Skip to main content

Enterprise AI Impact Assessment Playbook

One Control Map, Coverage Across U.S. and International Expectations

How NIST AI RMF and ISO/IEC 42001 fit together, with specific framework identifiers for every risk domain.

The problem

You already have ISO 27001 and SOC 2. You don't want to rebuild it for AI.

Your assurance and GRC teams are already juggling overlapping frameworks. Now the EU AI Act, NIST AI RMF, and ISO/IEC 42001 each add their own AI assessment and governance obligations on top. The instinct to stand up an entirely separate AI control set duplicates governance infrastructure you already run and maintain. The harder, more defensible move is to reuse what exists, then close only the gaps that are genuinely net-new to AI.

3
Distinct frameworks the playbook maps against: EU AI Act, NIST AI RMF, and ISO/IEC 42001, each with its own assessment obligation and trigger.
4-tier
Risk classification model aligned to EU AI Act, from prohibited practices through high-risk and lower-risk use cases.
27article
The EU AI Act Fundamental Rights Impact Assessment obligation the playbook walks through, alongside Annex III, Article 86, and GDPR Articles 35 and 9.

GET THE PLAYBOOK

Get instant access to the playbook

The full 19-page, 8-chapter playbook, from use case intake through fundamental rights analysis, control mapping, and scaling.
01
Assess and tier each use case
Map every identified risk to a specific control or set of controls.
02
Reuse before you rebuild
Reuse existing SOC 2 and ISO 27001 controls first, formally extending them in scope to cover the AI system with documented rationale.
03
Close net-new gaps
Close remaining gaps with AI-specific controls, each referencing a specific NIST AI RMF function and ISO/IEC 42001 clause identifier.
04
Log gaps as findings
Log any control gaps as open findings in the risk register, each with a named owner and target remediation date.
SIX ARTIFACTS YOU CAN APPLY DIRECTLY
A control mapping table by risk domain across NIST AI RMF and ISO/IEC 42001
Which existing SOC 2 / ISO 27001 controls to reuse and which gaps are net-new
AI-specific gap controls for bias, drift, explainability, and third-party model risk
A control mapping checklist to confirm before you close the exercise
How NIST AI RMF and ISO 42001 are complementary, not redundant
How to log control gaps as open findings with owners and remediation dates

Extend, don't rebuild

You reuse the ISO 27001 and SOC 2 controls already in place and add only the AI-specific controls that fill a real gap.

Audit coverage in both directions

Mapping to NIST AI RMF and ISO/IEC 42001 together gives you coverage across U.S. regulatory expectations and international standards at the same time.

Defensible classification decisions

Every tier and control decision carries a scoring rubric, rationale note, named reviewer, and review date that can survive regulatory scrutiny.

Findings that don't age into liability

A composite priority score sequences remediation, and named owners plus retest dates keep open findings moving to closure.

EU AI Act

References Article 27, Annex III, and Article 86.

GDPR

References Article 35 (DPIA) and Article 9 special category data.

NIST AI RMF

Maps to GOVERN, MAP, and MANAGE functions with specific identifiers.

ISO/IEC 42001

Maps to clauses including 6.1.2 and 8.4.

ISO 27001 & SOC 2

Cross-references existing controls for reuse rather than rebuild.

Scoring models

A four-tier risk classification model and a Composite Priority Score formula (Severity x Likelihood x Regulatory Exposure).

No. The playbook shows how to formally extend controls like SOC 2 CC6.6, CC6.1, and CC9.2 in scope to cover the AI system, then add AI-specific controls only where existing coverage falls short.

ONE CONTROL MAP. TWO STANDARDS. ZERO REBUILD.

Get the control mapping playbook

Instant access to the full 19-page playbook.