On this page

Pattern: Framework Crosswalk

A map from each control to the framework clauses it serves, generated from the controls: an index for reuse, never proof that a control fires.

Layer 01 · Govern-as-Code Layer 05 · Assurance & Continuous Compliance In the chapter 05 catalogue

Summary: Maintain a mapping from each control to the framework clauses it serves, generated from the controls themselves, as an index for navigation and reuse, never as the end state. A crosswalk proves you have read the framework; it does not prove the control fires.

Framework Crosswalk An architecture diagram generated by Archify. Control set · Policy Cards · Eval Gates · Layer 01 Govern-as-Code Control set Policy Cards · Eval Gates Evidence store · reused for all · Layer 05 Assurance & Continuous Compliance Evidence store reused for all EU AI Act · clauses · Architecture component EU AI Act clauses ISO/IEC 42001 · Annex A · Architecture component ISO/IEC 42001 Annex A NIST AI RMF · four functions · Architecture component NIST AI RMF four functions CSA AICM · control objectives · Architecture component CSA AICM control objectives OWASP · Agent Control Standard · Architecture component OWASP Agent Control Standard attach once Layer 01 Govern-as-Code Layer 05 Assurance & Continuous Compliance Legend Backend Database External
Framework CrosswalkOne internal control set is the hub that external frameworks map onto, with evidence attached once to the hub and reused for all of them. The crosswalk is an index, not the end state; the hub is what you maintain. Generated from the Body of Knowledge.Open interactive diagram (opens in a new tab)

Objectives

Let one control satisfy many frameworks and make coverage navigable, while refusing to mistake coverage for assurance.

Target users

AI governance engineer, compliance lead, auditor.

Impacted stakeholders

Auditors, regulators, model owners.

Relevant principles

Make the governed path the easiest path; instrument the build to produce its own proof.

Context

An organisation answering to several overlapping frameworks (EU AI Act, ISO/IEC 42001, NIST AI RMF, CSA AICM) that would otherwise implement the same control several times.

Problem

The crosswalk is where framework theatre begins. A green mapping matrix is mistaken for a working control; a 300-row spreadsheet mapping controls to five frameworks is presented as maturity while nothing measures whether any mapped control reduces risk. The anti-pattern is treating coverage as control: a mapping cell is not evidence.

Solution

Generate the crosswalk from the controls, not beside them: each Policy Card and Eval Gate declares the clauses it maps to, and the crosswalk is the aggregation. Use it to find gaps and reuse controls, not to report compliance. Every mapping cell must resolve to a running control and its emitted evidence; a cell with no evidence behind it is flagged, not counted. Reference vocabularies such as the CSA AICM (247 control objectives across 18 domains) 1 and the OWASP Agent Control Standard 2 anchor the mapping.

Consequences

Controls are reused across frameworks and gaps are visible, without inflating a matrix into false assurance. The trade-off is the discipline to keep cells honest and to resist reporting coverage as outcome.

Policy Card; Runtime Guardrail; Machine-Readable Evidence (OSCAL); Continuous Assurance Telemetry.

Maps to: EU AI Act (cross-cutting) · ISO/IEC 42001 · NIST AI RMF (Govern) · CSA AICM · OWASP Agent Control Standard · Layer 01 Govern-as-Code / Layer 05 Assurance & Continuous Compliance.

Function labels follow the NIST AI RMF3. Mappings are illustrative, not a claim of conformity.

Sources

  1. [1] AI Controls Matrix (AICM) v1.1 (247 control objectives across 18 domains). Cloud Security Alliance. 2026-06-22. https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1 (verified: primary)
  2. [2] OWASP GenAI Security Project unveils the Agent Control Standard (ACS) and 2026 Top 10 for LLM Applications. OWASP GenAI Security Project. 2026-09-01. https://genai.owasp.org/2026/09/01/owasp-genai-security-project-unveils-2026-top-10-for-llm-applications-new-agent-control-standard-and-sponsors-as-community-tops-30000-members/ (verified: primary)
  3. [3] AI Risk Management Framework (AI RMF 1.0; Govern, Map, Measure, Manage). NIST. 2023-01-26. https://www.nist.gov/itl/ai-risk-management-framework (verified: primary)
Edit this page on GitHub
Cite this pattern

García Aibar, J. (2026). Pattern: Framework Crosswalk. In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0), chapter 05, Patterns. https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/patterns/framework-crosswalk. CC BY 4.0

BibTeX

@misc{aige2026bok,
  author  = {Jorge García Aibar},
  title   = {{AI Governance Engineering: The Thesis \& Body of Knowledge}},
  chapter = {05. Patterns: Framework Crosswalk},
  year    = {2026},
  version = {0.5.0},
  doi     = {10.5281/zenodo.22956197},
  url     = {https://aigovernanceengineer.com/patterns/framework-crosswalk},
  note    = {Version 0.5.0}
}
Share on LinkedIn