CrosswalkFree · no accountNIST AI RMFEU AI ActISO/IEC 42001
NIST AI RMF ↔ EU AI Act ↔ ISO/IEC 42001 Crosswalk
Every recorded legal duty against the NIST AI RMF and ISO/IEC 42001 references it maps to, with the confidence of each mapping, so what is done for one counts for the others.
What's inside
- Crosswalk sheet: duty, instrument, jurisdiction, NIST reference, ISO reference, confidence, record link
- Coverage sheet: mappings per instrument and framework
- Editorial mappings with a stated confidence, not official crosswalks
Preview
The sheets and sections of version v1, as built. Columns marked ▾ have a dropdown; ƒ is a formula.
Sheet: Crosswalk
| Legal duty | Instrument | Jurisdiction | Source reference | NIST AI RMF | Confidence | ISO/IEC 42001 | Confidence | Mapping note | Record |
|---|---|---|---|---|---|---|---|---|---|
| Establish accountability processes and a risk-management process (guardrails 1 and 2) | Australian Voluntary AI Safety Standard | Australia | Guardrails 1 and 2 | GOVERN and MAP | high | Clauses 5 and 6 | high | The standard states it is aligned with ISO/IEC 42001 and the NIST AI RMF. | Original editorial mapping. | https://aipolicytracker.org/obligations/australia-vaiss-accountability-and-risk-management |
| Test and monitor systems, enable human control, and be transparent with users (guardrails 4 to 6) | Australian Voluntary AI Safety Standard | Australia | Guardrails 4, 5 and 6 | MEASURE and MANAGE functions | medium | Original editorial mapping. | https://aipolicytracker.org/obligations/australia-vaiss-testing-human-control-transparency | ||
| Provide contestability, supply-chain transparency and records (guardrails 7 to 9) | Australian Voluntary AI Safety Standard | Australia | Guardrails 7, 8 and 9 | GOVERN 6.x | medium | Third-party risk. | https://aipolicytracker.org/obligations/australia-vaiss-contestability-supply-chain-records | ||
| Large frontier developers must publish a frontier AI framework | California SB 53 | California (United States) | Business and Professions Code, Chapter 25.1 (as added by SB 53) | GOVERN 1.x; NIST AI 600-1 | medium | Original editorial mapping. | https://aipolicytracker.org/obligations/us-california-sb-53-frontier-ai-framework | ||
| Report critical safety incidents to the Office of Emergency Services | California SB 53 | California (United States) | Business and Professions Code, Chapter 25.1 (as added by SB 53) | MANAGE 4.3 | medium | Incident response. | https://aipolicytracker.org/obligations/us-california-sb-53-critical-safety-incident-reporting | ||
| Frontier developers must publish a transparency report before deploying a new frontier model | California SB 53 | California (United States) | Business and Professions Code Section 22757.12 (as added by SB 53) | GOVERN 4.2, MAP 5.1, MEASURE 2.6 | medium | Annex A.8.2, A.8.3 | medium | Public documentation of intended use and safety evaluation. | System documentation and external reporting. | https://aipolicytracker.org/obligations/us-california-sb-53-transparency-report |
Editorial crosswalks with a stated confidence; they cite clause numbers only and reproduce no standard text.
