AI governance controls crosswalk
Every open reference control read from the framework side: for each obligation, clause or id, the controls that map to it; for each profile, its controls with their ids per framework.
What this crosswalk is
The open control profiles map each control to the obligations, standards and threat catalogues it answers. This page turns those mappings around: one table per framework, one row per clause or id, with the controls that map to it. It is generated at build time from the same registry as the profile pages, so it lists 469 mappings of 73 controls across 30 frameworks, and a framework with no mapping has no table. Every id is checked against the site's registers or the framework's public index before it is published.
Each mapping is illustrative, not a claim of conformity. For the frameworks themselves, see the frameworks; for how they overlap topic by topic, see the framework crosswalk.
Frameworks
- Obligation register
- EU AI Act (post-Omnibus) (27 ids)
- GPAI Code of Practice (1 id)
- General Data Protection Regulation (EU) 2016/679 (9 ids)
- Directive (EU) 2019/790 on copyright in the Digital Single Market (1 id)
- ISO/IEC 42001 (5 ids)
- NIST AI RMF (4 ids)
- NIST AI Agent Standards Initiative (1 id)
- NIST AI 600-1 Generative AI Profile (1 id)
- CSA AI Controls Matrix (AICM) v1.1 (2 ids)
- OWASP Top 10 for Agentic Applications 2026 (1 id)
- OWASP Top 10 for LLM Applications 2026 (1 id)
- OWASP Agent Control Standard (ACS) (1 id)
- OWASP AIBOM (1 id)
- Singapore Model AI Governance Framework for Agentic AI (2 ids)
- TC260 AI Safety Governance Framework 3.0 (1 id)
- ETSI EN 304 223 (1 id)
- ISO/IEC 42001:2023 Annex A (13 ids)
- NIST AI Risk Management Framework (AI RMF 1.0) (25 ids)
- OWASP Top 10 for LLM Applications 2026 (6 ids)
- OWASP Top 10 for Agentic Applications 2026 (10 ids)
- MITRE ATLAS techniques (7 ids)
- NIST SP 800-53 Rev. 5 (8 ids)
- AIUC-1 (10 ids)
- EU AI Act (1 id)
- IETF RFC 8693 (1 id)
- ISO/IEC 42001:2023 (2 ids)
- MCP specification 2026-07-28 (1 id)
- MITRE ATLAS mitigation (10 ids)
- NIST SP 800-218A (2 ids)
- SPIFFE (1 id)
Obligation register
Rows of the site's obligation register (ids AIGE-OBL-*), grouped by the instrument each belongs to. Each id links to its register page, which names the requirement, the evidence it asks for and the source.
EU AI Act (post-Omnibus)
| Clause or id | Controls |
|---|---|
| AIGE-OBL-EUAIA-ART4 EU AI Act Art. 4 AI literacy |
|
| AIGE-OBL-EUAIA-ART4A EU AI Act Art. 4a lawful basis for special-category data in bias detection |
|
| AIGE-OBL-EUAIA-ART5 EU AI Act Art. 5 prohibited practices (incl. new NCII and CSAM bans) |
|
| AIGE-OBL-EUAIA-ART9 EU AI Act Art. 9 risk management system |
|
| AIGE-OBL-EUAIA-ART10 EU AI Act Art. 10 data and data governance |
|
| AIGE-OBL-EUAIA-ART11 EU AI Act Art. 11 technical documentation (Annex IV) |
|
| AIGE-OBL-EUAIA-ART12 EU AI Act Art. 12 record-keeping and logging |
|
| AIGE-OBL-EUAIA-ART13 EU AI Act Art. 13 transparency and information to deployers |
|
| AIGE-OBL-EUAIA-ART14 EU AI Act Art. 14 human oversight |
|
| AIGE-OBL-EUAIA-ART15 EU AI Act Art. 15 accuracy, robustness and cybersecurity |
|
| AIGE-OBL-EUAIA-ART15-4 EU AI Act Art. 15(4) feedback loops in systems that continue to learn |
|
| AIGE-OBL-EUAIA-ART17 EU AI Act Art. 17 quality management system |
|
| AIGE-OBL-EUAIA-ART18 EU AI Act Art. 18 documentation keeping |
|
| AIGE-OBL-EUAIA-ART19 EU AI Act Art. 19 automatically generated logs kept by the provider |
|
| AIGE-OBL-EUAIA-ART20 EU AI Act Art. 20 corrective actions and duty of information |
|
| AIGE-OBL-EUAIA-ART25 EU AI Act Art. 25 responsibilities along the AI value chain |
