Skip to main content

title: “Cross-Framework Mapping” description: “Relationships among AIGO, EU AI Act, ISO/IEC 42001, and NIST AI RMF.”

Cross-Framework Mapping

The AIGO cross-framework mapping provides a structured view of relationships among AIGO and selected external AI governance and regulatory frameworks.

Purpose

Organizations may need to operate against multiple frameworks simultaneously. The cross-framework mapping helps identify related governance concepts, requirements, controls, evidence expectations, lifecycle activities, and assurance considerations while preserving the distinctions between the underlying frameworks. The mapping can support: * governance architecture * requirements analysis * control alignment * evidence planning * implementation planning * assurance planning * gap analysis * traceability across frameworks

Current frameworks

The v0.1 cross-framework model considers: * AIGO Framework * European Union Artificial Intelligence Act * ISO/IEC 42001 * NIST AI Risk Management Framework

Shared concepts

Cross-framework relationships may involve areas such as: * governance * accountability * risk management * lifecycle management * controls * documentation * evidence * monitoring * transparency * assurance * continual improvement The presence of a relationship indicates an analytical connection between concepts. It does not necessarily indicate identical scope, obligation, implementation method, or evidence requirement.

Anti-equivalence principle

A shared relationship does not mean that the underlying requirements are interchangeable. AIGO intentionally preserves: * framework-specific authority * scope * terminology * applicability * obligation type * implementation expectations * evidence expectations * assurance requirements A mapping should therefore be interpreted as a traceability relationship rather than as a statement of equivalence.

Relationship to enterprise implementation

Cross-framework mappings can support organizations that need one internal governance operating model while maintaining traceability to multiple external frameworks. For example, an organization may use AIGO controls and governance processes as an internal operating layer while maintaining separate mappings to applicable regulatory, standards, or risk-management requirements. This can reduce duplicated governance activity while preserving the distinctions required by each external framework.

Mapping architecture

The repository separates cross-framework mapping concerns into dedicated mapping materials. The cross-framework package includes architecture, control, requirements, evidence, assurance, and gap-and-coverage perspectives. This allows organizations to examine a relationship at different levels rather than relying on a single high-level mapping table.

Maintenance

External frameworks can change independently of AIGO. Cross-framework mappings should therefore be reviewed when: * an external framework changes * AIGO requirements or controls change * regulatory applicability changes * mapping assumptions change * new evidence or assurance requirements emerge A mapping should always be interpreted against the current authoritative external source.

Important limitation

Cross-framework mappings are analytical and implementation-oriented materials. They do not: * establish legal compliance * provide legal advice * establish certification * establish accreditation * establish conformity assessment * imply endorsement by an external standards organization or regulator Organizations remain responsible for determining their own legal, regulatory, contractual, and certification obligations.

Canonical source

The complete cross-framework package is maintained in: mappings/cross-framework/ The repository is the canonical source for the AIGO-controlled mapping artifacts.