Framework Crosswalk

Framework Crosswalk An architecture diagram generated by Archify. Control set · Policy Cards · Eval Gates · Layer 01 Govern-as-Code Control set Policy Cards · Eval Gates Evidence store · reused for all · Layer 05 Assurance & Continuous Compliance Evidence store reused for all EU AI Act · clauses · Architecture component EU AI Act clauses ISO/IEC 42001 · Annex A · Architecture component ISO/IEC 42001 Annex A NIST AI RMF · four functions · Architecture component NIST AI RMF four functions CSA AICM · control objectives · Architecture component CSA AICM control objectives OWASP · Agent Control Standard · Architecture component OWASP Agent Control Standard attach once Layer 01 Govern-as-Code Layer 05 Assurance & Continuous Compliance Legend Backend Database External

One hub, many frameworks

  • • Each Policy Card and Eval Gate declares the clauses it maps to
  • • The crosswalk is the aggregation of those declarations, not a separate spreadsheet
  • • One control can satisfy several frameworks at once

Evidence attached once

  • • Evidence is attached to the hub and reused for every framework
  • • Every mapping cell must resolve to a running control and its emitted evidence
  • • A cell with no evidence behind it is flagged, not counted

An index, not the end state

  • • A crosswalk proves you read the framework; it does not prove the control fires
  • • Use it to find gaps and reuse controls, not to report compliance
  • • The hub is what you maintain