AIPolicyTracker
CrosswalkFree · no accountNIST AI RMFEU AI ActISO/IEC 42001

NIST AI RMF ↔ EU AI Act ↔ ISO/IEC 42001 Crosswalk

Every recorded legal duty against the NIST AI RMF and ISO/IEC 42001 references it maps to, with the confidence of each mapping, so what is done for one counts for the others.

Formats: XLSX · Version v1 · Built from dataset 7c0835db52c1 · CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.

What's inside

  • Crosswalk sheet: duty, instrument, jurisdiction, NIST reference, ISO reference, confidence, record link
  • Coverage sheet: mappings per instrument and framework
  • Editorial mappings with a stated confidence, not official crosswalks

Preview

The sheets and sections of version v1, as built. Columns marked ▾ have a dropdown; ƒ is a formula.

Sheet: Crosswalk · 10 columns · 108 rows from the records
First rows of the Crosswalk sheet
Legal dutyInstrumentJurisdictionSource referenceNIST AI RMFConfidenceISO/IEC 42001ConfidenceMapping noteRecord
Establish accountability processes and a risk-management process (guardrails 1 and 2)Australian Voluntary AI Safety StandardAustraliaGuardrails 1 and 2GOVERN and MAPhighClauses 5 and 6highThe standard states it is aligned with ISO/IEC 42001 and the NIST AI RMF. | Original editorial mapping.https://aipolicytracker.org/obligations/australia-vaiss-accountability-and-risk-management
Test and monitor systems, enable human control, and be transparent with users (guardrails 4 to 6)Australian Voluntary AI Safety StandardAustraliaGuardrails 4, 5 and 6MEASURE and MANAGE functionsmediumOriginal editorial mapping.https://aipolicytracker.org/obligations/australia-vaiss-testing-human-control-transparency
Provide contestability, supply-chain transparency and records (guardrails 7 to 9)Australian Voluntary AI Safety StandardAustraliaGuardrails 7, 8 and 9GOVERN 6.xmediumThird-party risk.https://aipolicytracker.org/obligations/australia-vaiss-contestability-supply-chain-records
Large frontier developers must publish a frontier AI frameworkCalifornia SB 53California (United States)Business and Professions Code, Chapter 25.1 (as added by SB 53)GOVERN 1.x; NIST AI 600-1mediumOriginal editorial mapping.https://aipolicytracker.org/obligations/us-california-sb-53-frontier-ai-framework
Report critical safety incidents to the Office of Emergency ServicesCalifornia SB 53California (United States)Business and Professions Code, Chapter 25.1 (as added by SB 53)MANAGE 4.3mediumIncident response.https://aipolicytracker.org/obligations/us-california-sb-53-critical-safety-incident-reporting
Frontier developers must publish a transparency report before deploying a new frontier modelCalifornia SB 53California (United States)Business and Professions Code Section 22757.12 (as added by SB 53)GOVERN 4.2, MAP 5.1, MEASURE 2.6mediumAnnex A.8.2, A.8.3mediumPublic documentation of intended use and safety evaluation. | System documentation and external reporting.https://aipolicytracker.org/obligations/us-california-sb-53-transparency-report

Editorial crosswalks with a stated confidence; they cite clause numbers only and reproduce no standard text.

Sheet: Coverage · 5 columns · 17 rows from the records
First rows of the Coverage sheet
InstrumentJurisdictionMapped dutiesWith NIST referenceWith ISO reference
Australian Voluntary AI Safety StandardAustralia331
California SB 53California (United States)553
Colorado AI ActColorado (United States)10108
EU AI ActEuropean Union444342
India DPDP ActIndia202
India AI Governance GuidelinesIndia110
Sheet: ISO references · 5 columns · 89 rows from the records
First rows of the ISO references sheet
ISO/IEC 42001 referenceDutiesControlsDutiesControls
Annex A.5.2, A.7.310Governmental entities must not use AI for biometric identification from public data without consent where it infringes rights (Texas Responsible AI Governance A
Annex A.6.1.2, A.9.410Developers and deployers must not use AI with the intent to unlawfully discriminate against a protected class (Texas Responsible AI Governance Act (TRAIGA))
Annex A.6.2.402Accuracy, robustness, fairness and security testing; Adversarial and red-team testing for generative AI
Annex A.6.2.4; Clause 9.210Employers and employment agencies must obtain an independent bias audit before using an automated employment decision tool (NYC Local Law 144 (automated employm
Annex A.6.2.5, A.9.2, A.9.301Human oversight design and override procedure
Annex A.6.2.7, A.8.2, A.10.410Providers of GPAI models must maintain technical documentation and inform downstream providers (EU AI Act)
Sheet: NIST references · 5 columns · 101 rows from the records
First rows of the NIST references sheet
NIST AI RMF referenceDutiesControlsDutiesControls
GOVERN 1.1, 1.2, 1.3, 2.1, 3.101AI governance policy and accountability structure
GOVERN 1.1, GOVERN 2.110Providers must meet the full set of provider duties for high-risk AI (EU AI Act)
GOVERN 1.1, MANAGE 1.320Law-enforcement deployers must obtain authorisation for post-remote biometric identification and report annually (EU AI Act); Deployers must use reasonable care
GOVERN 1.1, MAP 1.130Do not deploy or provide AI for prohibited practices (EU AI Act); Providers of GPAI models must notify the Commission within two weeks of meeting the systemic-r
GOVERN 1.1, MAP 1.1, MEASURE 2.610Developers and deployers must not use AI to incite self-harm, harm to others or crime (Texas Responsible AI Governance Act (TRAIGA))
GOVERN 1.1, MEASURE 2.6, MANAGE 2.310Developers and distributors must not build AI intended to produce child sexual abuse material or unlawful sexual deepfakes (Texas Responsible AI Governance Act

Duties this template covers (107)

Each is cited in the file with its source reference and a link back to the record.

See all 107 duties →

Legal basis

Version history

Versions of NIST AI RMF ↔ EU AI Act ↔ ISO/IEC 42001 Crosswalk
VersionBuiltDatasetWhat changed
v17c0835db52c1First version, built from dataset 7c0835db52c1.

Only the latest version is served. A rebuild that changes the content adds a version; a rebuild that does not is skipped.

Frequently asked questions

Is the NIST AI RMF ↔ EU AI Act ↔ ISO/IEC 42001 Crosswalk free?
Yes. Download the XLSX without an account, under CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
What is it generated from?
Version v1 was built on 26 September 2026 from dataset 7c0835db52c1: 108 recorded duties are cited in it, drawn from 20 instruments. Every row that cites a duty links to the record, and the record links to the official source.
How will I know when it changes?
The library is rebuilt daily. When a change to the records reaches this template it gets the next version, a changelog in the version history below, an entry in the AI policy updates hub and the templates feed, and a line in the weekly digest for subscribers of the templates topic.
Does completing it make us compliant?
No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.

Frequently asked questions

Is the NIST AI RMF ↔ EU AI Act ↔ ISO/IEC 42001 Crosswalk free?
Yes. Download the XLSX without an account, under CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
What is it generated from?
Version v1 was built on 26 September 2026 from dataset 7c0835db52c1: 108 recorded duties are cited in it, drawn from 20 instruments. Every row that cites a duty links to the record, and the record links to the official source.
How will I know when it changes?
The library is rebuilt daily. When a change to the records reaches this template it gets the next version, a changelog in the version history below, an entry in the AI policy updates hub and the templates feed, and a line in the weekly digest for subscribers of the templates topic.
Does completing it make us compliant?
No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.