Reference tool

One inventory, five frameworks — the crosswalk.

The whole point of anchoring your governance program on COSO ERM and NIST's four functions is that everything else — EU AI Act obligations, your existing SR 11-7 model risk program, ISO/IEC 42001 — maps onto the same structure. You don't need five separate programs.

NIST function COSO ERM component EU AI Act (high-risk obligation) SR 11-7 equivalent ISO/IEC 42001 area
GOVERN Governance & Culture Risk management system & quality management system (Arts. 9, 17) Board and senior management oversight of model risk Leadership & organizational context (Clause 5)
MAP Strategy & Objective-Setting Data governance & technical documentation (Arts. 10–11) Model inventory & use-case documentation Planning & AI system impact assessment (Clause 6, Annex A)
MEASURE Performance Accuracy, robustness & cybersecurity testing (Art. 15); conformity assessment Independent model validation Performance evaluation (Clause 9)
MANAGE Review & Revision; Information & Reporting Human oversight (Art. 14); logging (Art. 12); post-market monitoring (Art. 72) Ongoing monitoring & model performance review Improvement & nonconformity (Clause 10)

This is directional, not a certified legal mapping. It's the structure we use to keep one inventory and one set of controls instead of four. Whether a specific EU AI Act article applies to a specific system is a scoping question we work through in an assessment — and ultimately a question for your counsel.

Worked example

A community bank's fraud-detection model, walked through all four columns

GOVERN (COSO: Governance & Culture): The risk committee (not a new AI committee) signs off on the model before it goes live and reviews it annually — same cadence as your existing model risk policy already requires.

MAP (COSO: Strategy & Objective-Setting): The model is logged in your AI/model inventory with its purpose (transaction fraud scoring), data sources, and the population it affects. Under the EU AI Act it likely lands in the limited or minimal tier — fraud detection isn't Annex III credit scoring, but document the reasoning.

MEASURE (COSO: Performance): Quarterly false-positive and false-negative rate review, plus a disparate-impact check across protected classes, folded into your existing model validation cycle.

MANAGE (COSO: Review & Revision; Information & Reporting): A named owner monitors performance monthly; if false positives spike after a vendor update, there's a documented rollback path — not an ad hoc scramble.

Get this as a working template

The full crosswalk as a fillable inventory template — bring your own AI systems and score them against all four frameworks at once.

No spam. One spreadsheet, one follow-up email.