Resource
Twelve cells. Three frameworks. One set of codes.
Boards do not ask whether your framework is elegant. They ask whether it covers what they are required to cover.
This is the locked crosswalk behind the columns grid: thirteen rows, being the AI-literacy prerequisite plus twelve layer-by-column cells, each mapped to the EU AI Act, NIST AI RMF and ISO/IEC 42001. The graphic carries the EU codes because those are the ones a European board recognises on sight. The full NIST subcategory and ISO Annex A mappings are below and in the PDF.
Confidence is stated per framework rather than implied across all three. A crosswalk that does not tell you which rows are weakest is asking to be trusted rather than checked.
Twelve cells, with the codes that apply
-
Runtime × Human capability
Oversight that intervenes and overrides.
Art 14 · Art 26 · Art 4
-
Runtime × Governance
Record-keeping, post-market monitoring, serious-incident reporting.
Art 12 · Art 14 · Art 26 · Art 72 · Art 73
-
Runtime × Supply chain
Third-party post-market and robustness to updates.
Art 72 · Art 25 · Art 15 · Art 55 · Art 73
-
Application × Human capability
Deployer use per instructions; oversight design.
Art 4 · Art 14 · Art 26
-
Application × Governance
Prohibited practices, high-risk classification, FRIA, transparency.
Art 5 · Art 6 · Annex III · Art 9 · Art 26 · Art 27 · Art 50
-
Application × Supply chain
Value chain, information to deployers, marking of synthetic content.
Art 25 · Art 13 · Art 50(2)
-
Model assurance × Human capability
Accuracy and robustness testing you can actually read.
Art 4 · Art 14 · Art 15
-
Model assurance × Governance
Risk management, technical documentation, conformity assessment.
Art 9 · Art 11 · Annex IV · Art 15 · Art 17 · Art 43
-
Model assurance × Supply chain
GPAI provider obligations, including systemic risk.
Art 25 · Art 53 · Art 55
-
Data × Human capability
Data-governance competence at this layer.
Art 4 · Art 10
-
Data × Governance
Data and data governance, QMS, risk management system.
Art 10 · Art 17 · Art 9
-
Data × Supply chain
Sourcing, value chain, GPAI training-data summary.
Art 10 · Art 25 · Art 53
Mappings are conceptual correspondences for board explanation, not certified equivalences. On dates: Article 4 on AI literacy has been in force since 2 February 2025, and Article 50 transparency obligations apply from 2 December 2026 on post-Omnibus timing, which stays provisional until Official Journal publication. Do not anchor on 2 August 2026, and do not describe the Act as fully operational.
How to use this in the room
- 01
Pick the cell your initiative is weakest on. Read the codes aloud.
- 02
Ask who is named against each. Not which function — which person.
- 03
These are conceptual correspondences for board explanation, not certified equivalences.
Coverage is not the same as compliance. But you cannot argue compliance without it.
Source: Columns Not Layers locked verified crosswalk, July 2026 — 13 rows (the AI-literacy prerequisite plus 12 layer × column cells), verified against primary sources for the EU AI Act (Regulation (EU) 2024/1689, EUR-Lex) and NIST AI RMF 1.0 (NIST AI 100-1 plus the AIRC Playbook), and against agreeing secondary sources for ISO/IEC 42001 Annex A. Date discipline: Art 4 in force 2 February 2025; Art 50 transparency obligations apply 2 December 2026 (post-Omnibus timing, provisional until Official Journal publication). Never anchor on 2 August 2026 and never describe the Act as fully operational. Mappings are conceptual correspondences, not certified equivalences.
Related
What each AI tier actually decides — regulatory exposure tracked against the consequence of the decision, with the reversibility column most charts leave off.
The agent halt matrix — capability checklists grade agents on one axis and leave off the one that decides who is accountable.
The Governance Memo carries this work monthly for boards and CISOs — one breach post-mortem and two or three governance items.