On this page
Crosswalks

Frameworks & laws

One AI management system, many obligations

Why crosswalks

AI laws and frameworks keep multiplying, but they ask for the same core disciplines: an inventory of AI systems, risk and impact assessment, documentation, human oversight, monitoring and incident response. ISO 42001 is the certifiable management system that runs those disciplines once. Each crosswalk below shows where 42001 already produces the evidence, where it gets you partway, and what it leaves to you.

At a glance

FrameworkTypeStatusCertifiableRelationship to ISO 42001
EU AI Act
European Union
LawIn force; high-risk rules apply Dec 2027 and Aug 2028No; conformity assessment (mostly self-assessed) and CE marking for high-riskStrong foundation; no presumption of conformity
Colorado AI Act
Colorado, US
LawSB 26-189 effective Jan 1, 2027; rules pendingN/ANo safe harbor; 42001 supports documentation and records
Texas TRAIGA
Texas, US
LawIn force since Jan 1, 2026N/ARecognized-framework defense; 42001 plausibly qualifies
NIST AI RMF
United States
Voluntary frameworkAI RMF 1.0 (2023); revision announced, no draft yetNoHighly complementary; 42001 supplies the certifiable system
ISO 27001
Global
StandardCurrent edition 2022 (Amd 1:2024)YesShared structure; integrated audits common
SOC 2
United States
AttestationAICPA Trust Services CriteriaAttestation report, not a certificateComplementary; no AI-specific criteria

Laws

Frameworks & standards

General information, not legal advice. Laws change; confirm obligations with counsel.