AI Compliance Mapper

Map an AI compliance control across the EU AI Act, NIST AI RMF, ISO/IEC 42001, and SOC 2 — in one searchable table. Free, no signup.

15 controls · Last reviewed: · Illustrative only, not legal advice.

Operationalizes the Governance & Risk framework dimension.

Showing 15 of 15 controls

ControlEU AI ActNIST AI RMFISO/IEC 42001SOC 2 (TSC)
Classify AI systems by risk tier
Risk Management

The organization identifies which of its AI systems are high-risk, limited-risk, or minimal-risk based on intended use and deployment context.

Art. 6, Annex IIIMAP 1.1, MAP 5.1A.5.3, A.6.1CC3.2
Conduct pre-deployment risk assessment
Risk Management

Before deploying, the organization documents foreseeable risks (bias, safety, misuse, security) and mitigations.

Art. 9MAP 5, MEASURE 2A.5.4, A.6.2CC3.1, CC3.2
Document training data lineage and quality
Data Governance

Datasets used for training, validation, and testing have documented origin, licensing, and quality metrics; PII is handled per policy.

Art. 10MAP 2.3, MEASURE 2.10A.7.2, A.7.3CC6.1, CC6.7
Maintain technical documentation package
Documentation

A single accessible package describes system architecture, intended use, training data, evaluation methodology, known limitations, and human-oversight mechanisms.

Art. 11, Annex IVGOVERN 1.4, MAP 4.1A.6.2, A.8.1CC2.1
Automatic event logging
Logging & Traceability

The system logs events required to trace inferences and detect anomalies for the retention period required by policy or law.

Art. 12MEASURE 2.7, MANAGE 4.1A.8.2CC7.2, CC7.3
Disclose to users that they are interacting with AI
Transparency

End users are informed when they interact with an AI system or when content is AI-generated, unless obvious from context.

Note: SOC 2 does not directly address end-user AI disclosure; treat as EU-specific.

Art. 50MEASURE 2.8, MANAGE 4.2A.8.3
Enable meaningful human oversight
Human Oversight

Trained human oversight can monitor operation, intervene, override, and stop the system where risk warrants.

Art. 14GOVERN 2, MANAGE 3A.9.2CC4.2
Ensure accuracy, robustness, cybersecurity
Model Quality

The system meets documented accuracy targets, is robust to input variation and adversarial prompts, and is protected against tampering.

Art. 15MEASURE 2.5, MEASURE 2.6, MEASURE 2.7A.8.4, A.8.5CC7.1, CC7.2
Post-market monitoring and incident reporting
Incident Management

A monitoring plan detects incidents; serious incidents are reported to the appropriate authority within statutory timelines.

Art. 61, Art. 62, Art. 73MANAGE 2, MANAGE 4.3A.8.6, A.9.3CC7.4, CC7.5
Test for and mitigate discriminatory bias
Fairness

Datasets and outputs are evaluated for systemic bias across protected attributes; mitigation is documented.

Note: SOC 2 covers this only obliquely via non-discrimination policies (CC1.1). Treat as AI-specific.

Art. 10, Art. 15MEASURE 2.11, MANAGE 4.2A.6.2, A.8.4
Assess third-party AI components
Supply Chain

AI models, datasets, and services obtained from third parties are risk-assessed and contractually governed.

Art. 25GOVERN 6, MAP 4.1A.9.4CC9.2
Publish training-content summary and technical documentation for GPAI models
General-Purpose AI (2025+)

Providers of general-purpose AI (foundation) models publish a training-content summary, respect EU copyright, and provide technical documentation to downstream deployers.

Note: EU-specific obligation for GPAI providers introduced in 2025. No direct NIST/SOC 2 analogue.

Art. 53, Art. 55GOVERN 1, MAP 4A.6.2, A.7.2
Label AI-generated / synthetic content
Content Provenance

Content generated or manipulated by AI (text, image, audio, video) is machine-readable as such (e.g. C2PA, watermarking) where required.

Art. 50(2)GAI-PROFILE MEASURE 2.7 (content provenance)A.8.3
Adversarial testing / red-teaming
Model Quality

The system is subjected to structured adversarial testing (prompt injection, jailbreak, misuse) before release and periodically thereafter.

Art. 15, Art. 55 (GPAI)GAI-PROFILE MEASURE 2.6, MANAGE 4.3A.8.5CC7.1
Assigned AI governance responsibility
Governance

Named accountability for AI risk (e.g., Chief AI Officer, AI Governance Committee) with defined authority and reporting lines.

Note: EU AI Act does not mandate a specific role, but effective compliance functionally requires one.

GOVERN 1, GOVERN 2A.4.1, A.5.1CC1.2, CC1.3

FAQs

  • Which frameworks does the mapper cover?

    EU AI Act (Regulation 2024/1689), NIST AI Risk Management Framework 1.0 (2023) with the Generative AI Profile (2024), ISO/IEC 42001:2023, and SOC 2 Trust Services Criteria.

  • Is this legal advice?

    No. The mappings are curated by the GenAI Maturity Framework team and are illustrative only. Always consult qualified legal counsel before making compliance decisions.

  • How often is the mapping updated?

    We refresh quarterly and after material framework updates. Last reviewed: 2026-08-27.

  • Why do some cells say — (no mapping)?

    Not every framework addresses every control. A missing mapping is itself useful — it flags where a specific framework does not cover a topic (e.g., SOC 2 does not directly mandate end-user AI disclosure).

For developers

Call this framework and its tools from your own agent via the Model Context Protocol (MCP) server. Works with Claude Desktop, Cursor, Zed, Continue, and the OpenAI Agents SDK.