Reference tool
One inventory, five frameworks — the crosswalk.
The whole point of anchoring your governance program on COSO ERM and NIST's four functions is that everything else — EU AI Act obligations, your existing SR 11-7 model risk program, ISO/IEC 42001 — maps onto the same structure. You don't need five separate programs.
| NIST function | COSO ERM component | EU AI Act (high-risk obligation) | SR 11-7 equivalent | ISO/IEC 42001 area |
|---|---|---|---|---|
| GOVERN | Governance & Culture | Risk management system & quality management system (Arts. 9, 17) | Board and senior management oversight of model risk | Leadership & organizational context (Clause 5) |
| MAP | Strategy & Objective-Setting | Data governance & technical documentation (Arts. 10–11) | Model inventory & use-case documentation | Planning & AI system impact assessment (Clause 6, Annex A) |
| MEASURE | Performance | Accuracy, robustness & cybersecurity testing (Art. 15); conformity assessment | Independent model validation | Performance evaluation (Clause 9) |
| MANAGE | Review & Revision; Information & Reporting | Human oversight (Art. 14); logging (Art. 12); post-market monitoring (Art. 72) | Ongoing monitoring & model performance review | Improvement & nonconformity (Clause 10) |
This is directional, not a certified legal mapping. It's the structure we use to keep one inventory and one set of controls instead of four. Whether a specific EU AI Act article applies to a specific system is a scoping question we work through in an assessment — and ultimately a question for your counsel.
Worked example
A community bank's fraud-detection model, walked through all four columns
GOVERN (COSO: Governance & Culture): The risk committee (not a new AI committee) signs off on the model before it goes live and reviews it annually — same cadence as your existing model risk policy already requires.
MAP (COSO: Strategy & Objective-Setting): The model is logged in your AI/model inventory with its purpose (transaction fraud scoring), data sources, and the population it affects. Under the EU AI Act it likely lands in the limited or minimal tier — fraud detection isn't Annex III credit scoring, but document the reasoning.
MEASURE (COSO: Performance): Quarterly false-positive and false-negative rate review, plus a disparate-impact check across protected classes, folded into your existing model validation cycle.
MANAGE (COSO: Review & Revision; Information & Reporting): A named owner monitors performance monthly; if false positives spike after a vendor update, there's a documented rollback path — not an ad hoc scramble.
Get this as a working template
The full crosswalk as a fillable inventory template — bring your own AI systems and score them against all four frameworks at once.
No spam. One spreadsheet, one follow-up email.