AI Compliance Vendors

Directory

AI framework crosswalks

Clause-by-clause mappings between the major AI compliance frameworks. Every mapping cites the primary source published by the standard body or regulator. Use these to reuse controls across audits and cut duplicated effort.

NIST AI RMF ISO/IEC 42001

NIST AI RMF and ISO/IEC 42001 target overlapping objectives but use different structures. RMF is voluntary US guidance built around four functions; ISO/IEC 42001 is a certifiable I

15 mappings·3 primary sources

EU AI Act NIST AI RMF

The EU AI Act (Regulation 2024/1689) is a binding regulation with penalties; NIST AI RMF is voluntary US guidance. NIST AI RMF is widely used as the operational backbone to prove E

12 mappings·2 primary sources

ISO/IEC 42001 ISO/IEC 27001

Both are ISO harmonized-structure management-system standards, so clauses 4-10 are nearly identical in wording. The Annex A control sets diverge — 27001 focuses on information secu

12 mappings·2 primary sources

ISO/IEC 42001 SOC 2

SOC 2 is a US assurance report (Type I or Type II) against the AICPA Trust Services Criteria — Security, Availability, Processing Integrity, Confidentiality, Privacy. ISO/IEC 42001

8 mappings·2 primary sources

EU AI Act GDPR

The EU AI Act does not replace GDPR — they apply cumulatively. GDPR governs personal-data processing (including by AI); the EU AI Act adds product-safety-style obligations for AI s

8 mappings·3 primary sources

Colorado AI Act EU AI Act

Colorado SB 24-205 is the first US state law directly modeled on the EU AI Act. Both target "high-risk" AI systems that make consequential decisions about consumers (credit, employ

6 mappings·2 primary sources

NIST AI RMF EU AI Act GPAI Code of Practice

The EU AI Act General-Purpose AI Code of Practice (Chapter V, Article 56) sets voluntary commitments for GPAI model providers. NIST AI RMF, and specifically NIST AI 600-1 (Generati

5 mappings·2 primary sources

HIPAA EU AI Act

HIPAA regulates the use and disclosure of protected health information (PHI) by covered entities. The EU AI Act regulates AI systems placed on the EU market and, for healthcare, la

6 mappings·2 primary sources

More coming

We publish crosswalks only when a primary source exists (an official mapping from a standard body, regulator, or peer-reviewed publication). Suggest a mapping by contacting editorial.

Free vendor matchmaking

Running multiple frameworks in parallel?

Get matched with vendors that map controls across NIST AI RMF, ISO/IEC 42001, EU AI Act, GDPR, and SOC 2 so you can reuse evidence instead of duplicating audits.

No credit card. Independent directory — we do not sell software ourselves.