Crosswalks
Frameworks & laws
One AI management system, many obligations
Why crosswalks
AI laws and frameworks keep multiplying, but they ask for the same core disciplines: an inventory of AI systems, risk and impact assessment, documentation, human oversight, monitoring and incident response. ISO 42001 is the certifiable management system that runs those disciplines once. Each crosswalk below shows where 42001 already produces the evidence, where it gets you partway, and what it leaves to you.
At a glance
| Framework | Type | Status | Certifiable | Relationship to ISO 42001 |
|---|---|---|---|---|
| EU AI Act European Union | Law | In force; high-risk rules apply Dec 2027 and Aug 2028 | No; conformity assessment (mostly self-assessed) and CE marking for high-risk | Strong foundation; no presumption of conformity |
| Colorado AI Act Colorado, US | Law | SB 26-189 effective Jan 1, 2027; rules pending | N/A | No safe harbor; 42001 supports documentation and records |
| Texas TRAIGA Texas, US | Law | In force since Jan 1, 2026 | N/A | Recognized-framework defense; 42001 plausibly qualifies |
| NIST AI RMF United States | Voluntary framework | AI RMF 1.0 (2023); revision announced, no draft yet | No | Highly complementary; 42001 supplies the certifiable system |
| ISO 27001 Global | Standard | Current edition 2022 (Amd 1:2024) | Yes | Shared structure; integrated audits common |
| SOC 2 United States | Attestation | AICPA Trust Services Criteria | Attestation report, not a certificate | Complementary; no AI-specific criteria |
Laws
Frameworks & standards
General information, not legal advice. Laws change; confirm obligations with counsel.