FL Fredrik Lindstrom


Boards do not ask whether your framework is elegant. They ask whether it covers what they are required to cover.

This is the locked crosswalk behind the columns grid: thirteen rows, being the AI-literacy prerequisite plus twelve layer-by-column cells, each mapped to the EU AI Act, NIST AI RMF and ISO/IEC 42001. The graphic carries the EU codes because those are the ones a European board recognises on sight. The full NIST subcategory and ISO Annex A mappings are below and in the PDF.

Confidence is stated per framework rather than implied across all three. A crosswalk that does not tell you which rows are weakest is asking to be trusted rather than checked.

A four-by-three matrix of the columns framework with the EU AI Act article numbers that apply to each cell, from data through model assurance and application to runtime monitoring.
Download the crosswalk PDF, text selectable, prints for board packs. No email required.

Twelve cells, with the codes that apply

  1. Runtime × Human capability

    Oversight that intervenes and overrides.

    Art 14 · Art 26 · Art 4

  2. Runtime × Governance

    Record-keeping, post-market monitoring, serious-incident reporting.

    Art 12 · Art 14 · Art 26 · Art 72 · Art 73

  3. Runtime × Supply chain

    Third-party post-market and robustness to updates.

    Art 72 · Art 25 · Art 15 · Art 55 · Art 73

  4. Application × Human capability

    Deployer use per instructions; oversight design.

    Art 4 · Art 14 · Art 26

  5. Application × Governance

    Prohibited practices, high-risk classification, FRIA, transparency.

    Art 5 · Art 6 · Annex III · Art 9 · Art 26 · Art 27 · Art 50

  6. Application × Supply chain

    Value chain, information to deployers, marking of synthetic content.

    Art 25 · Art 13 · Art 50(2)

  7. Model assurance × Human capability

    Accuracy and robustness testing you can actually read.

    Art 4 · Art 14 · Art 15

  8. Model assurance × Governance

    Risk management, technical documentation, conformity assessment.

    Art 9 · Art 11 · Annex IV · Art 15 · Art 17 · Art 43

  9. Model assurance × Supply chain

    GPAI provider obligations, including systemic risk.

    Art 25 · Art 53 · Art 55

  10. Data × Human capability

    Data-governance competence at this layer.

    Art 4 · Art 10

  11. Data × Governance

    Data and data governance, QMS, risk management system.

    Art 10 · Art 17 · Art 9

  12. Data × Supply chain

    Sourcing, value chain, GPAI training-data summary.

    Art 10 · Art 25 · Art 53

Mappings are conceptual correspondences for board explanation, not certified equivalences. On dates: Article 4 on AI literacy has been in force since 2 February 2025, and Article 50 transparency obligations apply from 2 December 2026 on post-Omnibus timing, which stays provisional until Official Journal publication. Do not anchor on 2 August 2026, and do not describe the Act as fully operational.


How to use this in the room

  1. 01

    Pick the cell your initiative is weakest on. Read the codes aloud.

  2. 02

    Ask who is named against each. Not which function — which person.

  3. 03

    These are conceptual correspondences for board explanation, not certified equivalences.

Coverage is not the same as compliance. But you cannot argue compliance without it.

Source: Columns Not Layers locked verified crosswalk, July 2026 — 13 rows (the AI-literacy prerequisite plus 12 layer × column cells), verified against primary sources for the EU AI Act (Regulation (EU) 2024/1689, EUR-Lex) and NIST AI RMF 1.0 (NIST AI 100-1 plus the AIRC Playbook), and against agreeing secondary sources for ISO/IEC 42001 Annex A. Date discipline: Art 4 in force 2 February 2025; Art 50 transparency obligations apply 2 December 2026 (post-Omnibus timing, provisional until Official Journal publication). Never anchor on 2 August 2026 and never describe the Act as fully operational. Mappings are conceptual correspondences, not certified equivalences.


Related

What each AI tier actually decides — regulatory exposure tracked against the consequence of the decision, with the reversibility column most charts leave off.

The agent halt matrix — capability checklists grade agents on one axis and leave off the one that decides who is accountable.

The Governance Memo carries this work monthly for boards and CISOs — one breach post-mortem and two or three governance items.