Law / Frameworks / FINOS AIGF / Preventative
FINOS AIGF AIR-PREV-006Data Quality & Classification/Sensitivity
The integrity, security, and effectiveness of any AI system deployed within a financial institution are fundamentally dependent on the quality and appropriate handling of the data it uses. This control establishes the necessity for robust processes to: Ensure Data Quality; Implement Data Classification.FINOS AI Governance Framework, version 2, as maintained on , AIR-PREV-006
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Law library as of .
The kinds of duty that reach it: biometric, data subject rights, governance.
- 396
- laws
- 147
- places
- 2
- with court rulings behind them
- 53
- not yet in force
- 14
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFMAP 3.5 Processes for human oversight are defined, assessed, and documented in accordance with...
- NIST AI RMFGOVERN 1.1 Legal and regulatory requirements involving AI are understood, managed, and documented.
- NIST AI 600-1GAI-RISK-04 Data Privacy
- NIST AI 600-1GAI-RISK-07 Human-AI Configuration
- OWASP LLM Top 10LLM03:2026 Excessive Agency
- OWASP Agentic Top 10ASI09 Human-Agent Trust Exploitation
- MIT mitigations3.2 Data Governance
- MIT mitigations1.1 Board Structure & Oversight
- NIST Privacy FrameworkID.IM-P4 Data actions of the systems/products/services are inventoried.
- NIST Privacy FrameworkID.IM-P6 Data elements within the data actions are inventoried.
- NIST CSF 2.0GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including...
- NIST CSF 2.0GV.RR-01 Organizational leadership is responsible and accountable for cybersecurity risk and...
- CIS Controls3.2 A maintained catalogue of the sensitive data the enterprise holds and where it sits.
- CIS Controls8.2 Turning on and gathering logs from the enterprise's systems.
A law in force is unmarked; the rest wear their state: not yet in force proposed
Data subject rights
97 laws, 87 placesShow the other 87 laws
Comprehensive regime
80 laws, 79 placesShow the other 70 laws
Enforcement supervision
65 laws, 65 placesShow the other 55 laws
Sensitive categories
60 laws, 60 placesShow the other 50 laws
Sector security regimes
40 laws, 38 placesShow the other 30 laws
AI risk obligations
16 laws, 9 placesShow the other 6 laws
| Downcoding of Health Benefits Claims, automated and AI decision-making (House Enrolled Act 1271, 2026) |
Through its governance duty. What it requires |
|
| Digital Code, Chapter 23: AI system design and risk-management obligations |
Through its governance duty. What it requires |
|
| Artificial Intelligence (Designation of the Information and Data Protection Commissioner for the purposes of Regulation (EU) 2024/1689) Regulations, 2025 (L.N. 227 of 2025) |
Through its governance duty. What it requires |
|
| Right to Compute Act (SB 212, 2025), critical AI infrastructure risk management duty |
Through its governance duty. What it requires |
|
| AI Framework Act, Article 34 (business-operator duties for high-impact AI) |
Through its governance duty. What it requires |
|
| Law on Artificial Intelligence, risk classification and conformity assessment |
Through its governance duty. What it requires |
AI governance
10 laws, 7 placesSecurity baseline statutes
9 laws, 9 placesAI sector rules
7 laws, 7 placesBiometric privacy
5 laws, 5 places| Place | Law | How it reaches this control |
|---|---|---|
| Law on the Protection of Personal Data of Bosnia and Herzegovina, biometric data processing |
Through its biometric duty. What it requires |
|
| Biometric Information Privacy Act (BIPA) |
Through its biometric duty. What it requires |
|
| Law No. 06/L-082 on Protection of Personal Data, use of biometric characteristics |
Through its biometric duty. What it requires |
|
| Law on Personal Data Protection, biometric measures from a date not yet set |
Through its biometric duty. What it requires |
|
| Ley N° 18.331, biometric data |
Through its biometric duty. What it requires |
Product security requirements
2 laws, 2 places| Place | Law | How it reaches this control |
|---|---|---|
| Security Standards for Smart Devices |
Through its governance duty. What it requires |
|
| Cybersecurity Law, Network Product and Service Security Duties |
Through its governance duty. What it requires |
AI prohibited practices
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| Lov nr. 467 af 14. maj 2025, National Competent Authorities and Article 5 Enforcement |
Through its governance duty. What it requires |
AI training data
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| AI Act, Article 53 (obligations for providers of general-purpose AI models) |
Through its governance duty. What it requires |
AI transparency
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| Practice Direction No. 1 of 2025, Use of Generative Artificial Intelligence in Court Proceedings |
Through its governance duty. What it requires |
Cross border transfer
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| Resolución 58/2022 (MINCOM), security and localization rules for personal data in electronic form |
Through its data subject rights duty. What it requires |
Personal data
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| Loi n° 24.001 portant protection des données à caractère personnel, collecte de données publiquement accessibles et transfert transfrontalier |
Through its biometric duty. What it requires |
Full text of the FINOS AI Governance Framework, CC BY 4.0. FINOS AI Governance Framework, https://air-governance-framework.finos.org/, copyright 2025 FINOS, licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Titles and purpose text are quoted; markdown emphasis and links were removed. Every control of the framework.
CIS Critical Security Controls® (CIS Controls®) v8.1 © Center for Internet Security, Inc. Safeguard numbers are used under a CIS Controls Supporter License; the one-line descriptions beside them are our own, not CIS text.