SIS-licensed ISO clauses and controls·an add-on inside the AI clients and agents you already use
    coverage

    Does Ansvar cover what you need?

    Choose a place, a topic, or both. See the published source match and what the index cannot confirm.

    Check Ansvar coverage

    Try an example

    Your coverage answer

    Choose a place, a topic, or both. Ansvar will show the published match and any gap.

    The result combines coverage.json, generated 2026-09-08, with the reviewed website sector catalogue. It confirms published source records and leaves legal applicability unresolved. The checker reports missing relationships as gaps.

    Browse all live jurisdictionsCountry pages, source layers, and corpus size52
    JurisdictionPublished source layersLawsProvisionsCheck coverage
    AlbaniaALStatute law8,749104,288
    ArmeniaAMStatute law6,416223,942
    AustriaATStatute law · Case law · Data protection+ EU21,596415,046
    BahrainBHStatute law58014,506
    BelgiumBEStatute law · Case law · Data protection+ EU5,694117,983
    BrazilBRStatute law4,42954,862
    BulgariaBGStatute law · Data protection+ EU2,03017,568
    CanadaCAStatute law15,650389,485
    ChinaCNStatute law1,30165,933
    Costa RicaCRStatute law16,724120,455
    CroatiaHRStatute law · Data protection+ EU4,563158,765
    CzechiaCZStatute law · Case law · Data protection+ EU45,990748,779
    DenmarkDKStatute law · Data protection+ EU26,689631,836
    DjiboutiDJStatute law2,72828,473
    EstoniaEEStatute law · Case law · Data protection+ EU1,60063,989
    FinlandFIStatute law · Case law · Data protection · +1+ EU8,586153,199
    FranceFRStatute law+ EU117,615674,034
    GeorgiaGEStatute law29,747235,491
    GermanyDEStatute law · Case law · Data protection · +1+ EU5,957106,483
    GuatemalaGTStatute law85,539
    HaitiHTStatute law113,811
    HungaryHUStatute law · Data protection+ EU4,312130,568
    IcelandISStatute law · Data protection1,71019,036
    ItalyITStatute law · Data protection+ EU66,439239,043
    JapanJPStatute law9,522249,637
    KosovoXKStatute law1,03931,409
    LatviaLVStatute law · Case law · Data protection+ EU2,27358,987
    LiechtensteinLIStatute law · Data protection3,65090,992
    LithuaniaLTStatute law · Case law · Data protection+ EU12,04789,810
    LuxembourgLUStatute law+ EU5,07248,478
    MaltaMTStatute law+ EU5,00956,516
    NetherlandsNLStatute law · Case law · Data protection · +1+ EU4,37590,608
    NorwayNOStatute law · Data protection75728,640
    ParaguayPYStatute law7,07338,822
    PeruPEStatute law2,13113,857
    PolandPLStatute law · Case law · Data protection+ EU80975,428
    PortugalPTStatute law · Data protection+ EU1,12381,267
    QatarQAStatute law9,42871,155
    RomaniaROStatute law · Data protection+ EU11,975112,545
    San MarinoSMStatute law10,99293,815
    SerbiaRSStatute law82247,041
    SlovakiaSKStatute law · Data protection+ EU23,711223,065
    SloveniaSIStatute law · Case law · Data protection+ EU4011,878
    South KoreaKRStatute law6,494214,578
    SpainESStatute law · Data protection+ EU9,407317,394
    SwedenSEStatute law · Case law · Data protection · +1+ EU8,883207,646
    TaiwanTWStatute law11,746221,082
    Trinidad & TobagoTTStatute law53164,435
    UkraineUAStatute law8,16550,710
    United KingdomGBStatute law · Data protection · Cybersecurity2,735563,128
    United StatesUSStatute law · Data protection · Cybersecurity · +110,231384,514
    UruguayUYStatute law4,76837,131

    Screening a DPIA? The European DPIA trigger-source register records the national Article 35(4) source for each jurisdiction, the legal status the authority gave it, and whether the deployed workflow queries it.

    Coverage by sector

    What we cover for each sector — regulations and standards a live, source-licensed corpus serves today. Standards are surfaced as requirement mapping, not reproduced text. Premium adds case law and agency guidance.

    IT & cloud security

    AppSec, infrastructure security, and product-security obligations.

