Global AI Assurance · Regulatory assurance
Regulatory Crosswalk Engine
A regulated institution asks whether it is compliant. A supervisor asks something harder: how to supervise thousands of AI systems consistently, across different laws, jurisdictions and technical architectures.
The crosswalk is the answer to the second question. It reads the major frameworks together and names what they share, where they diverge, where they conflict, and where none of them has arrived yet.
Published as reference architecture. Control weights, grading rubrics and the full control set are set per engagement.
The entity asks
Am I compliant?
The supervisor asks
How do I consistently supervise thousands of AI systems operating under different laws, jurisdictions and technical architectures?
What is read together
Frameworks are described by posture, not ranked.
EU AI Act
Risk-tiered, prescriptive, documentation-heavy
NIST AI RMF and the emerging critical-infrastructure profile
Voluntary function-based framework, increasingly referenced in supervision
ISO/IEC 42001
Management-system certification; process rather than outcome
OECD AI Principles
Principles-level; the common vocabulary most regimes borrow from
UK principles-based approach with sector regulators
Outcome-focused, delegated to existing supervisors
Canadian federal directives and proposed AI legislation
Public-sector directives operative; private-sector regime still forming
Japanese guidelines and sector supervision
Guidance-led, with strong sector expectations
Singapore model governance and sector guidance
Testable, tooling-oriented, sector-aligned
Gulf national AI and data regimes
Sovereignty and residency forward
Requirement by requirement
The two entries marked missing are the ones that matter most for what is now being deployed.
Inventory of AI systems in use
Every framework assumes it. Almost no institution can produce it completely on first ask.
Common
Risk classification of each use
Tiers differ in name; the underlying test is consequence to a person or a critical service.
Common
Pre-deployment evaluation
One regime sets the documentation floor; others accept the same artefacts once mapped.
Higher local standard
Human oversight
Some regimes require oversight to exist; at least one requires it to be exercised locally.
Jurisdiction-specific
Transparency to affected persons
Trigger thresholds and the required content of the explanation both differ.
Jurisdiction-specific
Data governance and provenance
Different wording, same artefact: lineage from source to model with lawful basis.
Equivalent
Post-deployment monitoring
Increasingly explicit, and the requirement most often unevidenced in practice.
Common
Incident reporting
Clocks, thresholds and recipients differ from a single detection event.
Conflicting
Third-party and vendor AI duties
Flow-down obligations to providers and subprocessors, with audit rights.
Common
Agent authority and autonomous action
Almost no regime yet addresses an agent as a distinct actor with delegated authority.
Missing
Runtime intervention capability
Frameworks require oversight but rarely require the ability to interrupt an action in flight.
Missing
Evidence residency
Some supervisors require the record to remain where they can compel it.
Jurisdiction-specific
Sovereignty of compute and inference
Sovereignty-forward regimes set requirements the general frameworks do not contemplate.
Higher local standard
Independent assessment
Accepted or expected in some regimes, absent in others, and moving quickly.
Jurisdiction-specific
A crosswalk is a diagnosis. The baseline is what an institution can actually operate against.
See the baseline and the overlays