AI governance crosswalk: one topic, every framework.

Start from a governance topic, read across to the instrument that governs it, and land on the exact article, clause or control. Or start from one framework and see where another covers it, and where it does not.

EU AI Act, ISO/IEC 42001 and NIST AI RMF: where they overlap

The three overlap on 20 of the 25 topics in this crosswalk: each files at least one clause there. They differ in force. The EU AI Act is binding law; ISO/IEC 42001 is a certifiable AI management-system standard whose European adoption confers no presumption of conformity with the Act; the NIST AI RMF is a voluntary framework in four functions (Govern, Map, Measure, Manage). Of the topics the Act reaches, 5 have no ISO/IEC 42001 clause here and 2 no NIST AI RMF one. A shared topic means the instruments deal with the same thing, not that meeting one meets the other. How the three fit into the wider field is set out in AI governance and its main frameworks.

Clauses of the EU AI Act, ISO/IEC 42001 and the NIST AI RMF per crosswalk topic, core references first
Topic EU AI Act (post-Omnibus)ISO/IEC 42001NIST AI RMF
Risk management Art. 9, Art. 3 6.1.2, 6.1.3 (+4) MAP 1, MAP 5 (+7)
Governance and accountability Art. 17, Art. 4 (+1) 5.1, 5.2 (+7) GOVERN 1, GOVERN 2 (+2)
Impact assessment Art. 27, Art. 9 6.1.4, 8.4 (+1) MAP 3, MAP 5
Data governance Art. 10, Art. 10(2)(f)–(g) (+4) A.7, A.7.3 (+1) MAP 2, MEASURE 2.10 (+1)
Documentation and transparency Art. 11, Art. 13 (+7) 7.5, A.6 (+1) MAP 1, MEASURE 2.8 (+2)
Inventory and registration Art. 49, Art. 71 (+3) A.4 GOVERN 1.6, GOVERN 1.7
Logging and traceability Art. 12, Art. 26(6) (+2) A.6, A.6.2.8 MANAGE 4, MEASURE 3
Human oversight Art. 14, Art. 26 (+1) A.9 MANAGE 2.4, MAP 3.5 (+1)
Runtime guardrails Art. 5, Art. 15 (+1) A.9, A.6 MANAGE 2
Robustness, security and evaluations Art. 15, Art. 55 (+4) A.6, 9.1 MEASURE 2, MEASURE 2.7 (+2)
Incident response and monitoring Art. 72, Art. 73 (+4) A.8, 10.2 MANAGE 4, MANAGE 4.3 (+2)
Supply chain and third parties Art. 25, Art. 25(4) (+5) A.10 GOVERN 6, MAP 4 (+3)
Prohibited practices Art. 5 A.9.4 GOVERN 1.1
Fairness and non-discrimination Art. 10(2)(f)–(g), Art. 4a A.5.4 MEASURE 2.11, GOVERN 3.1
Privacy and data protection Art. 59, Art. 4a A.7 MEASURE 2.10
Explainability and right to explanation Art. 86, Art. 13(3)(b)(iv)–(v) A.8.2 MEASURE 2.9, MEASURE 2.8
AI literacy and competence Art. 4, Art. 26(2) (+1) 7.2, 7.3 GOVERN 2.2, MAP 3.4
Conformity assessment and certification Art. 43, Art. 47 (+2) 9.2 MEASURE 1.3
GPAI and foundation models Art. 53, Art. 55 (+2) Not mapped Not mapped
IP and copyright Art. 53(1)(c), Art. 53(1)(d) Not mapped GOVERN 6.1, MAP 4.1
Agent identity and autonomy Art. 14 Not mapped GOVERN 3.2
Content provenance and deepfakes Art. 50(2), Art. 50(4) (+1) Not mapped Not mapped
Sandboxes and real-world testing Art. 57, Art. 60 (+3) A.6.2.4 MEASURE 2.3
Environmental impact Annex XI 1(2)(e), Art. 40(2) (+1) Not mapped MEASURE 2.12
Deployment, change and decommissioning Art. 26, Art. 25 (+4) A.6.2.5, A.6.2.6 (+1) MANAGE 2.4, MANAGE 4.1 (+1)

Compare two frameworks

One page per pair readers compare most: legal force, scope and certification side by side, then a topic-by-topic clause mapping generated from this crosswalk.

Topic × framework

25 topics · 15 columns (29 instruments) · 520 references. Read each row across: this topic is governed here, and there, down to the clause. Four columns show at first; add the others with the column chooser.

Cross-reference: the obligation index · the Framework Crosswalk pattern · the clause-to-clause explorer.

Download CSV Download JSON

Crosswalk One topic per row, one framework family per column. Select a topic or a cell to read the mapped references.
  • Solid: maps to
  • Dashed: related
  • “?”: not yet verified

Scroll the grid sideways, or read each topic below.