    • ·Cyber Resilience Act (Reg (EU) 2024/2847)
    • ·NIS2 (Dir (EU) 2022/2555)
    • ·GDPR Art. 32 — security of processing
    • ·US federal cybersecurity regulation
    • ·NIST SP 800-53r5 · CSF 2.0 · SSDF 800-218 · AI RMF — served as full text
    • ·Control mapping: OWASP ASVS · ISO 27001 Annex A · CIS
    • ·Control mapping: BSI IT-Grundschutz · C5 · Technische Richtlinien · KRITIS · Mindeststandards
    • ·MITRE ATT&CK · CAPEC · CWE · D3FEND
    • ·ENISA Threat Landscape
    • ·Software supply-chain security · cryptographic algorithm guidance · premium
    • ·CVE · CISA KEV · EPSS — live vulnerability context
    Explore Security

    AI governance

    EU AI Act role classification, obligations, and conformity readiness.

    • ·EU AI Act (Reg (EU) 2024/1689)
    • ·Risk classification — prohibited practices (Art. 5), high-risk (Art. 6 + Annex III)
    • ·Role duties — provider (Art. 16), deployer (Art. 26), FRIA (Art. 27), conformity (Art. 43)
    • ·GPAI & systemic-risk model provisions (Art. 51–55)
    • ·GDPR intersection — automated decisions (Art. 22), DPIA trigger (Art. 35)
    • ·EU AI Office guidance · premium
    • ·NIST AI Risk Management Framework (AI 100-1) + Generative AI Profile — served as full text
    • ·ISO/IEC 42001 — AI management systems
    Explore AI governance

    Privacy & data protection

    DPIA, privacy-by-design, transfers, and data-subject rights — grounded in GDPR.

    • ·GDPR (Reg (EU) 2016/679)
    • ·ePrivacy Directive (2002/58/EC)
    • ·Law Enforcement Directive (EU) 2016/680
    • ·GDPR Art. 22 — automated individual decision-making
    • ·National GDPR-implementation statutes
    • ·US state comprehensive privacy statutes — 18 states
    • ·US federal privacy and data-security regulation
    • ·Canadian provincial law — Ontario and British Columbia
    • ·LINDDUN privacy threat & design-pattern library
    • ·Case-law fan-out where licensing permits · premium
    Explore Privacy

    Public sector

    Procurement lawfulness, public-body AI duties, and administration compliance.

    • ·National public-procurement law
    • ·Procurement case law & preparatory works · premium
    • ·US federal procurement — the Federal Acquisition Regulation (48 CFR)
    • ·US federal public-administration regulation
    • ·Dutch government security baseline — BIO2 v1.3
    • ·Dutch public-body statute — building code, civil protection and law enforcement
    • ·EU AI Act Art. 27 — public-body FRIA duty
    • ·GDPR Art. 35 — public-body DPIA basis
    • ·NIS2 (Dir (EU) 2022/2555) Art. 21 — public-administration security
    Explore Public sector

    Financial services

    DORA, MiCA, PSD2 and the prudential stack — at article level, with the technical standards.

    • ·DORA (Reg (EU) 2022/2554)
    • ·DORA RTS/ITS — 11 technical-standard instruments
    • ·MiCA (Reg (EU) 2023/1114) + RTS/ITS
    • ·PSD2 (Dir (EU) 2015/2366)
    • ·MiFID II / MiFIR · CRR/CRD · Solvency II · EMIR
    • ·National financial rulebooks — EU-27, EFTA and the UK
    • ·European Central Bank — legal acts, opinions and Banking Supervision material
    • ·EIOPA insurance and Solvency II material
    • ·US federal financial regulation — 12 CFR banking · 17 CFR SEC
    • ·US agency guidance — SEC cyber-disclosure interpretations · FTC data-security guidance · premium
    • ·Horizontal: GDPR · NIS2 · EU AI Act · eIDAS2
    • ·NIST SP 800-53r5 — served as full text
    • ·Control mapping: ISO 27001 Annex A
    • ·Case law · agency guidance · preparatory works · premium
    Explore Financial

    Automotive

    Vehicle type-approval, cybersecurity engineering, and TARA evidence.

    • ·UN R155 (cybersecurity) · UN R156 (software update)
    • ·EU vehicle type-approval & safety
    • ·EU automotive emissions & environment
    • ·EU L-category and agricultural / forestry tractor type-approval
    • ·EU automotive in-service & road use · circularity & materials
    • ·UN ECE vehicle regulations
    • ·In-vehicle data access for connected vehicles
    • ·Repair & maintenance information access — RMI / SERMI
    • ·Control mapping: ISO/SAE 21434
    • ·Control mapping: automotive engineering & diagnostics stack
    • ·Chinese national law
    • ·Horizontal: Cyber Resilience Act · GDPR (connected-vehicle data)
    Explore Automotive

    Drone & UAS

    Drone operations, product security, threat modelling, and counter-UAS.

