How the AI governance frameworks relate: cross-walks
Read on their own, the five frameworks in this set look like five separate obligations. Read together, they share a spine.
Read on their own, the five frameworks in this set look like five separate obligations. Read together, they share a spine. Each asks you to know the AI you run, understand its effect on people, manage its risk, keep a human in control, be transparent about it and keep records good enough for someone else to check. The frameworks differ in who wrote them, whether they bind you and how far they go, but the underlying work overlaps heavily. That overlap is what lets a maturing function do the work once and answer to more than one framework at a time.
This page maps the overlap discipline by discipline. Where a framework treats a discipline directly, the cell says how. Where the mapping is looser, the prose below the table says so, because inflating an overlap is as unhelpful as missing one.
The frameworks at a glance
The five differ first in their force and reach.
- The Privacy Act automated decision-making provisions are law, and narrow. They govern one thing, what your privacy policy says about automated decisions that significantly affect people.
- The National AI Centre's essential practices are national, voluntary and broad, a six-practice baseline any Australian organisation can adopt.
- The NSW AI Assessment Framework is mandatory for NSW government agencies and broad, a risk self-assessment against defined ethics principles.
- ISO/IEC 42001 is an international standard and certifiable, an auditable management system for AI.
- The NIST AI Risk Management Framework is international, voluntary and lifecycle-based, a shared language and structure for managing AI risk.
The cross-walk
| Discipline | Privacy Act ADM | NAIC essential practices | NSW AIAF | ISO/IEC 42001 | NIST AI RMF |
|---|---|---|---|---|---|
| Accountability and roles | Entity is accountable for an accurate privacy policy | Practice 1, decide who is accountable | Agency accountable, with AI Review Committee oversight for high or critical risk | Clause 5, leadership and assigned roles | Govern function |
| Knowing what you run | Identify systems that make in-scope decisions | AI registers named as an organisation-wide practice | Applies to every system with an AI component across its lifecycle | Context and operational planning, clauses 4 and 8 | Map function |
| Risk management | Not risk-based | Practice 3, measure and manage risks | Risk self-assessment against the ethics principles | AI risk assessment, clauses 6 and 8 | Measure function |
| Effect on people | Decisions that could significantly affect rights or interests | Practice 2, understand impacts | Risks and mitigations judged against the ethics principles | AI system impact assessment | Map, context and affected parties |
| Transparency | Disclose kinds of information and kinds of decisions in the privacy policy | Practice 4, share essential information | Transparency under the ethics principles | Information to interested parties | Govern and Map, documentation |
| Human oversight | Distinguishes solely automated from human-involved decisions | Practice 6, maintain human control | Human oversight under the ethics principles | Operational controls for oversight | Manage and Govern |
| Testing and monitoring | Not addressed directly | Practice 5, test and monitor | Keep the assessment current as the system changes | Performance evaluation, clause 9 | Measure and Manage |
| Records and verifiable evidence | Keep the privacy policy reconciled to the systems | Keep records of decisions, testing, incidents and monitoring | Document risks and mitigations, submit high or critical systems for review | Documented information for certification | Documentation, show your working |
Reading the overlaps
Knowing what you run is the discipline that every framework depends on and none of them can substitute for. The Privacy Act provisions cannot be answered without a list of the systems that make decisions about people. The NSW AIAF applies system by system. ISO/IEC 42001 and NIST both start from context and inventory. The National AI Centre names the AI register outright. If a maturing function invests in one thing first, an accurate register is the thing that pays back against all five.
Risk and impact are where the broad frameworks converge and the Privacy Act sits apart. The essential practices, the NSW AIAF, ISO/IEC 42001 and NIST all ask you to assess risk and to understand a system's effect on people, and the artefacts you produce for one are largely reusable for the others. The Privacy Act provisions are not a risk assessment. They are a transparency rule. What connects them is that you cannot describe the automated decisions in your privacy policy without first knowing which decisions significantly affect people, and that judgement is the same one the impact work makes.
Transparency runs through all five but at different depths. The Privacy Act sets a specific, legislated disclosure. The other four ask for transparency in general terms, to users, to affected people, to interested parties and across the supply chain. Meeting the specific legal requirement does not discharge the general ones, and meeting the general ones does not guarantee the specific wording the Privacy Act calls for. They are best treated as related but distinct.
Two limits are worth stating plainly. First, contestability, the ability of a person to challenge an AI-driven outcome, is explicit in the NSW ethics principles and implied in the others, but the Privacy Act provisions in this set do not create an individual right to an explanation of a specific automated decision. Second, none of these frameworks certifies you except ISO/IEC 42001, and that certificate comes from an accredited certification body, never from software. Doing the shared work well positions you for all five, but only a certification body issues conformity with ISO/IEC 42001.
Where Aicura fits
The shared spine is exactly what Aicura holds. Aicura is your AI Register. It holds the AI systems in use as the record, versions each record as systems change and prompts your people when something needs attention, which answers the knowing-what-you-run discipline that every framework rests on. Impact Assessments give your people one place to do the risk and impact work the broad frameworks share, so the same artefact serves the essential practices, the NSW AIAF, ISO/IEC 42001 and NIST. Incidents capture what testing and monitoring surface. Attestation records that the accountable owner signed off, which is the accountability discipline made evidence. When you need to show a board, an auditor, a regulator or a certification body that the shared work was done, the Evidence Vault holds the record as evidence you don't have to trust us for, cryptographically anchored and externally verifiable without Aicura in the loop, and the Trust Centre lets you show the relevant governance to a customer running due diligence.
Aicura applies framework reasoning to surface where your footprint sits against each framework and holds the record. It does not issue interpretive positions on what a framework requires, and it does not certify or attest that you conform to any of them. Those calls belong to your organisation, its accountable owners and, for ISO/IEC 42001, your certification body.
A note on this page
This is a plain-language guide, not legal advice. Each framework's primary source is linked on its own framework page on this site. Read those sources in full and take your own professional advice on how the frameworks apply to your organisation. Aicura does not certify or audit your organisation against any of these frameworks and does not issue a verdict on where you stand.
Get started with Aicura.
Sign up and start the work. From your first session, you can catalogue your AI systems, run your privacy policy through Aicura's guidance and put your first risk assessments in place.