Topic EU AI Act law GPAI Code code GDPR law ISO/IEC 42001 standard ISO/IEC 42005 · 23894 · 42006 3 instruments NIST AI RMF framework CSA AICM controls OWASP GenAI 2 instruments Korea AI Basic Act law United Kingdom 2 instruments Singapore 2 instruments Treaty and soft law 3 instruments GAO AI Accountability framework CEN-CENELEC 3 instruments China 6 instruments
Risk management Art. 9 Art. 3 Safety C1 Safety C3 no mapping 6.1.2 6.1.3 8.2 8.3 A.6 6.1.4 23894 6.4 ? 23894 6.5 ? 23894 6.6 ? MAP 1 MAP 5 MANAGE 1 GOVERN 1.3 MAP 1.5 MANAGE 1.3 MANAGE 1.4 MEASURE 3 MEASURE 2 GRC-02 MDS-12 no mapping Art. 34(1)(1) ATRS 2.5.2 Agentic 2.1 CoE Art. 16 OECD 1.5(c) 1.6 prEN 18228 ? TC260 2 TC260 Summary table TC260 5.3.19 GenAI Art. 17 AlgoRec Art. 27
Governance and accountability Art. 17 Art. 4 Art. 87 Safety C8 Art. 5(2) 5.1 5.2 5.3 A.2 A.3 9.3 ? 7.2 ? 9.2 ? 10.1 ? no mapping GOVERN 1 GOVERN 2 GOVERN 4 GOVERN 5 GRC-01 GRC-06 no mapping Art. 36 ATRS 2.1 GenAI 1 Agentic 2.2.1 OECD 1.5 CoE Art. 9 G7 Action 5 1.2 1.1 1.3 EN 18286 TC260 4 TC260 5.3.12 GenAI Art. 9 AlgoRec Art. 7 DeepSyn Art. 7
Impact assessment Art. 27 Art. 9 no mapping Art. 35 Art. 36 6.1.4 8.4 A.5 42005 5.8 ? 42005 6.8 ? 42005 5.12 ? MAP 3 MAP 5 GRC-10 DSP-09 no mapping Art. 35 ATRS 2.5.1 no mapping CoE Art. 16 1.5 no mapping TC260 Appendix 1 GenAI Art. 17 TC260 2.2
Data governance Art. 10 Art. 10(2)(f)–(g) Art. 4a Art. 53 Art. 53(1)(c) Art. 5(1)(e) Copyright 1.1–1.5 Art. 5(1)(c) Art. 25 Art. 9 A.7 A.7.3 ? A.4 no mapping MAP 2 MEASURE 2.10 MEASURE 2.11 DSP-20 DSP-21 LLM05:2026 no mapping ATRS 2.4.3 GenAI 2 no mapping 2.1 2.2 2.4 2.5 no mapping TC260 2.1.3 GenAI Art. 7 GenAI Art. 8 GenAI Art. 11 DeepSyn Art. 14 GB/T 45654 Corpus security ? TC260 5.1
Documentation and transparency Art. 11 Art. 13 Art. 53 Art. 50 Art. 86 Art. 18 Art. 43 Art. 53(1)(d) Art. 50(2), 50(4) Transparency 1.1 Transparency 1.2 Arts. 13–14 Art. 30 7.5 A.6 A.8 no mapping MAP 1 MEASURE 2.8 MAP 1.6 MEASURE 2.9 MDS-03 MDS-04 no mapping Art. 31 Art. 34(1)(2) ATRS Tier 1 ATRS 2.2 GenAI 3 CoE Art. 14(2) OECD 1.3 G7 Action 3 CoE Art. 15(2) 1.9 3.5 1.7 no mapping Label Art. 4 Label Art. 5 GenAI Art. 12 DeepSyn Art. 16 DeepSyn Art. 17 GenAI Art. 19 AlgoRec Art. 16 GB/T 45654 Content labelling ?
Inventory and registration Art. 49 Art. 71 Art. 6 Art. 3(1) Art. 52 no mapping no mapping A.4 no mapping GOVERN 1.6 GOVERN 1.7 STA-08 IAM-03 no mapping Art. 33 ATRS Tier 1 no mapping no mapping 3.1 no mapping AlgoRec Art. 24 DeepSyn Art. 19 GenAI Art. 17 TC260 App. 2 II.2 TC260 4.4.1
Logging and traceability Art. 12 Art. 26(6) Art. 26 Art. 19 no mapping no mapping A.6 A.6.2.8 ? no mapping MANAGE 4 MEASURE 3 LOG-09 LOG-12 no mapping Art. 34(1)(5) no mapping Agentic 2.3.3 OECD 1.5(b) 4.3 prEN 18229-1 ? TC260 App. 2 II.6 TC260 5.3.6 Label Art. 5
Human oversight Art. 14 Art. 26 Art. 14(4)(b) no mapping Art. 22 A.9 no mapping MANAGE 2.4 MAP 3.5 GOVERN 3.2 GRC-15 ASI09 Art. 34(1)(4) UK GDPR Art. 22C ATRS 2.3.2 Agentic 2.2.2 CoE Art. 8 OECD 1.2(b) 3.9 no mapping TC260 App. 2 II.3 AlgoRec Art. 17 GenAI Art. 10
Runtime guardrails Art. 5 Art. 15 Art. 5(1)(a)–(b) Safety C5 no mapping A.9 A.6 no mapping MANAGE 2 TVM-13 AIS-09 AIS-10 LLM01:2026 LLM10:2026 LLM06:2026 no mapping no mapping Agentic 2.3.1 no mapping no mapping no mapping TC260 App. 2 II.5 TC260 3.2.1 GenAI Art. 10 GenAI Art. 14 DeepSyn Art. 10 AlgoRec Art. 8 AlgoRec Art. 9
Robustness, security and evaluations Art. 15 Art. 55 Art. 60 Art. 15(3) Art. 9 Art. 42(3) Safety 3.2 Safety C6 Art. 32 A.6 9.1 no mapping MEASURE 2 MEASURE 2.7 MEASURE 2.1 MEASURE 1 MDS-06 MDS-07 AIS-05 LLM01:2026 ASI05 Art. 32(1) no mapping GenAI 5 GenAI 6 Agentic 2.3.2 CoE Art. 16(2)(g) OECD 1.4 G7 Action 1 3.7 3.2 no mapping TC260 3 TC260 App. 2 II.6 DeepSyn Art. 15 DeepSyn Art. 20 GB/T 45654 Security assessment ? TC260 5.3.14 GenAI Art. 17
Incident response and monitoring Art. 72 Art. 73 Art. 26(5) Art. 55 Art. 3(49) Art. 20 Safety C9 Safety 3.5 Arts. 33–34 A.8 10.2 no mapping MANAGE 4 MANAGE 4.3 MANAGE 2.4 GOVERN 4.3 SEF-07 SEF-08 no mapping Art. 32(1) no mapping GenAI 4 Agentic 2.3.3 G7 Action 2 G7 Action 4 4.1 4.2 no mapping TC260 5.3.7 TC260 5.3.18 GenAI Art. 14 GenAI Art. 15 TC260 App. 2 II.6 AlgoRec Art. 7
Supply chain and third parties Art. 25 Art. 25(4) Art. 26 Art. 22 Art. 23 Art. 24 Art. 54 Transparency 1.2 Art. 28 Arts. 44–46 A.10 no mapping GOVERN 6 MAP 4 MANAGE 3 MANAGE 3.1 GOVERN 6.2 STA-10 STA-09 LLM04:2026 ASI04 no mapping ATRS 2.1.4 no mapping G7 Action 11 2.6 no mapping TC260 App. 2 II.4 TC260 4.4.4 GenAI Art. 7 DeepSyn Art. 14
Prohibited practices Art. 5 no mapping no mapping A.9.4 ? no mapping GOVERN 1.1 GRC-09 HRS-15 no mapping no mapping no mapping Agentic 2.1.1 CoE Art. 16(4) no mapping no mapping GenAI Art. 4
Fairness and non-discrimination Art. 10(2)(f)–(g) Art. 4a no mapping Art. 5(1)(a) Art. 9 A.5.4 ? no mapping MEASURE 2.11 GOVERN 3.1 GRC-11 no mapping no mapping ATRS 2.4.2 no mapping CoE Art. 10 OECD 1.2 2.7 3.8 no mapping GenAI Art. 4(2) AlgoRec Art. 21
Privacy and data protection Art. 59 Art. 4a no mapping Art. 5 Art. 6 Art. 25 Art. 35 A.7 no mapping MEASURE 2.10 DSP-08 DSP-22 LLM02:2026 no mapping UK GDPR Art. 22B GenAI 2 CoE Art. 11 OECD 1.2 G7 Action 11 2.8 no mapping GenAI Art. 7(3) GenAI Art. 11
Explainability and right to explanation Art. 86 Art. 13(3)(b)(iv)–(v) no mapping Art. 15(1)(h) Art. 13(2)(f) Art. 22(3) A.8.2 ? no mapping MEASURE 2.9 MEASURE 2.8 GRC-13 GRC-14 no mapping Art. 34(1)(2) UK GDPR Art. 22C ATRS 2.3.5 GenAI 3 OECD 1.3 CoE Art. 14(2) no mapping no mapping AlgoRec Art. 17
AI literacy and competence Art. 4 Art. 26(2) Art. 95(2)(c) no mapping Art. 39(1)(b) ? 7.2 ? 7.3 ? no mapping GOVERN 2.2 MAP 3.4 HRS-14 HRS-11 no mapping no mapping ATRS 2.3.4 Agentic 2.4 GenAI 9 no mapping 1.4 no mapping GenAI Art. 10
Conformity assessment and certification Art. 43 Art. 47 Art. 48 Art. 40 no mapping Art. 42 ? 9.2 ? ISO/IEC 42006 MEASURE 1.3 A&A-02 A&A-04 no mapping Art. 33 no mapping GenAI 5 no mapping 1.8 EN 18286 GenAI Art. 17
GPAI and foundation models Art. 53 Art. 55 Art. 51 Art. 56 Transparency 1.1 Safety C1 Safety 3.2 Safety C7 no mapping no mapping no mapping no mapping MDS-12 MDS-03 no mapping Art. 32 no mapping GenAI 8 G7 Action 1 no mapping no mapping GenAI Art. 7
IP and copyright Art. 53(1)(c) Art. 53(1)(d) Copyright 1.1 Copyright 1.2 Copyright 1.3 Copyright 1.4 Copyright 1.5 no mapping no mapping no mapping GOVERN 6.1 MAP 4.1 DSP-20 no mapping no mapping no mapping GenAI 2 G7 Action 11 no mapping no mapping GenAI Art. 7(2) GenAI Art. 4(3)
Agent identity and autonomy Art. 14 no mapping no mapping no mapping no mapping GOVERN 3.2 IAM-18 AIS-11 IAM-12 ASI03 LLM03:2026 ASI02 ASI07 ASI10 no mapping no mapping Agentic 2.1.2 Agentic 2.2.2 no mapping no mapping no mapping TC260 App. 2 II.2 TC260 App. 2 II.3
Content provenance and deepfakes Art. 50(2) Art. 50(4) Art. 3(60) no mapping no mapping no mapping no mapping no mapping MDS-09 LLM07:2026 Art. 31 no mapping GenAI 7 G7 Action 7 no mapping no mapping Label Art. 4 Label Art. 5 DeepSyn Art. 17 GenAI Art. 12
Sandboxes and real-world testing Art. 57 Art. 60 Art. 58 Art. 59 Art. 61 no mapping no mapping A.6.2.4 ? no mapping MEASURE 2.3 AIS-13 no mapping no mapping no mapping Agentic 2.3.2 CoE Art. 13 no mapping no mapping TC260 App. 2 II.6
Environmental impact Annex XI 1(2)(e) Art. 40(2) Art. 95(2)(b) Transparency 1.1 no mapping no mapping no mapping MEASURE 2.12 no mapping no mapping no mapping no mapping GenAI 9 OECD 1.1 no mapping no mapping no mapping
Deployment, change and decommissioning Art. 26 Art. 25 Art. 43(4) Art. 20 Art. 79 Art. 86 no mapping no mapping A.6.2.5 ? A.6.2.6 ? A.9 no mapping MANAGE 2.4 MANAGE 4.1 GOVERN 1.7 AIS-06 CCC-01 DSP-02 no mapping no mapping no mapping Agentic 2.3.3 CoE Art. 16(2)(g) OECD 1.4 4.4 4.5 no mapping TC260 5.3 TC260 5.3.19

