RegTech Reviews

Compliance Framework Examples Across Common Regulatory Environments

Overlapping frameworks cost millions in redundant work when managed separately.

Contributing Editor · · 10 min read
Cover illustration for “Compliance Framework Examples Across Common Regulatory Environments”
Compliance Frameworks · September 8, 2026 · 10 min read · 2,224 words

Compliance frameworks help cut risk and satisfy regulators; mess up, and it costs an ugly sum. Ponemon’s data shows non-compliance costs firms $14.8 million on average, while up-to-date programs run $5.47 million. This nearly threefold difference should settle most budget disputes from the outset.

Setting the stakes before the framework talk

IBM's 2025 Cost of a Data Breach report adds another figure to consider: non-compliance adds $174,538 to the average breach cost, beyond any separate fine from a regulator. That's not a hypothetical penalty. That's cash lost after the breach, since the documents weren't ready.

Enforcement fuels the fear, and it’s the scale that matters: Amazon’s $746 million GDPR fine, Westpac’s A$1.3 billion anti-money-laundering penalty, BP’s $65 billion in Deepwater Horizon costs. Three rule sets, three continents, three unique failure types. That's why they look like the rule, not the exception. They come across as one lesson in different forms.

The main issue isn't about spending money on compliance. The key issue is identifying the applicable frameworks, their sequence, and their specific requirements when implementation begins. This article covers each framework, one at a time, in the regulatory areas where most companies work. The costliest mistake an organization can make here is managing these as separate projects, each with its own audit, binder, and team reinventing the same encryption policy from scratch. It's not that any single framework is wrong to follow, but that they overlap enough to make repeating the work a total waste. It’s just shelling out cash to show the same thing twice, to two auditors who never compare notes.

How organizations determine which frameworks apply to them

No one chooses a compliance framework just because it sounds good. Choosing depends on three factors: industry, location, and the type of data an organization manages. Two Ohio-based organizations, a payment processor and a hospital network, face different compliance frameworks despite their proximity, as they handle distinct data types: card numbers versus medical records.

Many companies use a basic sequence, even if they don't mention it. Revenue-generating frameworks come first, often SOC 2 or PCI DSS, because certain deals won't close without them. Next comes what each client or deal requires: HIPAA for medical work, FedRAMP for government contracts, ISO 27001 for big buyers needing a global badge. Third are rules triggered by company size or location: GDPR, SOX, CCPA. Sector-specific overlays that sit on top of other frameworks come fourth.

When this settles, many companies will manage several frameworks at the same time, and the aim was never to reduce that number. The aim is to create them all without repeating the same control five times. Control mapping shows SOC 2 and ISO 27001 overlap by over 80% at the control level. Write one encryption-at-rest policy properly, and it can satisfy SOC 2's CC6.1, ISO 27001's A.8.24, HIPAA's §164.312(a)(2)(iv), and PCI DSS Requirement 3 at the same time. That's not a theoretical efficiency gain: it's one policy document doing the work of four. The framework-by-framework walkthrough that follows isn't a menu to choose from. It's a map of what typically coexists within a single compliance program. The organizations that succeed here create one control map instead of making five separate policies with different titles. The losers write five binders and call it thorough.

GDPR: what data privacy compliance looks like for any organization touching EU personal data

GDPR kicks in when any business handles personal data from someone in the EU, no matter where that business is based. These all count: website analytics, employee records, one direct-sales email aimed at a customer in Lisbon. Fines max out at €20 million or 4% of worldwide yearly revenue, whichever’s bigger, under Article 83(5) for the worst breaches.

These requirements are really just a few simple duties. Consent must be freely given, clear, informed, and specific, not hidden in a cookie banner meant to be ignored. Organizations must have actual data security, be transparent about its use, and provide effective ways for people to exercise their rights: access, erasure, and portability. The focus is shifting toward privacy engineering integrated from the outset, with enforcement addressing dark patterns, AI-driven processing, and consent practices.

