Back to Frameworks

Japan AI Guidelines

Japan
v2023
13 domains
13 controls

Japanese Social Principles of Human-Centric AI

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (13)

JP AI Accountability + Governance

1 controls
Controls in the JP AI Accountability + Governance domain of Japan AI Guidelines1 controls
CodeTitle
JP-AIG-Accountability-Governance-AI-Inventory-Stakeholder-Engagement-Board-Reporting-Tone-at-TopJapan AI Guidelines Accountability + Governance + AI Inventory + Stakeholder Engagement + Board Reporting + Tone at Top + AI Ethics Committee + DPO + AI Officer + Regulatory Compliance + Multi-Stakeholder

JP AI Continuous Monitoring + Lifecycle

1 controls
Controls in the JP AI Continuous Monitoring + Lifecycle domain of Japan AI Guidelines1 controls
CodeTitle
JP-AIG-Continuous-Monitoring-Lifecycle-Model-Evaluation-Performance-Drift-Post-DeploymentJapan AI Guidelines Continuous Monitoring + AI System Lifecycle Management + Model Evaluation + Performance Drift + Concept Drift + Post-Deployment + Retraining Triggers + Safe Update + Decommissioning + Model Card Versioning

JP AI Data Governance

1 controls
Controls in the JP AI Data Governance domain of Japan AI Guidelines1 controls
CodeTitle
JP-AIG-Data-Governance-Training-Data-Quality-Provenance-Lineage-Copyright-APPI-Personal-Information-ProtectionJapan AI Guidelines Data Governance + Training Data Quality + Provenance + Lineage + Copyright Act 2018 Article 30-4 Text Data Mining Exception + APPI 2022 Amendment + Personal Information Protection + Privacy Principle

JP AI Fairness + Bias

1 controls
Controls in the JP AI Fairness + Bias domain of Japan AI Guidelines1 controls
CodeTitle
JP-AIG-Fairness-Bias-Detection-Mitigation-Inclusive-AI-Discrimination-Prevention-10-Principles-2019-HeritageJapan AI Guidelines Fairness + Bias Detection + Mitigation + Inclusive AI + Discrimination Prevention + 10 Principles 2019 Heritage + Protected Attributes + Disparate Impact + Statistical Parity + Counterfactual Fairness

JP AI Generative + Foundation Models

1 controls
Controls in the JP AI Generative + Foundation Models domain of Japan AI Guidelines1 controls
CodeTitle
JP-AIG-Generative-AI-Foundation-Model-Specific-Risks-Hallucination-Watermarking-Copyright-LLM-MultimodalJapan AI Guidelines Generative AI + Foundation Model Specific Risks + Hallucination + Watermarking + Copyright + LLM + Multimodal + Prompt Injection + Jailbreak + Model Extraction + Pre-Deployment Capability Evaluation + AISI Frontier AI

JP AI Human Oversight

1 controls
Controls in the JP AI Human Oversight domain of Japan AI Guidelines1 controls
CodeTitle
JP-AIG-Human-Oversight-Control-In-the-Loop-On-the-Loop-Article-22-GDPR-Equivalent-Automated-Decision-RestrictionsJapan AI Guidelines Human Oversight + Human-in-the-Loop + Human-on-the-Loop + Human-out-of-Loop + Article 22 GDPR Equivalent APPI Automated Decision Restrictions + Override Capability + Pause Functionality + Audit Trail

JP AI Incident Reporting

1 controls
Controls in the JP AI Incident Reporting domain of Japan AI Guidelines1 controls
CodeTitle
JP-AIG-Incident-Reporting-Response-AISI-METI-Notification-G7-Hiroshima-Reporting-Mechanism-VoluntaryJapan AI Guidelines AI Incident Reporting + Response + AISI/METI Notification + G7 Hiroshima Reporting Mechanism + Voluntary + AI Incident Database + OECD AI Incidents Monitor + Sector Regulator Notification + Coordinated Vulnerability Disclosure