Clause-to-clause explorer

Pick one or more source frameworks and a target. Two clauses are paired when the crosswalk files them under the same topic, so a pair says "these deal with the same thing" (OSCAL intersects-with), never "meeting one meets the other". The gap view lists the target clauses in this crosswalk that no chosen source reaches; it is not a list of every clause the target contains.

Every export says “illustrative, not a claim of conformity” inside the file. The OSCAL export is a mapping collection in the NIST OSCAL 1.2.3 Control Mapping model: one mapping per source framework, relationship intersects-with, with gap summaries. Its id-refs are the crosswalk clause ids (CSA’s own control ids for the AICM), because most of these instruments publish no OSCAL catalog to resolve against.

By topic

Each topic, its summary and stack layers, then every mapped reference in full.

Risk management

Identifying, analysing and treating AI risks across the lifecycle, and keeping the treatment current as the system and its context change.

L1 L3

In the Body of Knowledge: 13. Where risk management sits

Governance and accountability

The policies, roles and accountability structures that put a named owner behind every AI decision and control.

L1

In the Body of Knowledge: 12. Running the AI governance program

  • Art. 17 EU AI Act Quality management system The QMS that assigns and documents responsibilities. Source ↗ Obligation page →
  • Art. 4 related EU AI Act AI literacy Staff competence underpins accountable operation. Source ↗ Obligation page →
  • Art. 87 related EU AI Act Reporting of infringements and protection of reporting persons Source ↗
  • Safety C8 related GPAI Code Commitment 8: Systemic risk responsibility allocation Source ↗ Obligation page →
  • Art. 5(2) GDPR Accountability The controller must demonstrate compliance, including any claim that a model is anonymous. Source ↗
  • 5.1 ISO 42001 Leadership and commitment Source ↗
  • 5.2 ISO 42001 AI policy Source ↗
  • 5.3 ISO 42001 Roles, responsibilities and authorities Source ↗
  • A.2 ISO 42001 Policies related to AI Source ↗ Obligation page →
  • A.3 ISO 42001 Internal organization Source ↗ Obligation page →
  • 9.3 ? not yet verified against the source ISO 42001 Management review Clause id and title as listed in the AI RMF to ISO/IEC FDIS 42001 crosswalk (contributed by Microsoft to NIST's AI Resource Center) and in CSA's AICM v1.1.1 mapping; the published ISO text was not opened. Source ↗
  • 7.2 ? related not yet verified against the source ISO 42001 Competence Clause id and title as listed in the AI RMF to ISO/IEC FDIS 42001 crosswalk (contributed by Microsoft to NIST's AI Resource Center) and in CSA's AICM v1.1.1 mapping; the published ISO text was not opened. Source ↗
  • 9.2 ? related not yet verified against the source ISO 42001 Internal audit Clause id and title as listed in the AI RMF to ISO/IEC FDIS 42001 crosswalk (contributed by Microsoft to NIST's AI Resource Center) and in CSA's AICM v1.1.1 mapping; the published ISO text was not opened. Source ↗
  • 10.1 ? related not yet verified against the source ISO 42001 Continual improvement Clause id and title as listed in the AI RMF to ISO/IEC FDIS 42001 crosswalk (contributed by Microsoft to NIST's AI Resource Center) and in CSA's AICM v1.1.1 mapping; the published ISO text was not opened. Source ↗
  • GOVERN 1 NIST AI RMF GOVERN 1: Policies, processes, procedures, and practices across the organization related to the mapping, measuring, and managing of AI risks are in place, transparent, and implemented effectively Source ↗ Obligation page →
  • GOVERN 2 NIST AI RMF GOVERN 2: Accountability structures are in place so that the appropriate teams and individuals are empowered, responsible, and trained Source ↗ Obligation page →
  • GOVERN 4 related NIST AI RMF GOVERN 4: Organizational teams are committed to a culture that considers and communicates AI risk Source ↗ Obligation page →
  • GOVERN 5 related NIST AI RMF GOVERN 5: Processes are in place for robust engagement with relevant AI actors Source ↗ Obligation page →
  • GRC-01 CSA AICM Governance Program Policy and Procedures Source ↗ Obligation page →
  • GRC-06 CSA AICM Governance Responsibility Model Source ↗ Obligation page →
  • Art. 36 related Korea AI Act Domestic representative Source ↗ Obligation page →
  • ATRS 2.1 UK ATRS Owner and responsibility Source ↗
  • GenAI 1 Singapore GenAI Accountability Source ↗ Obligation page →
  • Agentic 2.2.1 Singapore Agentic Clear allocation of responsibilities within and outside the organisation Source ↗
  • OECD 1.5 OECD AI Principles Accountability Source ↗
  • CoE Art. 9 related CoE Convention Accountability and responsibility Source ↗
  • G7 Action 5 related G7 Code Develop, implement and disclose AI governance and risk-management policies Source ↗
  • 1.2 GAO AI Accountability Roles and responsibilities: define clear roles, responsibilities, and delegation of authority for the AI system Source ↗ Obligation page →
  • 1.1 related GAO AI Accountability Clear goals: define clear goals and objectives for the AI system Source ↗ Obligation page →
  • 1.3 related GAO AI Accountability Values: demonstrate a commitment to values and principles established by the entity Source ↗ Obligation page →
  • EN 18286 related EN 18286 Quality management system for EU AI Act regulatory purposes Published July 2026; supports Art. 17. No Official Journal citation, so no presumption of conformity, as of 2026-09-24. Source ↗
  • TC260 4 TC260 Framework 3.0 Comprehensive governance measures Organisational and institutional governance measures; printed p. 85. Source ↗ Obligation page →
  • TC260 5.3.12 TC260 Framework 3.0 Traceable chain of responsibility A traceable responsibility chain across the lifecycle; printed p. 103. Source ↗ Obligation page →
  • GenAI Art. 9 China GenAI Measures Provider responsibility as content producer Providers bear network-information content-producer responsibility; CAC text. Source ↗ Obligation page →
  • AlgoRec Art. 7 China Algo. Rec. Algorithm-security responsibility system Providers establish algorithm-security management systems; CAC text. Source ↗ Obligation page →
  • DeepSyn Art. 7 China Deep Synthesis Information-security responsibility system Providers establish management systems (registration, review, ethics, data and personal-information protection); CAC text. Source ↗ Obligation page →

Impact assessment

Assessing an AI system's impact on fundamental rights, individuals and society before and during deployment.

