Who this is for: Assessors (C3PAOs, Notified Bodies, ISO certification body auditors), multi-framework compliance teams managing overlapping AI obligations, GRC analysts building unified control catalogs, and organizations certified to one framework seeking to understand their coverage of the other two.

Assessor notice. This crosswalk is the publisher's analytical mapping for reference purposes. It is not an official mapping by NIST, ISO, CEN-CENELEC, or the European Commission. The three frameworks differ in legal authority, scope, and enforcement mechanisms. Organizations should consult qualified legal counsel when determining how compliance with one framework satisfies obligations under the others. SWT3 is an independent witness protocol -- it does not grant, deny, or influence compliance status under any framework.

All three frameworks are active. NIST AI RMF 1.0 published January 2023 (voluntary, US). ISO/IEC 42001:2023 published December 2023 (certifiable, international). EU AI Act entered into force August 1, 2024, with high-risk obligations effective August 2, 2026 (legally binding, EU). Organizations operating across jurisdictions increasingly face all three simultaneously.

Contents

1. The Convergence Thesis 2. Quick Reference 3. GOVERN Function Mapping 4. MAP Function Mapping 5. MEASURE Function Mapping 6. MANAGE Function Mapping 7. Coverage Analysis 8. Highest-Convergence Procedure Cards 9. How to Use This Crosswalk 10. References

1. The Convergence Thesis

NIST AI RMF, ISO/IEC 42001, and the EU AI Act were developed independently by different bodies with different mandates. NIST published a voluntary risk management framework for the US context. ISO published a certifiable management system standard for international adoption. The European Parliament enacted binding legislation for the EU market. Despite these different origins, the three frameworks converge on remarkably similar operational requirements.

The convergence is not accidental. All three frameworks draw from the same body of AI governance research, the same incident history, and the same fundamental recognition that AI systems require structured risk management, human oversight, transparency, and continuous monitoring. The practical consequence for organizations:

This crosswalk maps the convergence points explicitly, organized by NIST AI RMF function (GOVERN, MAP, MEASURE, MANAGE) as the structural backbone, with ISO 42001 clauses and EU AI Act articles aligned to each subcategory.

2. Quick Reference

DimensionValue
Frameworks covered3 (NIST AI RMF 1.0, ISO/IEC 42001:2023, EU AI Act Reg. 2024/1689)
Convergence points~25 explicit mappings across 21 NIST subcategories
NIST AI RMF functions4 (GOVERN, MAP, MEASURE, MANAGE)
SWT3 procedures referenced12 unique procedures
Highest convergenceAI-GOV.1, AI-SEC.1, AI-DRIFT.1, AI-DATA.1 (mapped by all 3 frameworks)
Evidence formatSWT3 Witness Anchors -- SHA-256 fingerprinted, timestamped, framework-agnostic

3. GOVERN Function Mapping

The GOVERN function addresses organizational governance, policies, roles, and risk management integration. All three frameworks require governance structures before any technical implementation begins.

NIST AI RMFISO 42001EU AI ActSWT3 Procedure
GV.1
AI governance policies, processes, procedures, and practices
Cl. 5.1
Leadership and commitment
Art. 9(1)
Risk management system shall be established
AI-GOV.1
GV.2
Accountability structures and policies
Cl. 5.2
AI policy
Art. 17
Quality management system
AI-GOV.1
GV.3
Workforce diversity, equity, inclusion, and accessibility
Cl. 5.3
Organizational roles, responsibilities, and authorities
Art. 16
Provider obligations
AI-AUDIT.1
GV.4
Organizational context is established
Cl. 4.1
Understanding the organization and its context
Art. 9(2)(a)
Intended purpose identification
AI-IMPACT.1
GV.5
Ongoing engagement with relevant AI actors
Cl. 4.2
Understanding the needs of interested parties
Art. 14
Human oversight
AI-HITL.1
GV.6
Risk management integrated into broader risk management
Cl. 6.1.2
AI risk assessment
Art. 9(4)
Risk management measures adopted
AI-SEC.1

4. MAP Function Mapping

The MAP function addresses context establishment, impact identification, and system characterization. It covers the "know what you have" stage of AI risk management.

