AI Control Crosswalk: EU AI Act, ISO/IEC 42001 and the NIST AI RMF Side by Side

Share Article

Table of Contents

AI control mapping is the artefact that records which control or clause in one instrument answers a requirement in another, so one record can serve more than one audit. The value sits in evidence reuse. The risk sits in the claim that certifying against a standard discharges a legal duty, which no mapping supports.

Most published comparisons share one defect: every cell carries the same confidence, whether it comes from a NIST document or from somebody’s reading of a clause over a weekend. Research reached the same verdict this year. Bridging AI Risk Frameworks, submitted on 1 July 2026, reconciles the three instruments into a taxonomy of five analytical layers and eight governance domains, and finds that they differ “in legal status, governance subject, and conception of risk, so that the control-level crosswalks now common in practice are both incomplete and, in places, misleading”. The map below is graded instead. Tier A cells come from NIST’s own document. Tier B cells are interpretation, labelled as such. Tier C names the duties that map to nothing at all.

Tier A: NIST published the mapping, so cite the document

Control mapping has published source material on one side. The NIST AI Resource Center hosts a crosswalk library of twelve documents, including AI RMF mappings to ISO/IEC 42001, to ISO/IEC 42005 on impact assessment, and to ISO/IEC 23894 on risk management, the last two revised on 14 August 2025.

NIST attaches a caveat worth quoting in your own methodology note: “Inclusion of a crosswalk below does not imply NIST endorsement of the resource the AI RMF is mapped to, nor does it imply that either resource comprehensively covers the contents of the other.”

The rows below are taken from that published mapping. Clause numbers are NIST’s, not ours, which is what makes them citable in an audit file.

NIST AI RMF subcategoryISO/IEC 42001 clauses, per NISTWhat the pair produces
GOVERN 1.1 legal and regulatory requirements understood and documented4.1, 6.2, B.2.2, B.2.4Scope statement naming each system, its role and its risk tier
GOVERN 1.4 risk management process established through transparent policies6.1.2, 6.1.3, 8.3Risk method plus the register it produces
GOVERN 2.1 roles, responsibilities and lines of communication documented5.3, 7.1, 7.2, 7.3, 7.4, 9.1, B.3.2Accountability matrix plus competence records
MAP 1.1 intended purposes, context and deployment settings documented6.1.4, B.5.2, B.5.3, B.5.4, B.5.5Impact assessment dated before first use
MAP 2.3 scientific integrity and TEVV considerations documentedB.6.1.3, B.6.2.4, B.6.2.7, B.7.2 to B.7.6Data and testing design records
MEASURE 1.1 approaches and metrics for measuring AI risks selected6.1.1, 6.1.2Documented risk measurement method
MEASURE 2.1 test sets, metrics and TEVV tooling documentedB.4.2, B.6.2.4, B.6.2.7, B.8.4Test report with datasets and tooling named
MEASURE 3.1 approaches and personnel to track emergent risks4.4, 8.2, 8.4Monitoring procedure with named owners
MANAGE 2.1 resources and non-AI alternatives considered7.1, B.4.2Resourcing and alternatives note in the decision record
MANAGE 4.1 post-deployment monitoring, appeal and override, incident response9.2.1, B.6.2.6, B.8.3, B.10.4Override log, incident record, change history

One row in that table has no EU counterpart worth claiming. MANAGE 2.1 asks whether a non-AI alternative was considered, a question the AI Act never puts. Good governance keeps the row; a compliance argument cannot use it.

Two more NIST mappings do work that 42001 alone cannot

The map can draw on two further NIST documents. The AI RMF to ISO/IEC 42001 crosswalk is the one everyone quotes, and it is not the only mapping NIST maintains. Two others carry weight for a high-risk programme.

ISO/IEC 42005, published on 28 May 2025, covers the AI system impact assessment, and NIST revised its crosswalk to that standard on 14 August 2025. For a team building the Article 27 assessment, 42005 gives structure that ISO/IEC 42001 alone does not, and the NIST mapping shows which MAP subcategories feed it.