L1 L2

In the Body of Knowledge: 18. The EU AI Act in one pass: fundamental rights impact assessment

  • Art. 27 EU AI Act Fundamental rights impact assessment for high-risk AI systems See pattern: /bok/patterns#pattern-fria-as-code Source ↗ Obligation page →
  • Art. 9 related EU AI Act Risk management system Risk management and the FRIA cross-reference each other. Source ↗ Obligation page →
  • Art. 35 GDPR Data protection impact assessment The DPIA is the privacy twin of the FRIA; an AI DPIA adds training sources, memorisation and inference risks. Source ↗
  • Art. 36 related GDPR Prior consultation Source ↗
  • 6.1.4 ISO 42001 AI system impact assessment Source ↗
  • 8.4 ISO 42001 AI system impact assessment (operation) Source ↗
  • A.5 ISO 42001 Assessing impacts of AI systems See pattern: /bok/patterns#pattern-fria-as-code Source ↗ Obligation page →
  • 42005 5.8 ? not yet verified against the source ISO 42005 Performing the AI system impact assessment Clause as listed in the INCITS/AI crosswalk against the DIS of ISO/IEC 42005 (2025-08-14, on NIST's AI Resource Center); numbering not checked against the published 2025 text. Source ↗
  • 42005 6.8 ? not yet verified against the source ISO 42005 Actual and reasonably foreseeable impacts Clause as listed in the INCITS/AI crosswalk against the DIS of ISO/IEC 42005 (2025-08-14, on NIST's AI Resource Center); numbering not checked against the published 2025 text. Source ↗
  • 42005 5.12 ? related not yet verified against the source ISO 42005 Monitoring and review Clause as listed in the INCITS/AI crosswalk against the DIS of ISO/IEC 42005 (2025-08-14, on NIST's AI Resource Center); numbering not checked against the published 2025 text. Source ↗
  • MAP 3 NIST AI RMF MAP 3: AI capabilities, targeted usage, goals, and expected benefits and costs are understood Source ↗ Obligation page →
  • MAP 5 NIST AI RMF MAP 5: Impacts to individuals, groups, communities, organizations, and society are characterized Source ↗ Obligation page →
  • GRC-10 CSA AICM AI Impact Assessment Source ↗ Obligation page →
  • DSP-09 related CSA AICM Data Protection Impact Assessment Source ↗ Obligation page →
  • Art. 35 Korea AI Act Impact assessment (best-effort duty) Operators shall endeavour to assess the effect of high-impact AI on fundamental rights. Source ↗ Obligation page →
  • ATRS 2.5.1 UK ATRS Impact assessments Source ↗
  • CoE Art. 16 related CoE Convention Risk and impact management framework Source ↗
  • 1.5 related GAO AI Accountability Stakeholder involvement: include diverse perspectives from a community of stakeholders throughout the AI life cycle Source ↗ Obligation page →
  • TC260 Appendix 1 TC260 Framework 3.0 Grading principles Grading principles for classifying risk; printed pp. 109-112. Source ↗ Obligation page →
  • GenAI Art. 17 China GenAI Measures Security assessment Pre-deployment security assessment for public-opinion services; CAC text. Source ↗ Obligation page →
  • TC260 2.2 related TC260 Framework 3.0 Safety risks in the application of AI Application-layer risks to assess (agentic, embodied, cybersecurity, content, personal information, real-world); printed p. 60. Source ↗ Obligation page →

Data governance

Governing the data an AI system trains on and processes: lawful sourcing, quality, lineage and protection of personal and input data.

L2 L3

In the Body of Knowledge: 14. Governing AI development

  • Art. 10 EU AI Act Data and data governance Training, validation and test data quality and governance. Source ↗ Obligation page →
  • Art. 10(2)(f)–(g) EU AI Act Examination for possible biases; measures to detect, prevent and mitigate them Source ↗ Obligation page →
  • Art. 4a related EU AI Act Special-category data for bias detection Post-Omnibus new article: a lawful basis to process special-category data to detect and correct bias. Obligation page →
  • Art. 53 related EU AI Act Obligations for providers of general-purpose AI models Art. 53(1)(d): public summary of the content used for training, on the AI Office template. Source ↗
  • Art. 53(1)(c) related EU AI Act Copyright policy, including rights reservations Source ↗
  • Art. 5(1)(e) related EU AI Act Prohibited: untargeted scraping of facial images Facial-recognition databases built by untargeted scraping of the internet or CCTV are banned; a sourcing rule for data pipelines. Source ↗
  • Copyright 1.1–1.5 related GPAI Code Commitment 1: Copyright policy (Measures 1.1 to 1.5) Source ↗ Obligation page →
  • Art. 5(1)(c) GDPR Data minimisation Minimisation argued feature by feature for training, retrieval, logs and eval sets. Source ↗
  • Art. 25 GDPR Data protection by design and by default Source ↗
  • Art. 9 related GDPR Processing of special categories of personal data Sits beside AI Act Art. 4a on bias-detection processing; inferred sensitive data counts. Source ↗
  • A.7 ISO 42001 Data for AI systems Source ↗ Obligation page →
  • A.7.3 ? not yet verified against the source ISO 42001 Acquisition of data Clause id and title as listed in the AI RMF to ISO/IEC FDIS 42001 crosswalk (contributed by Microsoft to NIST's AI Resource Center) and in CSA's AICM v1.1.1 mapping; the published ISO text was not opened. Source ↗ Obligation page →
  • A.4 related ISO 42001 Resources for AI systems Data as a governed resource. Source ↗ Obligation page →
  • MAP 2 related NIST AI RMF MAP 2: Categorization of the AI system is performed Data categorisation and provenance. Source ↗ Obligation page →
  • MEASURE 2.10 related NIST AI RMF MEASURE 2.10: Privacy risk of the AI system is examined and documented Source ↗ Obligation page →
  • MEASURE 2.11 related NIST AI RMF MEASURE 2.11: Fairness and bias are evaluated and results are documented Source ↗ Obligation page →
  • DSP-20 CSA AICM Data Provenance and Transparency Source ↗ Obligation page →
  • DSP-21 related CSA AICM Data Poisoning Prevention & Detection Source ↗ Obligation page →
  • LLM05:2026 related OWASP LLM Data and Model Poisoning Source ↗ Obligation page →
  • ATRS 2.4.3 UK ATRS Development data specification Source ↗
  • GenAI 2 Singapore GenAI Data Source ↗ Obligation page →
  • 2.1 GAO AI Accountability Sources: document sources and origins of data used to develop the models Source ↗ Obligation page →
  • 2.2 GAO AI Accountability Reliability: assess reliability of data used to develop the models Source ↗ Obligation page →
  • 2.4 related GAO AI Accountability Variable selection: assess data variables used in the AI component models Source ↗ Obligation page →
  • 2.5 related GAO AI Accountability Enhancement: assess the use of synthetic, imputed, and/or augmented data Source ↗ Obligation page →
  • TC260 2.1.3 TC260 Framework 3.0 Data safety risks Inherent data risks (quality, poisoning, leakage); printed p. 57. Source ↗ Obligation page →
  • GenAI Art. 7 China GenAI Measures Training-data lawful sourcing Lawful sources, IP and personal-information compliance for training data; CAC text. Source ↗ Obligation page →
  • GenAI Art. 8 China GenAI Measures Data-annotation standards Clear, specific annotation rules and quality checks; CAC text. Source ↗ Obligation page →
  • GenAI Art. 11 China GenAI Measures Protection of user input and records No unlawful retention of user input and usage records; CAC text. Source ↗ Obligation page →
  • DeepSyn Art. 14 China Deep Synthesis Training-data management Providers and technical supporters secure training data and personal information; CAC text. Source ↗ Obligation page →
  • GB/T 45654 Corpus security ? not yet verified against the source GB/T 45654 Training-corpus (data) security requirements GB/T 45654-2025 corpus-security requirements (TC260-003 predecessor §5). The official listing shows the standard as current (issued 2025-04-25, implemented 2025-11-01; checked 2026-09-24), but the full text is only offered there as an image preview, so the clause id is not verified against it. Source ↗ Obligation page →
  • TC260 5.1 related TC260 Framework 3.0 Model R&D safety guidelines Training-data governance during model R&D; printed p. 95. Source ↗ Obligation page →

Documentation and transparency

Technical documentation, disclosures and content labelling that make an AI system legible to regulators, deployers and users.