JP AI Risk-Based Categorisation

1 controls
Controls in the JP AI Risk-Based Categorisation domain of Japan AI Guidelines1 controls
CodeTitle
JP-AIG-Risk-Based-AI-System-Categorisation-Tiered-Approach-EU-AI-Act-Aligned-Generative-Foundation-ModelsJapan AI Guidelines Risk-Based AI System Categorisation + Tiered Approach + EU AI Act Aligned + Generative AI + Foundation Models + High-Risk + Limited-Risk + Minimal-Risk + AISI Capability-Based Thresholds

JP AI Safety + AISI

1 controls
Controls in the JP AI Safety + AISI domain of Japan AI Guidelines1 controls
CodeTitle
JP-AIG-Safety-Validation-Testing-Robustness-AISI-AI-Safety-Institute-Pre-Deployment-Evaluation-Red-TeamingJapan AI Guidelines Safety + Validation + Testing + Robustness + AISI AI Safety Institute (14 Feb 2024) + Pre-Deployment Evaluation + Red Teaming + Capability Evaluations + AI Incident Database + Safe Deployment + AI Safety Reports

JP AI Scope + Society 5.0 + Strategy

1 controls
Controls in the JP AI Scope + Society 5.0 + Strategy domain of Japan AI Guidelines1 controls
CodeTitle
JP-AIG-Scope-METI-MIC-AI-Guidelines-Business-v1.0-April2024-Society-5.0-Cabinet-Office-AI-Strategy-CouncilJapan AI Guidelines Scope + METI/MIC AI Guidelines for Business v1.0 (April 2024) + Society 5.0 + Cabinet Office AI Strategy Council + 10 Principles 2019 Heritage + Education + Literacy + Fair Competition + Innovation Principles

JP AI Security + Adversarial

1 controls
Controls in the JP AI Security + Adversarial domain of Japan AI Guidelines1 controls
CodeTitle
JP-AIG-Security-Adversarial-Attack-Protection-Prompt-Injection-Data-Poisoning-Model-Extraction-AISI-Red-TeamJapan AI Guidelines Security + Adversarial Attack Protection + Prompt Injection + Data Poisoning + Model Extraction + Membership Inference + AISI Red-Team + MLSecOps + Supply Chain Security + Foundation Model Vulnerabilities

JP AI Third-Party + Supply Chain

1 controls
Controls in the JP AI Third-Party + Supply Chain domain of Japan AI Guidelines1 controls
CodeTitle
JP-AIG-Third-Party-AI-Supplier-Assurance-Foundation-Model-Provider-AISI-Evaluation-Voluntary-AuditJapan AI Guidelines Third-Party AI Supplier Assurance + Foundation Model Provider + AISI Evaluation + Voluntary Audit + ISO/IEC 42001 AI Management System + Sub-Processor + Cloud AI Service Provider + Open Source AI Governance

JP AI Transparency + Documentation

1 controls
Controls in the JP AI Transparency + Documentation domain of Japan AI Guidelines1 controls
CodeTitle
JP-AIG-Transparency-Documentation-Model-Card-System-Card-Tier-Based-Disclosure-Hiroshima-Code-of-ConductJapan AI Guidelines Transparency + Documentation + Model Card + System Card + Datasheet + Tier-Based Disclosure + Hiroshima Code of Conduct + AI Generated Content + Watermarking + C2PA + User Notification

Your Compliance Coverage

If you comply with Japan AI Guidelines, you already cover:

