AI governance is new work — but you only do it once
Our earlier study found that mainstream security frameworks overlap so much that a second one is mostly free. AI governance is the exception that proves the rule: your SOC 2 program barely touches it. The good news is the three AI regimes overlap heavily with each other, so the work you do for one largely carries the other two.
The data set
Keel maintains a library of canonical controls, each pre-mapped ("crosswalked") to the specific requirements it satisfies across many frameworks. This report scopes to the 16 controls that satisfy at least one of the three AI-governance regimes: ISO/IEC 42001 (the AI management-system standard), the NIST AI Risk Management Framework, and the EU AI Act. Across those 16 controls there are 33 control-to-framework mappings into the three regimes — an average of 2.1 AI regimes per control. The underlying crosswalk is published as an open dataset (CC BY 4.0) on our open source page, so every figure here is reproducible.
Your security program does not cover this
The instinct after finishing SOC 2 or ISO 27001 is to assume AI governance is a small add-on. It is not. Of the 16 AI-governance controls, only 1 is also satisfied by any mainstream security, quality, or privacy framework in our library. The other 15 (94%) are net-new: AI-specific policy, an AI system inventory, impact assessments, human-oversight measures, model verification, transparency disclosures, and AI-supplier due diligence have no equivalent in a traditional infosec program. Treat AI governance as its own workstream, not a checkbox on an existing one.
But do it once, and you satisfy all three
The payoff is that the three AI regimes are describing much the same discipline in different dialects. 13 of the 16 controls (81%) satisfy two or more AI regimes at once, and 4 controls satisfy all three: AI monitoring & malfunction reporting, AI system impact assessment, AI system inventory, AI verification, validation & robustness. Stand up your AI-governance controls for one framework and most of the other two comes with it — the remaining work is mapping and evidence, not new controls.
How much the AI regimes share, pairwise
Reading the table: of the controls that satisfy the first regime, how many also satisfy the second?
| If you have... | ...how much of this is already covered | Shared controls |
|---|---|---|
| ISO 42001 | EU AI Act | 9 of 15 (60%) |
| ISO 42001 | NIST AI RMF | 7 of 15 (47%) |
| NIST AI RMF | EU AI Act | 5 of 8 (63%) |
Percentages are of the first regime's control count. Overlap is not symmetric: a regime with fewer mapped controls can be almost fully contained in a broader one while covering less of it in return.
How many controls each regime draws on
Coverage in this library, ordered by breadth. ISO 42001, as a full management-system standard with an Annex A control set, draws on the most controls; the NIST AI RMF and the EU AI Act map to a focused subset in this starter library and grow as more of each is authored.
| Framework | Controls in this library |
|---|---|
| ISO 42001 | 15 of 16 |
| EU AI Act | 10 of 16 |
| NIST AI RMF | 8 of 16 |
What this means for sequencing
- Budget AI governance as new work. With 94% of these controls net-new to a security program, do not assume your SOC 2 evidence carries over — most of it will not.
- Pick one AI regime as the anchor and map the rest. Because the average AI-governance control serves 2.1 of the three regimes, standing up controls for one is most of the work for all three.
- Start with the controls that satisfy all three. AI monitoring & malfunction reporting, AI system impact assessment, AI system inventory, AI verification, validation & robustness are the highest-leverage place to begin. (Explore the mappings in the crosswalk explorer.)
Methodology and limitations
Figures are computed directly from Keel's canonical starter control library, the same data published as the open compliance-crosswalks dataset (CC BY 4.0), so they are fully reproducible. A control is counted as covering a regime when it is crosswalked to at least one requirement of that regime (an ISO 42001 Annex A control, a NIST AI RMF subcategory, or an EU AI Act obligation). This measures control-level reuse, not clause-for-clause equivalence: satisfying any regime in practice still requires the specific evidence, scoping, and — for the EU AI Act — the risk-tier and conformity obligations that regime defines. The library covers the AI-governance essentials and grows as more of each framework is authored; it is not the complete text of any standard. This is general information, not audit or legal advice.
Govern AI once, prove it everywhere
Keel ships the AI-governance controls for ISO 42001, the NIST AI RMF, and the EU AI Act pre-crosswalked, with an AI system register and impact assessments built in. Implement once; Keel maps it to every regime it satisfies. Start free.
Start free Get the open dataset