L2
  • Art. 11 EU AI Act Technical documentation Annex IV technical documentation. Source ↗ Obligation page →
  • Art. 13 EU AI Act Transparency and provision of information to deployers Source ↗ Obligation page →
  • Art. 53 EU AI Act Obligations for providers of general-purpose AI models Model documentation and training-content summary for GPAI providers. Source ↗ Obligation page →
  • Art. 50 related EU AI Act Transparency obligations for providers and deployers of certain AI systems User-facing disclosure and machine-readable content marking. Source ↗ Obligation page →
  • Art. 86 related EU AI Act Right to explanation of individual decision-making Transparency that reaches the affected person: reason codes and an appeal route. Source ↗
  • Art. 18 related EU AI Act Documentation keeping Source ↗
  • Art. 43 related EU AI Act Conformity assessment Source ↗
  • Art. 53(1)(d) related EU AI Act Public summary of the content used for training Source ↗
  • Art. 50(2), 50(4) related EU AI Act Machine-readable marking of synthetic content; disclosure of deep fakes Source ↗ Obligation page →
  • Transparency 1.1 GPAI Code Drawing up and keeping up-to-date model documentation Source ↗ Obligation page →
  • Transparency 1.2 related GPAI Code Providing relevant information Source ↗ Obligation page →
  • Arts. 13–14 GDPR Information to be provided to the data subject Notice versioned with the model card; Art. 14 covers scraped or licensed training data. Source ↗
  • Art. 30 related GDPR Records of processing activities Source ↗
  • 7.5 ISO 42001 Documented information Source ↗
  • A.6 ISO 42001 AI system life cycle Lifecycle documentation. Source ↗ Obligation page →
  • A.8 ISO 42001 Information for interested parties Source ↗ Obligation page →
  • MAP 1 related NIST AI RMF MAP 1: Context is established and understood Documenting context and intended use. Source ↗ Obligation page →
  • MEASURE 2.8 related NIST AI RMF MEASURE 2.8: Risks associated with transparency and accountability are examined and documented Source ↗ Obligation page →
  • MAP 1.6 related NIST AI RMF MAP 1.6: System requirements are elicited from and understood by relevant AI actors. Design decisions take socio-technical implications into account to address AI risks Source ↗ Obligation page →
  • MEASURE 2.9 related NIST AI RMF MEASURE 2.9: The AI model is explained, validated, and documented, and AI system output is interpreted within its context as identified in the MAP function to inform responsible use and governance Source ↗ Obligation page →
  • MDS-03 CSA AICM Model Documentation Source ↗ Obligation page →
  • MDS-04 related CSA AICM Model Documentation Requirements Source ↗ Obligation page →
  • Art. 31 Korea AI Act Transparency: prior notice, output labelling, realistic synthetic content Source ↗ Obligation page →
  • Art. 34(1)(2) related Korea AI Act Explanation plan: result, main criteria, training-data overview Source ↗ Obligation page →
  • ATRS Tier 1 UK ATRS Summary information Source ↗
  • ATRS 2.2 related UK ATRS Description and rationale Source ↗
  • GenAI 3 Singapore GenAI Trusted Development and Deployment Source ↗ Obligation page →
  • CoE Art. 14(2) CoE Convention Documentation sufficient to contest decisions; complaint to authorities Source ↗
  • OECD 1.3 OECD AI Principles Transparency and explainability Source ↗
  • G7 Action 3 G7 Code Publicly report capabilities, limitations and domains of use Source ↗
  • CoE Art. 15(2) related CoE Convention Notification of interaction with an AI system Source ↗
  • 1.9 GAO AI Accountability Transparency: enable external stakeholders to access information on the design, operation, and limitations of the AI system Source ↗ Obligation page →
  • 3.5 GAO AI Accountability Documentation: document the methods for assessment, performance metrics, and outcomes of the AI system Source ↗ Obligation page →
  • 1.7 related GAO AI Accountability Specifications: establish and document technical specifications Source ↗ Obligation page →
  • Label Art. 4 China AI Labelling Explicit labels for generated content Visible labels on AI-generated and synthetic content; CAC text. Source ↗ Obligation page →
  • Label Art. 5 China AI Labelling Implicit (metadata) labels Implicit labels embedded in file metadata; CAC text. Source ↗ Obligation page →
  • GenAI Art. 12 China GenAI Measures Labelling of generated content Label generated images and video per the Deep Synthesis rules; CAC text. Source ↗ Obligation page →
  • DeepSyn Art. 16 China Deep Synthesis Implicit technical labels Non-disruptive technical marks on synthetic content; CAC text. Source ↗ Obligation page →
  • DeepSyn Art. 17 China Deep Synthesis Conspicuous labels for confusable content Prominent labels where synthetic media could mislead; CAC text. Source ↗ Obligation page →
  • GenAI Art. 19 related China GenAI Measures Disclosure to regulators Disclose training-data sources, scale and labelling mechanisms on request; CAC text. Source ↗ Obligation page →
  • AlgoRec Art. 16 related China Algo. Rec. Notice that recommendation is used Conspicuously inform users that algorithmic recommendation is in use; CAC text. Source ↗ Obligation page →
  • GB/T 45654 Content labelling ? related not yet verified against the source GB/T 45654 Generated-content labelling requirements GB/T 45654-2025 content-labelling requirements (aligned with the 2025 Labelling Measures). The official listing shows the standard as current (issued 2025-04-25, implemented 2025-11-01; checked 2026-09-24), but the full text is only offered there as an image preview, so the clause id is not verified against it. Source ↗ Obligation page →

Inventory and registration

Keeping an inventory of AI systems and agents and, where required, registering or filing them with the authorities.

L2

In the Body of Knowledge: 11. AI, defined for governance

Logging and traceability

Automatic, tamper-evident logs and records that make an AI system's behaviour reconstructable after the fact.

L4

Human oversight

Human-in-the-loop checkpoints, approval gates and the ability to intervene in or stop an AI system.

L4
  • Art. 14 EU AI Act Human oversight See pattern: /bok/patterns#pattern-human-in-the-loop-gate Source ↗ Obligation page →
  • Art. 26 related EU AI Act Obligations of deployers of high-risk AI systems Deployers assign the humans who oversee the system. Source ↗ Obligation page →
  • Art. 14(4)(b) related EU AI Act Awareness of automation bias Gate logs approver, time to decide and override rate so degrading oversight is visible. Source ↗ Obligation page →
  • Art. 22 GDPR Automated individual decision-making, including profiling Human intervention and contest for solely automated significant decisions. Source ↗
  • A.9 ISO 42001 Use of AI systems Oversight of AI systems in use. Source ↗ Obligation page →
  • MANAGE 2.4 NIST AI RMF MANAGE 2.4: Mechanisms are in place and applied, and responsibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use See pattern: /bok/patterns#pattern-human-in-the-loop-gate Source ↗ Obligation page →
  • MAP 3.5 NIST AI RMF MAP 3.5: Processes for human oversight are defined, assessed, and documented in accordance with organizational policies from the GOVERN function Source ↗ Obligation page →
  • GOVERN 3.2 related NIST AI RMF GOVERN 3.2: Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight of AI systems Source ↗ Obligation page →
  • GRC-15 CSA AICM Human supervision Source ↗ Obligation page →
  • ASI09 related OWASP Agentic Human-Agent Trust Exploitation Source ↗ Obligation page →
  • Art. 34(1)(4) Korea AI Act Human management and supervision Source ↗ Obligation page →
  • UK GDPR Art. 22C UK DUAA Safeguards for automated decision-making Inserted into the UK GDPR by DUAA s. 80: information, representations, human intervention and contest. Source ↗ Obligation page →
  • ATRS 2.3.2 UK ATRS Human review Source ↗
  • Agentic 2.2.2 Singapore Agentic Design for meaningful human oversight Source ↗
  • CoE Art. 8 related CoE Convention Transparency and oversight Source ↗
  • OECD 1.2(b) related OECD AI Principles Human agency and oversight safeguards Source ↗
  • 3.9 GAO AI Accountability Human supervision: define and develop procedures for human supervision of the AI system Source ↗ Obligation page →
  • TC260 App. 2 II.3 TC260 Framework 3.0 Strengthen human approval Human approval checkpoints, tamper-proof approval logs, deny-by-default; printed pp. 121-122. Source ↗ Obligation page →
  • AlgoRec Art. 17 related China Algo. Rec. User option to switch off Users can opt out of algorithmic recommendation; CAC text. Source ↗ Obligation page →
  • GenAI Art. 10 related China GenAI Measures User guidance and protection Disclose scope of use and protect minors from over-reliance; CAC text. Source ↗ Obligation page →

Runtime guardrails

Controls that constrain an AI system while it runs: input/output filtering, tool-invocation limits, isolation and memory management.