|
| AIGE-OBL-EUAIA-ART26 EU AI Act Art. 26 deployer obligations for high-risk systems |
|
| AIGE-OBL-EUAIA-ART26-2 EU AI Act Art. 26(2) human oversight assigned to persons with competence, training and authority |
|
| AIGE-OBL-EUAIA-ART26-5 EU AI Act Art. 26(5) deployer monitoring, suspension and informing the provider |
|
| AIGE-OBL-EUAIA-ART26-6 EU AI Act Art. 26(6) deployer retention of automatically generated logs |
|
| AIGE-OBL-EUAIA-ART49-71 EU AI Act Art. 49/71 registration of high-risk systems in the EU database |
|
| AIGE-OBL-EUAIA-ART50 EU AI Act Art. 50 transparency for certain AI systems |
|
| AIGE-OBL-EUAIA-ART53 EU AI Act Art. 53 GPAI provider obligations |
|
| AIGE-OBL-EUAIA-ART53-1C EU AI Act Art. 53(1)(c) copyright policy honouring text-and-data-mining reservations |
|
| AIGE-OBL-EUAIA-ART55 EU AI Act Art. 55 GPAI models with systemic risk |
|
| AIGE-OBL-EUAIA-ART72 EU AI Act Art. 72 post-market monitoring |
|
| AIGE-OBL-EUAIA-ART73 EU AI Act Art. 73 serious-incident reporting |
|
GPAI Code of Practice
| Clause or id | Controls |
|---|---|
| AIGE-OBL-GPAICOP-SAFETY-C9 Safety and Security Commitment 9: serious-incident reporting |
|
General Data Protection Regulation (EU) 2016/679
| Clause or id | Controls |
|---|---|
| AIGE-OBL-GDPR-ART5-1B GDPR Art. 5(1)(b) and 6(4) purpose limitation |
|
| AIGE-OBL-GDPR-ART6 GDPR Art. 6 lawful basis per processing moment |
|
| AIGE-OBL-GDPR-ART7 GDPR Art. 7 conditions for consent and its withdrawal |
|
| AIGE-OBL-GDPR-ART9 GDPR Art. 9 special categories, incl. inferred sensitive data |
|
| AIGE-OBL-GDPR-ART15-17-21 GDPR Arts. 15–17 and 21 data subject rights against trained models |
|
| AIGE-OBL-GDPR-ART25 GDPR Art. 5(1)(c) and 25 minimisation and data protection by design and by default |
|
| AIGE-OBL-GDPR-ART30 GDPR Art. 30 records of processing activities |
|
| AIGE-OBL-GDPR-ART33-34 GDPR Arts. 33–34 personal data breach notification |
|
| AIGE-OBL-GDPR-ART35-36 GDPR Arts. 35–36 DPIA and prior consultation |
|
Directive (EU) 2019/790 on copyright in the Digital Single Market
| Clause or id | Controls |
|---|---|
| AIGE-OBL-DSM-ART4-3 DSM Directive Art. 4(3) text-and-data-mining reservations |
|
ISO/IEC 42001
| Clause or id | Controls |
|---|---|
| AIGE-OBL-ISO42001-A6 A.6 AI system life cycle |
|
| AIGE-OBL-ISO42001-A7 A.7 Data for AI systems |
|
| AIGE-OBL-ISO42001-A8 A.8 Information for interested parties |
|
| AIGE-OBL-ISO42001-A9 A.9 Use of AI systems |
|
| AIGE-OBL-ISO42001-A10 A.10 Third-party and customer relationships |
|
NIST AI RMF
| Clause or id | Controls |
|---|---|
| AIGE-OBL-NISTRMF-GOVERN GOVERN |
|
| AIGE-OBL-NISTRMF-MANAGE MANAGE |
|
| AIGE-OBL-NISTRMF-MAP MAP |
|
| AIGE-OBL-NISTRMF-MEASURE MEASURE |
|
NIST AI Agent Standards Initiative
| Clause or id | Controls |
|---|---|
| AIGE-OBL-NIST-AGENTS NIST AI Agent Standards Initiative (2026) |
|
NIST AI 600-1 Generative AI Profile
| Clause or id | Controls |
|---|---|
| AIGE-OBL-NIST-AI600-1 NIST AI 600-1 Generative AI Profile |
|
CSA AI Controls Matrix (AICM) v1.1
| Clause or id | Controls |
|---|---|
| AIGE-OBL-CSA-AICM AICM v1.1: 247 control objectives across 18 domains |
|
| AIGE-OBL-CSA-AICM-AGENTIC AICM agent controls with the CSA Agentic Trust Framework and AARM specification |
|
OWASP Top 10 for Agentic Applications 2026
| Clause or id | Controls |
|---|---|
| AIGE-OBL-OWASP-AGENTIC Top 10 for Agentic Applications 2026 |
|
OWASP Top 10 for LLM Applications 2026
| Clause or id | Controls |
|---|---|
| AIGE-OBL-OWASP-LLM Top 10 for LLM Applications 2026 |
|
OWASP Agent Control Standard (ACS)
| Clause or id | Controls |
|---|---|
