Why I Built an AI Governance Crosswalk Instead of Another Checklist

I kept having the same irritating thought. 

"I'm sure I read something about this yesterday." 

It happened often enough that I eventually stopped trusting my own memory. 

I'd spend an evening reading the NIST AI Risk Management Framework, then move across  to ISO/IEC 42001, before disappearing into the EU AI Act. Every document made sense on  its own. The frustration only appeared when I closed one and opened the next. 

• Human oversight. 

• Documentation. 

• Risk assessment. 

• Governance. 

• Accountability. 

The terminology shifted, and the structure certainly did. 

Sometimes an idea appeared as a guiding principle. Somewhere else it became a  management system requirement. Then I'd find it again as a legal obligation. 

Different words. 

Different audiences. 

Oddly familiar conversations. 

At first I assumed I was simply confusing the documents. They all occupy roughly the same  professional space, after all. It wasn't unreasonable to think I was remembering one  framework while reading another. 

But the feeling became harder to dismiss, since I wasn't reading identical text. I was repeatedly bumping into familiar ideas wearing different clothes. 

After a while I found myself wondering whether I was really learning three different  frameworks at all. 

I was listening to three different professions describing many of the same ideas in their own  language and that question followed me around for weeks.

Eventually I did what I probably should have done much earlier. 

I resisted and opened Excel. 

Yeah, the world desperately needs another spreadsheet. 

Excel pain being clearly part of some grand plan. 

I need to an Advil and the quickest place I could think of to stop asking myself the same  questions because I was trying to stop losing track of my own thinking. 

Every time I reached a section on governance I'd catch myself wondering, "How did ISO describe this?" 

Then I'd open another document. 

Read a few pages. 

Find the paragraph. 

Close the document. 

Three days later I'd forgotten where I'd found it and start all over again. Eventually I became tired of answering my own questions. 

So I started writing the answers down. 

The spreadsheet wasn't particularly elegant. 

The first version certainly wasn't something I'd have shown anyone. 

It was simply somewhere to park observations before they disappeared again. One framework talked about accountability. 

Another talked about roles and responsibilities. 

A third described obligations. 

I stopped asking whether they were using the same words. 

I started asking whether they were trying to answer the same question. That small change turned out to matter far more than I expected. 

Somewhere around the tenth governance topic I realised something had quietly changed.

I wasn't really comparing frameworks anymore. 

The frameworks had almost faded into the background. 

The questions hadn't. 

Who owns AI risk? 

How should it be assessed? 

What evidence should exist? 

Who is accountable? 

How do you know governance is actually happening rather than simply being described? Those questions kept appearing regardless of which framework I happened to be reading. 

That surprised me because I'd assumed the frameworks themselves were the interesting  part. 

They weren't. 

They'd quietly become vehicles for something much more useful which were “The  questions”. What are “The Questions”? 

I'd mapped enough of them, I found myself caring less about which document I happened  to be reading and much more about the problem each one was trying to solve. 

That wasn't where I'd expected to end up. 

Like many people, I'd started by asking which framework was better. 

Which one should organisations adopt? 

Which one was more complete? 

Those questions gradually became less interesting. 

Instead I found myself asking, 

"What problem is this framework trying to solve?" That turned out to be a much better  question. 

NIST naturally approaches governance through the lens of risk. 

ISO approaches it as part of a management system.

The EU AI Act expresses many of the same ideas through legal obligations. Of course they sound different. 

They're written by different communities, for different audiences, trying to solve different  parts of the same problem. I'd accidentally been comparing vocabulary instead of purpose. 

Once I realised that, the frameworks became much easier to read. 

Looking back, I'm slightly embarrassed it took me so long to notice. 

I'd spent months trying to remember frameworks. 

What I really needed to remember were the questions they kept asking. 

I don't think I learned three frameworks. 

I think I learned one conversation that three different communities have been having for  years. 

If I'm honest, the spreadsheet was never really the point. 

Excel just happened to be where my thinking escaped onto the page. 

I thought I was building a reference document. Looking back, I think I was teaching myself  how to read governance frameworks differently. 

I went into the project expecting answers and I I came away with better questions. The crosswalk itself is simply evidence of that thinking. 

Version 1.0 isn't a finish line. 

It's more like a marker on the side of the road. 

If Version 2.0 looks almost identical, I'll know I haven't been paying enough attention. 

AI governance is moving too quickly for certainty to last very long. I hope people disagree  with parts of the crosswalk. I hope they challenge some of the mappings. I hope they point  me toward relationships I haven't noticed yet. 

Because that's how work like this improves. 

Not by pretending we've found the definitive answer but with Advil and continuing to ask  better questions.

Hayden Pritchard
Hayden Pritchard

I've spent much of my career helping organizations make difficult decisions about cybersecurity, governance, and risk.

That work has taken me through hospitals, regulated industries, boardrooms, investigations, and more standards documents than I'd care to admit. Along the way I've become increasingly interested in something that doesn't appear in most governance frameworks: how people actually think.

Here, I write essays rather than reports. I explore the ideas that stay with me long after the meeting ends: why frameworks often ask the same questions in different languages, why some human limitations may actually be strengths, and how emerging technologies quietly change the assumptions that regulation depends upon.

Professionally, my work focuses on AI governance, cyber risk, healthcare, and safety-critical systems.

Personally, I'm just trying to understand them a little better than I did yesterday.

https://www.solvingcyber.com
Previous
Previous

Why I studied AI Fundamentals after Sec+

Next
Next

To homelab or not to homelab is not a question