L4

Robustness, security and evaluations

Testing an AI system for accuracy, robustness, security and adversarial failure, including red-teaming and sandbox validation.

L3 L4

Incident response and monitoring

Post-market monitoring, incident detection and reporting, and the complaint channels that surface real-world failures.

L5

In the Body of Knowledge: 17. Incidents, issues and root causes

Supply chain and third parties

Allocating responsibility along the AI value chain and managing risks from third-party models, data, tools and technical supporters.

L2 L5

In the Body of Knowledge: 18. The EU AI Act in one pass: who you are in the value chain

  • Art. 25 EU AI Act Responsibilities along the AI value chain See pattern: /bok/patterns#pattern-vendor--model-due-diligence-gate Source ↗ Obligation page →
  • Art. 25(4) EU AI Act Written agreement with third-party suppliers Source ↗ Obligation page →
  • Art. 26 related EU AI Act Obligations of deployers of high-risk AI systems Deployer duties toward upstream providers. Source ↗ Obligation page →
  • Art. 22 related EU AI Act Authorised representatives of providers of high-risk AI systems Source ↗
  • Art. 23 related EU AI Act Obligations of importers Source ↗
  • Art. 24 related EU AI Act Obligations of distributors Source ↗
  • Art. 54 related EU AI Act Authorised representatives of providers of general-purpose AI models Source ↗
  • Transparency 1.2 related GPAI Code Providing relevant information Information for downstream providers that integrate the model into their AI systems. Source ↗ Obligation page →
  • Art. 28 GDPR Processor AI vendor contracts: no-training clauses, retention, region, sub-processors, change notice. Source ↗
  • Arts. 44–46 related GDPR Transfers to third countries Remote inference endpoints and vendor telemetry outside the EEA are transfers. Source ↗
  • A.10 ISO 42001 Third-party and customer relationships Source ↗ Obligation page →
  • GOVERN 6 NIST AI RMF GOVERN 6: Policies and procedures are in place to address AI risks and benefits arising from third-party software and data and other supply chain issues Source ↗ Obligation page →
  • MAP 4 NIST AI RMF MAP 4: Risks and benefits are mapped for all AI system components including third-party software and data Source ↗ Obligation page →
  • MANAGE 3 NIST AI RMF MANAGE 3: AI risks and benefits from third-party entities are managed Source ↗ Obligation page →
  • MANAGE 3.1 NIST AI RMF MANAGE 3.1: AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented Source ↗ Obligation page →
  • GOVERN 6.2 related NIST AI RMF GOVERN 6.2: Contingency processes are in place to handle failures or incidents in third-party data or AI systems deemed to be high-risk Source ↗ Obligation page →
  • STA-10 CSA AICM Supply Chain Risk Management Source ↗ Obligation page →
  • STA-09 CSA AICM Service Bill of Material (BOM) Source ↗ Obligation page →
  • LLM04:2026 OWASP LLM Supply Chain Source ↗ Obligation page →
  • ASI04 OWASP Agentic Agentic Supply Chain Vulnerabilities Source ↗ Obligation page →
  • ATRS 2.1.4 related UK ATRS Third party involvement Source ↗
  • G7 Action 11 related G7 Code Implement data input measures and protect personal data and intellectual property Source ↗
  • 2.6 related GAO AI Accountability Dependency: assess interconnectivities and dependencies of data streams that operationalize the AI system Source ↗ Obligation page →
  • TC260 App. 2 II.4 TC260 Framework 3.0 Supply chain and tool management Supply-chain and tool-invocation management for agents; printed pp. 122-123. Source ↗ Obligation page →
  • TC260 4.4.4 related TC260 Framework 3.0 Open-source ecosystem Governance of the open-source AI ecosystem; printed p. 92. Source ↗ Obligation page →
  • GenAI Art. 7 related China GenAI Measures Lawful data and model sources Upstream training-data (and model) sourcing must be lawful; CAC text. Source ↗ Obligation page →
  • DeepSyn Art. 14 related China Deep Synthesis Providers and technical supporters Providers and their technical supporters share training-data duties (a value-chain relationship); CAC text. Draft mapped this to Art. 7, but Art. 14 is the article that names technical supporters. Source ↗ Obligation page →

Prohibited practices

Uses of AI that a jurisdiction bans outright or a framework treats as unacceptable, and the intake controls that keep them out of the portfolio.

L1

In the Body of Knowledge: 18. The EU AI Act in one pass: prohibited practices

  • Art. 5 EU AI Act Prohibited AI practices The Digital Omnibus adds new prohibitions that apply from 2026-12-02. Source ↗ Obligation page →
  • A.9.4 ? related not yet verified against the source ISO 42001 Intended use of the AI system Clause id and title as listed in the AI RMF to ISO/IEC FDIS 42001 crosswalk (contributed by Microsoft to NIST's AI Resource Center) and in CSA's AICM v1.1.1 mapping; the published ISO text was not opened. Source ↗ Obligation page →
  • GOVERN 1.1 related NIST AI RMF GOVERN 1.1: Legal and regulatory requirements involving AI are understood, managed, and documented Source ↗ Obligation page →
  • GRC-09 related CSA AICM Acceptable Use of the AI Service Source ↗ Obligation page →
  • HRS-15 related CSA AICM AI Acceptable Use Source ↗ Obligation page →
  • Agentic 2.1.1 related Singapore Agentic Determine suitable use cases for agent deployment Source ↗
  • CoE Art. 16(4) CoE Convention Assess the need for a moratorium, ban or other measures for incompatible uses Source ↗
  • GenAI Art. 4 related China GenAI Measures Prohibited content and baseline duties Point (1) lists content that must not be generated; points (2) to (5) set non-discrimination, IP, rights and transparency duties; CAC text. Source ↗ Obligation page →

Fairness and non-discrimination

Detecting and correcting bias in data, models and outcomes, and the lawful handling of the sensitive data that bias testing needs.

L2 L3

In the Body of Knowledge: 16. Fairness and explainability for practitioners

  • Art. 10(2)(f)–(g) EU AI Act Examination for possible biases; measures to detect, prevent and mitigate them Source ↗ Obligation page →
  • Art. 4a EU AI Act Special-category data for bias detection Added by the Digital Omnibus; strictly necessary, pseudonymised, access-controlled and deleted after correction. Source ↗ Obligation page →
  • Art. 5(1)(a) GDPR Lawfulness, fairness and transparency Source ↗
  • Art. 9 related GDPR Processing of special categories of personal data Source ↗
  • A.5.4 ? related not yet verified against the source ISO 42001 Assessing AI system impact on individuals or groups of individuals Clause id and title as listed in the AI RMF to ISO/IEC FDIS 42001 crosswalk (contributed by Microsoft to NIST's AI Resource Center) and in CSA's AICM v1.1.1 mapping; the published ISO text was not opened. Source ↗ Obligation page →
  • MEASURE 2.11 NIST AI RMF MEASURE 2.11: Fairness and bias as identified in the MAP function are evaluated and results are documented Source ↗ Obligation page → In the BoK →
  • GOVERN 3.1 related NIST AI RMF GOVERN 3.1: Decision-making related to mapping, measuring, and managing AI risks throughout the lifecycle is informed by a diverse team Source ↗ Obligation page →
  • GRC-11 CSA AICM Bias and Fairness Assessment Source ↗ Obligation page →
  • ATRS 2.4.2 related UK ATRS Model specification Model performance and the bias checks behind it are recorded here. Source ↗
  • CoE Art. 10 CoE Convention Equality and non-discrimination Source ↗
  • OECD 1.2 related OECD AI Principles Rule of law, human rights and democratic values, including fairness and privacy Source ↗
  • 2.7 GAO AI Accountability Bias: assess reliability, quality, and representativeness of the data used in operation, including potential biases Source ↗ Obligation page →
  • 3.8 GAO AI Accountability Bias: identify potential biases, inequities, and other societal concerns resulting from the AI system Source ↗ Obligation page →
  • GenAI Art. 4(2) China GenAI Measures Prevent discrimination in design, data, training and service Ethnicity, belief, country, region, sex, age, occupation and health; CAC text. Source ↗ Obligation page →
  • AlgoRec Art. 21 related China Algo. Rec. No unreasonable differential treatment in trading conditions Bars algorithmic price discrimination based on consumer preferences and habits; CAC text. Source ↗ Obligation page →

Privacy and data protection

Lawful basis, minimisation, privacy by design and the privacy attacks specific to models, wherever an AI system touches personal data.

