EU AI Act ↔ NIST AI RMF

EU AI Act vs NIST AI RMF — Crosswalk and Practical Differences

A side-by-side of the EU AI Act and NIST AI Risk Management Framework 1.0. Where they overlap, where they diverge, and how to leverage one to satisfy the other.

Source: Regulation (EU) 2024/1689 on EUR-Lex · Last published 2026-04-28 · Draft pending human review

Why this comparison matters

The EU AI Act is regulation — binding under EU law, with Article 99 penalties up to €35 million or 7% of global turnover. The NIST AI Risk Management Framework 1.0 (NIST AI 100-1, January 2023) is voluntary guidance issued by the U.S. National Institute of Standards and Technology. They share a vocabulary and a common ancestry in risk-management-system thinking, but they answer different questions.

A SaaS vendor selling into both EU regulated markets and U.S. Fortune 500 / federal accounts faces both. This pillar maps the overlap, names the gaps, and suggests an integration pattern.

Top-level structure

DimensionEU AI ActNIST AI RMF 1.0
Legal forceBinding regulationVoluntary framework
Geographic scopeEU + extraterritorial reach via Article 2(1)(c)Global voluntary use; baseline for U.S. federal procurement
TriggersHigh-risk classification under Article 6 + Annex III, GPAI under Article 51, prohibited practices under Article 5Self-determined applicability based on AI system risk
FunctionsRisk mgmt, data governance, technical docs, transparency, oversight, accuracy, conformity, post-market monitoringGOVERN, MAP, MEASURE, MANAGE
Conformity modelInternal control (Annex VI) or notified body (Annex VII)Self-attestation
PenaltiesUp to €35M / 7% global turnoverNone directly; reputational + procurement-eligibility consequences

Where they overlap

The Governancer crosswalk maps every item in the 30-item EU AI Act checklist to NIST AI RMF subcategories. Headline overlaps:

  • Article 9 risk management ↔ GOVERN 1.1, MANAGE 1.3. Continuous risk identification, mitigation, documentation.
  • Article 10 data governance ↔ MEASURE 2.2, MEASURE 2.11, MAP 2.3. Data representativeness, fairness/bias, scientific integrity.
  • Article 11 / Annex IV technical documentation ↔ MAP 4.1, GOVERN 1.4. System purpose, intended use, users, limitations; documented and regularly reviewed risk-management process.
  • Article 14 human oversight ↔ GOVERN 3.2, MEASURE 2.8. Roles for human-AI configurations; transparency and accountability.
  • Article 15 accuracy / robustness / cybersecurity ↔ MEASURE 2.5, MEASURE 2.7. Validity, reliability, security, resilience.
  • Article 27 FRIA ↔ MAP 5.1, MAP 5.2. Likelihood and magnitude of impacts; engagement with relevant AI Actors.
  • Article 72 post-market monitoring ↔ MEASURE 4.1, MANAGE 4.1. Tracking risks over time; post-deployment monitoring plans.
  • Article 73 / 79 incidents ↔ MANAGE 4.3. Incident communication.

Where they diverge — five gaps

  1. Conformity assessment. EU AI Act requires a formal pre-market conformity assessment (Article 43) and CE marking. NIST AI RMF is silent on conformity certification.
  2. EU Database registration. Article 49 EU Database has no NIST analogue.
  3. Authorised representative. Non-EU providers need an Article 22 representative; NIST has no such concept.
  4. FRIA. Article 27 FRIA for specific deployer classes is EU-specific; NIST MAP 5.1 / 5.2 is closest but voluntary and broader.
  5. Penalty structure. EU AI Act has explicit fine tiers; NIST doesn't.

Where NIST has more depth

NIST AI RMF goes deeper on:

  • Workforce considerations under GOVERN 2.x and MAP 3.4 — competency frameworks for AI staff.
  • AI Actors stakeholder mapping under GOVERN 5.x — broader than the EU's deployer/provider/user trio.
  • MEASURE 2.x trustworthy-AI characteristics — explicit decomposition into validity, reliability, safety, security, resilience, accountability, transparency, explainability, interpretability, privacy enhancement, fairness with managed bias.

A team that has fully implemented MEASURE 2.x has an evidence base that translates directly into the EU AI Act technical file.

Integration pattern — leverage one to satisfy the other

If you have a NIST AI RMF self-attestation program in place, you have ~70% of the EU AI Act technical-file evidence. The remaining 30% is the AI-Act-specific scaffolding:

  • The Article 43 conformity assessment procedure.
  • The Article 47 declaration of conformity and Article 48 CE marking (where applicable).
  • The Article 49 EU Database registration.
  • The Article 22 authorised representative (if non-EU).
  • The Article 27 FRIA (for covered deployers).

If you have an EU AI Act program, you can produce a NIST AI RMF self-attestation by re-tagging your evidence using the GOVERN/MAP/MEASURE/MANAGE structure. The Governancer Pro crosswalk PDF does this re-tagging automatically.

