Law / Frameworks / FINOS AIGF / Preventative
FINOS AIGF AIR-PREV-005System Acceptance Testing
System Acceptance Testing (SAT) for AI systems is a crucial validation phase within a financial institution. Its primary goal is to confirm that a developed AI solution rigorously meets all agreed-upon business and user requirements, functions as intended from an end-user perspective, and is fit for its designated purpose before being deployed into any live operational environment. This testing focuses on the user's viewpoint and verifies the system's overall operational readiness, including its alignment with risk and compliance standards.FINOS AI Governance Framework, version 2, as maintained on , AIR-PREV-005
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Law library as of .
The kinds of duty that reach it: DPIA, governance, prohibition.
- 512
- laws
- 191
- places
- 1
- with court rulings behind it
- 47
- not yet in force
- 1
- blocked by a court
- 14
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFGOVERN 1.1 Legal and regulatory requirements involving AI are understood, managed, and documented.
- NIST AI RMFGOVERN 1.4 The risk management process and its outcomes are established through transparent...
- NIST AI 600-1GAI-RISK-04 Data Privacy
- NIST AI 600-1GAI-RISK-07 Human-AI Configuration
- OWASP LLM Top 10LLM03:2026 Excessive Agency
- OWASP Agentic Top 10ASI09 Human-Agent Trust Exploitation
- MIT mitigations1.2 Risk Management
- MIT mitigations1.1 Board Structure & Oversight
- NIST Privacy FrameworkGV.PO-P1 Organizational privacy values and policies (e.g., conditions on data processing such...
- NIST Privacy FrameworkID.IM-P4 Data actions of the systems/products/services are inventoried.
- NIST CSF 2.0GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including...
- NIST CSF 2.0GV.RR-01 Organizational leadership is responsible and accountable for cybersecurity risk and...
- CIS Controls3.2 A maintained catalogue of the sensitive data the enterprise holds and where it sits.
- CIS Controls8.2 Turning on and gathering logs from the enterprise's systems.
A law in force is unmarked; the rest wear their state: not yet in force blocked by a court proposed
AI prohibited practices
101 laws, 74 placesShow the other 91 laws
Comprehensive regime
75 laws, 73 placesShow the other 65 laws
Enforcement supervision
69 laws, 68 placesShow the other 59 laws
Sensitive categories
67 laws, 66 placesShow the other 57 laws
Telephone contact
42 laws, 20 placesShow the other 32 laws
Sector security regimes
40 laws, 38 placesShow the other 30 laws
Interception and recording consent
23 laws, 20 placesShow the other 13 laws
AI governance
15 laws, 11 placesShow the other 5 laws
| Artificial Intelligence Safety Measures Act from , in 3 months |
Through its governance duty. What it requires |
|
| Council of Europe Framework Convention on Artificial Intelligence, signed by Moldova proposed |
Through its DPIA duty. What it requires |
|
| Federal Law No. 243-FZ, Article 8, Duties of Sovereign and National Foundation Model Developers from , in 5 months |
Through its governance duty. What it requires |
|
| Digital Transformation Act 2025, ICT service permit for AI and AI-related data services |
Through its governance duty. What it requires |
|
| Guidelines on Artificial Intelligence of Vatican City State (Decree No. DCCII) |
Through its governance, prohibition duties. What it requires |
AI risk obligations
15 laws, 8 placesShow the other 5 laws
| Digital Code, Chapter 23: AI system design and risk-management obligations |
Through its DPIA, governance duties. What it requires |
|
| Artificial Intelligence (Designation of the Information and Data Protection Commissioner for the purposes of Regulation (EU) 2024/1689) Regulations, 2025 (L.N. 227 of 2025) |
Through its governance duty. What it requires |
|
| Right to Compute Act (SB 212, 2025), critical AI infrastructure risk management duty |
Through its governance duty. What it requires |
|
| AI Framework Act, Article 34 (business-operator duties for high-impact AI) |
Through its governance duty. What it requires |
|
| Law on Artificial Intelligence, risk classification and conformity assessment |
Through its governance duty. What it requires |
Commercial messages
15 laws, 14 placesShow the other 5 laws
| Unsolicited commercial electronic mail labeling and opt-out |
Through its prohibition duty. What it requires |
|
| Oregon Unsolicited Facsimile Machine Transmissions Statute |
Through its prohibition duty. What it requires |
|
| Unsolicited Telecommunication Advertisement Act |
Through its prohibition duty. What it requires |
|
| Regulation of Electronic Mail |
Through its prohibition duty. What it requires |
|
| Commercial Electronic Mail Act, Text Messages |
Through its prohibition duty. What it requires |
Device storage and tracking consent
12 laws, 11 placesShow the other 2 laws
| Unlawful Use of Pen Register or Trap and Trace Device |
Through its prohibition duty. What it requires |
|
| Virginia Pen Register and Trap and Trace Device Prohibition |
Through its prohibition duty. What it requires |
AI sector rules
11 laws, 11 placesShow the other 1 law
| Health Insurance Preauthorization AI Disclosure (SB 319, 2026 General Session) from , in 3 months |
Through its governance duty. What it requires |
AI transparency
10 laws, 10 placesSecurity baseline statutes
9 laws, 9 placesData subject rights
2 laws, 2 places| Place | Law | How it reaches this control |
|---|---|---|
| SPDP Norma General guaranteeing personal-data protection in the use of AI systems from a date not yet set |
Through its DPIA, governance duties. What it requires |
|
| Loi n° 2022-59, droits des personnes concernées |
Through its prohibition duty. What it requires |
Product security requirements
2 laws, 2 places| Place | Law | How it reaches this control |
|---|---|---|
| Security Standards for Smart Devices |
Through its governance duty. What it requires |
|
| Cybersecurity Law, Network Product and Service Security Duties |
Through its governance duty. What it requires |
AI training data
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| AI Act, Article 53 (obligations for providers of general-purpose AI models) |
Through its governance duty. What it requires |
Biometric privacy
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| Ley N° 18.331, biometric data |
Through its DPIA duty. What it requires |
Computer misuse
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| Tuvalu Telecommunications Corporation Act 1993, offences and penalties |
Through its prohibition duty. What it requires |
Social media and minors
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| HB 3 (2024), social media use for minors |
Through its prohibition duty. What it requires |
Full text of the FINOS AI Governance Framework, CC BY 4.0. FINOS AI Governance Framework, https://air-governance-framework.finos.org/, copyright 2025 FINOS, licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Titles and purpose text are quoted; markdown emphasis and links were removed. Every control of the framework.
CIS Critical Security Controls® (CIS Controls®) v8.1 © Center for Internet Security, Inc. Safeguard numbers are used under a CIS Controls Supporter License; the one-line descriptions beside them are our own, not CIS text.