EU AI Act ↔ NIST AI RMF
EU AI Act vs NIST AI RMF — Crosswalk and Practical Differences
A side-by-side of the EU AI Act and NIST AI Risk Management Framework 1.0. Where they overlap, where they diverge, and how to leverage one to satisfy the other.
Source: Regulation (EU) 2024/1689 on EUR-Lex · Last published 2026-04-28 · Draft pending human review
Why this comparison matters
The EU AI Act is regulation — binding under EU law, with Article 99 penalties up to €35 million or 7% of global turnover. The NIST AI Risk Management Framework 1.0 (NIST AI 100-1, January 2023) is voluntary guidance issued by the U.S. National Institute of Standards and Technology. They share a vocabulary and a common ancestry in risk-management-system thinking, but they answer different questions.
A SaaS vendor selling into both EU regulated markets and U.S. Fortune 500 / federal accounts faces both. This pillar maps the overlap, names the gaps, and suggests an integration pattern.
Top-level structure
| Dimension | EU AI Act | NIST AI RMF 1.0 |
|---|---|---|
| Legal force | Binding regulation | Voluntary framework |
| Geographic scope | EU + extraterritorial reach via Article 2(1)(c) | Global voluntary use; baseline for U.S. federal procurement |
| Triggers | High-risk classification under Article 6 + Annex III, GPAI under Article 51, prohibited practices under Article 5 | Self-determined applicability based on AI system risk |
| Functions | Risk mgmt, data governance, technical docs, transparency, oversight, accuracy, conformity, post-market monitoring | GOVERN, MAP, MEASURE, MANAGE |
| Conformity model | Internal control (Annex VI) or notified body (Annex VII) | Self-attestation |
| Penalties | Up to €35M / 7% global turnover | None directly; reputational + procurement-eligibility consequences |
Where they overlap
The Governancer crosswalk maps every item in the 30-item EU AI Act checklist to NIST AI RMF subcategories. Headline overlaps:
- Article 9 risk management ↔ GOVERN 1.1, MANAGE 1.3. Continuous risk identification, mitigation, documentation.
- Article 10 data governance ↔ MEASURE 2.2, MEASURE 2.11, MAP 2.3. Data representativeness, fairness/bias, scientific integrity.
- Article 11 / Annex IV technical documentation ↔ MAP 4.1, GOVERN 1.4. System purpose, intended use, users, limitations; documented and regularly reviewed risk-management process.
- Article 14 human oversight ↔ GOVERN 3.2, MEASURE 2.8. Roles for human-AI configurations; transparency and accountability.
- Article 15 accuracy / robustness / cybersecurity ↔ MEASURE 2.5, MEASURE 2.7. Validity, reliability, security, resilience.
- Article 27 FRIA ↔ MAP 5.1, MAP 5.2. Likelihood and magnitude of impacts; engagement with relevant AI Actors.
- Article 72 post-market monitoring ↔ MEASURE 4.1, MANAGE 4.1. Tracking risks over time; post-deployment monitoring plans.
- Article 73 / 79 incidents ↔ MANAGE 4.3. Incident communication.
Where they diverge — five gaps
- Conformity assessment. EU AI Act requires a formal pre-market conformity assessment (Article 43) and CE marking. NIST AI RMF is silent on conformity certification.
- EU Database registration. Article 49 EU Database has no NIST analogue.
- Authorised representative. Non-EU providers need an Article 22 representative; NIST has no such concept.
- FRIA. Article 27 FRIA for specific deployer classes is EU-specific; NIST MAP 5.1 / 5.2 is closest but voluntary and broader.
- Penalty structure. EU AI Act has explicit fine tiers; NIST doesn't.
Where NIST has more depth
NIST AI RMF goes deeper on:
- Workforce considerations under GOVERN 2.x and MAP 3.4 — competency frameworks for AI staff.
- AI Actors stakeholder mapping under GOVERN 5.x — broader than the EU's deployer/provider/user trio.
- MEASURE 2.x trustworthy-AI characteristics — explicit decomposition into validity, reliability, safety, security, resilience, accountability, transparency, explainability, interpretability, privacy enhancement, fairness with managed bias.
A team that has fully implemented MEASURE 2.x has an evidence base that translates directly into the EU AI Act technical file.
Integration pattern — leverage one to satisfy the other
If you have a NIST AI RMF self-attestation program in place, you have ~70% of the EU AI Act technical-file evidence. The remaining 30% is the AI-Act-specific scaffolding:
- The Article 43 conformity assessment procedure.
- The Article 47 declaration of conformity and Article 48 CE marking (where applicable).
- The Article 49 EU Database registration.
- The Article 22 authorised representative (if non-EU).
- The Article 27 FRIA (for covered deployers).
If you have an EU AI Act program, you can produce a NIST AI RMF self-attestation by re-tagging your evidence using the GOVERN/MAP/MEASURE/MANAGE structure. The Governancer Pro crosswalk PDF does this re-tagging automatically.
What we ship
- Free. Maps your quiz answers to both frameworks at a high level.
- Pro. Full per-checklist-item NIST AI RMF crosswalk with rationale; downloadable PDF for buyer due-diligence.
