Compliance and standards mappings¶
Informative mapping only
This page traces the framework's architecture capabilities and evidence to an external source. It is not legal advice, and it is not an audit, a certification, an authorization or a conformity assessment. Mapping a capability does not show that a control is implemented or effective.
Confirm applicability, edition and dates against the authoritative source, and obtain review from qualified legal, compliance, security, privacy and audit professionals before relying on it. Standards text is copyrighted: this page gives identifiers and short titles only, so obtain the licensed standard for the full requirements.
These mappings help teams trace architecture capabilities and evidence to external frameworks. Use them as informative starting points for qualified review.
Available mappings¶
| Mapping | Source | Maps |
|---|---|---|
| NIST AI RMF | NIST AI 100-1 and the Generative AI Profile (AI 600-1) | All 19 categories, the 7 trustworthiness characteristics, the 12 generative AI risks |
| ISO/IEC 42001 | ISO/IEC 42001:2023 | Clauses 4 to 10, and all 38 Annex A controls |
| EU AI Act | Regulation (EU) 2024/1689, as amended by (EU) 2026/1744 | Timeline, roles, obligations for all systems, provider and deployer obligations for high-risk systems, incident reporting, penalties |
| FedRAMP | FedRAMP CR26 and NIST SP 800-53 Rev. 5 | Certification classes, Key Security Indicators, the SP 800-53 families where AI changes the evidence |
| Control mapping template | Any framework | A blank traceability matrix |
Each mapping records the date its facts were checked. Recheck any date-sensitive fact against the source before you rely on it.
Mapping method¶
- Record the authoritative source, edition, jurisdiction, and access date.
- Decompose requirements without changing their meaning.
- Link each requirement to responsible capabilities and architecture layers.
- Identify implementation and independent validation evidence.
- Record applicability, inheritance, gaps, compensating controls, and status.
- Obtain review from qualified legal, compliance, security, privacy, and audit functions.
- Revalidate after authoritative-source or system changes.
Compliance evidence
A mapped architecture supports traceability. A compliance claim requires evidence that controls are implemented, operate effectively, and suit the specific organization and system.