Skip to content

    ISO/IEC 42001:2023 (clauses and Annex A) to NIST AI RMF 1.0 control mapping

    ISO/IEC 42001:2023 (clauses and Annex A) and NIST AI RMF 1.0 both map to 63 NIST SP 800-53 controls. Every one is listed below, with the controls on each side that map to it.

    Shared NIST 800-53 controls
    63
    ISO/IEC 42001:2023 (clauses and Annex A) controls involved
    47
    NIST AI RMF 1.0 controls involved
    43
    NIST 800-53 families touched
    20

    How this pairing is derived

    Both frameworks are mapped to NIST SP 800-53 Rev 5 in the source dataset, so the ground they share is the set of NIST controls they both reference. That set is what the table shows. It is not an authored ISO/IEC 42001:2023 (clauses and Annex A) to NIST AI RMF 1.0 crosswalk: two controls on the same row are related through the NIST control between them, not asserted to be equivalent to each other.

    Shared controls in full

    NIST SP 800-53 Rev 5 controls mapped by both ISO/IEC 42001:2023 (clauses and Annex A) and NIST AI RMF 1.0, with the controls on each side that map to them.
    NIST 800-53 controlFamilyISO/IEC 42001:2023 (clauses and Annex A) controlsNIST AI RMF 1.0 controls
    AC-1Policy and ProceduresACAccess Control5.1, 5.2, 7.5.1, 7.5.2, 7.5.3, A.2, A.2.2, A.2.3, A.2.4GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 3.2, GOVERN 4.1, GOVERN 5.1, GOVERN 6.1, MAP 3.5
    AT-1Policy and ProceduresATAwareness and Training5.1, 5.2, 7.5.1, 7.5.2, 7.5.3, A.2, A.2.2, A.2.3, A.2.4GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 3.2, GOVERN 4.1, GOVERN 5.1, GOVERN 6.1, MAP 3.5
    AU-1Policy and ProceduresAUAudit and Accountability5.1, 5.2, 7.5.1, 7.5.2, 7.5.3, A.2, A.2.2, A.2.3, A.2.4GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 3.2, GOVERN 4.1, GOVERN 5.1, GOVERN 6.1, MAP 3.5
    CA-1Policy and ProceduresCAAssessment, Authorization, and Monitoring5.1, 5.2, 7.5.1, 7.5.2, 7.5.3, A.2, A.2.2, A.2.3, A.2.4, A.6.2.5GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 3.2, GOVERN 4.1, GOVERN 4.3, GOVERN 5.1, GOVERN 6.1, MANAGE 1.1, MAP 3.5
    CA-2Control AssessmentsCAAssessment, Authorization, and Monitoring7.4, A.4.2, A.6.2.2, A.6.2.5GOVERN 1.5
    CA-2(2)Specialized AssessmentsCAAssessment, Authorization, and MonitoringA.6.2.5MAP 2.3, MEASURE 3.1, MEASURE 3.2
    CA-5Plan of Action and MilestonesCAAssessment, Authorization, and Monitoring10.2, 9.3.2MANAGE 1.1, MANAGE 1.2, MANAGE 1.3, MANAGE 1.4, MANAGE 3.1, MEASURE 3.1, MEASURE 3.2
    CA-6AuthorizationCAAssessment, Authorization, and MonitoringA.6.2.5MANAGE 1.1
    CA-7(1)Independent AssessmentCAAssessment, Authorization, and Monitoring9.2.2GOVERN 1.5
    CM-1Policy and ProceduresCMConfiguration Management5.1, 5.2, 7.5.1, 7.5.2, 7.5.3, A.2, A.2.2, A.2.3, A.2.4GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 3.2, GOVERN 4.1, GOVERN 5.1, GOVERN 6.1, MAP 3.5