NIST AI RMFISO 42001EU AI ActSWT3 Procedure
MP.1
Context is established and understood
Annex B.5
AI system lifecycle
Art. 9(1)
Risk management system scope
AI-LCM.1
MP.2
AI system impacts identified and documented
Cl. 8.4
AI system impact assessment
Art. 27
Fundamental rights impact assessment (FRIA)
AI-IMPACT.1
MP.3
Benefits and costs mapped
Cl. 6.1
Actions to address risks and opportunities
Art. 9(5)
Testing to identify appropriate risk measures
AI-PERF.1
MP.4
Risks and benefits mapped for all components
Cl. 6.1.2
AI risk assessment
Art. 9
Risk management system
AI-SEC.1
MP.5
AI system is characterized with relevant data
Annex B.2
Data for AI systems
Art. 10
Data and data governance
AI-DATA.1

5. MEASURE Function Mapping

The MEASURE function addresses assessment, monitoring, metrics, and documentation. This is where all three frameworks converge most strongly -- each requires ongoing measurement of AI system behavior and documented evidence that measurement is occurring.

NIST AI RMFISO 42001EU AI ActSWT3 Procedure
MS.1
Appropriate measurement approach identified
Cl. 9.2
Internal audit
Art. 43
Conformity assessment
AI-ASSESS.1
MS.2
AI system is monitored for trustworthy characteristics
Cl. 10.1
Continual improvement
Art. 72
Post-market monitoring
AI-DRIFT.1
MS.3
Metrics are developed and appropriate
Cl. 9.1
Monitoring, measurement, analysis, and evaluation
Art. 9(7)
Performance metrics appropriate for the situation
AI-PERF.1
MS.4
Bias evaluation on AI systems
Annex B.3
Bias considerations
Art. 10(2)(f)
Examination of possible biases in datasets
AI-FAIR.1
MS.5
AI system documentation maintained
Cl. 7.5
Documented information
Art. 11
Technical documentation
AI-TRANS.1

6. MANAGE Function Mapping

The MANAGE function addresses risk treatment, prioritization, response, supply chain, and communication. It covers the "act on what you found" stage.

NIST AI RMFISO 42001EU AI ActSWT3 Procedure
MG.1
Risk treatment is determined and applied
Cl. 6.1.4
AI risk treatment
Art. 9(4)
Appropriate risk management measures
AI-SEC.1
MG.2
Risks are prioritized based on impact
Cl. 6.1.3
AI risk criteria
Art. 9(2)(b)
Risk estimation and evaluation
AI-GOV.1
MG.3
Respond to risk based on assessment
Cl. 8.2
AI risk treatment implementation
Art. 62
Corrective actions
AI-DRIFT.1
MG.4
Risk managed in third-party and supply chain
Annex B.7
Third-party and customer relationships
Art. 28
Obligations of deployers (provider chain)
AI-SUPPLY.1
MG.5
Risk communicated to relevant stakeholders
Cl. 7.4
Communication
Art. 13
Transparency and provision of information
AI-TRANS.1

7. Coverage Analysis

The mapping tables above reveal which SWT3 procedures appear across all three frameworks (highest convergence), across two, or in only one. Higher convergence means a single evidence stream satisfies more framework obligations simultaneously.

Convergence Heat Map

Procedures mapped by all 3 frameworks represent the highest-value evidence targets. Implementing these first covers the widest regulatory surface area with the least operational effort.