Maps to 128 other frameworks

13 total controls
ISO/IEC 23894:2023
6 source controls mapped|8 target controls covered
46%
NIST Privacy Framework
5 source controls mapped|2 target controls covered
38%
ISO/IEC 27557:2022 - Organisational Privacy Risk Management
5 source controls mapped|7 target controls covered
38%
IEC 62443
5 source controls mapped|4 target controls covered
38%
NIST AI Risk Management Framework (AI RMF 1.0)
5 source controls mapped|6 target controls covered
38%
API 1164
5 source controls mapped|4 target controls covered
38%
ISO 27019
5 source controls mapped|4 target controls covered
38%
UK Defence Standard 05-138 - Cyber Security for Defence Suppliers
4 source controls mapped|1 target controls covered
31%
Protective Security Policy Framework (PSPF) Release 2024
4 source controls mapped|2 target controls covered
31%
ISO 27005
4 source controls mapped|6 target controls covered
31%
AML/CTF Act 2006 (Australia)
4 source controls mapped|2 target controls covered
31%
IEC 60601-1 - Medical Electrical Equipment Safety
4 source controls mapped|4 target controls covered
31%
EASA Part-IS - Information Security in Aviation
4 source controls mapped|5 target controls covered
31%
ISO/IEC 23837 - Security Requirements for Quantum Key Distribution
4 source controls mapped|2 target controls covered
31%
ISO 31000
4 source controls mapped|6 target controls covered
31%
ISO/IEC 38500:2024 - Governance of IT
4 source controls mapped|3 target controls covered
31%
AS9100D:2016 - Quality Management Systems for Aviation, Space, and Defence
4 source controls mapped|3 target controls covered
31%
AS9100D - Aerospace Quality Management System
4 source controls mapped|4 target controls covered
31%
ISO/IEC 27003:2017
4 source controls mapped|4 target controls covered
31%
APRA CPS 230 Operational Risk Management
4 source controls mapped|4 target controls covered
31%
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
4 source controls mapped|3 target controls covered
31%
FBI CJIS Security Policy
4 source controls mapped|2 target controls covered
31%
Annex 11 to EU GMP - Computerised Systems
4 source controls mapped|1 target controls covered
31%
ICAO Annex 17 - Aviation Security (AVSEC)
4 source controls mapped|2 target controls covered
31%
German Supply Chain Due Diligence Act (LkSG)
4 source controls mapped|2 target controls covered
31%
AWS Well-Architected Security Pillar
4 source controls mapped|6 target controls covered
31%
ISO 27017
4 source controls mapped|6 target controls covered
31%
ISO 27018
4 source controls mapped|5 target controls covered
31%
Azure Security Benchmark
4 source controls mapped|7 target controls covered
31%
OCC Heightened Standards (12 CFR Part 30, Appendix D)
3 source controls mapped|2 target controls covered
23%
Aged Care Quality Standards (Australia)
3 source controls mapped|1 target controls covered
23%
APRA CPS 234
3 source controls mapped|6 target controls covered
23%
IEC 62304:2015 Medical Device Software Lifecycle Processes
3 source controls mapped|3 target controls covered
23%
ISO 20400:2017 - Sustainable Procurement
3 source controls mapped|1 target controls covered
23%
ISO 22320:2018
3 source controls mapped|1 target controls covered
23%
IAIS Insurance Core Principles (ICPs)
3 source controls mapped|2 target controls covered
23%
FFIEC IT Examination Handbook
3 source controls mapped|6 target controls covered
23%
FFIEC Cybersecurity Assessment Tool (CAT)
3 source controls mapped|3 target controls covered
23%
BS 65000:2014 - Guidance on Organizational Resilience
3 source controls mapped|3 target controls covered
23%
ISO 37000:2021 - Governance of Organizations
3 source controls mapped|2 target controls covered
23%
ICH Q10 - Pharmaceutical Quality System
3 source controls mapped|1 target controls covered
23%
23%
ISO 28001:2007 Supply Chain Security Management
3 source controls mapped|1 target controls covered
23%
Privacy Act 1988 (Australia)
3 source controls mapped|5 target controls covered
23%
Ley Orgánica de Protección de Datos Personales (LOPDP)