    • ·EU drone law — Reg (EU) 2019/947 (operations) · 2019/945 (product)
    • ·UAS threat library
    • ·SORA determination chain — Reg (EU) 2019/947 Art. 11
    • ·Control mapping: UAS standards stack
    • ·National UAS rulebooks — BE, DE, ES, GB, HU, IS, LT, LU, LV, NL and SE
    • ·US federal aviation regulation (FAA) + 14 CFR Part 107
    • ·Horizontal: Cyber Resilience Act · RED · GPSR
    Explore Drone / UAS

    Agriculture & machinery

    Autonomous-machinery safety and the AI duties that ride on top.

    • ·Machinery Regulation (EU) 2023/1230
    • ·EU AI Act — high-risk safety-component duties (Reg (EU) 2024/1689)
    • ·Control mapping: agri-machinery safety stack (ISO 4254 · ISOBUS 11783 · ISO 25119 · IEC 62061 · EN 690)
    • ·Control mapping: functional safety & autonomous-machine stack (ISO 12100 · ISO 13849 · ISO 18497 · ISO 3691-4 · ISO 10218)
    • ·Farm-data governance — EU Data Act (Reg (EU) 2023/2854)
    • ·EUDR (Reg (EU) 2023/1115) — deforestation-free supply-chain duties
    • ·US federal agriculture & food regulation (USDA)
    • ·EU machinery harmonised-standards index
    • ·Horizontal: Cyber Resilience Act · GDPR
    Explore Agri & machinery

    Healthcare & medical devices

    Medical-device regulation, clinical data, and special-category privacy.

    • ·Medical Device Regulation (Reg (EU) 2017/745)
    • ·In Vitro Diagnostic Regulation (Reg (EU) 2017/746)
    • ·Clinical Trials Regulation (Reg (EU) 536/2014)
    • ·European Health Data Space (Reg (EU) 2025/327)
    • ·GDPR Art. 9 — special-category health data (+ full GDPR)
    • ·US federal health regulation — FDA (21 CFR) and CMS (42 CFR)
    • ·National medical-device regulation outside the EU — GB, CA, CH, KR, JP, AU, CO
    • ·Control mapping: medical-device software, safety and security standards
    • ·Horizontal: NIS2 · EU AI Act (software as a medical device) · CRA
    • ·MDCG medical-device guidance · premium
    • ·US FDA guidance documents · premium
    • ·Dutch statutory disciplinary-tribunal rulings · premium
    Explore Healthcare

    Industrial / OT / ICS

    OT security, robot-cell safety, and live ICS advisory enrichment.

    • ·Control mapping: IEC 62443 (1-1…4-2)
    • ·Control mapping: ISO 10218-1/-2:2025 + the safety-security bridge
    • ·OT protocol security models: Modbus/TCP, DNP3, OPC UA, PROFINET, EtherNet/IP (CIP), IEC 61850/62351, BACnet/SC
    • ·NIST SP 800-82r3 — the OT overlay
    • ·DOE C2M2 v2.1
    • ·EU Machinery Regulation (EU) 2023/1230
    • ·Cyber Resilience Act · NIS2
    • ·ENISA OT / ICS-SCADA good practices
    • ·ANSSI industrial-system security guides
    • ·UK NCSC operational-technology guidance
    • ·CISA ICS/OT advisories
    Explore Industrial / OT

    Robotics & automation

    Robot and cobot safety, machinery conformity, and the security of the robot stack.

    • ·Machinery Regulation (EU) 2023/1230
    • ·EU AI Act — high-risk safety-component duties (Reg (EU) 2024/1689)
    • ·Control mapping: ISO 10218-1/-2:2025 + ISO/TS 15066 collaborative operation
    • ·Control mapping: mobile & service robot safety (ISO 3691-4 · ANSI/A3 R15.08 · ISO 13482)
    • ·Control mapping: functional safety (ISO 12100 · ISO 13849 · IEC 61508 · IEC 62061) + IEC 62443 industrial cyber
    • ·EU machinery harmonised-standards index
    • ·ROS 2 / DDS security + robot exploitation chains
    • ·US robot-safety authority material — OSHA and NIOSH
    • ·Chinese national law
    • ·Horizontal: Cyber Resilience Act · NIS2
    Explore Robotics

    Rail & signalling

    Railway cybersecurity and signalling safety, from CLC/TS 50701 zones to the safety case.

