Open · crawlable · citable
The AI governance framework crosswalk.
How 13 AI-governance & adjacent compliance frameworks map to 8 universal controls. Comply once, evidence everywhere. The signed, article-level version runs inside the CSOAI OS.
EU AI Act — staggered application
| Control | EU AI Act | NIST AI RMF | ISO/IEC 42001 | DORA | NIS2 | GDPR | ISO 27001 | SOC 2 | HIPAA | MiCA | PCI DSS | CRA | TC260 |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Risk management | Art. 9 | MAP/MEASURE | 6.1 / 8.2 | Art. 5–6 | Art. 21 | · | · | · | · | · | · | Annex I | · |
| Data governance | Art. 10 | MAP 2 | Annex A (data) | · | · | Art. 5–6 | · | · | 164.514 | · | · | · | 5.x |
| Transparency & disclosure | Art. 13 / 50 | GOVERN 4 | Annex A (transparency) | · | · | Art. 13–14 | · | · | · | · | · | · | labelling |
| Human oversight | Art. 14 | GOVERN 2 | Annex A (oversight) | Art. 5 | · | · | · | · | · | · | · | · | · |
| Accountability & governance | Art. 17 | GOVERN 1 | 5.1–5.3 | · | Art. 20 | · | · | CC1 | · | · | · | · | · |
| Security & resilience | Art. 15 | MANAGE 4 | · | Art. 9 | Art. 21 | · | A.5–A.8 | · | · | Art. 68 | Req. 6 | Annex I | · |
| Bias & fairness | Art. 10 / Annex III | MEASURE 2.11 | Annex A (impact) | · | · | Art. 22 | · | · | · | · | · | · | · |
| Documentation & records | Art. 11–12 / Annex IV | GOVERN 1.4 | 7.5 | Art. 28 (RoI) | · | · | · | CC2 | · | · | · | · | · |
References are indicative and for orientation — not legal advice. The signed, verifiable article-level mapping runs as a governed tool in the OS. Verify against primary sources.
Frequently asked
What is an AI governance framework crosswalk?
A crosswalk maps the overlapping requirements of different regulations and standards to a single set of controls, so that implementing one control satisfies the equivalent obligation in every framework it maps to — you comply once and evidence everywhere.
Which frameworks does the CSOAI crosswalk cover?
13+ including the EU AI Act, NIST AI RMF, ISO/IEC 42001, DORA, NIS2, GDPR, ISO 27001, SOC 2, HIPAA, MiCA, PCI DSS, the Cyber Resilience Act (CRA), and China TC260 — mapped to 8 universal AI-governance controls.
How does a crosswalk save time on EU AI Act compliance?
Most EU AI Act obligations (risk management, data governance, transparency, oversight, documentation) already overlap with ISO 42001 and NIST AI RMF. Mapping them means existing controls can be reused as evidence rather than rebuilt, cutting duplicate work ahead of the 2 August 2026 enforcement date.
Is the CSOAI crosswalk verifiable?
Yes — the signed, article-level crosswalk runs as a governed MCP tool inside the CSOAI OS and every output can be sealed to Layer 0 (Ed25519) for an auditable, reproducible record.