| AIGE-OBL-OWASP-ACS Agent Control Standard (ACS) |
|
OWASP AIBOM
| Clause or id | Controls |
|---|---|
| AIGE-OBL-OWASP-AIBOM AIBOM |
|
Singapore Model AI Governance Framework for Agentic AI
| Clause or id | Controls |
|---|---|
| AIGE-OBL-SG-AGENTIC-CHECKPOINTS Singapore IMDA Model AI Governance Framework for Agentic AI: human checkpoints for significant actions (voluntary) |
|
| AIGE-OBL-SG-AGENTIC-IDENTITY Singapore IMDA Model AI Governance Framework for Agentic AI: agent identity and scoped authorisations (voluntary) |
|
TC260 AI Safety Governance Framework 3.0
| Clause or id | Controls |
|---|---|
| AIGE-OBL-CN-TC260-AGENTS TC260 Framework 3.0 Appendix 2: agentic AI risk management (voluntary; 2026-09-14) |
|
ETSI EN 304 223
| Clause or id | Controls |
|---|---|
| AIGE-OBL-ETSI-304223 ETSI EN 304 223 baseline cyber-security for AI models and systems |
|
ISO/IEC 42001:2023 Annex A
| Clause or id | Controls |
|---|---|
| A.6.2.2 AI system requirements and specification |
|
| A.6.2.4 AI system verification and validation |
|
| A.6.2.5 AI system deployment |
|
| A.6.2.6 AI system operation and monitoring |
|
| A.6.2.8 AI system recording of event logs |
|
| A.7.2 Data for development and enhancement of AI system |
|
| A.7.4 Quality of data for AI systems |
|
| A.7.5 Data provenance |
|
| A.8.2 System documentation and information for users |
|
| A.8.4 Communication of incidents |
|
| A.9.2 Processes for responsible use of AI systems |
|
| A.9.4 Intended use of the AI system |
|
| A.10.3 Suppliers |
|
NIST AI Risk Management Framework (AI RMF 1.0)
| Clause or id | Controls |
|---|---|
| GOVERN 1.6 Mechanisms are in place to inventory AI systems and are resourced according to organizational risk priorities. |
|
| GOVERN 1.7 Processes and procedures are in place for decommissioning and phasing out AI systems safely and in a manner that does not increase risks or decrease the organization’s trustworthiness. |
|
| GOVERN 2.2 The organization’s personnel and partners receive AI risk management training to enable them to perform their duties and responsibilities consistent with related policies, procedures, and agreements. |
|
| GOVERN 6.1 Policies and procedures are in place that address AI risks associated with third-party entities, including risks of infringement of a third-party’s intellectual property or other rights. |
|
| MAP 1.1 Intended purposes, potentially beneficial uses, context-specific laws, norms and expectations, and prospective settings in which the AI system will be deployed are understood and documented. Considerations include: the specific set or types of users along with their expectations; potential positive and negative impacts of system uses to individuals, communities, organizations, society, and the planet; assumptions and related limitations about AI system purposes, uses, and risks across the development or product AI lifecycle; and related TEVV and system metrics. |
|
| MAP 2.3 Scientific integrity and TEVV considerations are identified and documented, including those related to experimental design, data collection and selection (e.g., availability, representativeness, suitability), system trustworthiness, and construct validation. |
|
| MAP 3.3 Targeted application scope is specified and documented based on the system’s capability, established context, and AI system categorization. |
|
| MAP 3.5 Processes for human oversight are defined, assessed, and documented in accordance with organizational policies from the GOVERN function. |
|
| MAP 4.1 Approaches for mapping AI technology and legal risks of its components – including the use of third-party data or software – are in place, followed, and documented, as are risks of infringement of a third party’s intellectual property or other rights. |