L1 L2 L4

In the Body of Knowledge: 19. Privacy and data protection law applied to AI

Explainability and right to explanation

Explaining a model and an individual output to the people who use it or are affected by it, and the legal rights to an explanation and to contest.

L2 L4

In the Body of Knowledge: 18. The EU AI Act in one pass: explanation and notice to affected people

  • Art. 86 EU AI Act Right to explanation of individual decision-making Source ↗
  • Art. 13(3)(b)(iv)–(v) EU AI Act Information relevant to explain output; performance for specific persons or groups Source ↗ Obligation page →
  • Art. 15(1)(h) GDPR Meaningful information about the logic involved Source ↗
  • Art. 13(2)(f) related GDPR Existence of automated decision-making Source ↗
  • Art. 22(3) related GDPR Right to obtain human intervention and to contest the decision Source ↗
  • A.8.2 ? related not yet verified against the source ISO 42001 System documentation and information for users Clause id and title as listed in the AI RMF to ISO/IEC FDIS 42001 crosswalk (contributed by Microsoft to NIST's AI Resource Center) and in CSA's AICM v1.1.1 mapping; the published ISO text was not opened. Source ↗ Obligation page →
  • MEASURE 2.9 NIST AI RMF MEASURE 2.9: The AI model is explained, validated, and documented, and AI system output is interpreted within its context as identified in the MAP function to inform responsible use and governance Source ↗ Obligation page →
  • MEASURE 2.8 related NIST AI RMF MEASURE 2.8: Risks associated with transparency and accountability as identified in the MAP function are examined and documented Source ↗ Obligation page →
  • GRC-13 CSA AICM Explainability Requirement Source ↗ Obligation page →
  • GRC-14 CSA AICM Explainability Evaluation Source ↗ Obligation page →
  • Art. 34(1)(2) Korea AI Act Explanation plan: result, main criteria, training-data overview Source ↗ Obligation page →
  • UK GDPR Art. 22C UK DUAA Safeguards for automated decision-making Information about the decision, representations, human intervention and contest. Source ↗ Obligation page →
  • ATRS 2.3.5 related UK ATRS Appeals and review Source ↗
  • GenAI 3 related Singapore GenAI Trusted Development and Deployment Source ↗ Obligation page →
  • OECD 1.3 OECD AI Principles Transparency and explainability Source ↗
  • CoE Art. 14(2) related CoE Convention Documentation sufficient to contest decisions; complaint to authorities Source ↗
  • AlgoRec Art. 17 related China Algo. Rec. Explain where an algorithm significantly affects user rights Third paragraph; the first two give an opt-out and control over user tags; CAC text. Source ↗ Obligation page →

AI literacy and competence

Making sure the people who build, operate, oversee and use an AI system have the knowledge their role needs, with a record that shows it.

L1

In the Body of Knowledge: 18. The EU AI Act in one pass: AI literacy and bias-detection data

  • Art. 4 EU AI Act AI literacy Reworded by the Digital Omnibus: providers and deployers take measures to support AI literacy, without a guaranteed level. Source ↗ Obligation page → In the BoK →
  • Art. 26(2) related EU AI Act Oversight by people with the competence, training and authority it needs Source ↗ Obligation page →
  • Art. 95(2)(c) related EU AI Act Codes of conduct: promoting AI literacy Source ↗
  • Art. 39(1)(b) ? related not yet verified against the source GDPR DPO tasks: awareness-raising and training of staff Read on a secondary reproduction of the GDPR; EUR-Lex refused automated access on 2026-09-24 and chapter 19 does not cite this article (verify). Source ↗
  • 7.2 ? not yet verified against the source ISO 42001 Competence Clause id and title as listed in the AI RMF to ISO/IEC FDIS 42001 crosswalk (contributed by Microsoft to NIST's AI Resource Center) and in CSA's AICM v1.1.1 mapping; the published ISO text was not opened. Source ↗
  • 7.3 ? related not yet verified against the source ISO 42001 Awareness Clause id and title as listed in the AI RMF to ISO/IEC FDIS 42001 crosswalk (contributed by Microsoft to NIST's AI Resource Center) and in CSA's AICM v1.1.1 mapping; the published ISO text was not opened. Source ↗
  • GOVERN 2.2 NIST AI RMF GOVERN 2.2: The organization's personnel and partners receive AI risk management training to enable them to perform their duties and responsibilities consistent with related policies, procedures, and agreements Source ↗ Obligation page →
  • MAP 3.4 related NIST AI RMF MAP 3.4: Processes for operator and practitioner proficiency with AI system performance and trustworthiness, and relevant technical standards and certifications, are defined, assessed, and documented Source ↗ Obligation page →
  • HRS-14 CSA AICM AI Competency Training Source ↗ Obligation page →
  • HRS-11 related CSA AICM Security Awareness Training Source ↗ Obligation page →
  • ATRS 2.3.4 related UK ATRS Required training Source ↗
  • Agentic 2.4 Singapore Agentic Enable end-user responsibility Source ↗
  • GenAI 9 related Singapore GenAI AI for Public Good Includes upskilling workers. Source ↗ Obligation page →
  • 1.4 related GAO AI Accountability Workforce: recruit, develop, and retain personnel with multidisciplinary skills and experiences Source ↗ Obligation page →
  • GenAI Art. 10 related China GenAI Measures Guide users to understand and use generative AI rationally Also protects minors from over-reliance; CAC text. Source ↗ Obligation page →

Conformity assessment and certification

Demonstrating conformity before market entry, independent audit and certification, and the standards that carry a presumption of conformity.

L5

In the Body of Knowledge: 18. The EU AI Act in one pass: conformity assessment, declaration, marking and registration

  • Art. 43 EU AI Act Conformity assessment Source ↗ Obligation page →
  • Art. 47 related EU AI Act EU declaration of conformity Source ↗ Obligation page →
  • Art. 48 related EU AI Act CE marking Source ↗
  • Art. 40 related EU AI Act Harmonised standards and standardisation deliverables Presumption of conformity once a harmonised standard is cited in the Official Journal. Source ↗
  • Art. 42 ? related not yet verified against the source GDPR Certification Read on a secondary reproduction of the GDPR; EUR-Lex refused automated access on 2026-09-24 and chapter 19 does not cite this article (verify). Source ↗
  • 9.2 ? related not yet verified against the source ISO 42001 Internal audit Clause id and title as listed in the AI RMF to ISO/IEC FDIS 42001 crosswalk (contributed by Microsoft to NIST's AI Resource Center) and in CSA's AICM v1.1.1 mapping; the published ISO text was not opened. Source ↗
  • ISO/IEC 42006 ISO 42006 Requirements for bodies providing audit and certification of AI management systems The whole standard: who may credibly certify an organisation to ISO/IEC 42001. Source ↗ Obligation page →
  • MEASURE 1.3 related NIST AI RMF MEASURE 1.3: Internal experts who did not serve as front-line developers for the system and/or independent assessors are involved in regular assessments and updates Source ↗ Obligation page →
  • A&A-02 CSA AICM Independent Assessments Source ↗ Obligation page →
  • A&A-04 related CSA AICM Requirements Compliance Source ↗ Obligation page →
  • Art. 33 related Korea AI Act Confirmation of high-impact AI Source ↗ Obligation page →
  • GenAI 5 related Singapore GenAI Testing and Assurance Third-party testing and common testing standards. Source ↗ Obligation page →
  • 1.8 related GAO AI Accountability Compliance: ensure the AI system complies with relevant laws, regulations, standards, and guidance Source ↗ Obligation page →
  • EN 18286 related EN 18286 Quality management system for EU AI Act regulatory purposes A harmonised-standard candidate for Art. 17; not cited in the Official Journal as of 2026-09-24. Source ↗
  • GenAI Art. 17 related China GenAI Measures Security assessment and algorithm filing Services with public-opinion attributes or social-mobilisation capacity; CAC text. Source ↗ Obligation page →

GPAI and foundation models

Duties that attach to general-purpose and foundation models themselves: documentation for downstream providers, evaluation, and systemic-risk management.

