Frameworks

How the AI governance frameworks relate: cross-walks

Read on their own, the five frameworks in this set look like five separate obligations. Read together, they share a spine.

Read on their own, the five frameworks in this set look like five separate obligations. Read together, they share a spine. Each asks you to know the AI you run, understand its effect on people, manage its risk, keep a human in control, be transparent about it and keep records good enough for someone else to check. The frameworks differ in who wrote them, whether they bind you and how far they go, but the underlying work overlaps heavily. That overlap is what lets a maturing function do the work once and answer to more than one framework at a time.

This page maps the overlap discipline by discipline. Where a framework treats a discipline directly, the cell says how. Where the mapping is looser, the prose below the table says so, because inflating an overlap is as unhelpful as missing one.

The frameworks at a glance

The five differ first in their force and reach.

The cross-walk

DisciplinePrivacy Act ADMNAIC essential practicesNSW AIAFISO/IEC 42001NIST AI RMF
Accountability and rolesEntity is accountable for an accurate privacy policyPractice 1, decide who is accountableAgency accountable, with AI Review Committee oversight for high or critical riskClause 5, leadership and assigned rolesGovern function
Knowing what you runIdentify systems that make in-scope decisionsAI registers named as an organisation-wide practiceApplies to every system with an AI component across its lifecycleContext and operational planning, clauses 4 and 8Map function
Risk managementNot risk-basedPractice 3, measure and manage risksRisk self-assessment against the ethics principlesAI risk assessment, clauses 6 and 8Measure function
Effect on peopleDecisions that could significantly affect rights or interestsPractice 2, understand impactsRisks and mitigations judged against the ethics principlesAI system impact assessmentMap, context and affected parties
TransparencyDisclose kinds of information and kinds of decisions in the privacy policyPractice 4, share essential informationTransparency under the ethics principlesInformation to interested partiesGovern and Map, documentation
Human oversightDistinguishes solely automated from human-involved decisionsPractice 6, maintain human controlHuman oversight under the ethics principlesOperational controls for oversightManage and Govern
Testing and monitoringNot addressed directlyPractice 5, test and monitorKeep the assessment current as the system changesPerformance evaluation, clause 9Measure and Manage
Records and verifiable evidenceKeep the privacy policy reconciled to the systemsKeep records of decisions, testing, incidents and monitoringDocument risks and mitigations, submit high or critical systems for reviewDocumented information for certificationDocumentation, show your working

Reading the overlaps

Knowing what you run is the discipline that every framework depends on and none of them can substitute for. The Privacy Act provisions cannot be answered without a list of the systems that make decisions about people. The NSW AIAF applies system by system. ISO/IEC 42001 and NIST both start from context and inventory. The National AI Centre names the AI register outright. If a maturing function invests in one thing first, an accurate register is the thing that pays back against all five.

Risk and impact are where the broad frameworks converge and the Privacy Act sits apart. The essential practices, the NSW AIAF, ISO/IEC 42001 and NIST all ask you to assess risk and to understand a system's effect on people, and the artefacts you produce for one are largely reusable for the others. The Privacy Act provisions are not a risk assessment. They are a transparency rule. What connects them is that you cannot describe the automated decisions in your privacy policy without first knowing which decisions significantly affect people, and that judgement is the same one the impact work makes.

Transparency runs through all five but at different depths. The Privacy Act sets a specific, legislated disclosure. The other four ask for transparency in general terms, to users, to affected people, to interested parties and across the supply chain. Meeting the specific legal requirement does not discharge the general ones, and meeting the general ones does not guarantee the specific wording the Privacy Act calls for. They are best treated as related but distinct.

Two limits are worth stating plainly. First, contestability, the ability of a person to challenge an AI-driven outcome, is explicit in the NSW ethics principles and implied in the others, but the Privacy Act provisions in this set do not create an individual right to an explanation of a specific automated decision. Second, none of these frameworks certifies you except ISO/IEC 42001, and that certificate comes from an accredited certification body, never from software. Doing the shared work well positions you for all five, but only a certification body issues conformity with ISO/IEC 42001.

Where Aicura fits

The shared spine is exactly what Aicura holds. Aicura is your AI Register. It holds the AI systems in use as the record, versions each record as systems change and prompts your people when something needs attention, which answers the knowing-what-you-run discipline that every framework rests on. Impact Assessments give your people one place to do the risk and impact work the broad frameworks share, so the same artefact serves the essential practices, the NSW AIAF, ISO/IEC 42001 and NIST. Incidents capture what testing and monitoring surface. Attestation records that the accountable owner signed off, which is the accountability discipline made evidence. When you need to show a board, an auditor, a regulator or a certification body that the shared work was done, the Evidence Vault holds the record as evidence you don't have to trust us for, cryptographically anchored and externally verifiable without Aicura in the loop, and the Trust Centre lets you show the relevant governance to a customer running due diligence.

Aicura applies framework reasoning to surface where your footprint sits against each framework and holds the record. It does not issue interpretive positions on what a framework requires, and it does not certify or attest that you conform to any of them. Those calls belong to your organisation, its accountable owners and, for ISO/IEC 42001, your certification body.


A note on this page

This is a plain-language guide, not legal advice. Each framework's primary source is linked on its own framework page on this site. Read those sources in full and take your own professional advice on how the frameworks apply to your organisation. Aicura does not certify or audit your organisation against any of these frameworks and does not issue a verdict on where you stand.

Get started with Aicura.

Sign up and start the work. From your first session, you can catalogue your AI systems, run your privacy policy through Aicura's guidance and put your first risk assessments in place.