Why I Built an AI Governance Crosswalk Instead of Another Checklist
I kept having the same irritating thought.
"I'm sure I read something about this yesterday."
It happened often enough that I eventually stopped trusting my own memory.
I'd spend an evening reading the NIST AI Risk Management Framework, then move across to ISO/IEC 42001, before disappearing into the EU AI Act. Every document made sense on its own. The frustration only appeared when I closed one and opened the next.
• Human oversight.
• Documentation.
• Risk assessment.
• Governance.
• Accountability.
The terminology shifted, and the structure certainly did.
Sometimes an idea appeared as a guiding principle. Somewhere else it became a management system requirement. Then I'd find it again as a legal obligation.
Different words.
Different audiences.
Oddly familiar conversations.
At first I assumed I was simply confusing the documents. They all occupy roughly the same professional space, after all. It wasn't unreasonable to think I was remembering one framework while reading another.
But the feeling became harder to dismiss, since I wasn't reading identical text. I was repeatedly bumping into familiar ideas wearing different clothes.
After a while I found myself wondering whether I was really learning three different frameworks at all.
I was listening to three different professions describing many of the same ideas in their own language and that question followed me around for weeks.
Eventually I did what I probably should have done much earlier.
I resisted and opened Excel.
Yeah, the world desperately needs another spreadsheet.
Excel pain being clearly part of some grand plan.
I need to an Advil and the quickest place I could think of to stop asking myself the same questions because I was trying to stop losing track of my own thinking.
Every time I reached a section on governance I'd catch myself wondering, "How did ISO describe this?"
Then I'd open another document.
Read a few pages.
Find the paragraph.
Close the document.
Three days later I'd forgotten where I'd found it and start all over again. Eventually I became tired of answering my own questions.
So I started writing the answers down.
The spreadsheet wasn't particularly elegant.
The first version certainly wasn't something I'd have shown anyone.
It was simply somewhere to park observations before they disappeared again. One framework talked about accountability.
Another talked about roles and responsibilities.
A third described obligations.
I stopped asking whether they were using the same words.
I started asking whether they were trying to answer the same question. That small change turned out to matter far more than I expected.
Somewhere around the tenth governance topic I realised something had quietly changed.
I wasn't really comparing frameworks anymore.
The frameworks had almost faded into the background.
The questions hadn't.
Who owns AI risk?
How should it be assessed?
What evidence should exist?
Who is accountable?
How do you know governance is actually happening rather than simply being described? Those questions kept appearing regardless of which framework I happened to be reading.
That surprised me because I'd assumed the frameworks themselves were the interesting part.
They weren't.
They'd quietly become vehicles for something much more useful which were “The questions”. What are “The Questions”?
I'd mapped enough of them, I found myself caring less about which document I happened to be reading and much more about the problem each one was trying to solve.
That wasn't where I'd expected to end up.
Like many people, I'd started by asking which framework was better.
Which one should organisations adopt?
Which one was more complete?
Those questions gradually became less interesting.
Instead I found myself asking,
"What problem is this framework trying to solve?" That turned out to be a much better question.
NIST naturally approaches governance through the lens of risk.
ISO approaches it as part of a management system.
The EU AI Act expresses many of the same ideas through legal obligations. Of course they sound different.
They're written by different communities, for different audiences, trying to solve different parts of the same problem. I'd accidentally been comparing vocabulary instead of purpose.
Once I realised that, the frameworks became much easier to read.
Looking back, I'm slightly embarrassed it took me so long to notice.
I'd spent months trying to remember frameworks.
What I really needed to remember were the questions they kept asking.
I don't think I learned three frameworks.
I think I learned one conversation that three different communities have been having for years.
If I'm honest, the spreadsheet was never really the point.
Excel just happened to be where my thinking escaped onto the page.
I thought I was building a reference document. Looking back, I think I was teaching myself how to read governance frameworks differently.
I went into the project expecting answers and I I came away with better questions. The crosswalk itself is simply evidence of that thinking.
Version 1.0 isn't a finish line.
It's more like a marker on the side of the road.
If Version 2.0 looks almost identical, I'll know I haven't been paying enough attention.
AI governance is moving too quickly for certainty to last very long. I hope people disagree with parts of the crosswalk. I hope they challenge some of the mappings. I hope they point me toward relationships I haven't noticed yet.
Because that's how work like this improves.
Not by pretending we've found the definitive answer but with Advil and continuing to ask better questions.