L2 L3

In the Body of Knowledge: 18. The EU AI Act in one pass: general-purpose AI models

Agent identity and autonomy

Giving each agent its own identity and scoped permissions, bounding what it may do on its own, and keeping a human able to stop it.

L2 L4

In the Body of Knowledge: 05. Patterns: Agent Identity & Scoped Credentials

Content provenance and deepfakes

Marking synthetic content so it can be detected, labelling deepfakes for the people who see them, and verifying where content came from.

L2 L4

In the Body of Knowledge: 18. The EU AI Act in one pass: transparency cases

Sandboxes and real-world testing

Supervised regulatory sandboxes and testing in real-world conditions, with the plans, consent records and reversal paths they require.

L3

In the Body of Knowledge: 18. The EU AI Act in one pass: sandboxes and real-world testing

  • Art. 57 EU AI Act AI regulatory sandboxes At least one national sandbox per Member State, due by 2 Aug 2027 after the Digital Omnibus (was 2 Aug 2026). Source ↗ In the BoK →
  • Art. 60 EU AI Act Testing of high-risk AI systems in real world conditions outside AI regulatory sandboxes Source ↗ Obligation page →
  • Art. 58 related EU AI Act Detailed arrangements for, and functioning of, AI regulatory sandboxes Source ↗
  • Art. 59 related EU AI Act Further processing of personal data in the AI regulatory sandbox Source ↗
  • Art. 61 related EU AI Act Informed consent to participate in testing in real world conditions Source ↗
  • A.6.2.4 ? related not yet verified against the source ISO 42001 AI system verification and validation Clause id and title as listed in the AI RMF to ISO/IEC FDIS 42001 crosswalk (contributed by Microsoft to NIST's AI Resource Center) and in CSA's AICM v1.1.1 mapping; the published ISO text was not opened. Source ↗ Obligation page →
  • MEASURE 2.3 related NIST AI RMF MEASURE 2.3: AI system performance or assurance criteria are measured qualitatively or quantitatively and demonstrated for conditions similar to deployment setting(s) Source ↗ Obligation page →
  • AIS-13 related CSA AICM AI Sandboxing Technical isolation of AI tools and plugins, not a regulatory sandbox. Source ↗ Obligation page →
  • Agentic 2.3.2 related Singapore Agentic Before deploying, test agents Source ↗
  • CoE Art. 13 CoE Convention Safe innovation (controlled testing environments) Source ↗
  • TC260 App. 2 II.6 related TC260 Framework 3.0 Sandbox validation and red teaming Technical sandbox validation for agents, not a regulatory sandbox; printed pp. 124-125. Source ↗ Obligation page →

Environmental impact

Measuring and reporting the energy and resource use of training and running AI systems, and weighing it in design decisions.

L2 L5

In the Body of Knowledge: 22. Principles, soft law and standards: OECD AI Principles

  • Annex XI 1(2)(e) EU AI Act Known or estimated energy consumption of the GPAI model Part of the technical documentation GPAI providers keep under Art. 53(1)(a); may be estimated from compute where unknown. Source ↗ Obligation page →
  • Art. 40(2) related EU AI Act Standardisation deliverables on energy and resource performance Source ↗
  • Art. 95(2)(b) related EU AI Act Codes of conduct: environmental sustainability Source ↗
  • Transparency 1.1 GPAI Code Drawing up and keeping up-to-date model documentation The Model Documentation Form asks for energy used in training and inference. Source ↗ Obligation page →
  • MEASURE 2.12 NIST AI RMF MEASURE 2.12: Environmental impact and sustainability of AI model training and management activities as identified in the MAP function are assessed and documented Source ↗ Obligation page →
  • GenAI 9 related Singapore GenAI AI for Public Good Includes developing AI systems sustainably. Source ↗ Obligation page →
  • OECD 1.1 OECD AI Principles Inclusive growth, sustainable development and well-being Source ↗

Deployment, change and decommissioning

Putting a system into service, controlling changes that alter its risk, and withdrawing or retiring it safely when it no longer performs as intended.

L4 L5

In the Body of Knowledge: 15. Governing deployment and use

  • Art. 26 EU AI Act Obligations of deployers of high-risk AI systems Source ↗ Obligation page →
  • Art. 25 related EU AI Act Responsibilities along the AI value chain A substantial modification or a changed intended purpose makes the deployer a provider. Source ↗ Obligation page →
  • Art. 43(4) related EU AI Act New conformity assessment on substantial modification Source ↗ Obligation page →
  • Art. 20 related EU AI Act Corrective actions and duty of information Bring into conformity, withdraw, disable or recall. Source ↗
  • Art. 79 related EU AI Act Procedure at national level for dealing with AI systems presenting a risk Source ↗
  • Art. 86 related EU AI Act Right to explanation of individual decision-making Source ↗
  • A.6.2.5 ? not yet verified against the source ISO 42001 AI system deployment Clause id and title as listed in the AI RMF to ISO/IEC FDIS 42001 crosswalk (contributed by Microsoft to NIST's AI Resource Center) and in CSA's AICM v1.1.1 mapping; the published ISO text was not opened. Source ↗ Obligation page →
  • A.6.2.6 ? not yet verified against the source ISO 42001 AI system operation and monitoring Clause id and title as listed in the AI RMF to ISO/IEC FDIS 42001 crosswalk (contributed by Microsoft to NIST's AI Resource Center) and in CSA's AICM v1.1.1 mapping; the published ISO text was not opened. Source ↗ Obligation page →
  • A.9 related ISO 42001 Use of AI systems Source ↗ Obligation page →
  • MANAGE 2.4 NIST AI RMF MANAGE 2.4: Mechanisms are in place and applied, and responsibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use Source ↗ Obligation page →
  • MANAGE 4.1 NIST AI RMF MANAGE 4.1: Post-deployment AI system monitoring plans are implemented, including mechanisms for capturing and evaluating input from users and other relevant AI actors, appeal and override, decommissioning, incident response, recovery, and change management Source ↗ Obligation page →
  • GOVERN 1.7 NIST AI RMF GOVERN 1.7: Processes and procedures are in place for decommissioning and phasing out AI systems safely and in a manner that does not increase risks or decrease the organization's trustworthiness Source ↗ Obligation page →
  • AIS-06 CSA AICM Secure Application Deployment Source ↗ Obligation page →
  • CCC-01 related CSA AICM Change Management Policy and Procedures Source ↗ Obligation page →
  • DSP-02 related CSA AICM Secure Disposal Source ↗ Obligation page →
  • Agentic 2.3.3 related Singapore Agentic When deploying, continuously monitor and test Source ↗
  • CoE Art. 16(2)(g) related CoE Convention Testing before first use and when significantly modified Source ↗
  • OECD 1.4 related OECD AI Principles Robustness, security and safety The 2024 revision asks for mechanisms to override, repair or decommission safely. Source ↗
  • 4.4 related GAO AI Accountability Ongoing assessment: assess the utility of the AI system to ensure its relevance to the current context Source ↗ Obligation page →
  • 4.5 related GAO AI Accountability Scaling: identify conditions, if any, under which the AI system may be scaled or expanded beyond its current use Source ↗ Obligation page →
  • TC260 5.3 related TC260 Framework 3.0 Operators' safety guidelines Logs kept at least six months and audited; voluntary. Source ↗ Obligation page →
  • TC260 5.3.19 related TC260 Framework 3.0 Re-assessment on material change Source ↗ Obligation page →