ISO/IEC 23894, published in 2023, applies ISO 31000 risk management to AI, and NIST revised its mapping to that standard on the same date. Programmes that already run an enterprise risk method usually find their bridge there rather than in 42001.

Using all three mappings tends to produce fewer orphan controls than forcing every row through the management system standard.

Tier B: every EU column is interpretation, so label it

Crosswalk coverage runs dry on the EU side. No Commission document maps AI Act articles to ISO/IEC 42001 clauses, and the absence is structural: the Act routes conformity through harmonised standards instead.

Everything in the table below is our reading, labelled that way. Each row starts from the binding duty, names the standard material that generates a similar record, and states the artefact that can serve both.

EU AI Act dutyNearest ISO/IEC 42001 materialNearest NIST subcategoryShared artefactBasis
Article 9 risk management system6.1.1 to 6.1.3GOVERN 1.4, MEASURE 1.1Risk assessment and registerInference, supported by NIST rows
Article 10(2) data governanceAnnex A data controlsMAP 2.3Dataset documentation with bias examinationInference
Article 11 and Annex IV technical documentationDocumented information requirementsNone specificThe technical fileInference
Article 12 record-keepingOperational recordsMANAGE 4.1 in partEvent logs with retention setInference
Article 13 instructions for useInformation for interested partiesNone specificVersioned instructions issued to deployersInference
Article 14(4) human oversightOversight controls in Annex AMANAGE 4.1 appeal and overrideOversight design plus override recordsInference
Article 17 quality management systemClauses 4 to 10 as a wholeGOVERN 1.1, GOVERN 2.1QMS procedures and internal audit reportsInference
Article 27 fundamental rights impact assessment6.1.4 impact assessmentMAP 1.1Completed FRIA before first useInference, and the scopes differ
Article 72 post-market monitoring8.2, 8.4 performance evaluationMEASURE 3.1, MANAGE 4.1Monitoring plan inside Annex IV plus its outputInference
Article 4 AI literacy7.2 competenceGOVERN 2.1Role-based training recordsInference

Two warnings belong with those rows. The FRIA row looks tidy and is not: ISO/IEC 42001 asks for an AI system impact assessment as a management system output, while Article 27 binds a narrow set of deployers, public bodies plus private operators running creditworthiness assessment or life and health insurance pricing, and requires it before first use. Article 11 has no NIST counterpart because the AI RMF never contemplated a regulator-defined technical file.

Tier C: four duties map to nothing, and certification never produces them

Declaration of conformity. Article 47 requires a written EU declaration of conformity drawn up by the provider.

CE marking. Article 48 requires the marking itself, which is a product act rather than a management system output.

Registration. Article 49 requires the provider or authorised representative to register themselves and the system in the EU database before an Annex III high-risk system is placed on the market.

Serious incident notification. Article 73 sets external reporting deadlines to the market surveillance authority of the Member State where the incident occurred. ISO treats incidents as a process to run; the Act treats them as a notice to file.

General-purpose AI belongs in the same tier. Chapter V duties have applied to model providers since 2 August 2025, whatever standards they hold.

Presumption of conformity is the only official bridge, and it is not open yet

The map has one official bridge, and Article 40(1) defines it. Systems “in conformity with harmonised standards or parts thereof the references of which have been published in the Official Journal of the European Union” are “presumed to be in conformity with the requirements set out in Section 2 of this Chapter”, to the extent the standards cover them.

Read the condition twice before relying on it. Publication of the reference in the Official Journal is what triggers the presumption. EN 18286 on AI quality management was approved in June 2026 as the first European standard approved under the Act, according to CEN-CENELEC, and its citation has not appeared, so it confers nothing yet. On risk management, prEN 18228 remains a draft.

Until a citation lands, no certificate and no crosswalk gives a presumption of conformity. What they give is a faster route to the records an assessment will ask for.

