Open · crawlable · citable · East-West v1
The AI governance framework crosswalk.
How published AI-governance and adjacent compliance frameworks map to a shared control set. Map once, evidence everywhere. The signed, article-level version runs inside Council OS.
EU AI Act — staggered application
EU — AI Act high-risk obligations (Art. 9–15)
| Reference | Obligation | Mapped control |
|---|---|---|
| Art. 9 | Risk management system | Risk management |
| Art. 10 | Data and data governance | Data governance |
| Art. 11 | Technical documentation | Documentation & records |
| Art. 12 | Record-keeping | Documentation & records |
| Art. 13 | Transparency and provision of information | Transparency & disclosure |
| Art. 14 | Human oversight | Human oversight |
| Art. 15 | Accuracy, robustness and cybersecurity | Security & resilience |
UK — DRCF AI alignment principles
Roadmap alignment with EU AI Act; not a substitute for UK AI Bill obligations.
| Reference | Obligation | Mapped control |
|---|---|---|
| DRCF 1 | Safety & security | Security & resilience |
| DRCF 2 | Transparency & explainability | Transparency & disclosure |
| DRCF 3 | Fairness | Bias & fairness |
| DRCF 4 | Accountability & governance | Accountability & governance |
| DRCF 5 | Contestability & redress | Human oversight |
US — Illinois SB 315
AI governance audit requirements — clocked for audits from 1 January 2028.
| Reference | Obligation | Mapped control |
|---|---|---|
| SB 315 · Audits from 1 Jan 2028 | Impact assessment | Risk management |
| SB 315 · Audits from 1 Jan 2028 | Documentation of AI systems | Documentation & records |
| SB 315 · Audits from 1 Jan 2028 | Bias & discrimination testing | Bias & fairness |
| SB 315 · Audits from 1 Jan 2028 | Cybersecurity controls | Security & resilience |
China — GB/T (TC260 alignment)
Honest line: mapping to GB/T is measurement alignment, not equivalence to TC260 or MIIT certification.
| Reference | Obligation | Mapped control |
|---|---|---|
| GB/T | Algorithmic transparency / labelling | Transparency & disclosure |
| GB/T | Data security & cross-border transfer | Data governance |
| GB/T | Human-in-the-loop oversight | Human oversight |
| GB/T | Risk assessment & monitoring | Risk management |
Shared control set — multi-framework matrix
| Control | EU AI Act | NIST AI RMF | ISO/IEC 42001 | DORA | NIS2 | GDPR | ISO 27001 | SOC 2 | HIPAA | MiCA | PCI DSS | CRA | TC260 |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Risk management | Art. 9 | MAP/MEASURE | 6.1 / 8.2 | Art. 5–6 | Art. 21 | · | · | · | · | · | · | Annex I | · |
| Data governance | Art. 10 | MAP 2 | Annex A (data) | · | · | Art. 5–6 | · | · | 164.514 | · | · | · | 5.x |
| Transparency & disclosure | Art. 13 / 50 | GOVERN 4 | Annex A (transparency) | · | · | Art. 13–14 | · | · | · | · | · | · | labelling |
| Human oversight | Art. 14 | GOVERN 2 | Annex A (oversight) | Art. 5 | · | · | · | · | · | · | · | · | · |
| Accountability & governance | Art. 17 | GOVERN 1 | 5.1–5.3 | · | Art. 20 | · | · | CC1 | · | · | · | · | · |
| Security & resilience | Art. 15 | MANAGE 4 | · | Art. 9 | Art. 21 | · | A.5–A.8 | · | · | Art. 68 | Req. 6 | Annex I | · |
| Bias & fairness | Art. 10 / Annex III | MEASURE 2.11 | Annex A (impact) | · | · | Art. 22 | · | · | · | · | · | · | · |
| Documentation & records | Art. 11–12 / Annex IV | GOVERN 1.4 | 7.5 | Art. 28 (RoI) | · | · | · | CC2 | · | · | · | · | · |
References are indicative and for orientation — not legal advice. The signed, verifiable article-level mapping runs as a governed tool in the OS. Verify against primary sources.
Frequently asked
What is an AI governance framework crosswalk?
A crosswalk maps the overlapping requirements of different regulations and standards to a single set of controls, so that implementing one control satisfies the equivalent obligation in every framework it maps to — you map once and evidence everywhere. Determination stays with authorities; the crosswalk is a map, not a certificate.
Which frameworks does the CSOAI crosswalk cover?
Published frameworks including the EU AI Act (Art. 9–15), UK DRCF alignment, Illinois SB 315, China GB/T (TC260 alignment — honest mapping, not equivalence claims), NIST AI RMF, ISO/IEC 42001, DORA, NIS2, GDPR, and more — mapped to a shared control set.
How does a crosswalk save time on EU AI Act compliance?
Most EU AI Act obligations (risk management, data governance, transparency, oversight, documentation) already overlap with ISO 42001 and NIST AI RMF. Mapping them means existing controls can be reused as evidence rather than rebuilt, cutting duplicate work ahead of enforcement dates.
Is the CSOAI crosswalk verifiable?
The machine-readable v1 mapping is published at /crosswalk/east-west-v1.json. Inspect that exact artifact and any attached signature separately; a tool output is not automatically signed, and a crosswalk is not a compliance determination.