Based Approach to Compliant GxP Computerised Systems · 17 controlsMaslach Burnout Prevention Model · 17 controlsNFPA 1600 — Standard on Continuity, Emergency, and Crisis Management · 17 controlsNIST SP 800-34 Rev 1 — Contingency Planning Guide · 17 controlsOman National Cybersecurity Framework · 17 controlsPIC/S Guide to Good Manufacturing Practice for Medicinal Products · 17 controlsTSA Pipeline Cybersecurity Directives · 17 controlsAPRA SPS 220 Risk Management (Superannuation) · 16 controlsEU Whistleblower Protection Directive (2019/1937) · 16 controlsFSSC 22000 — Food Safety System Certification · 16 controlsGLOBALG.A.P. Integrated Farm Assurance (IFA) Standard v6 · 16 controlsICC Incoterms 2020 — International Commercial Terms · 16 controlsKids Online Safety Act (KOSA) · 16 controlsKuwait National Cybersecurity Framework · 16 controlsLloyd's Minimum Standards — Cyber Security · 16 controlsOWASP Top 10:2025 · 16 controlsPEGI — Pan European Game Information Age Rating System · 16 controlsPapua New Guinea National Cybersecurity Policy & Cybercrime Act (2016) · 16 controlsSOC for Cybersecurity — Cybersecurity Risk Management Examination · 16 controlsSingapore Model AI Governance Framework (2nd Edition) · 16 controlsSri Lanka Personal Data Protection Act (No. 9 of 2022) · 16 controlsSweden Data Protection Act (Dataskyddslag, 2018:218) · 16 controlsAzerbaijan Law on Personal Data (2010) · 15 controlsCSA STAR (Security, Trust, Assurance, and Risk) · 15 controlsCritical Infrastructure Risk Management Program (CIRMP) Rules 2023 · 15 controlsEMV 3-D Secure (3DS2) — Payment Authentication Protocol · 15 controlsENISA Privacy Enhancing Technologies (PETs) Guidance · 15 controlsICH Q10 — Pharmaceutical Quality System · 15 controlsIRM Enterprise Risk Management Framework (Institute of Risk Management) · 15 controlsISO 22000 · 15 controlsISO 45001 · 15 controlsNABERS — National Australian Built Environment Rating System · 15 controlsNIST SP 800-124 Rev 2 — Mobile Device Security · 15 controlsSWIFT Customer Security Programme (CSP) · 15 controlsSingapore Cybersecurity Act 2018 · 15 controlsUK Concordat on Open Research Data (UKRI) · 15 controlsAustria Data Protection Act (Datenschutzgesetz, DSG, amended 2018) · 14 controlsBelgium Data Protection Act (Wet van 30 juli 2018, Loi du 30 juillet 2018) · 14 controlsCSRD · 14 controlsCyber Security Act 2024 (Australia) · 14 controlsEDM Council CDMC — Cloud Data Management Capabilities Framework · 14 controlsGRI Standards · 14 controlsIEC 62351 — Power Systems Communication Security · 14 controlsISO 14001 · 14 controlsISSB Standards · 14 controlsITU-T X.805 — Security Architecture for End-to-End Communications · 14 controlsIsrael Protection of Privacy Law (5741-1981) · 14 controlsNigeria Open Banking Regulatory Framework (CBN, 2023) · 14 controlsOECD AI Principles (2024 Update) · 14 controlsPropTech Security Standards — Smart Building Cybersecurity · 14 controlsRegional Comprehensive Economic Partnership (RCEP) — E-Commerce Chapter · 14 controlsResponsible Minerals Initiative (RMI) — Responsible Minerals Assurance Process · 14 controlsSEC Cybersecurity Disclosure Rules · 14 controlsTCFD Recommendations · 14 controlsAustralian Privacy Principles (APPs) · 13 controlsBermuda Personal Information Protection Act 2016 (PIPA) · 13 controlsEquator Principles (EP4, 2020) · 13 controlsGerman Supply Chain Due Diligence Act (LkSG) · 13 controlsHL7 FHIR Security Framework · 13 controlsISAE 3402 — Assurance Reports on Controls at a Service Organisation · 13 controlsNATO Cyber Defence Standards and