The crosswalk

Where the frameworks genuinely meet — and where they only look alike.

Five regimes ask for overlapping work, and vendors sell that overlap as a mapping. The honest version is narrower: the EU AI Act grants six explicit routes for earlier work to count. Those are cited below. Everything beyond them is a resemblance, and we say so rather than counting it.

Three relations

Only one of them counts.

Closes

A step closes a requirement of its own framework. This is the only relation that moves a completion figure or appears in the coverage matrix.

It counts.

Related · unverified

A requirement in another framework that plainly concerns the same ground. Shown so you can see the neighbourhood — never credited, and every EU AI Act link in this class is marked unverified.

It is a signpost.

Statutory reuse

One of the six routes below, where the EU AI Act's own text says earlier work may be drawn on. It prefills a form and explains itself. It does not change a status.

It saves typing, not judgement.

Statutory routes

The places the Act itself lets earlier work count.

Each row quotes the provision that grants it. Where a route is open only to certain organisations, the condition is stated — a route offered to someone with no right to it is worse than no route at all.

EU AI Act Art. 27(4)

Fundamental-rights impact assessment / DPIA

What the Act says — Where the obligations of Art. 27 are already met through the data-protection impact assessment carried out under GDPR Art. 35, the fundamental-rights assessment complements that assessment — the deployer may cross-reference it or incorporate the relevant parts.

What you are asked to confirm: Draw the overlapping parts from your data-protection impact assessment, then check they reach the fundamental-rights questions the DPIA was never written to answer.

EU AI Act Art. 26(9)

Provider's instructions for use, feeding the DPIA

What the Act says — Deployers of high-risk systems shall use the information provided under Art. 13 to carry out their data-protection impact assessment under GDPR Art. 35.

What you are asked to confirm: Bring the provider's instructions for use into the impact assessment, then check they describe this deployment rather than the product in general.

EU AI Act Art. 8(2)

Technical documentation and testing

What the Act says — Where a product is covered both by this Regulation and by the Annex I harmonisation legislation, the provider may integrate the testing, reporting, information and documentation into procedures that legislation already requires.

Open only where: Only where the product also falls under Annex I harmonisation legislation — a medical device, machinery, a vehicle and so on.

What you are asked to confirm: Name the Annex I procedure the documentation is integrated into, then check it carries the Art. 11 content as well as its own.

EU AI Act Art. 17(3)

Quality management system

What the Act says — Providers already subject to quality-management obligations under sectoral Union law may include the Art. 17(1) aspects within that existing system.

Open only where: Only where sectoral UNION LAW already imposes a quality-management duty. A voluntary standard is not sectoral Union law — ISO/IEC 42001 does not open this route.

What you are asked to confirm: Name the sectoral instrument and the system it requires, then check the Art. 17(1) aspects are written into it rather than assumed.

EU AI Act Art. 17(4)

Quality management system

What the Act says — For providers that are financial institutions subject to internal governance requirements under Union financial-services law, the quality-management duty is deemed fulfilled by complying with those rules — except for the aspects at Art. 17(1)(g), (h) and (i).

Open only where: Only for financial institutions subject to internal governance requirements under Union financial-services law. Points (g), (h) and (i) stay yours whatever those rules say.

What you are asked to confirm: Name the internal governance arrangements you rely on, then account separately for Art. 17(1)(g), (h) and (i), which this route does not reach.

EU AI Act Art. 26(5)

Post-deployment monitoring

What the Act says — Deployers that are financial institutions subject to internal governance requirements under Union financial-services law are deemed to fulfil the monitoring obligation by complying with those arrangements.

Open only where: Only for financial institutions subject to internal governance requirements under Union financial-services law.

What you are asked to confirm: Name the internal governance arrangements that monitor this system, then check they observe it in operation rather than only at approval.

Declaring one of these prefills a form and records that you relied on it. It does not tick the obligation. Whether your own governance arrangements really reach far enough is a judgement only you can make, and the record keeps it in your name.

What we do not claim

The part most crosswalks leave out.

No requirement equivalence. Nowhere does Veritome assert that an ISO/IEC 42001 control meets an EU AI Act article. That claim needs the harmonised standard — prEN 18286 — cited in the Official Journal, and it is not. A table that asserts it anyway is an opinion formatted as a fact.

Shared artefacts are not built. There is a real set of cases where two frameworks plainly want the same document without either saying one stands in for the other. We have not shipped it, and we name it so the absence is visible rather than mistaken for completeness.

A related link is never credit. Where a requirement of one framework sits on the same ground as another, the register shows it and marks it unverified. Reading a signpost as a credit is how an organisation arrives at an audit believing work was done that nobody did.

How the five frameworks run on one register
Straight answers

About the crosswalk.

Does running one framework get me credit against another?

Only where the law says so, and the law says so in six places. Everything else is a resemblance. A step in one programme can close a requirement of that framework, and it may be related to a requirement of another — but related is a signpost, not a credit, and Veritome never counts it as one.

Why not map ISO 42001 controls onto EU AI Act articles?

Because asserting that a control meets an article is a claim about requirement equivalence, and the instrument that would carry it — prEN 18286, the harmonised standard — is not yet cited in the Official Journal. Until it is, a mapping presented as compliance is somebody's opinion wearing a table.

So what does a reuse route actually do?

It changes what a form is prefilled with and what the screen explains. It never moves a completion percentage, never changes an obligation's status and never counts toward coverage. You declare the reliance; the status stays yours, because whether an organisation truly complies with its own internal governance is not a fact this product can observe.

What are Tier B and Tier C?

Tier B is the set of shared artefacts — cases where two frameworks plainly want the same document, without either instrument saying one satisfies the other. Tier C is interpretive mapping. Neither is built. They are named so the ladder is legible and so nobody assumes the six statutory routes are the whole story.