AIPolicyTracker

Which AI legal duties map to which standard

Organisations are audited against standards, but regulated by statutes. These crosswalks record, duty by duty, which clause of a standard corresponds to a legal requirement — so you can see which duties your existing evidence already reaches, and which it does not.

Every mapping is an editorial judgement recorded against one obligation and reviewable in the open data. Mappings cite clause numbers only and reproduce no standard text. Compare the frameworks side by side, or start from the controls that meet the duties.

Frameworks

  • Voluntary Risk framework National Institute of Standards and Technology · 2023
    NIST AI Risk Management Framework 1.0

    A voluntary framework for managing risk across the AI lifecycle. There is no certification against it; organisations adopt it as a common vocabulary for identifying, measuring and treating AI risk.

    Duties mapped
    97
    Jurisdictions
    12
    Legally binding
    84
    Controls
    26
    See the 97 mapped duties →
  • Certifiable Management standard ISO and IEC · 2023
    ISO/IEC 42001:2023

    A certifiable management system standard for artificial intelligence. It sets out what an organisation must put in place to govern the AI systems it develops or uses: scope, leadership, objectives, risk and impact assessment, operational controls, monitoring and improvement.

    Duties mapped
    89
    Jurisdictions
    13
    Legally binding
    79
    Controls
    26
    See the 89 mapped duties →
  • Certifiable Management standard ISO and IEC · 2022
    ISO/IEC 27001:2022

    A certifiable management system standard for information security. It predates the AI standards and is the control set most organisations already hold, which is why some AI duties - security, incident handling, access - land on it rather than on an AI-specific standard.

    Duties mapped
    3
    Jurisdictions
    2
    Legally binding
    3
    Controls
    6
    See the 3 mapped duties →
  • Voluntary Threat model MITRE · living knowledge base
    MITRE ATLAS

    A knowledge base of adversary tactics, techniques and case studies against machine-learning systems, with mitigations, modelled on ATT&CK. Openly licensed; techniques and mitigations are cited by identifier.

    Duties mapped
    1
    Jurisdictions
    1
    Legally binding
    1
    Controls
    8
    See the 1 mapped duties →
  • Voluntary Principles Organisation for Economic Co-operation and Development · 2019, updated 2024

    OECD AI Principles

    An intergovernmental statement of values-based principles for trustworthy AI, plus recommendations addressed to governments. It is not an organisational control set, and it is the source much national AI policy language is drawn from.

    No legal duty is crosswalked to it directly; 6 controls cite it. See the controls.

  • Voluntary Assessment method ISO and IEC · 2023

    ISO/IEC 23894:2023

    Guidance on managing the risks an organisation faces from developing or using AI, written as an AI-specific application of the general risk-management standard. It is guidance, not a requirements standard: nothing is certified against it.

    No legal duty is crosswalked to it directly; 2 controls cite it. See the controls.

  • Voluntary Assessment method ISO and IEC · 2025

    ISO/IEC 42005:2025

    Guidance for assessing the impact of an AI system on individuals, groups and society across its lifecycle. It is a process standard for one artefact, the impact assessment, and is not certified against.

    No legal duty is crosswalked to it directly; 1 control cite it. See the controls.

  • Voluntary Threat model OWASP GenAI Security Project · 2025 edition, updated 2026

    OWASP Top 10 for LLM Applications

    A community list of the most consequential security weaknesses in applications built on large language models, each with attack scenarios and mitigations. Openly licensed; entries are cited by identifier.

    No legal duty is crosswalked to it directly; 7 controls cite it. See the controls.

Law-to-standard crosswalks

Each row is one jurisdiction's AI duties mapped to one standard. The count is how many duties carry a mapping, not how many exist.

Available law-to-standard crosswalks
JurisdictionFrameworkDuties mappedInstruments
European Union NIST AI RMF 43 1
Colorado (United States) NIST AI RMF 10 1
South Korea NIST AI RMF 9 1
United Kingdom NIST AI RMF 7 2
Texas (United States) NIST AI RMF 7 1
California (United States) NIST AI RMF 5 1
New York (United States) NIST AI RMF 5 1
Singapore NIST AI RMF 4 2
Australia NIST AI RMF 3 1
United States NIST AI RMF 2 1
India NIST AI RMF 1 1
United Arab Emirates NIST AI RMF 1 1
European Union ISO/IEC 42001 42 1
South Korea ISO/IEC 42001 9 1
Colorado (United States) ISO/IEC 42001 8 1
Texas (United States) ISO/IEC 42001 7 1
New York (United States) ISO/IEC 42001 5 1
United States ISO/IEC 42001 4 1
Singapore ISO/IEC 42001 3 2
United Kingdom ISO/IEC 42001 3 2
California (United States) ISO/IEC 42001 3 1
India ISO/IEC 42001 2 1
Australia ISO/IEC 42001 1 1
Nepal ISO/IEC 42001 1 1
United Arab Emirates ISO/IEC 42001 1 1
European Union ISO/IEC 27001 2 1
India ISO/IEC 27001 1 1
European Union MITRE ATLAS 1 1

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.

Frequently asked questions

What is a law-to-standard crosswalk?
A row-by-row mapping from a legal duty to the clause or function of a standard that asks for overlapping work. It tells you where evidence you already produce for an audit may be reusable against a statute, and where it is not.
Does ISO/IEC 42001 certification make an organisation EU AI Act compliant?
No. ISO/IEC 42001 is a management system standard and carries no legal force in any jurisdiction. Certification evidences a practice, not conformity with a statute. A crosswalk shows the overlap so evidence can be reused; it never transfers the legal obligation.
Which frameworks are covered?
ISO/IEC 42001 and the NIST AI Risk Management Framework carry most of the mappings, with a small number against ISO/IEC 27001 where an AI duty is really a security duty. Each framework page states how many duties are mapped to it and across how many jurisdictions.
How were the mappings decided?
They are editorial judgements recorded against one obligation at a time, each with a confidence level showing how direct the correspondence is. They cite clause numbers only and reproduce no text from any standard, which remains the publisher's copyright.