Research

AI governance is mostly new work — and the AI regimes only partly overlap

Our earlier study found that mainstream security frameworks overlap enough that a second one never starts from zero. AI governance is the exception that proves the rule: 67% of these controls are net-new to a security program. What reuse there is sits between the three AI regimes themselves — 16 of the 64 controls serve two or more of them, and 6 serve all three.

The data set

Keel maintains a library of canonical controls, each pre-mapped ("crosswalked") to the specific requirements it satisfies across many frameworks. This report scopes to the 64 controls that satisfy at least one of the three AI-governance regimes: ISO/IEC 42001 (the AI management-system standard), the NIST AI Risk Management Framework, and the EU AI Act. Across those 64 controls there are 86 control-to-framework mappings into the three regimes — an average of 1.3 AI regimes per control. The underlying crosswalk is published as an open dataset (CC BY 4.0) on our open source page.

Your security program does not cover this

The instinct after finishing SOC 2 or ISO 27001 is to assume AI governance is a small add-on. It is not. Of the 64 AI-governance controls, only 21 are also satisfied by any mainstream security, quality, or privacy framework in our library. The other 43 (67%) are net-new: AI-specific policy, an AI system inventory, impact assessments, human-oversight measures, model verification, transparency disclosures, and AI-supplier due diligence have no equivalent in a traditional infosec program. Treat AI governance as its own workstream, not a checkbox on an existing one.

Where the three AI regimes do overlap

The three AI regimes are aimed at the same discipline in different dialects, but they do not ask for the same controls. 16 of the 64 controls (25%) satisfy two or more AI regimes at once, and 6 controls satisfy all three: AI monitoring & malfunction reporting, AI risk management process, AI technical documentation, AI transparency & disclosure, AI verification, validation & robustness, Human oversight of AI. Stand up your AI-governance controls for one framework and a real share of the other two comes with it — the table below is the exact figure for each pair. The rest is new control work, not just mapping and evidence.

How much the AI regimes share, pairwise

Reading the table: of the controls that satisfy the first regime, how many also satisfy the second?

Pairwise control overlap between the AI regimes
If you have... ...how much of this is already covered Shared controls
ISO 42001 EU AI Act8 of 38 (21%)
ISO 42001 NIST AI RMF14 of 38 (37%)
NIST AI RMF EU AI Act6 of 27 (22%)

Percentages are of the first regime’s control count. Overlap is not symmetric: the same shared controls are a larger share of the smaller regime’s set than of the larger one’s, so every pair reads differently in the other direction.

How many controls each regime draws on

Coverage in this library, ordered by breadth. ISO 42001, as a full management-system standard with an Annex A control set, draws on the most controls; the NIST AI RMF and the EU AI Act map to a focused subset in this starter library and grow as more of each is authored.

Controls per AI regime in this library
Framework Controls in this library
ISO 42001 38 of 64
NIST AI RMF 27 of 64
EU AI Act 21 of 64

What this means for sequencing

  • Budget AI governance as new work. With 67% of these controls net-new to a security program, do not assume your SOC 2 evidence carries over — most of it will not.
  • Pick one AI regime as the anchor and map the rest. The average AI-governance control serves 1.3 of the three regimes, so an anchor gives you a running start on the other two rather than a free pass.
  • Start with the controls that satisfy all three. AI monitoring & malfunction reporting, AI risk management process, AI technical documentation, AI transparency & disclosure, AI verification, validation & robustness, Human oversight of AI are the highest-leverage place to begin. (Explore the mappings in the crosswalk explorer.)

Methodology and limitations

Govern AI once, prove it everywhere

Keel ships the AI-governance controls for ISO 42001, the NIST AI RMF, and the EU AI Act pre-crosswalked, with an AI system register and impact assessments built in. Implement once; Keel maps it to every regime it satisfies. Start free.