3 source controls mapped|4 target controls covered
23%
Law No. 172-13 on the Protection of Personal Data
3 source controls mapped|2 target controls covered
23%
Bahrain PDPL
3 source controls mapped|7 target controls covered
23%
23%
Vermont Artificial Intelligence and Consumer Data Act (AICDA)
3 source controls mapped|2 target controls covered
23%
ISO 27001:2022
3 source controls mapped|4 target controls covered
23%
ISO 22000
2 source controls mapped|2 target controls covered
15%
ISO 45001
2 source controls mapped|2 target controls covered
15%
Vietnam Law on Cybersecurity (No. 24/2018/QH14)
2 source controls mapped|2 target controls covered
15%
South Korea PIPA
2 source controls mapped|2 target controls covered
15%
Barbados Data Protection Act 2019
2 source controls mapped|6 target controls covered
15%
GDPR
2 source controls mapped|6 target controls covered
15%
APPI
2 source controls mapped|5 target controls covered
15%
ISO/IEC 29134:2023
2 source controls mapped|3 target controls covered
15%
ISO/IEC 27014:2020
2 source controls mapped|2 target controls covered
15%
ITU-T X.805 - Security Architecture for End-to-End Communications
2 source controls mapped|2 target controls covered
15%
ISO 13485
2 source controls mapped|4 target controls covered
15%
ISO 27799
2 source controls mapped|4 target controls covered
15%
ASD Strategies to Mitigate Cyber Security Incidents
2 source controls mapped|2 target controls covered
15%
ISO/IEC 25012:2008 - Data Quality Model
2 source controls mapped|4 target controls covered
15%
ASIS SPC.1-2009 - Organizational Resilience Standard
2 source controls mapped|4 target controls covered
15%
ISO/IEC 27031:2011
2 source controls mapped|3 target controls covered
15%
BSI IT-Grundschutz
2 source controls mapped|3 target controls covered
15%
Regulation on the European Health Data Space (EHDS)
1 source controls mapped|1 target controls covered
8%
OWASP DevSecOps Maturity Model (DSOMM)
1 source controls mapped|1 target controls covered
8%
ISO 14001
1 source controls mapped|1 target controls covered
8%
FedRAMP High
1 source controls mapped|1 target controls covered
8%
NIST SP 800-53 Revision 5.1 HIGH
1 source controls mapped|1 target controls covered
8%
FedRAMP Moderate
1 source controls mapped|1 target controls covered
8%
NIST SP 800-53 Rev 5 MODERATE
1 source controls mapped|1 target controls covered
8%
NIST SP 800-53 Rev 5 LOW
1 source controls mapped|1 target controls covered
8%
USMCA Chapter 19 - Digital Trade (United States-Mexico-Canada Agreement)
1 source controls mapped|2 target controls covered
8%
Tennessee Information Protection Act (TIPA)
1 source controls mapped|3 target controls covered
8%
TEFCA - Trusted Exchange Framework and Common Agreement
1 source controls mapped|1 target controls covered
8%
Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA)
1 source controls mapped|1 target controls covered
8%
Russia Federal Law on Personal Data (152-FZ)
1 source controls mapped|2 target controls covered
8%
Pakistan Personal Data Protection Bill 2023
1 source controls mapped|3 target controls covered
8%
Law on Personal Data Protection (Official Gazette No. 42/2020)
1 source controls mapped|1 target controls covered
8%
Jordan Draft Personal Data Protection Law (2022)
1 source controls mapped|2 target controls covered
8%
Australian Privacy Principles (APPs)
1 source controls mapped|3 target controls covered
8%
Estonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019)
1 source controls mapped|1 target controls covered
8%
Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018)
1 source controls mapped|6 target controls covered
8%
8%
ISO/IEC 29100:2024
1 source controls mapped|3 target controls covered
8%
COSO Internal Control - Integrated Framework (2013)
1 source controls mapped|1 target controls covered
8%
Illinois Biometric Information Privacy Act (BIPA)
1 source controls mapped|1 target controls covered
8%
Armenia Law on Protection of Personal Data (2015)
1 source controls mapped|3 target controls covered
8%
ISO/IEC 27400:2022
