AI Control Mapper

A working tool, not a document. Select the parts of an AI system — system prompt, RAG, tool calling, third-party model, and so on — and the mapper selects the risks those parts create, the ISO/IEC 42001 Annex A controls that apply, and where each control lands in the NIST AI Risk Management Framework, with the reason for every hop. It ends with a draft Statement of Applicability, control checklist, and evidence list you can download. Runs entirely in your browser; nothing you select is collected.

Design decisions

All 38 Annex A controls appear in the Statement of Applicability, not just the ones your selections trigger. Controls that weren't triggered are marked "not triggered — review before excluding" instead of disappearing. A real SoA justifies every exclusion; a tool that silently drops controls would teach the wrong habit.

Every mapping shows its reasoning. Each control names the exact parts and risks that triggered it, and each NIST placement says why it sits under Govern, Map, Measure, or Manage. A crosswalk you can't interrogate is just a table.

Risks carry their OWASP GenAI LLM Top 10 (2026) numbers. The three frameworks — OWASP for the threats, ISO 42001 for the management controls, NIST AI RMF for the functions — are how practitioners actually talk about this work, so the tool speaks all three.

No free text, no data collection. Everything runs in the browser from a fixed set of selections. Nothing is sent anywhere, which is also why it can't drift from the framework mappings it was built on.

It produces a draft, and says so. The output is a starting point for the people accountable for the system, not certification evidence. Control names are paraphrased; the standard's text isn't reproduced.