AI Governance Control Crosswalk
One control program, mapped across every regime in play. The amber column reads it in plain English, the pain and the trigger an executive feels. The AI spine, NIST AI RMF and ISO 42001, is constant; the compliance regime flexes. Pick your view below.
| Control domain | Why it matters | What good looks like | NIST AI RMF | ISO/IEC 42001 | SOC 2 / ISO 27001 | NIST 800-171 / CMMC | Privacy | Enforced in |
|---|---|---|---|---|---|---|---|---|
| 1. Governance, Accountability & Policy | No one owns your AI. When the board or a regulator asks who's accountable and what your rules are, you have no answer, and your projects stall waiting for someone to say yes. | Named AI owner + oversight body, an approved AI policy & acceptable-use standard, and decision rights (RACI) for AI. | GOVERN 1-4 (policy, accountability, roles, culture) | Cl.5 Leadership; A.2 AI policy; A.3 Internal org & roles | SOC 2 CC1 (control environment); ISO 27001 A.5.1-5.4 | No standalone family; carried by the SSP + org policy. CMMC L2 assessment expects documented governance. | NIST PF GOVERN-P; ISO 27701 s.6 (PIMS leadership) | Policy of record in Purview / ServiceNow IRM; posture tracked in Compliance Manager |
| 2. AI System & Agent Inventory + Risk Classification | You can't say how many AI tools and agents you're running, or which are risky. Shadow AI is already in your environment, and the next security review wants the inventory you don't have. | Live inventory of every AI system and agent (owner, data access, tool access, risk tier) on a defined risk-classification scheme. | MAP 1-5 (context, categorization, risk) | A.4 AI system resources; A.5 AI system impact assessment | SOC 2 CC3 (risk assessment); ISO 27001 A.5.9 (asset inventory) | 3.11 Risk Assessment; 3.4 Config Mgmt (inventory); CMMC L2 RA/CM | NIST PF IDENTIFY-P; ISO 27701 (PII inventory / RoPA) | Purview Data Map + AI Hub inventory; ServiceNow CMDB; Vanta asset inventory |
| 3. Data Governance & Privacy | Your AI surfaces the wrong data to the wrong person. One slip and you're sending a breach notice, paying a fine, or losing a regulated client. | Data minimization, quality & classification for AI; privacy-by-design; PII handling and data-sharing controls. | MAP 2 (data); MEASURE 2 (data quality); GOVERN 1.2 | A.7 Data for AI systems | SOC 2 Confidentiality + Privacy (P-series); ISO 27001 A.5.34 (PII), A.8.10-8.12 | 3.1 / 3.13 (CUI protection & boundary); 3.8 Media Protection; CMMC L2 AC/SC/MP | ISO 27701 PIMS / GDPR; NIST PF CONTROL-P & PROTECT-P; PIA/PTA (federal) | Purview Info Protection (sensitivity labels) + DLP + DSPM for AI; OneTrust for privacy ops |
| 4. Identity & Access Governance, incl. agents (your Domain 1) | One of your agents quietly gains access it shouldn't have, or a shadow agent runs in your environment unseen. Now you've got an actor in your systems you can't track. | Unique non-human identity per agent, least-privilege + just-in-time scoping, no privilege drift; agent identity events audited separately. | MANAGE 1-2; GOVERN 1.5 | A.9 Use of AI systems; A.4 resources | SOC 2 CC6.1-6.3 (logical access); ISO 27001 A.5.15-5.18, A.8.2 (privileged), A.8.5 (auth) | 3.1 Access Control; 3.5 Identification & Authentication; CMMC L2 AC/IA | ISO 27701 (access to PII); NIST PF PR.AC | Entra ID workload/agent identities; Purview; ServiceNow access mgmt |
| 5. Human Oversight & Decision Rights (your Domain 2) | Your AI made a consequential call (a denial, a price, a clinical flag) with no human check, and now you're explaining to a regulator why no one was in the loop. | Oversight tier (autonomous / advisory / required) designed into the workflow at each material decision; override rates tracked. | GOVERN 1.2; MANAGE 1.3 & 2.3 (human oversight, override) | A.9.2 Human oversight; A.6 lifecycle | Generic governance only (SOC 2 CC5 / ISO 27001 A.5.4); no control for human oversight of AI decisions | No direct control (design-level); supports 3.1 (authorized actions only) | GDPR Art.22 (automated decisions); ISO 27701; NIST PF CONTROL-P | Approval gates in Power Platform / ServiceNow; Copilot Studio guardrails |