Sheet: Coverage
| Instrument | Jurisdiction | Mapped duties | With NIST reference | With ISO reference |
|---|---|---|---|---|
| Australian Voluntary AI Safety Standard | Australia | 3 | 3 | 1 |
| California SB 53 | California (United States) | 5 | 5 | 3 |
| Colorado AI Act | Colorado (United States) | 10 | 10 | 8 |
| EU AI Act | European Union | 44 | 43 | 42 |
| India DPDP Act | India | 2 | 0 | 2 |
| India AI Governance Guidelines | India | 1 | 1 | 0 |
Sheet: ISO references
| ISO/IEC 42001 reference | Duties | Controls | Duties | Controls |
|---|---|---|---|---|
| Annex A.5.2, A.7.3 | 1 | 0 | Governmental entities must not use AI for biometric identification from public data without consent where it infringes rights (Texas Responsible AI Governance A | |
| Annex A.6.1.2, A.9.4 | 1 | 0 | Developers and deployers must not use AI with the intent to unlawfully discriminate against a protected class (Texas Responsible AI Governance Act (TRAIGA)) | |
| Annex A.6.2.4 | 0 | 2 | Accuracy, robustness, fairness and security testing; Adversarial and red-team testing for generative AI | |
| Annex A.6.2.4; Clause 9.2 | 1 | 0 | Employers and employment agencies must obtain an independent bias audit before using an automated employment decision tool (NYC Local Law 144 (automated employm | |
| Annex A.6.2.5, A.9.2, A.9.3 | 0 | 1 | Human oversight design and override procedure | |
| Annex A.6.2.7, A.8.2, A.10.4 | 1 | 0 | Providers of GPAI models must maintain technical documentation and inform downstream providers (EU AI Act) |
Sheet: NIST references
| NIST AI RMF reference | Duties | Controls | Duties | Controls |
|---|---|---|---|---|
| GOVERN 1.1, 1.2, 1.3, 2.1, 3.1 | 0 | 1 | AI governance policy and accountability structure | |
| GOVERN 1.1, GOVERN 2.1 | 1 | 0 | Providers must meet the full set of provider duties for high-risk AI (EU AI Act) | |
| GOVERN 1.1, MANAGE 1.3 | 2 | 0 | Law-enforcement deployers must obtain authorisation for post-remote biometric identification and report annually (EU AI Act); Deployers must use reasonable care | |
| GOVERN 1.1, MAP 1.1 | 3 | 0 | Do not deploy or provide AI for prohibited practices (EU AI Act); Providers of GPAI models must notify the Commission within two weeks of meeting the systemic-r | |
| GOVERN 1.1, MAP 1.1, MEASURE 2.6 | 1 | 0 | Developers and deployers must not use AI to incite self-harm, harm to others or crime (Texas Responsible AI Governance Act (TRAIGA)) | |
| GOVERN 1.1, MEASURE 2.6, MANAGE 2.3 | 1 | 0 | Developers and distributors must not build AI intended to produce child sexual abuse material or unlawful sexual deepfakes (Texas Responsible AI Governance Act |
Duties this template covers (107)
Each is cited in the file with its source reference and a link back to the record.
- Establish accountability processes and a risk-management process (guardrails 1 and 2)
- Test and monitor systems, enable human control, and be transparent with users (guardrails 4 to 6)
- Provide contestability, supply-chain transparency and records (guardrails 7 to 9)
- Large frontier developers must publish a frontier AI framework
- Report critical safety incidents to the Office of Emergency Services
- Frontier developers must publish a transparency report before deploying a new frontier model
- Large frontier developers must send periodic summaries of catastrophic-risk assessments to the state
- Frontier developers must protect employees who report catastrophic-risk concerns
- Notify consumers before automated decision-making technology influences a consequential decision
- Disclose the use of the technology and the principal reasons after an adverse consequential decision
- Offer meaningful human review of an adverse consequential decision
- Keep records of consequential decisions influenced by the technology for three years
Legal basis
Version history
| Version | Built | Dataset | What changed |
|---|---|---|---|
| v1 | 7c0835db52c1 | First version, built from dataset 7c0835db52c1. |
Only the latest version is served. A rebuild that changes the content adds a version; a rebuild that does not is skipped.
Frequently asked questions
- Is the NIST AI RMF ↔ EU AI Act ↔ ISO/IEC 42001 Crosswalk free?
- Yes. Download the XLSX without an account, under CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
- What is it generated from?
- Version v1 was built on 26 September 2026 from dataset 7c0835db52c1: 108 recorded duties are cited in it, drawn from 20 instruments. Every row that cites a duty links to the record, and the record links to the official source.
- How will I know when it changes?
- The library is rebuilt daily. When a change to the records reaches this template it gets the next version, a changelog in the version history below, an entry in the AI policy updates hub and the templates feed, and a line in the weekly digest for subscribers of the templates topic.
- Does completing it make us compliant?
- No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.
Frequently asked questions
- Is the NIST AI RMF ↔ EU AI Act ↔ ISO/IEC 42001 Crosswalk free?
- Yes. Download the XLSX without an account, under CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
- What is it generated from?
- Version v1 was built on 26 September 2026 from dataset 7c0835db52c1: 108 recorded duties are cited in it, drawn from 20 instruments. Every row that cites a duty links to the record, and the record links to the official source.
- How will I know when it changes?
- The library is rebuilt daily. When a change to the records reaches this template it gets the next version, a changelog in the version history below, an entry in the AI policy updates hub and the templates feed, and a line in the weekly digest for subscribers of the templates topic.
- Does completing it make us compliant?
- No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.