A large bank I advised counted its AI-relevant obligations and stopped at forty-one distinct documents across seven regulators and three jurisdictions. The team's instinct was to build forty-one control sets. That instinct is the most expensive mistake in AI governance, and it is wrong. Underneath the forty-one documents sits one control set with maybe thirty members. The regulators disagree on vocabulary, thresholds and paperwork. They agree, almost completely, on what good looks like.
This article gives you the map. It sets the three anchor frameworks side by side, adds the GCC rulebooks, and shows the crosswalk that lets you satisfy many regulators with one architecture. Read it as a translation table, not a reading list.
§ 2.1The three anchors
Three instruments define the global center of gravity. Learn these and most national rules become dialects.
EU AI Act — the regulation
The Act is law, it is extraterritorial, and it is risk-tiered. It bans a short list of practices, designates a set of high-risk uses (creditworthiness assessment among them, which is why banks care), and attaches obligations to each tier: risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness. It also imposes transparency duties on general-purpose and generative models. The Act is the most prescriptive of the three and the one with real penalties.
NIST AI RMF — the practice
The US framework is voluntary, principle-based and built around four functions: Govern, Map, Measure, Manage. Govern is the culture and accountability layer that runs through the other three. Map establishes context and risk. Measure quantifies and tests. Manage acts on what you found. It carries no penalties, but US supervisors increasingly treat it as the reference for what reasonable AI risk management looks like, which gives it teeth by proxy.
ISO/IEC 42001 — the management system
ISO 42001 is the AI management system standard, the AI equivalent of ISO 27001 for information security. It is certifiable. It requires a defined AI policy, roles, risk and impact assessment, controls, and a plan-do-check-act improvement loop. Its value is structural: it gives you an auditable management system that a certification body can attest to, which is a strong signal to any regulator and a genuine asset in a procurement or partnership conversation.
How they fit together
Treat them as layers, not competitors. ISO 42001 gives you the management system (the enduring structure). NIST AI RMF gives you the method (how to run risk work inside it). The EU AI Act gives you the obligations (what a regulator will check). One institution runs all three at once, and they reinforce rather than duplicate.
§ 2.2The GCC rulebooks
Gulf regulators did not wait for consensus. Several moved directly to AI-specific expectations, often ahead of Western peers, and they layer onto Basel-aligned prudential regimes and, in several markets, Sharia-governance requirements.
Saudi Arabia · SAMA
The Saudi Central Bank governs AI use in banking through its broader technology, cyber and outsourcing frameworks, with explicit attention to accountability, model governance and data localization. SDAIA's national AI ethics principles set the surrounding expectation. The practical demands: named accountable owners, in-kingdom data control, documented model governance, and human oversight of consequential decisions.
UAE · CBUAE, DFSA, ADGM FSRA
The CBUAE supervises AI in the onshore banking sector; the DFSA (DIFC) and ADGM FSRA run principle-based regimes in the financial free zones, with the FSRA publishing specific AI guidance. Dubai's VARA adds virtual-asset context. Across all, the recurring themes are accountability, explainability, data protection under the federal PDPL, and proportional human oversight.
Notice the convergence. SAMA's "named accountable owner" is the EU AI Act's human oversight requirement is NIST's Govern function is ISO 42001's defined roles. Four rulebooks, one control: every consequential model has a person who is answerable for it and can intervene. You build that control once.
§ 2.3The crosswalk
This is the working core of the article. The left column is the control as you build it. The remaining columns show which obligation it satisfies in each framework. Build down the left; attest across the right.
| Architectural control | EU AI Act | NIST AI RMF | ISO/IEC 42001 | GCC (SAMA / CBUAE / DFSA) |
|---|---|---|---|---|
| Model inventory with risk tiering | Risk-mgmt system; high-risk classification | Map 1–5 | 6.1 risk assessment; 8.x | Model governance; risk-based supervision |
| Named accountable owner + human oversight | Art. 14 human oversight | Govern 2; Manage 1 | 5.3 roles; Annex A controls | Accountability; senior-mgmt ownership |
| Data governance & lineage | Art. 10 data & data governance | Map 2; Measure 2 | Data mgmt controls | Data quality; localization / residency |
| Independent validation / effective challenge | Accuracy & robustness (Art. 15) | Measure 1–4 | 9.1 monitoring; internal audit | SR 11-7-style validation expectations |
| Technical documentation & logging | Art. 11–12; Annex IV | Map 4; Manage 4 | 7.5 documented info; 8.x | Auditability; record-keeping |
| Ongoing monitoring & drift detection | Post-market monitoring | Measure 4; Manage 2 | 9.1 monitoring & measurement | Ongoing model performance oversight |
| Transparency to affected persons | Art. 13; GPAI transparency | Govern 5; Map 5 | Transparency controls | Explainability; consumer protection |
| Incident response & escalation | Serious-incident reporting | Manage 4 | 10.x improvement | Incident reporting to regulator |
Eight controls carry most of the obligation weight across four frameworks. That is the leverage. When a business unit asks why they must register a model, the answer is not "the policy says so." The answer is that a single registry entry is simultaneously the evidence for Article 11, NIST Map 4, ISO clause 7.5 and SAMA record-keeping. One action, four attestations.
§ 2.4A worked example: one control, three exams
Worked example
A credit-decisioning model is deployed by a bank operating in Frankfurt, New York and Riyadh. The bank built a single control: the model cannot serve traffic unless the registry holds an approved validation report, a named owner, a data-lineage record and an active fairness monitor. That one gate produced, without additional work, the Article 15 accuracy evidence for the EU exam, the Measure-function artifacts for the US supervisor, and the model-governance and record-keeping evidence for SAMA. Three exams, one control, zero duplicated engineering.
§ 2.5Dates and moving targets
Two cautions. First, the EU AI Act's obligations phase in over several years, and the timelines have been adjusted, including through the Omnibus process. Do not hard-code a compliance date into your architecture or your training material; verify the current applicable date for each obligation tier when you plan. Second, GCC guidance is evolving quickly, and free-zone regimes update faster than onshore ones. Treat the crosswalk as a living artifact with an owner and a review cadence, not a one-time deliverable.
With the map in hand, the next article turns to the human structure that operates it: the committees, roles and decision rights that make the crosswalk something an institution actually runs.
Forty documents hide behind roughly thirty controls. Build the control set once and map it to each regulator, rather than building per-regulator.
Three anchors, three layers: ISO/IEC 42001 is the management system, NIST AI RMF is the method, the EU AI Act is the obligation set. Run all three together.
GCC regulators moved early. SAMA, CBUAE, DFSA and ADGM FSRA converge with the anchors on accountability, data control and human oversight.
Eight architectural controls carry most of the obligation weight across all frameworks. That overlap is your efficiency.
Keep the crosswalk living. EU AI Act dates phase in and shift; GCC guidance evolves. Assign an owner and a review cadence.