    CP-1Policy and ProceduresCPContingency Planning5.1, 5.2, 7.5.1, 7.5.2, 7.5.3, A.2, A.2.2, A.2.3, A.2.4GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 3.2, GOVERN 4.1, GOVERN 5.1, GOVERN 6.1, GOVERN 6.2, MAP 3.5
    IA-1Policy and ProceduresIAIdentification and Authentication5.1, 5.2, 7.5.1, 7.5.2, 7.5.3, A.2, A.2.2, A.2.3, A.2.4GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 3.2, GOVERN 4.1, GOVERN 5.1, GOVERN 6.1, MAP 3.5
    IR-1Policy and ProceduresIRIncident Response5.1, 5.2, 7.5.1, 7.5.2, 7.5.3, A.2, A.2.2, A.2.3, A.2.4GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 3.2, GOVERN 4.1, GOVERN 5.1, GOVERN 6.1, GOVERN 6.2, MANAGE 2.3, MANAGE 2.4, MAP 3.5
    IR-4Incident HandlingIRIncident ResponseA.3.3GOVERN 6.2, MANAGE 2.3, MANAGE 2.4
    IR-6Incident ReportingIRIncident ResponseA.8.3, A.8.4MANAGE 4.3
    MA-1Policy and ProceduresMAMaintenance5.1, 5.2, 7.5.1, 7.5.2, 7.5.3, A.2, A.2.2, A.2.3, A.2.4GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 3.2, GOVERN 4.1, GOVERN 5.1, GOVERN 6.1, MAP 3.5
    PE-1Policy and ProceduresPEPhysical and Environmental Protection5.1, 5.2, 7.5.1, 7.5.2, 7.5.3, A.2, A.2.2, A.2.3, A.2.4GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 3.2, GOVERN 4.1, GOVERN 5.1, GOVERN 6.1, MAP 3.5
    PL-1Policy and ProceduresPLPlanning4.1, 5.1, 5.2, 7.1, 7.5.1, 7.5.2, 7.5.3, A.2, A.2.2, A.2.3, A.2.4, A.4.2, A.6.1, A.6.1.3, A.6.2.3GOVERN 1.1, GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 3.1, GOVERN 3.2, GOVERN 4.1, GOVERN 4.2, GOVERN 5.1, GOVERN 6.1, MANAGE 2.1, MANAGE 2.2, MAP 3.5
    PL-4Rules of BehaviorPLPlanning7.3GOVERN 4.1
    PL-9Central ManagementPLPlanning5.3, A.3.2GOVERN 1.2, GOVERN 1.3, GOVERN 2.1, GOVERN 2.3
    RA-1Policy and ProceduresRARisk Assessment5.1, 5.2, 6.1.1, 6.1.2, 6.1.3, 7.5.1, 7.5.2, 7.5.3, 8.2, A.2, A.2.2, A.2.3, A.2.4, A.5GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 1.5, GOVERN 3.2, GOVERN 4.1, GOVERN 5.1, GOVERN 6.1, MAP 3.5
    RA-2(1)Impact-level PrioritizationRARisk Assessment6.1.2MANAGE 1.2, MAP 5.1
    RA-3Risk AssessmentRARisk Assessment6.1.2, 8.2, A.5.3, A.5.4, A.5.5GOVERN 1.5
    RA-7Risk ResponseRARisk Assessment6.1.3, 8.3MANAGE 1.3, MANAGE 2.3, MANAGE 2.4
    RA-8Privacy Impact AssessmentsRARisk Assessment6.1.4, 8.4, A.5.3, A.5.4, A.5.5MAP 1.1, MEASURE 2.10
    RA-9Criticality AnalysisRARisk Assessment4.1, 4.2, A.4.2, A.6.2.2MAP 1.6
    SA-1Policy and ProceduresSASystem and Services Acquisition5.1, 5.2, 7.5.1, 7.5.2, 7.5.3, A.2, A.2.2, A.2.3, A.2.4, A.6.1, A.6.1.3, A.6.2.3GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 3.1, GOVERN 3.2, GOVERN 4.1, GOVERN 4.2, GOVERN 5.1, GOVERN 6.1, MAP 3.5
    SA-2Allocation of ResourcesSASystem and Services Acquisition5.1, 7.1, A.4.2MANAGE 2.1