| 6. AI / Agent Security & Tool-Use, MCP (your Domain 3) | A prompt injection or a rogue tool call turns your AI into a data-exfiltration path, a new attack surface you haven't covered yet. | Deny-by-default tool/MCP allowlist per agent; tool calls logged as security events; output validation; prompt-injection red-teaming. | MEASURE 2 (security / robustness); MANAGE 2 (risk treatment) | A.6 lifecycle (secure dev/op); A.10 third-party components | SOC 2 CC6.6-6.8, CC7 (operations); ISO 27001 A.8.7-8.9, A.8.16, A.8.23, A.8.26 | 3.13 System & Comms Protection; 3.14 System & Info Integrity; CMMC L2 SC/SI | Exfiltration controls protect PII (ISO 27701); NIST PF PROTECT-P | Purview DLP + DSPM for AI; Defender for Cloud Apps; API gateway / MCP allowlist; Azure AI Content Safety |
| 7. Audit Trail, Logging & Explainability (your Domain 4) | An auditor asks why your AI did that, and you can't reconstruct it. A routine decision becomes a finding you can't close. | Full reasoning trace (not just I/O) for consequential decisions, immutable & tamper-evident, navigable by a non-technical compliance officer. | MEASURE 1 & 3; MANAGE 4 (documentation, transparency) | A.6 lifecycle records; A.8 information for interested parties | SOC 2 CC4, CC7.2-7.3 (monitoring); ISO 27001 A.8.15 (logging), A.8.16 (monitoring) | 3.3 Audit & Accountability; CMMC L2 AU | Records of processing (ISO 27701 / GDPR Art.30); NIST PF | Purview Audit + eDiscovery; Microsoft Sentinel (immutable); Azure Monitor; ServiceNow |
| 8. Monitoring: Bias, Fairness & Performance (your Domain 6) | Your AI is quietly biased or drifting on decisions about real people, and you find out from a complaint, a headline, or a lawsuit. | Fairness metrics set pre-deployment; disparate-impact + drift monitored on a cadence (tool-inherited bias included); review thresholds defined. | MEASURE 2 (fairness, bias, performance) & 4 (feedback) | A.6 performance evaluation; Cl.9 monitoring | Monitoring only (SOC 2 CC4 / ISO 27001 A.8.16); no fairness control | No direct control (not a security regime); flag the gap to leadership | Disparate impact on individuals (NIST PF); ISO 27701 | Azure ML / AI Foundry responsible-AI dashboards & evals; Credo AI / Holistic AI (model governance) |
| 9. Incident Response & Resilience, autonomous failures (your Domain 5) | Your agent goes off the rails at machine speed and you have no kill switch. Your IR team has never seen this and can't stop it. | Documented kill switch per agent (who / when / in-flight handling); IR trained on agent architecture; tabletops; governance-failure post-mortems. | MANAGE 2.4, 3, 4 (response, recovery, incidents) | A.6 operation; Cl.10 nonconformity & improvement | SOC 2 CC7.3-7.5 (incident); ISO 27001 A.5.24-5.28 (incident), A.5.29-5.30 (continuity) | 3.6 Incident Response; CMMC L2 IR | Breach notification (ISO 27701 / GDPR Art.33-34); NIST PF | Sentinel + Defender (SOAR / kill-switch automation); agent disable controls; ServiceNow IR |
| 10. Regulatory Alignment & Third-Party / Supply Chain (your Domain 7) | You're suddenly in scope for the EU AI Act, CMMC, or HIPAA, or your vendor's model fails and it's your problem. Your deal stays blocked until you prove compliance. | Each deployment mapped to applicable regimes (EU AI Act tier, HIPAA, CMMC/CUI, federal AI transparency); model & tool vendors risk-reviewed; compliance is a deployment prerequisite. | GOVERN 3 & 4 (legal/regulatory, third party); MAP 4 (legal) | A.10 Third-party & supplier; A.5 impact; Cl.4 context | SOC 2 CC9 (vendor risk); ISO 27001 A.5.19-5.23 (supplier), A.5.31 (legal) | 3.12 Security Assessment; 3.16/3.17 (r3 supply chain); CMMC L2 + SPRS score; flow-down to subs | Cross-border transfers & DPAs (ISO 27701 / GDPR); NIST PF | Compliance Manager (regime templates); OneTrust (vendor/AI risk); ServiceNow VRM; eMASS / SPRS (federal) |
The amber column is the plain-English pain and trigger for leadership; the shaded columns are the constant AI spine. v1 draft: technical mappings are at the control-family / criteria level; exact sub-control IDs are validated per engagement. Two domains, human oversight and fairness (rows 5 and 8), sit outside every security regime, not SOC 2, ISO 27001, CMMC, or 800-171. They exist only in the AI spine. That gap is the case for AI governance as its own discipline.
Mapped your controls? The Expert Readiness Assessment scores them against evidence and turns the gaps into a roadmap you can defend.
Book a conversation →