    • ·Control mapping: CLC/TS 50701 railway cybersecurity
    • ·Control mapping: EN 50126 RAMS · EN 50129 signalling safety case
    • ·Control mapping: IEC 62443 industrial cyber
    • ·ENISA transport threat landscape — railway
    • ·US federal transportation regulation
    • ·Horizontal: NIS2 (Dir (EU) 2022/2555) · CER (EU) 2022/2557
    Explore Rail

    Energy & utilities

    Grid and generation compliance, anchored on NIS2 essential-entity duties.

    • ·National energy statutes
    • ·National energy-regulator decisions, grid codes and network regulations
    • ·US federal energy regulation — FERC (18 CFR) and the NRC nuclear rules (10 CFR)
    • ·Dutch radiation-protection and nuclear-safety regulation (ANVS)
    • ·NIS2 (Dir (EU) 2022/2555)
    • ·Critical Entities Resilience Directive (EU) 2022/2557
    • ·Cybersecurity Act (EUCC) · Cyber Solidarity Act
    • ·DOE C2M2 v2.1
    • ·CISA Cross-Sector Cybersecurity Performance Goals v2.0
    • ·Energy case law · preparatory works · agency guidance · premium
    Explore Energy

    ESG & sustainability

    Sustainability reporting, the EU green-finance taxonomy, and US environmental regulation.

    • ·CSRD (Dir (EU) 2022/2464)
    • ·EU Taxonomy Regulation (Reg (EU) 2020/852)
    • ·CBAM (Reg (EU) 2023/956)
    • ·US federal environmental regulation (EPA)

    Telecommunications

    National regulatory-authority decisions, the US federal rules, and NIS2 operator obligations.

    • ·National telecom regulatory-authority decisions · premium
    • ·US federal telecommunications regulation (FCC)
    • ·NIS2 — telecom-operator obligations

    Defense & aerospace

    Aviation-information-security regulation, defence procurement, and US arms export control.

    • ·EASA Part-IS (Reg (EU) 2023/203)
    • ·National security-protection law
    • ·US federal acquisition regulation (FAR, 48 CFR)
    • ·ITAR — US International Traffic in Arms Regulations (22 CFR 120-130)
    • ·Dutch defence procurement
    • ·Horizontal: NIS2

    Consumer & retail

    Consumer-contract, marketing and product-safety duties across EU/EFTA and the US.

    • ·National consumer-protection statutes — AT, DE, EE, FI, LV, NL, NO, SE
    • ·EU consumer instruments — Consumer Rights Directive · UCPD · unfair contract terms · GPSR · price indication · consumer omnibus
    • ·National competition-authority decisions
    • ·US federal competition & consumer-protection regulation — FTC (16 CFR)

    Trade & export control

    US arms export control, the export administration rules, and the customs code.

    • ·ITAR — US International Traffic in Arms Regulations (22 CFR 120-130)
    • ·US trade & customs regulation — export administration (15 CFR) and customs (19 CFR)

    Work environment & employment

    Occupational safety, labor and benefits regulation — US federal, with the Ontario layer and the robot-safety guidance.

    • ·US federal labor & occupational-safety regulation (29 CFR)
    • ·US federal employees' benefits regulation (20 CFR)
    • ·US robot-safety authority material — OSHA and NIOSH
    • ·Ontario occupational health & safety and employment standards
    More sectors in development
    • Chemicals & REACHChemicals Regulation is serving while its methodology corpus completes a content review.
    • MaritimeUS federal maritime and navigation regulation (46 and 33 CFR) is searchable today, but it is one jurisdiction and gets no sector of its own: the international maritime-security material is held offline pending a source-licensing audit.

    Listed only where a live MCP serves the corpus and its source licensing is GREEN. Per the No Silent Fallbacks policy, planned coverage is in the "in development" list, not above.

    Missing a corpus you need? Tell us.

    The published index includes sources its producer marks live after licence review. If the source you need is absent, ask us to review it.

    Tell us the source, the workflow it would unlock, and any licence terms you know. We will tell you whether we can host it and what review remains.

    Check your jurisdiction from your own client.

    One MCP connection to gateway.ansvar.eu — Claude, Claude Code, Cursor, VS Code Copilot, or Open WebUI. Free tier: 100 searches a day with a B2B sign-up.