What we ship

  • Free. Maps your quiz answers to both frameworks at a high level.
  • Pro. Full per-checklist-item NIST AI RMF crosswalk with rationale; downloadable PDF for buyer due-diligence.

Inline crosswalk source

The full Governancer crosswalk lives in the codebase module crosswalk-data.ts, with sources cited inline (NIST AI 100-1 PDF; NIST Playbook).


Disclaimer. Reference; not legal advice. Verify with counsel. Reg text from Regulation (EU) 2024/1689; NIST AI RMF from NIST AI 100-1.

Reference checklist

From the Governancer 30-item EU AI Act checklist. Each item joins to the ISO 42001 + NIST AI RMF crosswalk table below.

  • Article 11 · Starter tier · critical

    Draft technical documentation (system purpose, design, risk)

    Required for all high-risk AI systems before market placement. Our template covers the eight mandatory sections in one .docx.

  • Article 9 · Starter tier · high

    Establish risk management system

    A continuous iterative process. Identify foreseeable risks, estimate impact, document mitigations, review at least quarterly.

  • Article 15 · Starter tier · medium

    Define accuracy, robustness, and cybersecurity measures

    Benchmarks, adversarial testing, incident detection, lifecycle monitoring. Documented in the technical file.

ISO 42001 + NIST AI RMF crosswalk

Pulled live from the Governancer crosswalk module. Mapping reference; not a substitute for ISO 42001 certification audit or NIST AI RMF self-attestation.

ISO/IEC 42001:2023

Checklist itemISO 42001 controlRationale
art11-tech-docsISO/IEC 42001:2023 Clause 7.5 — Documented informationArticle 11 technical file is the AIMS-required documented information evidencing AI system design, purpose, and risk decisions.
art11-tech-docsISO/IEC 42001:2023 Annex A.6.2 — AI system life cycle documentationAnnex A.6.2 requires lifecycle documentation; the Article 11 technical file is its EU AI Act manifestation.
art9-risk-mgmtISO/IEC 42001:2023 Clause 6.1.2 — AI risk assessmentA continuous Article 9 risk management process is the EU-AI-Act realisation of Clause 6.1.2 risk assessment.
art9-risk-mgmtISO/IEC 42001:2023 Clause 6.1.3 — AI risk treatmentArticle 9 mitigation, residual-risk recording and quarterly review provide the risk-treatment evidence required by Clause 6.1.3.
art15-accuracyISO/IEC 42001:2023 Annex A.6.2.4 — Verification and validationArticle 15 accuracy/robustness benchmarks satisfy the verification-and-validation control objective in the lifecycle annex.

NIST AI RMF 1.0

Checklist itemNIST AI RMF subcategoryRationale
art11-tech-docsNIST AI RMF MAP 4.1 — Approaches and metrics for measurement of AI risks are followed; documentation includes purpose, intended use, users, and limitationsArticle 11 technical file documents purpose, design and limitations — the system-context output expected by MAP 4.1.
art11-tech-docsNIST AI RMF GOVERN 1.4 — The risk management process is documented and is regularly reviewedMaintaining a living technical file is the documented and regularly reviewed risk-management evidence under GOVERN 1.4.
art9-risk-mgmtNIST AI RMF GOVERN 1.1 — Legal and regulatory requirements involving AI are understood, managed, and documentedEU AI Act Article 9 risk management explicitly captures the regulatory requirements GOVERN 1.1 wants documented.
art9-risk-mgmtNIST AI RMF MANAGE 1.3 — Responses to the AI risks deemed high priority are developed, planned, and documentedArticle 9 mitigation plans for residual high-priority risks are exactly the responses MANAGE 1.3 expects.
art15-accuracyNIST AI RMF MEASURE 2.5 — The AI system to be deployed is demonstrated to be valid and reliableArticle 15 accuracy benchmarks and robustness evidence demonstrate validity and reliability per MEASURE 2.5.
art15-accuracyNIST AI RMF MEASURE 2.7 — AI system security and resilience are evaluated and documentedArticle 15 cybersecurity measures and adversarial resilience are the security/resilience evaluation in MEASURE 2.7.

Pro feature

Generate Article 11 with AI

LLM-assisted draft of all eight Annex IV sections, pre-filled from your system intake. 5 drafts/month on Pro.

Pro template

Download FRIA template

15-page Article 27 FRIA template (.docx) with the six elements pre-structured and a worked example.

Get the 30-item EU AI Act compliance checklist

Free PDF. No spam. Maps every Article and Annex IV section we ship to a ready-to-action checklist row.


Reference; not legal advice. Verify with qualified counsel before relying on it for compliance decisions. Reg text quoted from the Official Journal version of Regulation (EU) 2024/1689. Published by Agonist Development AB.