← Lead & Assurance
Module 6 of 7 · 15 min
Stage 5 · Review, challenge and mentor

Cross-framework mapping: EU AI Act, ISO/IEC 42001, GDPR and NIST AI RMF

Use cross-framework mapping without pretending one framework certifies another.

Learn

Map shared governance themes such as inventory, risk, impact, data, oversight, monitoring, incident management and accountability.

Keep legal obligations, certifiable management-system requirements and voluntary risk-framework practices distinct in the evidence matrix.

Use mapping to reuse evidence and reduce duplication, not to claim equivalence where none exists.

Remember
  • •Map controls, not labels.
  • •Shared evidence does not mean identical requirements.
  • •Preserve framework-specific conclusions.
Client practice

Take one human-oversight control and map what evidence could support EU AI Act, ISO/IEC 42001 and NIST AI RMF objectives.

Evidence you should be able to produce
Cross-framework matrixEvidence reuse mapFramework-specific gaps
Source basis

Training synthesis. Legal/privacy conclusions require authoritative source review; NIST AI RMF is voluntary guidance.

← Previous moduleNext module →