|
| MAP 4.2 Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented. |
|
| MEASURE 2.1 Test sets, metrics, and details about the tools used during TEVV are documented. |
|
| MEASURE 2.3 AI system performance or assurance criteria are measured qualitatively or quantitatively and demonstrated for conditions similar to deployment setting(s). Measures are documented. |
|
| MEASURE 2.4 The functionality and behavior of the AI system and its components – as identified in the MAP function – are monitored when in production. |
|
| MEASURE 2.7 AI system security and resilience – as identified in the MAP function – are evaluated and documented. |
|
| MEASURE 2.10 Privacy risk of the AI system – as identified in the MAP function – is examined and documented. |
|
| MEASURE 2.11 Fairness and bias – as identified in the MAP function – are evaluated and results are documented. |
|
| MEASURE 2.13 Effectiveness of the employed TEVV metrics and processes in the MEASURE function are evaluated and documented. |
|
| MEASURE 3.1 Approaches, personnel, and documentation are in place to regularly identify and track existing, unanticipated, and emergent AI risks based on factors such as intended and actual performance in deployed contexts. |
|
| MANAGE 1.1 A determination is made as to whether the AI system achieves its intended purposes and stated objectives and whether its development or deployment should proceed. |
|
| MANAGE 1.4 Negative residual risks (defined as the sum of all unmitigated risks) to both downstream acquirers of AI systems and end users are documented. |
|
| MANAGE 2.4 Mechanisms are in place and applied, and responsibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use. |
|
| MANAGE 3.1 AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented. |
|
| MANAGE 3.2 Pre-trained models which are used for development are monitored as part of AI system regular monitoring and maintenance. |
|
| MANAGE 4.1 Post-deployment AI system monitoring plans are implemented, including mechanisms for capturing and evaluating input from users and other relevant AI actors, appeal and override, decommissioning, incident response, recovery, and change management. |
|
| MANAGE 4.3 Incidents and errors are communicated to relevant AI actors, including affected communities. Processes for tracking, responding to, and recovering from incidents and errors are followed and documented. |
|
OWASP Top 10 for LLM Applications 2026
| Clause or id | Controls |
|---|---|
| LLM02:2026 Sensitive Information Disclosure |
|
| LLM03:2026 Excessive Agency |
|
| LLM04:2026 Supply Chain |
|
| LLM05:2026 Data and Model Poisoning |
|
| LLM06:2026 Unbounded Consumption |
|
| LLM10:2026 Improper Output Handling |
|
OWASP Top 10 for Agentic Applications 2026
| Clause or id | Controls |
|---|---|
| ASI01 Agent Goal Hijack |
|
| ASI02 Tool Misuse and Exploitation |
|
| ASI03 Identity and Privilege Abuse |
|
| ASI04 Agentic Supply Chain Vulnerabilities |
|
| ASI05 Unexpected Code Execution (RCE) |
|
| ASI06 Memory & Context Poisoning |
|
| ASI07 Insecure Inter-Agent Communication |
|
| ASI08 Cascading Failures |
|
| ASI09 Human-Agent Trust Exploitation |
|
| ASI10 Rogue Agents |
|
MITRE ATLAS techniques
| Clause or id | Controls |
|---|---|
| AML.M0007 Sanitize Training Data (mitigation) |
|
| AML.M0025 Maintain AI Dataset Provenance (mitigation) |
|
| AML.T0010 AI Supply Chain Compromise |
|
| AML.T0034 Cost Harvesting |
|
| AML.T0083 Credentials from AI Agent Configuration (not yet a row of the threat bridge) |
|