AI-GOV.1
3 frameworks GV.1, GV.2, MG.2 + Cl. 5.1, 5.2, 6.1.3 + Art. 9(1), 9(2)(b), 17
AI-SEC.1
3 frameworks GV.6, MP.4, MG.1 + Cl. 6.1.2, 6.1.4 + Art. 9, 9(4)
AI-DRIFT.1
3 frameworks MS.2, MG.3 + Cl. 9.1, 10.1, 8.2 + Art. 62, 72
AI-DATA.1
3 frameworks MP.5 + Annex B.2 + Art. 10
AI-IMPACT.1
3 frameworks GV.4, MP.2 + Cl. 4.1, 8.4 + Art. 9(2)(a), 27
AI-TRANS.1
3 frameworks MS.5, MG.5 + Cl. 7.4, 7.5 + Art. 11, 13
AI-PERF.1
3 frameworks MP.3, MS.3 + Cl. 6.1, 9.1 + Art. 9(5), 9(7)
AI-HITL.1
2 frameworks GV.5 + Cl. 4.2 + Art. 14
AI-FAIR.1
2 frameworks MS.4 + Annex B.3 + Art. 10(2)(f)
AI-SUPPLY.1
2 frameworks MG.4 + Annex B.7 + Art. 28
AI-ASSESS.1
2 frameworks MS.1 + Cl. 9.2 + Art. 43
AI-AUDIT.1
1 function GV.3 + Cl. 5.3 + Art. 16
AI-LCM.1
1 function MP.1 + Annex B.5 + Art. 9(1)

Key finding: 7 of 13 SWT3 procedures referenced in this crosswalk are mapped by all three frameworks. This means implementing these 7 procedures creates a unified evidence base that simultaneously satisfies requirements from NIST, ISO, and the EU AI Act. The remaining 6 procedures are mapped by 2 or more frameworks each -- none are single-framework only.

8. Highest-Convergence Procedure Cards

AI-GOV.1

AI Governance Policy Attestation

Why it converges: Every framework begins with governance. NIST AI RMF requires governance policies (GV.1, GV.2) and risk prioritization (MG.2). ISO 42001 requires leadership commitment (Cl. 5.1), an AI policy (Cl. 5.2), and defined risk criteria (Cl. 6.1.3). The EU AI Act requires a risk management system (Art. 9(1)), a quality management system (Art. 17), and risk estimation (Art. 9(2)(b)). All three converge on the same operational need: a documented, reviewed, and enforced AI governance policy.

What the anchor records: AI-GOV.1 anchors capture the policy version in effect, compliance status against the organization's own criteria, and the most recent review date. Over time, these anchors create a longitudinal record that proves governance is active and evolving -- not a document written once and forgotten.

What to show the assessor

For NIST assessors: AI-GOV.1 anchors demonstrate GV.1/GV.2 implementation. For ISO auditors: the same anchors serve as objective evidence for Cl. 5.1/5.2 during Stage 2. For Notified Body evaluations: they document the quality management system required by Art. 17. The timestamp trail shows management review frequency. If an organization claims annual policy review, there should be at least one AI-GOV.1 anchor per 12-month period.

AI-SEC.1

AI Security Control Verification

Why it converges: NIST AI RMF addresses AI security across three subcategories: risk integration (GV.6), component-level risk mapping (MP.4), and risk treatment (MG.1). ISO 42001 covers risk assessment (Cl. 6.1.2) and risk treatment (Cl. 6.1.4). The EU AI Act requires risk management measures (Art. 9(4)) appropriate to the level of risk. All three recognize that AI systems introduce unique security considerations beyond traditional IT security.

What the anchor records: AI-SEC.1 anchors capture the specific security control tested, the test result, and the coverage scope. These anchors prove that security controls are not just documented but are being actively verified against the AI system's attack surface.

What to show the assessor

AI-SEC.1 anchors should span the AI system's threat landscape: adversarial inputs, data poisoning, model extraction, prompt injection (where applicable), and infrastructure security. Factor A identifies the security control. Factor B records the test outcome. Factor C records the scope of coverage. For EU AI Act Art. 9(4), pair AI-SEC.1 anchors with AI-IMPACT.1 anchors to show that security measures are proportionate to identified risks.

AI-DRIFT.1

Model Drift Detection

Why it converges: NIST AI RMF requires monitoring for trustworthy characteristics (MS.2) and risk-based response (MG.3). ISO 42001 mandates performance monitoring (Cl. 9.1), continual improvement (Cl. 10.1), and risk treatment implementation (Cl. 8.2). The EU AI Act requires post-market monitoring (Art. 72) and corrective actions (Art. 62). The common thread: AI systems change over time, and all three frameworks require organizations to detect and respond to that change.

