Directory
AI framework crosswalks
Clause-by-clause mappings between the major AI compliance frameworks. Every mapping cites the primary source published by the standard body or regulator. Use these to reuse controls across audits and cut duplicated effort.
NIST AI RMF → ISO/IEC 42001
NIST AI RMF and ISO/IEC 42001 target overlapping objectives but use different structures. RMF is voluntary US guidance built around four functions; ISO/IEC 42001 is a certifiable I…
EU AI Act → NIST AI RMF
The EU AI Act (Regulation 2024/1689) is a binding regulation with penalties; NIST AI RMF is voluntary US guidance. NIST AI RMF is widely used as the operational backbone to prove E…
ISO/IEC 42001 → ISO/IEC 27001
Both are ISO harmonized-structure management-system standards, so clauses 4-10 are nearly identical in wording. The Annex A control sets diverge — 27001 focuses on information secu…
ISO/IEC 42001 → SOC 2
SOC 2 is a US assurance report (Type I or Type II) against the AICPA Trust Services Criteria — Security, Availability, Processing Integrity, Confidentiality, Privacy. ISO/IEC 42001…
EU AI Act → GDPR
The EU AI Act does not replace GDPR — they apply cumulatively. GDPR governs personal-data processing (including by AI); the EU AI Act adds product-safety-style obligations for AI s…
Colorado AI Act → EU AI Act
Colorado SB 24-205 is the first US state law directly modeled on the EU AI Act. Both target "high-risk" AI systems that make consequential decisions about consumers (credit, employ…
NIST AI RMF → EU AI Act GPAI Code of Practice
The EU AI Act General-Purpose AI Code of Practice (Chapter V, Article 56) sets voluntary commitments for GPAI model providers. NIST AI RMF, and specifically NIST AI 600-1 (Generati…
HIPAA → EU AI Act
HIPAA regulates the use and disclosure of protected health information (PHI) by covered entities. The EU AI Act regulates AI systems placed on the EU market and, for healthcare, la…
More coming
We publish crosswalks only when a primary source exists (an official mapping from a standard body, regulator, or peer-reviewed publication). Suggest a mapping by contacting editorial.
Free vendor matchmaking
Running multiple frameworks in parallel?
Get matched with vendors that map controls across NIST AI RMF, ISO/IEC 42001, EU AI Act, GDPR, and SOC 2 so you can reuse evidence instead of duplicating audits.
No credit card. Independent directory — we do not sell software ourselves.