    SA-3System Development Life CycleSASystem and Services AcquisitionA.3.3, A.4.2, A.6.2.2, A.6.2.7, A.6.2.8GOVERN 1.7, MANAGE 2.2
    SA-3(1)Manage Preproduction EnvironmentSASystem and Services AcquisitionA.3.3, A.4.2, A.6.2.2, A.6.2.7, A.6.2.8GOVERN 1.7, MANAGE 2.2
    SA-4Acquisition ProcessSASystem and Services AcquisitionA.10, A.10.2, A.10.3, A.6.1, A.6.1.3, A.6.2.2, A.6.2.3GOVERN 1.2, GOVERN 3.1, GOVERN 4.2
    SA-4(3)Development Methods, Techniques, and PracticesSASystem and Services AcquisitionA.6.1.3, A.6.2.3GOVERN 4.1, GOVERN 4.2
    SA-5System DocumentationSASystem and Services Acquisition4.3, A.6.2.7, A.6.2.8GOVERN 4.2
    SA-8(30)Procedural RigorSASystem and Services AcquisitionA.3.3, A.4.2, A.6.2.2, A.6.2.7, A.6.2.8GOVERN 1.7, MANAGE 2.2
    SA-8(32)Sufficient DocumentationSASystem and Services Acquisition7.5.1, 7.5.2, 7.5.3, A.6.2.7, A.6.2.8GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 3.2, GOVERN 4.1, GOVERN 5.1, GOVERN 6.1, MAP 3.5
    SA-11(5)Penetration TestingSASystem and Services Acquisition10.2, A.6.2.5MAP 2.3, MEASURE 3.1, MEASURE 3.2
    SA-15(2)Security and Privacy Tracking ToolsSASystem and Services Acquisition10.2, 9.3.2MANAGE 1.1, MANAGE 1.2, MANAGE 1.3, MANAGE 1.4, MANAGE 3.1, MEASURE 3.1, MEASURE 3.2
    SA-23SpecializationSASystem and Services AcquisitionA.6.1, A.6.1.3, A.6.2, A.6.2.2, A.6.2.3, A.6.2.7, A.6.2.8GOVERN 1.2, GOVERN 3.1, GOVERN 4.1, GOVERN 4.2, GOVERN 5.1, GOVERN 5.2, MANAGE 2.2, MAP 2.1
    SC-1Policy and ProceduresSCSystem and Communications Protection5.1, 5.2, 7.5.1, 7.5.2, 7.5.3, A.2, A.2.2, A.2.3, A.2.4GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 3.2, GOVERN 4.1, GOVERN 5.1, GOVERN 6.1, MAP 3.5
    SC-38Operations SecuritySCSystem and Communications Protection7.5.3GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 3.2, GOVERN 4.1, GOVERN 5.1, GOVERN 6.1, MAP 3.5
    SI-1Policy and ProceduresSISystem and Information Integrity5.1, 5.2, 7.5.1, 7.5.2, 7.5.3, A.2, A.2.2, A.2.3, A.2.4GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 3.2, GOVERN 4.1, GOVERN 5.1, GOVERN 6.1, MAP 3.5
    MP-1Policy and ProceduresMPMedia Protection5.1, 5.2, 7.5.1, 7.5.2, 7.5.3, A.2, A.2.2, A.2.3, A.2.4GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 3.2, GOVERN 4.1, GOVERN 5.1, GOVERN 6.1, MAP 3.5
    PS-1Policy and ProceduresPSPersonnel Security5.1, 5.2, 7.2, 7.5.1, 7.5.2, 7.5.3, A.2, A.2.2, A.2.3, A.2.4GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 3.2, GOVERN 4.1, GOVERN 5.1, GOVERN 6.1, MAP 3.5
    PS-2Position Risk DesignationPSPersonnel Security7.2GOVERN 4.1, MAP 1.2, MAP 3.4
    PS-3(1)Classified InformationPSPersonnel Security7.2, A.3.2GOVERN 4.1
    PS-3(3)Information Requiring Special Protective MeasuresPSPersonnel Security7.2, A.3.2GOVERN 4.1
    PS-9Position DescriptionsPSPersonnel Security5.3, 7.2, A.3.2GOVERN 2.1