Inline crosswalk source
The full Governancer crosswalk lives in the codebase module crosswalk-data.ts, with sources cited inline (NIST AI 100-1 PDF; NIST Playbook).
Internal links
Disclaimer. Reference; not legal advice. Verify with counsel. Reg text from Regulation (EU) 2024/1689; NIST AI RMF from NIST AI 100-1.
Reference checklist
From the Governancer 30-item EU AI Act checklist. Each item joins to the ISO 42001 + NIST AI RMF crosswalk table below.
Article 11 · Starter tier · critical
Draft technical documentation (system purpose, design, risk)
Required for all high-risk AI systems before market placement. Our template covers the eight mandatory sections in one .docx.
Article 9 · Starter tier · high
Establish risk management system
A continuous iterative process. Identify foreseeable risks, estimate impact, document mitigations, review at least quarterly.
Article 15 · Starter tier · medium
Define accuracy, robustness, and cybersecurity measures
Benchmarks, adversarial testing, incident detection, lifecycle monitoring. Documented in the technical file.
ISO 42001 + NIST AI RMF crosswalk
Pulled live from the Governancer crosswalk module. Mapping reference; not a substitute for ISO 42001 certification audit or NIST AI RMF self-attestation.
ISO/IEC 42001:2023
| Checklist item | ISO 42001 control | Rationale |
|---|---|---|
art11-tech-docs | ISO/IEC 42001:2023 Clause 7.5 — Documented information | Article 11 technical file is the AIMS-required documented information evidencing AI system design, purpose, and risk decisions. |
art11-tech-docs | ISO/IEC 42001:2023 Annex A.6.2 — AI system life cycle documentation | Annex A.6.2 requires lifecycle documentation; the Article 11 technical file is its EU AI Act manifestation. |
art9-risk-mgmt | ISO/IEC 42001:2023 Clause 6.1.2 — AI risk assessment | A continuous Article 9 risk management process is the EU-AI-Act realisation of Clause 6.1.2 risk assessment. |
art9-risk-mgmt | ISO/IEC 42001:2023 Clause 6.1.3 — AI risk treatment | Article 9 mitigation, residual-risk recording and quarterly review provide the risk-treatment evidence required by Clause 6.1.3. |
art15-accuracy | ISO/IEC 42001:2023 Annex A.6.2.4 — Verification and validation | Article 15 accuracy/robustness benchmarks satisfy the verification-and-validation control objective in the lifecycle annex. |
NIST AI RMF 1.0
| Checklist item | NIST AI RMF subcategory | Rationale |
|---|---|---|
art11-tech-docs | NIST AI RMF MAP 4.1 — Approaches and metrics for measurement of AI risks are followed; documentation includes purpose, intended use, users, and limitations | Article 11 technical file documents purpose, design and limitations — the system-context output expected by MAP 4.1. |
art11-tech-docs | NIST AI RMF GOVERN 1.4 — The risk management process is documented and is regularly reviewed | Maintaining a living technical file is the documented and regularly reviewed risk-management evidence under GOVERN 1.4. |
art9-risk-mgmt | NIST AI RMF GOVERN 1.1 — Legal and regulatory requirements involving AI are understood, managed, and documented | EU AI Act Article 9 risk management explicitly captures the regulatory requirements GOVERN 1.1 wants documented. |
art9-risk-mgmt | NIST AI RMF MANAGE 1.3 — Responses to the AI risks deemed high priority are developed, planned, and documented | Article 9 mitigation plans for residual high-priority risks are exactly the responses MANAGE 1.3 expects. |
art15-accuracy | NIST AI RMF MEASURE 2.5 — The AI system to be deployed is demonstrated to be valid and reliable | Article 15 accuracy benchmarks and robustness evidence demonstrate validity and reliability per MEASURE 2.5. |
art15-accuracy | NIST AI RMF MEASURE 2.7 — AI system security and resilience are evaluated and documented | Article 15 cybersecurity measures and adversarial resilience are the security/resilience evaluation in MEASURE 2.7. |
Related
Article 9
EU AI Act Article 9 — Risk Management System Requirements
Article 11
EU AI Act Article 11 — Technical Documentation Requirements
EU AI Act ↔ ISO/IEC 42001
EU AI Act vs ISO 42001 — Crosswalk and Integration Pattern
Articles 6 / 16 / 25 / 53
EU AI Act for SaaS — Are You a Provider, Deployer, or Both?
Article 53
EU AI Act Article 53 — General-Purpose AI Model Provider Obligations
Articles 51 / 53 / 55
GPAI Compliance — Obligations for General-Purpose AI Model Providers
Pro feature
Generate Article 11 with AI
LLM-assisted draft of all eight Annex IV sections, pre-filled from your system intake. 5 drafts/month on Pro.
Pro template
Download FRIA template
15-page Article 27 FRIA template (.docx) with the six elements pre-structured and a worked example.
Get the 30-item EU AI Act compliance checklist
Free PDF. No spam. Maps every Article and Annex IV section we ship to a ready-to-action checklist row.
Reference; not legal advice. Verify with qualified counsel before relying on it for compliance decisions. Reg text quoted from the Official Journal version of Regulation (EU) 2024/1689. Published by Agonist Development AB.