AI Act, ISO/IEC 42001 and NIST AI RMF Crosswalk

One table for three frameworks. Each row is an obligation from the EU AI Act, split by who carries it, provider, deployer or provider of a general-purpose AI model, with the ISO/IEC 42001 clauses and Annex A controls and the NIST AI RMF 1.0 subcategories that help meet it. Where neither framework covers an obligation, the row says so. Switch view to start from an ISO control or a NIST subcategory instead and see which obligations it supports, or to read the AI RMF to ISO/IEC 42001 crosswalk that NIST publishes.

  • 28 AI Act obligations
  • 55 of 74 ISO/IEC 42001 clauses and controls linked
  • 48 of 72 NIST AI RMF subcategories linked

The mapping from the AI Act to the two frameworks is this site's own reading, not an official crosswalk; no such crosswalk has been published. Meeting an ISO or NIST item does not by itself discharge the AI Act obligation next to it, and ISO/IEC 42001 is not a harmonised standard under the AI Act, so certification gives no presumption of conformity. Obligations are paraphrased: follow the article links to the AI Act Digest for each article in full. Not legal advice.

Method and sources

  • EU AI Act. Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744. Article titles and application dates are taken from this site's AI Act Digest, which reads every article from the consolidated text. High-risk obligations apply from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems; a high-risk system already on the market before its date is caught only after a significant change in its design, except systems intended for public authorities, which must comply by 2 August 2030 (Article 111(2)). Importers and distributors are outside the scope of this page. EUR-Lex.
  • NIST AI RMF 1.0. NIST AI 100-1 (January 2023), Tables 1 to 4. Subcategory text is quoted as published; NIST publications are in the public domain. NIST AI 100-1.
  • ISO/IEC 42001:2023. Cited by clause or control number and title only. The standard's text is copyright and is not reproduced; buy it from ISO or a national standards body. ISO/IEC 42001.
  • The published AI RMF to ISO/IEC 42001 crosswalk. Hosted by NIST on its crosswalks page and provided by a third party. NIST states that hosting it does not imply endorsement or that either document covers the other comprehensively. It was written against the final draft of ISO/IEC 42001 and cites the guidance annex (B.x) rather than the controls (A.x); the controls column shown here converts B.x to the matching A.x. NIST AI RMF crosswalks.
  • ISO/IEC 42005:2025. AI system impact assessment, cited on the fundamental rights impact assessment row as the method behind the ISO/IEC 42001 impact assessment references. NIST hosts a crosswalk from it to the AI RMF, provided by INCITS/AI against the draft standard and mapped at category level; the NIST categories it gives agree with the subcategories cited on that row. NIST AI RMF crosswalks.
  • Harmonised standards. ISO/IEC 42001 is not a harmonised standard under the AI Act, so certification is not a presumption of conformity. EN 18286:2026, the quality management standard written for Article 17, was published in July 2026 and gives a presumption of conformity only once its reference is cited in the Official Journal. CEN-CENELEC on EN 18286; why ISO/IEC 42001 certification is not a presumption of conformity.

Mapping written on 3 October 2026. Related tools: the AI Risk Assessment for classification, the Fundamental Rights Impact Assessment for Article 27, and the Generative AI Risk Assessment for the NIST Generative AI Profile.