AI Governance Essentials ↔ ISO/IEC 42001
3 canonical controls in Keel's library satisfy clauses of both AI Governance Essentials and ISO/IEC 42001. Implement each once, attach the evidence once, and it counts toward each standard. The overlap is the work you don't repeat.
Controls that satisfy both
| Canonical control | AI Governance Essentials clauses | ISO/IEC 42001 clauses |
|---|---|---|
| AI system inventory A maintained inventory of the AI systems the organization develops, deploys, or uses, with each system's purpose, owner, and risk classification. | GV.3 | A.4.2 |
| AI system impact assessment A process to assess the potential impacts of AI systems on individuals, groups, and society, and to document and act on the results. | RM.1, RM.2 | A.5.2, A.5.4 |
| Human oversight of AI Appropriate human oversight of AI systems, so people can understand, monitor, and intervene in how an AI system operates. | HO.1, HO.2 | A.6.2.6, A.9.2 |
Clause identifiers (AI Governance Essentials and ISO/IEC 42001) are referenced factually for mapping. Keel is not affiliated with or endorsed by the bodies that publish these standards. Control descriptions are Keel's own; a framework's full authored control count is on its framework page.
Why this is one project, not two
On a crosswalk-native model, ISO/IEC 42001 mostly lights up controls you already built for AI Governance Essentials. You're not re-uploading the same screenshot for a second audit. You apply the framework and see the genuine delta worth working. That's the whole idea behind collect once, comply everywhere.