SolutionsServicesLive DemosMCPEngineeringAboutProcessContactGet Started
All articles
Targets: “NIST AI RMF ISO 42001 EU AI Act mapping

NIST AI RMF, ISO 42001, EU AI Act: one mapping, not three checklists

Governance teams often treat these as three separate compliance projects. In practice, the same underlying evidence — a decision log with control tags — satisfies all three, if it's built that way from the start.

Evidence: the actual control-tag structure from our live Governance Ledger and AP Exception Workflow demos.

Same evidence, three vocabularies

NIST AI RMF organizes controls under four functions — GOVERN, MAP, MEASURE, MANAGE. ISO 42001 and the EU AI Act use different labels for largely the same underlying obligations: documented authority and scope, risk identification, ongoing monitoring, and incident response. Teams that treat these as three separate audits end up building three separate evidence trails for the same operational fact.

Our own live demos tag every policy decision against the NIST function it maps to — GOVERN-1.5 for documented scope enforcement, MEASURE-2.7 for system behavior monitored against expectations, MANAGE-1.3 for risk escalation, MANAGE-4.1 for post-deployment monitoring. That tag is attached once, at the point the check runs — not retrofitted later by a compliance team trying to reconstruct what happened from application logs never designed to answer that question.

Why this has to be architectural, not a spreadsheet

A control mapping built after the fact — a spreadsheet matching NIST subcategories to ISO clauses to EU AI Act articles — only proves the mapping exists on paper. It doesn't prove the control actually ran on a specific decision at a specific time. The difference matters the moment an auditor asks for evidence on one real transaction, not the policy document describing the intended process.

What this looks like in a real system

In our Governance Ledger demo, every model call our own routing infrastructure makes is logged automatically — not sampled, not added later — as a byproduct of how the router already works. That same principle extends to any agent action: the control tag is data on the decision record itself, which is what makes it possible to hand a reviewer one ledger and have it answer NIST, ISO, and EU AI Act questions without three different exports.

See it built, not just described

AI Governance engagement is the engagement this pattern comes from.

AI Governance engagement