Free resourceVersion 1.1 · 5 Sep 2026

SundAI AI Control Matrix

A practical map for connecting the EU AI Act, ISO/IEC 42001, ISO/IEC 27001 and NIST AI RMF without creating four separate governance silos.

How to use it

Use the matrix as a control-design aid. Start with one concrete AI use case, identify legal obligations separately, then use the matrix to reuse evidence across governance and security frameworks. It is intentionally not a clause-by-clause legal equivalence map.

Control areaEU AI ActISO 42001ISO 27001NIST AI RMF
AI inventoryStrong relevanceStrongSupportingStrong
Roles & accountabilityExplicit value-chain rolesCoreCore governanceGOVERN
Risk classificationCore legal relevanceRisk processSupportingMAP
Human oversightSpecific duties where relevantStrong relevanceIndirectMANAGE
Data governanceStrong relevanceStrongSecurity relevanceMAP / MEASURE
Information securityImportant in relevant regulated contextsIntegratedPrimary focusMEASURE / MANAGE
Supplier riskValue-chain relevanceStrongStrongMAP / GOVERN
TransparencyArticle 50 + other dutiesStrongSupportingGovernance relevance
Logging & traceabilitySpecific regulated relevanceStrongStrongMEASURE
Testing & evaluationRegulated-system relevanceStrongSupportingMEASURE
Incident managementRelevant dutiesStrongPrimary control areaMANAGE
Change managementOngoing relevanceContinual improvementCoreGOVERN / MANAGE
AI literacyLegal relevanceStrongSecurity-awareness linkGOVERN

A reusable evidence model

Important: the matrix does not claim legal equivalence between standards and the AI Act. A control theme can support multiple frameworks while still requiring framework-specific interpretation and evidence.

Recommended workflow

  1. Choose one AI system or use case.
  2. Determine the organisation’s role and legal scope.
  3. Identify the relevant control areas.
  4. Reuse existing ISMS, privacy and procurement evidence where appropriate.
  5. Close AI-specific gaps such as model governance, transparency, evaluation and human oversight.
  6. Assign an owner and review date to every material gap.

Framework sources

Version 1.1. Last reviewed 5 September 2026. Method: thematic mapping of recurring governance and security control areas using public primary-source descriptions and the AI Act text. The matrix is a practical SundAI resource, not legal advice, an official crosswalk or a clause-level conformity assessment.

Cite this resource

SundAI (2026), SundAI AI Control Matrix, version 1.1, reviewed 5 September 2026. https://sundaibot.com/resources/ai-control-matrix/

For legal or standards-specific claims, cite the relevant underlying EU, ISO or NIST source alongside this practical mapping aid.

Want to adapt the matrix to your organisation?

SundAI can turn the generic control map into a proportionate operating model with owners, evidence and implementation priorities.

Explore AI Governance →