Note this regulatory update: a new rule issued on December 12, 2025, takes effect April 2, 2027, changing how agencies handle international cases. That lead time is exactly what it sounds like: time to tighten governance documentation and clarify who owns what, not something to bolt on retroactively once it lands. Organizations seeking a certifiable way through this increasingly use ISO/IEC 27701:2025, the standard for structured privacy management. Firms working in both the EU and California must handle GDPR and CCPA separately, as their data-request steps differ enough to create compliance gaps. Amazon's $746 million fine remains a prominent example, and its lesson is clear: a company can still be vulnerable if it reviews consent practices infrequently rather than continuously.

HIPAA: the compliance structure governing protected health information in the United States

HIPAA regulates covered entities, healthcare providers, health plans, and clearinghouses, as well as their business associates handling protected health information. Three rules do the heavy lifting. The Privacy Rule restricts sharing patient info only for care, billing, and operations. The Security Rule stipulates administrative, physical, and technical measures for electronic PHI. The Breach Notification Rule requires notifying HHS and affected individuals when there's a qualifying breach.

Unlike most frameworks here, HIPAA doesn’t offer a certification to hang on the wall. It's about staying legally compliant, with OCR audits and enforcement actions as checks, not a one-time certificate a company displays.

The January 2025 Security Rule revision remains just a proposal. HHS plans to finalize the rule by July 2027, according to its July 2026 agenda, so it's best to monitor the situation without investing in infrastructure for an unfinalized rule. HITRUST certification combines multiple frameworks, including HIPAA, ISO 27001, and NIST, into a single certification that some healthcare companies seek from vendors. That leaves many organizations balancing HIPAA compliance with additional certifications that the market may favor. To be clear: companies treating HIPAA compliance as sufficient may find themselves at a disadvantage against competitors with broader certifications.

PCI DSS: payment card security requirements and the obligations that became mandatory in 2025

PCI DSS v4.0.1 came out on June 11, 2024. Version 4.0 was retired in late 2024, so organizations still assessed against it are using the wrong version. The real deadline now is that v4.0 introduced new requirements beyond v3.2.1, with many becoming mandatory on March 31, 2025. Organizations that delayed implementing the new requirements are now non-compliant. Not approaching a deadline. Past it.

Here, enforcement comes from contracts, not laws. The card networks slap on penalties, processing costs go up, and sometimes a company can’t take payments anymore. There's no prosecutor, but a retail business that can't accept Visa is essentially doomed, and maybe even quicker than it would be from a regulatory fine that comes with a payment schedule.

Small merchants submit a Self-Assessment Questionnaire, while larger ones require a Report on Compliance and Attestation of Compliance from a Qualified Security Assessor. A useful tip is that businesses reducing their cardholder data environment by using tokenization or point-to-point encryption lower the total number of requirements they must follow. Reducing scope is part of the compliance plan, not an afterthought if the audit doesn't go well. And Requirement 3, which mandates encrypting stored cardholder data, may also address encryption requirements in other frameworks like SOC 2, HIPAA, and ISO 27001. Organizations with multiple frameworks should explicitly note this overlap, so they don't prove encryption four times to four auditors wanting the same evidence.

SOX: what financial reporting compliance requires from executives, IT teams, and internal controls

After Enron and WorldCom collapsed, Congress passed Sarbanes-Oxley in 2002 for U.S. public firms and their subsidiaries. Four sections spell out the details of implementation. Under Section 302, the CEO and CFO must personally confirm the accuracy of financial statements every reporting period. Under Section 404, management must assess internal controls over financial reporting every year, with outside auditors verifying their findings. Section 409 says companies must report important financial changes immediately. Section 802 imposes tight rules for keeping financial records and audit documents.

Personal liability means SOX isn't a framework a compliance team can just quietly manage in the background. Executives who knowingly certify false financial statements face fines up to $5 million and prison terms up to 20 years, so this isn't work that gets handed downward and forgotten. In 2025, a UK tribunal fined Metro Bank's former CEO and CFO for regulatory breaches, showing how enforcement can extend beyond U.S. borders.

SOX isn’t just a finance framework, despite its reputation, but most IT teams still misunderstand this: they see SOX as mainly an accounting issue that sometimes needs a spreadsheet from IT. Section 404 assessments include IT controls for financial systems, access, changes, and logs, and cybersecurity leaders now often appear in SOX governance. Organizations must have documented IT general controls that safeguard financial data integrity, not just unused accounting procedures stored in a binder between audits.