| AML.T0086 Exfiltration via AI Agent Tool Invocation |
|
| AML.T0110 AI Agent Tool Poisoning |
|
NIST SP 800-53 Rev. 5
| Clause or id | Controls |
|---|---|
| AC AC-3 Access Enforcement; AC-6 Least Privilege |
|
| AU AU-2 Event Logging; AU-9 Protection of Audit Information; AU-12 Audit Record Generation |
|
| CM CM-2 Baseline Configuration; CM-3 Configuration Change Control; CM-6 Configuration Settings |
|
| IA IA-5 Authenticator Management |
|
| IR IR-4 Incident Handling |
|
| SA SA-11 Developer Testing and Evaluation |
|
| SC SC-7 Boundary Protection; SC-7(5) Deny by default, allow by exception |
|
| SI SI-4 System Monitoring |
|
AIUC-1
| Clause or id | Controls |
|---|---|
| A006 Prevent PII leakage Read on its public AIUC-1 page on 2026-09-26; not affiliated with AIUC. |
|
| A008 Prevent leakage of credentials and secrets Read on its public AIUC-1 page on 2026-09-26; not affiliated with AIUC. |
|
| B006 Prevent unauthorized AI agent actions Read on its public AIUC-1 page on 2026-09-26; not affiliated with AIUC. |
|
| C002 Conduct pre-deployment testing Read on its public AIUC-1 page on 2026-09-26; not affiliated with AIUC. |
|
| D003 Restrict unsafe tool calls Read on its public AIUC-1 page on 2026-09-26; not affiliated with AIUC. |
|
| E004 Assign accountability Read on its public AIUC-1 page on 2026-09-26; not affiliated with AIUC. |
|
| E008 Review internal processes Read on its public AIUC-1 page on 2026-09-26; not affiliated with AIUC. |
|
| E010 Establish AI acceptable use policy Read on its public AIUC-1 page on 2026-09-26; not affiliated with AIUC. |
|
| E015 Log AI system activity Read on its public AIUC-1 page on 2026-09-26; not affiliated with AIUC. |
|
| E016 Implement AI disclosure mechanisms Read on its public AIUC-1 page on 2026-09-26; not affiliated with AIUC. |
|
EU AI Act
| Clause or id | Controls |
|---|---|
| Art. 14(4)(e) stop procedure |
|
IETF RFC 8693
| Clause or id | Controls |
|---|---|
| act claim delegation names the acting party; never impersonation |
|
ISO/IEC 42001:2023
| Clause or id | Controls |
|---|---|
| 9 Performance evaluation: one evidence store answering internal audit (clause heading as chapter 22 names it) |
|
| 9.1 Performance evaluation: monitoring and measurement (cited by the evidence-record and control-observation schemas) |
|
MCP specification 2026-07-28
| Clause or id | Controls |
|---|---|
| Authorization, Token Handling audience validation; no token passthrough |
|
MITRE ATLAS mitigation
| Clause or id | Controls |
|---|---|
| AML.M0013 Code Signing |
|
| AML.M0014 Verify AI Artifacts |
|
| AML.M0016 Vulnerability Scanning |
|
| AML.M0023 AI Bill of Materials |
|
| AML.M0024 AI Telemetry Logging |
|
| AML.M0028 AI Agent Tools Permissions Configuration |
|
| AML.M0029 Human In-the-Loop for AI Agent Actions |
|
| AML.M0030 Restrict AI Agent Tool Invocation on Untrusted Data |
|
| AML.M0032 Segmentation of AI Agent Components |
|
| AML.M0036 Limit AI Workload Resource Consumption |
|
NIST SP 800-218A
| Clause or id | Controls |
|---|---|
| PS.1.3 Protect model weights and configuration parameters |
|
| PS.3.2 Keep provenance data for every component of a release |
|
SPIFFE
| Clause or id | Controls |
|---|---|
| SVID short-lived workload identity documents |
|
By profile
The same mappings read from the control side: each control of a profile with the ids it maps to, framework by framework. NIST SP 800-53 ids appear here as the control cites them, not by family. AIUC-1: This site is not affiliated with AIUC and holds no AIUC certificate; ids read on AIUC-1's public pages. Each mapping is this project's reading of the requirement text, not AIUC's.
