AIPolicyTracker

Framework relationships

What can be reused between frameworks?

Organisations are audited against standards but regulated by statutes. This page puts the documents side by side and then, for every category of legal duty, counts the controls that meet those duties and have a home in each framework. It is computed from the recorded mappings, so it moves when they do.

It is not a ranking. A management-system standard, a risk framework, an assessment method and a threat model exist for different purposes and cover different parts of the lifecycle, so a column with more filled cells is broader in this corpus, not better. Read the purpose row first.

What kind of document each one is

Frameworks compared by type
DimensionISO/IEC 42001NIST AI RMFISO/IEC 27001OECD AI PrinciplesISO/IEC 23894ISO/IEC 42005OWASP LLM Top 10MITRE ATLAS
PurposeA certifiable management system standard for artificial intelligence. It sets out what an organisation must put in place to govern the AI systems it develops or uses: scope, leadership, objectives, risk and impact assessment, operational controls, monitoring and improvement.A voluntary framework for managing risk across the AI lifecycle. There is no certification against it; organisations adopt it as a common vocabulary for identifying, measuring and treating AI risk.A certifiable management system standard for information security. It predates the AI standards and is the control set most organisations already hold, which is why some AI duties - security, incident handling, access - land on it rather than on an AI-specific standard.An intergovernmental statement of values-based principles for trustworthy AI, plus recommendations addressed to governments. It is not an organisational control set, and it is the source much national AI policy language is drawn from.Guidance on managing the risks an organisation faces from developing or using AI, written as an AI-specific application of the general risk-management standard. It is guidance, not a requirements standard: nothing is certified against it.Guidance for assessing the impact of an AI system on individuals, groups and society across its lifecycle. It is a process standard for one artefact, the impact assessment, and is not certified against.A community list of the most consequential security weaknesses in applications built on large language models, each with attack scenarios and mitigations. Openly licensed; entries are cited by identifier.A knowledge base of adversary tactics, techniques and case studies against machine-learning systems, with mitigations, modelled on ATT&CK. Openly licensed; techniques and mitigations are cited by identifier.
TypeManagement system standardRisk frameworkManagement system standardPrinciplesAssessment methodAssessment methodThreat modelThreat model
Legally bindingNoNoNoNoNoNoNoNo
CertificationYesNoYesNoNoNoNoNo
PublisherISO and IEC · 2023National Institute of Standards and Technology · 2023ISO and IEC · 2022Organisation for Economic Co-operation and Development · 2019, updated 2024ISO and IEC · 2023ISO and IEC · 2025OWASP GenAI Security Project · 2025 edition, updated 2026MITRE · living knowledge base
Structure and unit citedRequirements sit in clauses 4 to 10, following the harmonised structure shared by other ISO management system standards. Annex A lists reference controls that an organisation selects from and justifies. Cited here by clause.Four functions - GOVERN, MAP, MEASURE and MANAGE - each broken into categories and subcategories. GOVERN runs throughout; the other three describe a cycle. Cited here by function.Requirements in clauses 4 to 10, with Annex A reference controls grouped into organisational, people, physical and technological themes. Cited here by clause.Values-based principles addressed to AI actors, and recommendations addressed to policymakers. Cited here by principle.Follows the risk-management process of principles, framework and process, with AI-specific sources of risk and an annex of example controls across the AI lifecycle. Cited here by clause.Describes when to assess, what an assessment covers, how it is documented and how it feeds the management system, with an annex of example content. Cited here by clause.Ten numbered entries (LLM01 to LLM10) covering prompt injection, sensitive information disclosure, supply chain, data and model poisoning, improper output handling, excessive agency, system prompt leakage, vector and embedding weaknesses, misinformation and unbounded consumption. Cited here by entry.Tactics group techniques (AML.Txxxx) across the attack lifecycle; each mitigation (AML.Mxxxx) names the techniques it addresses. Cited here by mitigation.
Cited by26 of 26 controls26 of 26 controls6 of 26 controls6 of 26 controls2 of 26 controls1 of 26 controls7 of 26 controls8 of 26 controls

None of these documents is itself law. The statutes and regulations that bind are the instruments in the policy explorer; the crosswalks from those to each framework are on the frameworks page.

Where the work overlaps, by category of duty

Each cell: distinct controls that meet at least one recorded duty in the row and cite the column's framework. A filled cell means evidence may be reusable; it never means the framework discharges the duty. Zero means no recorded control cites it.

Controls per obligation category and framework
Duty categoryDutiesControlsISO/IEC 42001NIST AI RMFISO/IEC 27001OECD AI PrinciplesISO/IEC 23894ISO/IEC 42005OWASP LLM Top 10MITRE ATLAS
AI risk management 8 9 9 9 3 3 2 1 3 2
Data governance and quality 3 4 4 4 1 1 2 3
Transparency and disclosure 23 16 16 16 5 5 1 4 4
Human oversight 8 6 6 6 1 3 1 2 2
Technical documentation 4 6 6 6 1 1 3
Record keeping and logging 3 2 2 2 1 1
Accuracy, robustness and cybersecurity 3 5 5 5 2 1 3 3
Quality management system 1 3 3 3 1 1
Conformity assessment and registration 1 3 3 3
Post-market monitoring 2 3 3 3 2 1 1
Incident reporting and handling 7 7 7 7 5 1 2 3
Vendor and supply-chain governance 3 5 5 5 1 1 1 1
Impact assessment 7 5 5 5 1 1 2 1 1 1
AI literacy and training 1 1 1 1 1
Prohibited practices 6 6 6 6 2 1 3 3
Governance and accountability 19 20 20 20 5 5 2 1 4 6
Copyright and training-data transparency 1 2 2 2 1
Public-sector use and procurement 2 3 3 3 1 2 1
Privacy and personal-data protection 5 4 4 4 1 1 1 2 2
Safety testing and evaluation 5 5 5 5 2 1 2 3

Shaded green where at least half the controls in the category cite the framework. A cell compares a framework with a category of duty, never one framework with another: a threat model is not expected to cover quality management, and a management standard is not expected to name an attack technique.

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.

Frequently asked questions

Does ISO/IEC 42001 certification satisfy the EU AI Act?
No. A certifiable management standard evidences a management practice; a regulation creates legal duties. The matrix shows where the work overlaps so evidence can be reused, and the statute decides whether the duty is discharged.
Which framework should an organisation start with?
The one its counterparties already ask about: ISO/IEC 42001 where certification is expected, the NIST AI RMF where US procurement or federal policy applies. Either gives most of the controls the binding instruments require; the rows with the fewest cells filled are the duties neither reaches.
What does a number in the matrix mean?
The count of distinct controls that meet at least one recorded duty in that category and cite that framework by clause, function, entry or mitigation identifier. Zero means no recorded control in the category cites it, not that the framework is silent.