NCIRC (NATO Computer Incident Response Capability) · 13 controlsNERC CIP · 13 controlsO-RAN Alliance Security Specifications (O-RAN.WG11) · 13 controlsPhilippines Data Privacy Act (RA 10173) · 13 controlsSigstore — Software Artifact Signing and Verification · 13 controlsStudent Privacy Pledge 2020 · 13 controlsArgyris Double-Loop Learning · 12 controlsAustralia IRAP — Information Security Registered Assessors Program · 12 controlsGS1 Global Standards — Supply Chain Traceability and Data Security · 12 controlsIMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.2) · 12 controlsIRS Publication 1075 — Tax Information Security Guidelines · 12 controlsITU Radio Regulations and Space Security Standards · 12 controlsIndia Account Aggregator Framework (RBI) · 12 controlsRICS Professional Standards — Data and Technology in Property · 12 controlsRight to Disconnect (Australia) · 12 controlsVUCA Leadership Framework · 12 controlsVirginia Consumer Data Protection Act (VCDPA) · 12 controlsETSI QKD Standards — Quantum Key Distribution (ETSI ISG QKD) · 11 controlsFIDO2 / WebAuthn — Passwordless Authentication Standard · 11 controlsFrench Sapin II Law (Law No. 2016-1691) · 11 controlsHersey & Blanchard Situational Leadership Model · 11 controlsNATO STANAG 4774/4778 — Confidentiality Metadata Labels · 11 controlsNSA CNSA Suite 2.0 — Commercial National Security Algorithm Suite · 11 controlsOwn Risk and Solvency Assessment (ORSA) — NAIC Model Act · 11 controlsSEC Climate Disclosure Rule · 11 controlsICMM Mining Principles (2024 Update) · 10 controlsILO Declaration on Fundamental Principles and Rights at Work (Core Conventions) · 10 controlsLloyd's of London Cyber Insurance Requirements and Underwriting Standards · 10 controlsOWASP API Security Top 10:2023 · 10 controlsOWASP Top 10 for LLM Applications 2025 · 10 controlsEthical Trading Initiative (ETI) Base Code · 9 controlsFair Labor Association (FLA) Workplace Code of Conduct · 9 controlsNSA Quantum-Resistant (QR) Cryptography Migration Guidance · 9 controlsAPRA CPS 220 Risk Management · 8 controlsBSI C5 — Cloud Computing Compliance Criteria Catalogue · 8 controlsKolb Experiential Learning Cycle · 8 controlsKotter 8-Step Change Model · 8 controlsMTCS — Multi-Tier Cloud Security (Singapore) · 4 controlsSamoa Telecommunications Act (2005) — Privacy & Data Protection · 4 controlsHong Kong Personal Data (Privacy) Ordinance (PDPO, Cap 486) · 3 controlsSarbanes-Oxley Act (SOX)

Frequently Asked Questions

What is the Compliance Intelligence API?
A REST and MCP API providing programmatic access to 692 compliance frameworks, 13,700+ controls, and 819,000+ cross-framework control mappings. Query framework details, map controls between standards, run gap analyses, and get coverage reports.
Is there a free tier?
Yes. Anonymous access gives you 10 API calls per day with no signup required. Free accounts get 100 calls/month with an API key. Professional plans start at $49/month with 10,000 calls included.
Does it work with AI agents?
Yes. The API is available as an MCP (Model Context Protocol) server at api.theartofservice.com/mcp. Add it to Claude Desktop, Cursor, Windsurf, or any MCP client. AI agents can query compliance data directly.
What frameworks are available?
692 frameworks including ISO 27001, SOC 2, NIST CSF, GDPR, HIPAA, PCI DSS, CMMC, NIS2, DORA, EU AI Act, and hundreds more. Each framework includes controls, domains, and cross-framework mappings.

Start building with the Compliance API

No signup required for 10 free API calls per day. Create a free account for 100 calls/month.