Standards and regulation define obligations and management expectations; ratings interpret governance condition.
Enterprise AI governance draws on multiple sources of authority. Risk frameworks guide practice, management-system standards define organizational requirements, legislation creates legal obligations and sector rules add context. A governance rating can map to these instruments while remaining a separate, proprietary governance opinion.
| Instrument | Institutional role | Use in rating analysis |
|---|---|---|
| NIST AI RMF ↗ | Voluntary AI risk-management framework. | Reference language for governance, risk mapping, measurement and management. |
| ISO/IEC 42001:2023 ↗ | AI management-system standard. | Organizational governance, management-system discipline and continual improvement context. |
| ISO/IEC 23894:2023 ↗ | AI risk-management guidance. | Risk identification, assessment, treatment and integration into enterprise processes. |
| EU AI Act ↗ | Risk-based statutory regulation. | Jurisdiction-specific obligations that can affect control and evidence expectations. |
A crosswalk is not a certificate.
Mapping a rating control to an external framework should identify the relevant requirement, internal control, evidence artifact, accountable owner, review state and interpretation assumptions. A crosswalk can support governance analysis but does not establish conformity, accreditation, statutory approval or endorsement by the referenced organization.
Versions and jurisdictions must remain visible.
Standards, regulations and sector requirements are subject to revision. Institutional research should identify the source version or review date, maintain controlled crosswalks and avoid treating standards mappings as permanent. The rating scope should state the jurisdictional context applied.