EU AI ActGDPRISO 42001ISO 27001NIST AI RMF
FRAMEWORKS · ONE REGISTER

Five frameworks.
One register.

The EU AI Act is the spine: statutory, derived per system, always on. The GDPR joins it wherever personal data flows. The standards you switch on — ISO/IEC 42001, ISO/IEC 27001, NIST AI RMF — become programmes whose steps produce records, and a record that satisfies a clause in two frameworks is written once and counted twice.

385
requirements across the five
83
programme steps → 69 records
55
of 69 records touch two or more
THE FIVE

Each framework has its own page

What it is, who it applies to, the dates, what it asks, how Veritome runs it, and where it overlaps the other four — with every figure computed from the shipped catalogues and templates.

EU AI Act

EU AI Act

Regulation (EU) 2024/1689
Statutory · always on
Requirements
69
Path
6 phases

Per-system obligations derived by the rules engine from your role, risk tier and the system's behaviour, across six gated phases.

Not: A certificate. No harmonised standard has been cited in the Official Journal, so nothing gives a presumption of conformity today.

GDPR

GDPR

Regulation (EU) 2016/679
Statutory · always on
Requirements
61
Steps
19

The articles the EU AI Act sends you to — lawful basis, transparency, Art. 22, DPIA, processor terms, transfers — attached per system by five data questions.

Not: Your whole GDPR programme. Veritome models where the two regimes meet, and a DPIA shares its parts with the FRIA.

ISO 42001

ISO/IEC 42001

ISO/IEC 42001:2023
Voluntary · certifiable by an accredited body
Requirements
65
Steps
27

A gated programme of steps producing the AI management system: policy, roles, risk method, impact assessment, competence, audit, review, and the Statement of Applicability.

Not: A legal shield, and not certified by us — ISO/IEC 17021-1 §5.2.5 keeps the consultant and the certifier apart.

ISO 27001

ISO/IEC 27001

ISO/IEC 27001:2022
Voluntary · certifiable by an accredited body
Requirements
118
Steps
25

One management system with ISO/IEC 42001 where the clauses are the same; the 93 Annex A controls as guided themes with a generated SoA.

Not: A second set of forms for the clauses you already answered — a shared step is one record.

EU AI Act

The dates are the law's, read from one registry: Art. 5 prohibitions and Art. 4 literacy since 02.02.2025, Art. 50 transparency since 02.08.2026, the Annex III high-risk obligations from 02.12.2027 under the Digital Omnibus deferral. Nothing on any screen turns red before its statutory date. The GDPR has applied since 25.05.2018; the three standards are voluntary and carry no date of their own.

IN THE PRODUCT

Programmes, not checklists

A framework you switch on becomes a programme: gate-locked phases, one record per step, and the coverage matrix that shows which requirement each record closes. A record that is a step in two programmes is written once.

ISO 42001ISO 42001 programme
27 steps · 27 records · 14 shared
01Establish
5 steps · Complete
02Plan
5 steps · In progress
03Support
3 steps · Locked
04Operate
8 steps · Locked
05Evaluate & improve
4 steps · Locked
06Certification audit
2 steps · Locked
Plan · the steps
  1. 01Risk methodology and AI risk assessmentShared recordApproved
  2. 02Risk treatment and Statement of ApplicabilityIn draft
  3. 03AI system impact assessmentPer systemTo do
  4. 04AI objectives and planning to achieve themShared recordTo do
Phases and steps as the product generates them · progress shown is illustrative
THE CROSSOVER

Where the frameworks ask for the same thing

Each cell is the number of shipped records whose one piece of evidence is credited in both frameworks, then how many more only carry a related link between them. Credit follows the owner-verified matrix, checked clause by clause against each standard; a related link is a supporting candidate the product shows and never counts.

Credited in both · related onlyEU AI ActGDPRISO 42001ISO 27001NIST AI RMF
EU AI Act0 · 17 related0 · 34 related0 · 17 related0 · 21 related
GDPR0 · 17 related0 · 16 related0 · 11 related0 · 4 related
ISO/IEC 420010 · 34 related0 · 16 related14 · 18 related0 · 23 related
ISO/IEC 270010 · 17 related0 · 11 related14 · 18 related0 · 7 related
NIST AI RMF0 · 21 related0 · 4 related0 · 23 related0 · 7 related

55 of the 69 records behind the shipped programme steps touch two or more frameworks. The first number in a cell is records whose one piece of evidence is credited in both; a related count is a supporting link the verified matrix shows but never counts. Counted from the step templates on every build.

THE RECORDS THAT COUNT THE MOST TIMES · CREDITED FIRST, RELATED IN GREY
Resources and competence
ISO 42001§7, A.4.2ISO 27001§7, A.6.3EU AI ActArt. 4 · relatedNIST AI RMFGOVERN 2.2 · related
Monitoring, measurement, analysis and evaluation
ISO 42001§9, A.6.2.6ISO 27001§9EU AI ActArt. 72 · relatedNIST AI RMFMEASURE 2, MEASURE 3 · related
Risk methodology and AI risk assessment
ISO 42001§6ISO 27001§6, §8EU AI ActArt. 9 · relatedNIST AI RMFMAP 1–4, MEASURE 1 · related
Roles, responsibilities and authorities
ISO 42001§5, A.3.2ISO 27001§5, A.5.2EU AI ActArt. 14, Art. 26(2) · relatedNIST AI RMFGOVERN 2.1 · related
Nonconformity, corrective action and continual improvement
ISO 42001§10ISO 27001§10EU AI ActArt. 20 · related
Planning of changes
ISO 42001§6ISO 27001§6EU AI ActArt. 25(1)(b) · related
Context of the organisation
ISO 42001§4ISO 27001§4NIST AI RMFGOVERN 1.1 · related
Operational planning and control
ISO 42001§8, A.6.1.2ISO 27001§8EU AI ActArt. 17(1) · related
TRY IT

Switch a framework on

Each toggle adds a programme; the figures update from the same templates the product ships.

  • EU AI ActEU AI ActRegulation (EU) 2024/1689 · statutory · always on69 req
  • GDPRGDPRRegulation (EU) 2016/679 · statutory · always on61 req · 19 steps
  • ISO 42001ISO/IEC 42001ISO/IEC 42001:2023 · voluntary · certifiable by an accredited body65 req · 27 steps
  • ISO 27001ISO/IEC 27001ISO/IEC 27001:2022 · voluntary · certifiable by an accredited body118 req · 25 steps
  • NIST AI RMFNIST AI RMFNIST AI RMF 1.0 · voluntary · no certification exists72 req · 12 steps
Requirements
195
in the frameworks switched on
Programme steps
46
guided records to produce
Done once, counted twice
0
switch on both ISO standards
Point at the EU AI Act
23
steps with a related article — a link, not evidence