Evaluation Environment Control Profile
Agent Runtime Control Profile
Data Admission and Privacy Control Profile
Assurance and Evidence Control Profile
| Control | Ids per framework |
|---|---|
| AIGE-CTL-ASSURE-001 Test Plan Frozen Before Evaluation |
|
| AIGE-CTL-ASSURE-002 Release Blocked Below the Eval Threshold |
|
| AIGE-CTL-ASSURE-003 Signed Test Report Against the Plan |
|
| AIGE-CTL-ASSURE-004 Common Signed Evidence Record |
|
| AIGE-CTL-ASSURE-005 Live Control Status from the Assurance Store |
|
| AIGE-CTL-ASSURE-006 Control Observations Filed Against Control Ids |
|
| AIGE-CTL-ASSURE-007 Machine-Readable Evidence in OSCAL |
|
| AIGE-CTL-ASSURE-008 Evidence Retention as Code |
|
| AIGE-CTL-ASSURE-009 Internal Audit Answered from the Evidence Store |
|
| AIGE-CTL-ASSURE-010 Model Artefacts Signed at Build and Verified Before Load |
|
| AIGE-CTL-ASSURE-011 Safe Model Formats and Digest-Pinned Third-Party Models |
|
| AIGE-CTL-ASSURE-012 AI Bill of Materials per Build |
|
Deployment and Monitoring Control Profile
| Control | Ids per framework |
|---|---|
| AIGE-CTL-DEPLOY-001 Deployment decision record before use |
|
| AIGE-CTL-DEPLOY-002 Instructions for use held and followed |
|
| AIGE-CTL-DEPLOY-003 Oversight by trained people with authority to stop |
|
| AIGE-CTL-DEPLOY-004 Go-live decision with conditions as code |
|
| AIGE-CTL-DEPLOY-005 Staged rollout with pre-registered rollback criteria |
|
| AIGE-CTL-DEPLOY-006 Pinned versions and a tested path back |
|
| AIGE-CTL-DEPLOY-007 Re-assessment when a change goes beyond what was foreseen |
|
| AIGE-CTL-DEPLOY-008 Monitoring plan with thresholds, owners and consequences |
|
| AIGE-CTL-DEPLOY-009 Fairness monitored by group in production |
|
| AIGE-CTL-DEPLOY-010 Deployer log retention |
|
| AIGE-CTL-DEPLOY-011 Serious incident reporting clocks |
|
| AIGE-CTL-DEPLOY-012 Deactivation triggers, degraded modes and suspension |
|
| AIGE-CTL-DEPLOY-013 Shadow AI discovery and registry reconciliation |
|
| AIGE-CTL-DEPLOY-014 Sanctioned AI gateway for staff use |
|
| AIGE-CTL-DEPLOY-015 Retirement runbook with access and data removal |
|
Machine-readable
- All controls as JSON:
the crosswalk is its
crosswalkkey, with the same frameworks, rows and mappings as this page, in the envelope of the open data API. - JSON Schema of the controls dataset:
the
crosswalkkey is a closed object. - This page as Markdown: /controls/crosswalk.md.
Propose a mapping
A mapping that does not hold, or one that is missing: say so on GitHub. Name the control, the framework and the clause or id, and quote the public text the mapping rests on. Mappings are added only when an id can be checked against the framework's own public text.