Skip to content

Standards paper

AI Governance Ratings: Standards and Regulatory Mapping

Standards paper defining how AI governance rating criteria can map to recognized management, risk and regulatory instruments without representing certification, audit equivalence or legal compliance.

ReferenceAIGR-S-2026-01
Versionv1.3
StatusPublished
ReviewedAugust 2026

Purpose

This publication defines the role of standards and regulatory mapping within an AI Governance Rating. The purpose of mapping is to identify where rating criteria and evidence requirements correspond to recognized governance, risk-management and legal concepts. Mapping does not convert a private rating into certification, regulatory approval or a legal determination.

Mapping principles

Standards and regulations differ in purpose, legal effect, scope and assurance model. A rating methodology should therefore map at the level of governance objective, control expectation and evidence requirement rather than assert one-to-one equivalence.

  1. Purpose before terminology. Similar words may serve different functions across instruments.
  2. Scope before alignment. An instrument can apply to a different entity, system, lifecycle stage or jurisdiction.
  3. Evidence before declaration. Stated alignment should be supported by records relevant to the assessed system.
  4. No implied certification. Standards mapping does not represent accredited certification.
  5. No legal conclusion. Regulatory mapping does not determine compliance or legal sufficiency.

Reference instruments

Instrument Primary role Rating use
NIST AI Risk Management Framework Voluntary framework for managing AI risk through Govern, Map, Measure and Manage functions. Supports control taxonomy, risk lifecycle and evidence mapping.
ISO/IEC 42001 Requirements for an artificial intelligence management system. Supports management-system governance, accountability, objectives, controls and continual improvement mapping.
ISO/IEC 23894 Guidance on AI risk management. Supports risk identification, analysis, evaluation, treatment and monitoring concepts.
OECD AI Principles Policy principles for trustworthy AI and accountable stewardship. Supports high-level governance outcome mapping.
EU AI Act Risk-based legal framework for AI systems and actors within scope. Supports jurisdiction-specific obligations mapping where applicable.

Control crosswalk design

A crosswalk should identify the rating criterion, related external provision, nature of relationship and evidence expected. Relationship categories can include direct alignment, partial alignment, contextual relevance and no direct mapping. This avoids overstating equivalence when a rating criterion is broader or narrower than the external instrument.

Where a standard contains certifiable management-system requirements, the rating methodology may consider evidence generated through certification activities, but the rating should independently determine whether that evidence is relevant to the rated scope and current period.

Regulatory overlays

Regulatory mapping should be jurisdiction-specific and version-controlled. The existence of a mapped obligation does not mean the rating provider has determined legal applicability or compliance. The assessment can record whether the organization has identified an obligation, assigned ownership, implemented related controls and retained evidence of its governance process.

Legal interpretation remains the responsibility of appropriately qualified legal counsel and competent authorities. The rating methodology evaluates governance evidence, not the ultimate legal status of the organization or system.

Standards evidence

Relevant evidence may include management-system documentation, risk registers, impact assessments, system inventories, validation records, monitoring procedures, accountability records, internal audit findings, certification records and corrective-action records. External assurance can strengthen the evidence base where its scope and period correspond to the rating scope, but should not be treated as dispositive where the rating asks a different question.

Version and change control

Standards and laws evolve. Each mapping should therefore identify the source version, publication or effective date and the date on which the crosswalk was reviewed. Material revisions should trigger review of affected criteria. Historical rating records should preserve the mapping version used at the time of the decision.

Institutional boundary

Mapping is not equivalenceA standards or regulatory crosswalk identifies analytical relationships. It does not represent certification, accreditation, regulator endorsement, legal advice or a determination that the rated entity complies with any external instrument.

Research status and limitations

This publication provides a methodology for standards and regulatory mapping. It does not provide jurisdiction-specific legal advice and does not replace the official text of any standard, regulation, guidance document or regulatory decision.

Sources and research basis