AI governance

You already did some of this. Here is exactly how much.

Three AI governance regimes, judged against each other control by control. If you have done ISO/IEC 42001, some of the EU AI Act is already answered. It is not most of it, and this page says which parts and how many.

What each one buys you toward the others

Read a row as: holding the first, this much of the second is already evidenced. The reverse direction is a different number, usually very different, and both are shown because that difference is the useful part.

The direction that matters most is the weakest one

Look at the bottom of that list rather than the top. A management-system standard tells you to govern AI; the EU AI Act tells you what to do about a specific high-risk system. The first does not buy much of the second, and any tool claiming otherwise has not read both.

Why a moving standard is the argument for this, not against it

Every claim carries its reasoning

A mapping is a judgement, so it shows what grounds it: the control text on both sides, who judged it, when, and whether it survived a pass that argued against it.

The rejections are published

42,246 claims across the graph were argued against, rejected, and kept with the reason on each. When a standard moves, what we withdrew is as informative as what we kept.

The denominator is verified

Each of these three frameworks carries a control count checked against the issued document, so a percentage is over a real total rather than an editorial grouping.

Nothing here certifies anyone

A crosswalk narrows the work. It is not an assessment, it does not make an organisation compliant, and no tool can.

Ask it yourself, free

Every number on this page is queryable without an account. An agent can call agent_coverage_crosswalk for the headline, agent_crosswalk_provenance for the reasoning, and agent_crosswalk_refuted for what was rejected.