    PM-1Information Security Program PlanPMProgram Management5.1, 5.2, 7.5.1, 7.5.2, 7.5.3, A.2, A.2.2, A.2.3, A.2.4GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 3.2, GOVERN 4.1, GOVERN 5.1, GOVERN 6.1, MAP 3.5
    PM-2Information Security Program Leadership RolePMProgram Management5.3, A.3.2GOVERN 1.3, GOVERN 2.1, GOVERN 2.3
    PM-3Information Security and Privacy ResourcesPMProgram Management5.1, 7.1, A.6.2.2MANAGE 2.1
    PM-4Plan of Action and Milestones ProcessPMProgram Management10.2, 9.3.2MANAGE 1.1, MANAGE 1.2, MANAGE 1.3, MANAGE 1.4, MANAGE 3.1, MEASURE 3.1, MEASURE 3.2
    PM-6Measures of PerformancePMProgram Management5.1, 5.3, 9.3.2, A.3.2GOVERN 1.3, GOVERN 1.5, GOVERN 2.1, GOVERN 2.3, MAP 5.2, MEASURE 1.1, MEASURE 1.2, MEASURE 4.3
    PM-8Critical Infrastructure PlanPMProgram Management4.1GOVERN 1.1, GOVERN 6.2
    PM-9Risk Management StrategyPMProgram Management6.1.1, 6.1.2, 6.1.3, 8.2, A.5GOVERN 1.3, GOVERN 1.4, GOVERN 1.5
    PM-10Authorization ProcessPMProgram ManagementA.6.2.5GOVERN 4.3, MANAGE 1.1
    PM-11Mission and Business Process DefinitionPMProgram Management4.1, 4.2, 7.4MAP 1.1, MAP 1.4, MAP 2.1
    PM-13Security and Privacy WorkforcePMProgram Management5.3, 7.2, A.3.2GOVERN 2.1, GOVERN 4.1
    PM-28Risk FramingPMProgram Management6.1.2, 6.1.4, 8.4GOVERN 1.3, GOVERN 1.4
    PM-29Risk Management Program Leadership RolesPMProgram Management5.3, 6.1.1, 6.1.2, 6.1.3, 8.2, A.10, A.10.2, A.10.3, A.3.2, A.5GOVERN 1.3, GOVERN 1.4, GOVERN 1.5, GOVERN 2.1, GOVERN 2.3
    PT-1Policy and ProceduresPTPII Processing and Transparency5.1, 5.2, 7.5.1, 7.5.2, 7.5.3, A.2, A.2.2, A.2.3, A.2.4GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 3.2, GOVERN 4.1, GOVERN 5.1, GOVERN 6.1, MAP 1.6, MAP 3.5
    SR-1Policy and ProceduresSRSupply Chain Risk Management5.1, 5.2, 7.5.1, 7.5.2, 7.5.3, A.10, A.10.2, A.10.3, A.2, A.2.2, A.2.3, A.2.4GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 3.2, GOVERN 4.1, GOVERN 5.1, GOVERN 6.1, MAP 3.5
    SR-3(1)Diverse Supply BaseSRSupply Chain Risk ManagementA.6.1.3, A.6.2.3GOVERN 4.1, GOVERN 4.2
    SR-7Supply Chain Operations SecuritySRSupply Chain Risk Management7.5.3, A.10, A.10.2, A.10.3GOVERN 1.2, GOVERN 1.3, GOVERN 1.4, GOVERN 3.2, GOVERN 4.1, GOVERN 5.1, GOVERN 6.1, MAP 3.5

    Source and method

    Derived from the Top Floor framework mapping dataset: 4,123 cross-framework control mappings across 19 frameworks, every one pivoted through NIST SP 800-53 Rev 5.

    Cross-framework mappings on this page are derived from the 2026.2 release of the Secure Controls Framework, used under CC BY-ND 4.0.

    Mappings are illustrative aids for planning and are not a substitute for the official text of any framework or for an assessor’s judgment. Always verify control requirements against the authoritative publication. Where no official crosswalk exists, the mapping judgment is our own analysis.