1 source controls mapped|4 target controls covered
8%
Azerbaijan Law on Personal Data (2010)
1 source controls mapped|4 target controls covered
8%
Florida Digital Bill of Rights (FDBR)
1 source controls mapped|2 target controls covered
8%
FTC GLBA Safeguards Rule (16 CFR Part 314)
1 source controls mapped|2 target controls covered
8%
ISO 26000:2010
1 source controls mapped|1 target controls covered
8%
ISO/IEC 27011:2024
1 source controls mapped|3 target controls covered
8%
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
1 source controls mapped|1 target controls covered
8%
DAMA-DMBOK2 - Data Management Body of Knowledge (2nd Edition)
1 source controls mapped|2 target controls covered
8%
South Korea Cloud Security Assurance Program (CSAP)
1 source controls mapped|1 target controls covered
8%
ISO 20000-1
1 source controls mapped|1 target controls covered
8%
IEC 62351 - Power Systems Communication Security
1 source controls mapped|2 target controls covered
8%
ISO/IEC 27007:2020
1 source controls mapped|1 target controls covered
8%
COBIT 2019
1 source controls mapped|1 target controls covered
8%
ITIL 4
1 source controls mapped|1 target controls covered
8%
OWASP ASVS
1 source controls mapped|1 target controls covered
8%
MITRE D3FEND
1 source controls mapped|1 target controls covered
8%
ISO 27043
1 source controls mapped|1 target controls covered
8%
ISO/SAE 21434
1 source controls mapped|1 target controls covered
8%
ISO 14064 - Greenhouse Gas Accounting and Verification (Parts 1-3)
1 source controls mapped|1 target controls covered
8%
ISO/IEC 27010:2015
1 source controls mapped|1 target controls covered
8%
21 CFR Part 211 - Current Good Manufacturing Practice
1 source controls mapped|3 target controls covered
8%
FDA Quality Management System Regulation (QMSR)
1 source controls mapped|1 target controls covered
8%
US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule
1 source controls mapped|2 target controls covered
8%
PCAOB AS 2201 - Audit of Internal Control Over Financial Reporting (ICFR)
1 source controls mapped|2 target controls covered
8%
Nevada Gaming Control Board Cybersecurity Requirements
1 source controls mapped|3 target controls covered
8%
ISO/IEC 29147:2018
1 source controls mapped|1 target controls covered
8%
ISO 26262:2018 - Functional Safety for Road Vehicles
1 source controls mapped|1 target controls covered
8%
French Sapin II Law (Law No. 2016-1691)
1 source controls mapped|2 target controls covered
8%
ISO 41001:2018 - Facility Management Systems
1 source controls mapped|1 target controls covered
8%
ISO 39001:2012 - Road Traffic Safety Management
1 source controls mapped|1 target controls covered
8%
ISO 50001:2018 - Energy Management Systems
1 source controls mapped|1 target controls covered
8%
ISO 22313:2020 - Guidance on Business Continuity Management Systems
1 source controls mapped|1 target controls covered
8%

Frequently Asked Questions

What is Japan AI Guidelines?

Japan AI Guidelines is a compliance framework from Japan with 13 domains and 13 controls. Japanese Social Principles of Human-Centric AI It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does Japan AI Guidelines have?

Japan AI Guidelines has 13 controls organised across 13 domains. The largest domains are JP AI Accountability + Governance (1 controls), JP AI Continuous Monitoring + Lifecycle (1 controls), JP AI Data Governance (1 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does Japan AI Guidelines map to?

Japan AI Guidelines maps to 128 other compliance frameworks. The top mapping partners are ISO/IEC 23894:2023 (46% coverage), NIST Privacy Framework (38% coverage), ISO/IEC 27557:2022 - Organisational Privacy Risk Management (38% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with Japan AI Guidelines compliance?

Start your Japan AI Guidelines compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Japan AI Guidelines requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 13 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.

Get Started Free →

Free forever — no credit card required