Every cell carries an edition, so the map carries a version

Crosswalk cells inherit the edition they were drawn from. NIST’s mapping references the FDIS text of ISO/IEC 42001, published before the final 2023 edition. Clause numbers can move between a final draft and a published standard, so copy them into your own file with the edition noted and check them against your licensed copy.

Legal drift moves faster than standards drift. Regulation (EU) 2026/1744 entered into force on 27 July 2026 and moved the Annex III high-risk application date to 2 December 2027. Every mapping row that still carried the old deadline became wrong that day. The change ledger is in the dates the omnibus moved.

The map runs like any controlled document: an owner, a version, a review date, and a line recording which edition of each instrument each column was built against.

Counts and percentages are how crosswalks inherit errors

Crosswalk errors usually enter through a number. Ask how many controls sit in ISO/IEC 42001 Annex A and vendor pages disagree. The ISO catalogue entry gives the publication date, the edition and the page count, and no control count.

A map built on a number lifted from a blog carries that error into every row that references it. Count the controls in your licensed copy, record the edition you counted, and describe Annex A by its structure until then.

Overlap percentages deserve the same treatment. Claims such as “half the controls map across” are outputs of one person’s scope decisions. Publish your own figure with your own scope statement, or cite nothing.

One artefact, three readers

Control mapping earns its keep on a single system. Take a CV screening tool used by an EU employer, the standard Annex III case under the employment heading.

Article 9 requires a risk management system across the lifecycle. NIST’s crosswalk puts GOVERN 1.4 and MEASURE 1.1 against ISO/IEC 42001 clauses 6.1.1 to 6.1.3, which describe the risk method and its outputs. One artefact answers all three readers: a dated risk assessment naming the system version, the hazards considered, the metrics applied, the mitigations chosen, the residual risk accepted and the role that accepted it.

What that artefact cannot do is close the deployer’s own duties. The employer still owes a fundamental rights impact assessment under Article 27 before first use, monitoring under Article 26(5), and log retention of at least six months under Article 26(6). None of those appear in an ISO audit plan unless somebody puts them there. The full set of records behind each duty is listed in the records that prove conformity.

Assurance is younger than the mapping conversation

Crosswalk work has outrun certification capacity. ISO/IEC 42006, which sets requirements for bodies that audit and certify AI management systems, was published in July 2025. UKAS granted the first accreditation under it to BSI on 15 January 2026.

Crosswalk owners face two consequences. Audit teams with AI experience are scarce, so book early and expect scope negotiation. A certificate from a body without accreditation under 42006 also carries less weight with a regulator or an enterprise buyer, which is worth checking before signing, alongside what certification costs and how long it takes.

What an assessor actually does with your map

Auditors do not accept a mapping as evidence. An assessor treats it as a routing table, then tests the records it points to.

The map faces three moves in an assessment. First, the methodology question: who built the map, against which editions, and which cells are inference. A map that answers that in its own header survives the conversation. Second, sampling: the assessor picks two or three rows and asks for the artefact named in each, with its date, version and approver. Third, the gap list: an assessor who finds a duty missing from your table treats the omission as a scoping failure rather than a clerical one.

The practical implication runs backwards into how the map is written. Cells should name artefacts rather than describe similarity, and the header should carry the edition and the author. Both are cheap while the map is being built and expensive to reconstruct afterwards.

Where the map lives decides whether anyone maintains it

Crosswalk spreadsheets die quietly. The law changes, the author leaves, a second product enters scope, and nobody notices until an auditor quotes a row back.

Govern365 keeps the mapping attached to the systems it governs. The Compliance Dashboard tracks each requirement clause by clause across the instruments in scope. The Audit Evidence Manager attaches one artefact to every obligation it answers, so a single record serves several rows without duplication. The AI System Registry holds the scope statement that decides which rows apply to which system. All three are features of one platform at govern365.ai, built for teams maintaining one control library rather than three spreadsheets. How a requirement, its control and its evidence stay linked is shown on where these approvals are tracked.

