Why map once?
A company selling AI products in several markets may face the EU AI Act, pursue ISO/IEC 42001 certification and use the NIST AI RMF internally, while its security team works from the OWASP Top 10 for LLM Applications and MITRE ATLAS. If each framework gets its own controls and its own evidence, the same work is done several times and the records drift apart.
The alternative is a control library: each control written once, with its evidence, mapped to every framework clause it supports.
What does one mapped control look like?
Take a customer-facing assistant at a bank. Policy: it must not give individual investment advice. Control: a runtime guardrail that detects and blocks such responses. Evidence: pre-launch test results, a log of blocked responses and monthly retests. That one control can support:
- EU AI Act: risk management, record-keeping through logs and post-market monitoring, where the system falls under those obligations.
- ISO/IEC 42001: risk treatment, operational control and monitoring records.
- NIST AI RMF: the Measure function (tests) and the Manage function (runtime response and monitoring).
- OWASP Top 10 for LLM Applications: prompt injection, if the tests include attempts to trick the assistant into giving advice.
- MITRE ATLAS: the adversary techniques the red team used.
What do platforms offer for mapping?
Alice maps WonderFence guardrails to the EU AI Act, ISO 42001, NIST, MITRE ATLAS and OWASP. Pillar Security maps red teaming findings to OWASP and MITRE ATLAS and says it generates audit-ready reports for GDPR, the EU AI Act, ISO 42001 and SOC. SPLX's Enterprise plan lists a compliance framework check for MITRE ATLAS and the OWASP LLM Top 10. Lasso maps red teaming to MITRE and OWASP and describes an audit trail for the EU AI Act, NIST AI RMF and ISO 42001. Credo AI and Holistic AI map their assessments and reports to the EU AI Act, NIST and ISO.
How do you check a mapping is real?
- Ask for one control and follow it end to end: policy text, control configuration, a piece of evidence, and the report line that cites it.
- Check that the mapping names clauses or articles, not only framework names.
- Check that evidence carries dates and system identifiers, so an auditor can tie it to a specific system and period.
- Check what happens to the mapping when the framework is updated.