Research

AI governance is new work — but you only do it once

Our earlier study found that mainstream security frameworks overlap so much that a second one is mostly free. AI governance is the exception that proves the rule: your SOC 2 program barely touches it. The good news is the three AI regimes overlap heavily with each other, so the work you do for one largely carries the other two.

The data set

Keel maintains a library of canonical controls, each pre-mapped ("crosswalked") to the specific requirements it satisfies across many frameworks. This report scopes to the 18 controls that satisfy at least one of the three AI-governance regimes: ISO/IEC 42001 (the AI management-system standard), the NIST AI Risk Management Framework, and the EU AI Act. Across those 18 controls there are 32 control-to-framework mappings into the three regimes — an average of 1.8 AI regimes per control. The underlying crosswalk is published as an open dataset (CC BY 4.0) on our open source page.

Your security program does not cover this

The instinct after finishing SOC 2 or ISO 27001 is to assume AI governance is a small add-on. It is not. Of the 18 AI-governance controls, only 3 are also satisfied by any mainstream security, quality, or privacy framework in our library. The other 15 (83%) are net-new: AI-specific policy, an AI system inventory, impact assessments, human-oversight measures, model verification, transparency disclosures, and AI-supplier due diligence have no equivalent in a traditional infosec program. Treat AI governance as its own workstream, not a checkbox on an existing one.

But do it once, and you satisfy all three

The payoff is that the three AI regimes are describing much the same discipline in different dialects. 12 of the 18 controls (67%) satisfy two or more AI regimes at once, and 2 controls satisfy all three: AI monitoring & malfunction reporting, AI verification, validation & robustness. Stand up your AI-governance controls for one framework and most of the other two comes with it — the remaining work is mapping and evidence, not new controls.

How much the AI regimes share, pairwise

Reading the table: of the controls that satisfy the first regime, how many also satisfy the second?

Pairwise control overlap between the AI regimes
If you have... ...how much of this is already covered Shared controls
ISO 42001 EU AI Act7 of 16 (44%)
ISO 42001 NIST AI RMF6 of 16 (38%)
NIST AI RMF EU AI Act3 of 8 (38%)

Percentages are of the first regime’s control count. Overlap is not symmetric: a regime with fewer mapped controls can be almost fully contained in a broader one while covering less of it in return.

How many controls each regime draws on

Coverage in this library, ordered by breadth. ISO 42001, as a full management-system standard with an Annex A control set, draws on the most controls; the NIST AI RMF and the EU AI Act map to a focused subset in this starter library and grow as more of each is authored.

Controls per AI regime in this library
Framework Controls in this library
ISO 42001 16 of 18
NIST AI RMF 8 of 18
EU AI Act 8 of 18

What this means for sequencing

  • Budget AI governance as new work. With 83% of these controls net-new to a security program, do not assume your SOC 2 evidence carries over — most of it will not.
  • Pick one AI regime as the anchor and map the rest. Because the average AI-governance control serves 1.8 of the three regimes, standing up controls for one is most of the work for all three.
  • Start with the controls that satisfy all three. AI monitoring & malfunction reporting, AI verification, validation & robustness are the highest-leverage place to begin. (Explore the mappings in the crosswalk explorer.)

Methodology and limitations

Govern AI once, prove it everywhere

Keel ships the AI-governance controls for ISO 42001, the NIST AI RMF, and the EU AI Act pre-crosswalked, with an AI system register and impact assessments built in. Implement once; Keel maps it to every regime it satisfies. Start free.