What the anchor records: AI-DRIFT.1 anchors record the metric being tracked, the current measured value, and the baseline value. Consecutive anchors create a time series that proves continuous monitoring is active -- not just planned but operating.

What to show the assessor

AI-DRIFT.1 anchors are the strongest multi-framework evidence available. For NIST: they satisfy MS.2 (monitoring) and MG.3 (response, when drift triggers corrective action). For ISO 42001: they are objective evidence for Cl. 9.1 (measurement) and feed Cl. 10.1 (improvement). For EU AI Act: they satisfy Art. 72 (post-market monitoring) and document when Art. 62 (corrective action) was triggered. Gaps in the monitoring timeline -- periods with no AI-DRIFT.1 anchors -- represent potential nonconformity across all three frameworks.

AI-DATA.1

Data Provenance and Governance

Why it converges: NIST AI RMF requires system characterization with relevant data properties (MP.5). ISO 42001 addresses data for AI systems in Annex B.2. The EU AI Act imposes specific data governance obligations in Art. 10 -- one of the most detailed articles in the regulation. All three frameworks recognize that AI system trustworthiness is fundamentally dependent on data quality, provenance, and governance.

What the anchor records: AI-DATA.1 anchors capture the data source identifier, the record count or dataset size, and the collection method or provenance chain. These anchors prove that data governance is being applied at the point of data use, not just described in documentation.

What to show the assessor

AI-DATA.1 anchors should appear whenever training data, fine-tuning data, or RAG context data is consumed by the AI system. Factor A identifies the data source. Factor B records the volume (record count, token count, or dataset size). Factor C identifies the collection method or provenance chain. For EU AI Act Art. 10 specifically, assessors will look for evidence covering data relevance, representativeness, freedom from errors, and completeness -- pair AI-DATA.1 with AI-FAIR.1 anchors to address Art. 10(2)(f) (bias examination of datasets).

9. How to Use This Crosswalk

Starting from NIST AI RMF

If your organization has implemented NIST AI RMF, use this crosswalk to identify which ISO 42001 clauses and EU AI Act articles your existing evidence already covers. Focus on the GOVERN and MAP tables first -- these map governance and context requirements that are hardest to retrofit. Your existing AI-GOV.1, AI-SEC.1, and AI-IMPACT.1 anchors likely satisfy the corresponding ISO and EU obligations with minimal additional work.

Starting from ISO 42001

If your organization holds or is pursuing ISO 42001 certification, the clause-to-NIST mapping shows where your management system implementation overlaps with NIST AI RMF functions. The MEASURE function (Section 5) maps most directly to ISO Clause 9 (Performance Evaluation). Note that ISO 42001 certification does not create a legal presumption of EU AI Act conformity -- harmonized European standards (hENs) for that purpose are still under development by CEN-CENELEC JTC 21.

Starting from EU AI Act

If your organization is preparing for EU AI Act high-risk obligations, this crosswalk shows which NIST functions and ISO clauses align with each article. The EU AI Act's requirements in Articles 9-15 map to specific NIST subcategories and ISO clauses that can inform your implementation approach. SWT3 evidence generated for EU AI Act compliance simultaneously builds the evidence base for voluntary NIST AI RMF adoption or ISO 42001 certification.

Unified approach

For organizations facing all three frameworks, implement the 7 highest-convergence procedures first (AI-GOV.1, AI-SEC.1, AI-DRIFT.1, AI-DATA.1, AI-IMPACT.1, AI-TRANS.1, AI-PERF.1). These 7 procedures cover requirements from all three frameworks simultaneously. Then add the remaining procedures (AI-HITL.1, AI-FAIR.1, AI-SUPPLY.1, AI-ASSESS.1, AI-AUDIT.1, AI-LCM.1) to close coverage gaps in specific framework requirements.

10. References