Six steps to a map that survives an audit

  1. Write the scope first. Systems, the role you hold for each, and the instruments in scope. A map without a scope statement cannot be tested.
  2. Grade every cell. Mark NIST-published mappings separately from your own interpretation. Auditors trust a labelled inference and distrust an unlabelled one.
  3. Start from the binding instrument. Work outward from the articles that apply to your systems, then attach the standard material that produces the same record.
  4. Name the artefact in every row. A row without a record is an opinion about similarity.
  5. Keep a gap list. The declaration, the marking, the registration and the incident notice go on it, with owners.
  6. Version and review. Note each instrument’s edition, and revisit on amendment, on a new harmonised standard citation, and on any scope change.

Frequently asked questions

What is AI control mapping?

AI control mapping is a documented comparison showing which control or clause in one instrument answers a requirement in another, and which record satisfies both. Mapping reduces duplicate evidence across the EU AI Act, ISO/IEC 42001 and the NIST AI RMF, and never merges the obligations themselves.

Is there an official EU AI Act to ISO 42001 crosswalk?

No. The Commission publishes no such mapping. The Act routes conformity through Article 40, where harmonised standards cited in the Official Journal give a presumption of conformity. EN 18286 was approved in June 2026 and is not yet cited, so EU columns in published tables are practitioner interpretation.

Where can I find the NIST AI RMF crosswalks?

The NIST AI Resource Center hosts a library of them, including mappings to ISO/IEC 42001, ISO/IEC 42005 and ISO/IEC 23894. NIST states that inclusion implies neither endorsement nor comprehensive coverage of one document by the other, which is the right caveat to carry into your own file.

Does an ISO/IEC 42001 certificate satisfy the EU AI Act?

No. Certification shows a management system meets the standard, and produces none of the product duties: no EU declaration of conformity under Article 47, no CE marking under Article 48, no EU database entry under Article 49, and no serious incident notification under Article 73.

How many controls does ISO/IEC 42001 Annex A contain?

Published counts differ across vendor pages and ISO’s free pages state none. Count them in your licensed copy, note the edition, and avoid quoting a number from secondary sources, because a table built on a wrong count carries the error into every row.

How often should a control mapping be reviewed?

On events rather than on a calendar. Amendments to the Act, new harmonised standard citations, a new edition of a standard, and any change of scope each invalidate rows. Regulation (EU) 2026/1744 proved the point on 27 July 2026 by moving dates that appeared in thousands of published tables.

Stay ahead of the curve

Join 5,000+ industry leaders who receive our weekly briefing on AI governance and secure enterprise collaboration.

About the Author

Dr Faiz Rasool

Director at the Global AI Certification Council (GAICC) and PM Training School

Globally certified instructor in ISO/IEC, PMI®, TOGAF®, and Scrum.org disciplines with hands-on experience in ISO/IEC 42001 AI governance across the US, EU, and Asia-Pacific.

Summarize with AI

AI-Powered Data Governance Platform

Secure, Govern, and Collaborate on Sensitive Data—All Within Microsoft 365

Further Reading

Related Insights

ai-regulations

Global AI Regulation Tracker: Which Countries Have Binding AI Law in 2026

Five claims about global AI regulation are repeated so widely that they have stopped being

Read More →
ai-evidence

AI Compliance Evidence: The Records That Prove an AI Obligation Was Met

AI compliance evidence is the set of dated, attributable records that show an AI obligation

Read More →
eu-ai-act-digital-omnibus-timeline

EU AI Act Timeline After the Digital Omnibus: What Moved and What Did Not

Regulation (EU) 2026/1744, the Digital Omnibus on AI, moved the EU AI Act’s high-risk deadlines

Read More →

Summarize with AI

Transforming AI Risks into Strategic Assets.

Request a Personalized Demo

Our governance experts will walk you through the platform and help you map out your ISO 42001 or EU AI Act roadmap.