AI Compliance Mapper
Map an AI compliance control across the EU AI Act, NIST AI RMF, ISO/IEC 42001, and SOC 2 — in one searchable table. Free, no signup.
15 controls · Last reviewed: · Illustrative only, not legal advice.
Operationalizes the Governance & Risk framework dimension.
Showing 15 of 15 controls
| Control | EU AI Act | NIST AI RMF | ISO/IEC 42001 | SOC 2 (TSC) |
|---|---|---|---|---|
Classify AI systems by risk tier Risk Management The organization identifies which of its AI systems are high-risk, limited-risk, or minimal-risk based on intended use and deployment context. | Art. 6, Annex III | MAP 1.1, MAP 5.1 | A.5.3, A.6.1 | CC3.2 |
Conduct pre-deployment risk assessment Risk Management Before deploying, the organization documents foreseeable risks (bias, safety, misuse, security) and mitigations. | Art. 9 | MAP 5, MEASURE 2 | A.5.4, A.6.2 | CC3.1, CC3.2 |
Document training data lineage and quality Data Governance Datasets used for training, validation, and testing have documented origin, licensing, and quality metrics; PII is handled per policy. | Art. 10 | MAP 2.3, MEASURE 2.10 | A.7.2, A.7.3 | CC6.1, CC6.7 |
Maintain technical documentation package Documentation A single accessible package describes system architecture, intended use, training data, evaluation methodology, known limitations, and human-oversight mechanisms. | Art. 11, Annex IV | GOVERN 1.4, MAP 4.1 | A.6.2, A.8.1 | CC2.1 |
Automatic event logging Logging & Traceability The system logs events required to trace inferences and detect anomalies for the retention period required by policy or law. | Art. 12 | MEASURE 2.7, MANAGE 4.1 | A.8.2 | CC7.2, CC7.3 |
Disclose to users that they are interacting with AI Transparency End users are informed when they interact with an AI system or when content is AI-generated, unless obvious from context. Note: SOC 2 does not directly address end-user AI disclosure; treat as EU-specific. | Art. 50 | MEASURE 2.8, MANAGE 4.2 | A.8.3 | — |
Enable meaningful human oversight Human Oversight Trained human oversight can monitor operation, intervene, override, and stop the system where risk warrants. | Art. 14 | GOVERN 2, MANAGE 3 | A.9.2 | CC4.2 |
Ensure accuracy, robustness, cybersecurity Model Quality The system meets documented accuracy targets, is robust to input variation and adversarial prompts, and is protected against tampering. | Art. 15 | MEASURE 2.5, MEASURE 2.6, MEASURE 2.7 | A.8.4, A.8.5 | CC7.1, CC7.2 |
Post-market monitoring and incident reporting Incident Management A monitoring plan detects incidents; serious incidents are reported to the appropriate authority within statutory timelines. | Art. 61, Art. 62, Art. 73 | MANAGE 2, MANAGE 4.3 | A.8.6, A.9.3 | CC7.4, CC7.5 |
Test for and mitigate discriminatory bias Fairness Datasets and outputs are evaluated for systemic bias across protected attributes; mitigation is documented. Note: SOC 2 covers this only obliquely via non-discrimination policies (CC1.1). Treat as AI-specific. | Art. 10, Art. 15 | MEASURE 2.11, MANAGE 4.2 | A.6.2, A.8.4 | — |
Assess third-party AI components Supply Chain AI models, datasets, and services obtained from third parties are risk-assessed and contractually governed. | Art. 25 | GOVERN 6, MAP 4.1 | A.9.4 | CC9.2 |
Publish training-content summary and technical documentation for GPAI models General-Purpose AI (2025+) Providers of general-purpose AI (foundation) models publish a training-content summary, respect EU copyright, and provide technical documentation to downstream deployers. Note: EU-specific obligation for GPAI providers introduced in 2025. No direct NIST/SOC 2 analogue. | Art. 53, Art. 55 | GOVERN 1, MAP 4 | A.6.2, A.7.2 | — |
Label AI-generated / synthetic content Content Provenance Content generated or manipulated by AI (text, image, audio, video) is machine-readable as such (e.g. C2PA, watermarking) where required. | Art. 50(2) | GAI-PROFILE MEASURE 2.7 (content provenance) | A.8.3 | — |
Adversarial testing / red-teaming Model Quality The system is subjected to structured adversarial testing (prompt injection, jailbreak, misuse) before release and periodically thereafter. | Art. 15, Art. 55 (GPAI) | GAI-PROFILE MEASURE 2.6, MANAGE 4.3 | A.8.5 | CC7.1 |
Assigned AI governance responsibility Governance Named accountability for AI risk (e.g., Chief AI Officer, AI Governance Committee) with defined authority and reporting lines. Note: EU AI Act does not mandate a specific role, but effective compliance functionally requires one. | — | GOVERN 1, GOVERN 2 | A.4.1, A.5.1 | CC1.2, CC1.3 |
FAQs
Which frameworks does the mapper cover?
EU AI Act (Regulation 2024/1689), NIST AI Risk Management Framework 1.0 (2023) with the Generative AI Profile (2024), ISO/IEC 42001:2023, and SOC 2 Trust Services Criteria.
Is this legal advice?
No. The mappings are curated by the GenAI Maturity Framework team and are illustrative only. Always consult qualified legal counsel before making compliance decisions.
How often is the mapping updated?
We refresh quarterly and after material framework updates. Last reviewed: 2026-08-27.
Why do some cells say — (no mapping)?
Not every framework addresses every control. A missing mapping is itself useful — it flags where a specific framework does not cover a topic (e.g., SOC 2 does not directly mandate end-user AI disclosure).
Related on this site
Framework dimensions
Whitepapers
Call this framework and its tools from your own agent via the Model Context Protocol (MCP) server. Works with Claude Desktop, Cursor, Zed, Continue, and the OpenAI Agents SDK.