Open · crawlable · citable · East-West v1

The AI governance framework crosswalk.

How published AI-governance and adjacent compliance frameworks map to a shared control set. Map once, evidence everywhere. The signed, article-level version runs inside Council OS.

Determination stays with authorities. This crosswalk maps obligations across regimes; it is not a conformity opinion, certificate, or legal verdict. Measurement, not certification.

EU AI Act — staggered application

you are here2 Feb 2025
Prohibited practices + AI literacy
2 Aug 2025
GPAI model obligations
2 Aug 2026
Art. 50 transparency + penalties
2 Aug 2027
Legacy GPAI compliance + sandboxes
308 days
2 Dec 2027
High-risk (Annex III) — Digital Omnibus
2 Aug 2028
Annex I product-safety high-risk

EU — AI Act high-risk obligations (Art. 9–15)

ReferenceObligationMapped control
Art. 9Risk management systemRisk management
Art. 10Data and data governanceData governance
Art. 11Technical documentationDocumentation & records
Art. 12Record-keepingDocumentation & records
Art. 13Transparency and provision of informationTransparency & disclosure
Art. 14Human oversightHuman oversight
Art. 15Accuracy, robustness and cybersecuritySecurity & resilience

UK — DRCF AI alignment principles

Roadmap alignment with EU AI Act; not a substitute for UK AI Bill obligations.

ReferenceObligationMapped control
DRCF 1Safety & securitySecurity & resilience
DRCF 2Transparency & explainabilityTransparency & disclosure
DRCF 3FairnessBias & fairness
DRCF 4Accountability & governanceAccountability & governance
DRCF 5Contestability & redressHuman oversight

US — Illinois SB 315

AI governance audit requirements — clocked for audits from 1 January 2028.

ReferenceObligationMapped control
SB 315 · Audits from 1 Jan 2028Impact assessmentRisk management
SB 315 · Audits from 1 Jan 2028Documentation of AI systemsDocumentation & records
SB 315 · Audits from 1 Jan 2028Bias & discrimination testingBias & fairness
SB 315 · Audits from 1 Jan 2028Cybersecurity controlsSecurity & resilience

China — GB/T (TC260 alignment)

Honest line: mapping to GB/T is measurement alignment, not equivalence to TC260 or MIIT certification.

ReferenceObligationMapped control
GB/TAlgorithmic transparency / labellingTransparency & disclosure
GB/TData security & cross-border transferData governance
GB/THuman-in-the-loop oversightHuman oversight
GB/TRisk assessment & monitoringRisk management

Shared control set — multi-framework matrix

ControlEU AI ActNIST AI RMFISO/IEC 42001DORANIS2GDPRISO 27001SOC 2HIPAAMiCAPCI DSSCRATC260
Risk managementArt. 9MAP/MEASURE6.1 / 8.2Art. 5–6Art. 21······Annex I·
Data governanceArt. 10MAP 2Annex A (data)··Art. 5–6··164.514···5.x
Transparency & disclosureArt. 13 / 50GOVERN 4Annex A (transparency)··Art. 13–14······labelling
Human oversightArt. 14GOVERN 2Annex A (oversight)Art. 5·········
Accountability & governanceArt. 17GOVERN 15.1–5.3·Art. 20··CC1·····
Security & resilienceArt. 15MANAGE 4·Art. 9Art. 21·A.5–A.8··Art. 68Req. 6Annex I·
Bias & fairnessArt. 10 / Annex IIIMEASURE 2.11Annex A (impact)··Art. 22·······
Documentation & recordsArt. 11–12 / Annex IVGOVERN 1.47.5Art. 28 (RoI)···CC2·····

References are indicative and for orientation — not legal advice. The signed, verifiable article-level mapping runs as a governed tool in the OS. Verify against primary sources.

Frequently asked

What is an AI governance framework crosswalk?

A crosswalk maps the overlapping requirements of different regulations and standards to a single set of controls, so that implementing one control satisfies the equivalent obligation in every framework it maps to — you map once and evidence everywhere. Determination stays with authorities; the crosswalk is a map, not a certificate.

Which frameworks does the CSOAI crosswalk cover?

Published frameworks including the EU AI Act (Art. 9–15), UK DRCF alignment, Illinois SB 315, China GB/T (TC260 alignment — honest mapping, not equivalence claims), NIST AI RMF, ISO/IEC 42001, DORA, NIS2, GDPR, and more — mapped to a shared control set.

How does a crosswalk save time on EU AI Act compliance?

Most EU AI Act obligations (risk management, data governance, transparency, oversight, documentation) already overlap with ISO 42001 and NIST AI RMF. Mapping them means existing controls can be reused as evidence rather than rebuilt, cutting duplicate work ahead of enforcement dates.

Is the CSOAI crosswalk verifiable?

The machine-readable v1 mapping is published at /crosswalk/east-west-v1.json. Inspect that exact artifact and any attached signature separately; a tool output is not automatically signed, and a crosswalk is not a compliance determination.