NIST CSF 2.0: a voluntary cybersecurity framework that has become a de facto cross-sector standard

NIST released CSF 2.0 on February 26, 2024, now covering all organizations in all sectors, not just critical infrastructure. It now has six main parts, not five, with expanded structure and detail. The new sixth function, Govern, is the one worth paying attention to.

Govern adds organizational perspective to cybersecurity choices, requires a real risk management plan in writing, and makes supply chain risk management a governance duty instead of just an IT issue. It pulls cybersecurity from the server room into board meetings, regardless of whether the board was ready for it.

Labeling CSF 2.0 "voluntary" downplays its real-world impact, so let's be clear: ignoring it is unwise, even if you don't work with the federal government. Federal contractors must follow NIST frameworks. State regulators frequently cite CSF in their rules. More and more enterprise procurement teams are checking CSF alignment when qualifying vendors, making it pointless for a company to opt out since they'll still face CSF-related questions in every RFP. It lines up neatly with HIPAA, PCI DSS, SOX IT rules, and ISO 27001, so teams that roll it out step by step usually end up meeting many required rules by accident. Organizations can use the tiered maturity model to assess their current state and prioritize controls over multiple cycles.

AML and financial crime compliance: the framework layer specific to banks and payment businesses

Banks, credit unions, money services businesses, broker-dealers, and more fintech payment processors all have to follow anti-money-laundering rules. The rules apply if you handle money, regardless of your business size, meaning even a tiny startup might face the same oversight as a big bank. Founders are often surprised by this, more than is necessary, typically when their first regulator letter appears.

The work is defined by three pillars. Customer Due Diligence checks who you are with papers and constant checks, covering who really owns a business, there’s always a real owner behind the shell. Transaction Monitoring uses real-time systems to detect suspicious activity based on known patterns. Suspicious Activity Reporting requires filing reports with FinCEN in the U.S. or its equivalent elsewhere, when certain thresholds are met.

Westpac's A$1.3 billion fine is a key example of financial crime penalties in Australia. The case is instructive because the fine resulted from gaps in transaction monitoring and correspondent banking controls at scale, not from having no program at all: the program looked fine on paper but failed under real transaction volume. The AML rules overlap with the Foreign Corrupt Practices Act for global companies. FCPA demands accurate books, records, and internal accounting controls, and though third-party due diligence isn’t a specific legal requirement, it’s firmly expected under FCPA enforcement guidance. Both cover third-party risk in practice. A policy binder won't meet any of these requirements. You need transaction monitoring technology, trained analysts, and regularly tested escalation procedures, not ones that get filed away and dusted off at audit time.

ESG and emerging regulatory frameworks: what is becoming mandatory and what remains voluntary

Right now, ESG compliance ranges from being voluntary and led by investors to becoming strict legal requirements based on location and company size. The EU's Corporate Sustainability Reporting Directive requires phased sustainability reports from big EU firms and those listed in the EU, and applies to non-EU firms when their EU revenue hits set levels.

SEC climate disclosure rules in the U.S. are still caught up in legal disputes at this time, making their status uncertain and hard to predict. Keep an eye on it, but don’t base your compliance strategy on it being final. EU financial firms must follow DORA since January 2025, which sets rules on ICT risk, incident reports, and third-party tech oversight. NIS2 increases cybersecurity requirements for key EU service operators, making them stricter than before and holding management personally accountable, a change that EU-facing executives can't ignore.

Collectively, these frameworks make it clear: the line between voluntary best practice and mandatory legal obligation is always shifting, and only in one direction." Here's the simple truth: organizations still treating ESG reporting as "optional, nice-to-have" aren't being careful. They're dragging their feet, and delays quickly become costly when a once-optional deadline turns into a mandatory filing with penalties.

Sources

  1. The NIST CSF 2.0 is Here! | CSRC
  2. compyl.com
  3. bitsight.com
  4. hhs.gov
  5. federalregister.gov
  6. twosense.ai
  7. compyl.com
  8. onspring.com

More in Compliance Frameworks