Using the AI RMF Playbook and Published Crosswalks

Lesson concept diagram
Using the AI RMF Playbook and Published Crosswalks

The AI Risk Management Framework (AI RMF) provides a structured approach to managing AI systems through four core functions: Govern, Map, Measure, and Manage. The AI RMF Playbook offers practical guidance for implementing these functions. The playbook is designed to support organisations in aligning AI governance with existing frameworks such as ISO/IEC 42001:2023, which sets out requirements for an AI management system. The playbook helps teams identify and address AI risks through clearly defined steps and outcomes.

Using the AI RMF Playbook

Organisations can apply the AI RMF Playbook by following its structured approach to AI governance. For example, when mapping AI systems, teams might begin by identifying data sources, algorithms, and decision-making processes. The playbook suggests documenting these elements to understand how AI systems interact with existing business processes. In practice, this involves creating visual diagrams or data flow maps that show how data moves through an AI system. These visual tools support internal audits and external compliance reviews.

  • Begin by identifying AI systems in use across the organisation
  • Document data sources, algorithms, and decision points
  • Map these elements against existing risk frameworks
  • Ensure alignment with ISO/IEC 42001:2023 requirements

For instance, a financial services company using AI for credit scoring must map its AI system to understand data inputs, such as credit history or income data. The playbook helps ensure these data sources are reviewed for bias or accuracy. The mapping step also highlights where AI decisions are made, such as through machine learning models or rule-based systems. This allows compliance staff to identify potential risk areas early in the AI lifecycle.

Applying Crosswalks

Published crosswalks help align AI governance with existing regulatory frameworks. These documents show how AI RMF functions map to other standards or laws. For example, crosswalks can illustrate how AI governance aligns with EU AI Act requirements. The EU AI Act introduces obligations such as prohibited practices, AI literacy, and transparency duties. The crosswalks help teams understand which AI RMF activities support these obligations.

  • Link AI RMF functions to EU AI Act Article 5 prohibited practices
  • Map AI literacy duties to AI RMF Govern and Measure
  • Align transparency requirements with AI RMF Manage

Organisations must ensure that AI systems comply with EU AI Act Article 5, which became effective on 2 February 2025. The crosswalks guide teams through actions such as conducting risk assessments or implementing human oversight. For example, a healthcare organisation using AI for clinical decision support must ensure its AI systems meet these obligations. The crosswalks help identify which AI RMF activities support these efforts, such as through risk evaluation or impact assessment.

Other EU regulations also apply. The Digital Omnibus on AI, which came into force on 27 July 2026, defers certain high-risk AI obligations. The crosswalks help teams understand these deadlines. For example, high-risk AI systems must comply by 2 December 2027, while embedded AI products have until 2 August 2028. These dates must be tracked through AI RMF processes such as Measure and Manage.

Implementation Examples

In practice, using the AI RMF Playbook and crosswalks involves integrating these tools into existing governance processes. For example, a government department using AI for public services must apply these frameworks to ensure compliance. The department might start by mapping AI systems through the playbook, then cross-reference these with EU AI Act requirements. The crosswalks guide them through actions such as training staff or publishing AI impact assessments.

ISO/IEC 42001:2023 provides a framework for AI management systems. The playbook helps teams implement these requirements through practical steps. For example, an organisation might begin by defining AI governance roles, such as AI risk owners or data stewards. The crosswalks then show how these roles align with ISO/IEC 42001 clause 5.3, which addresses leadership and commitment. The AI RMF framework makes these alignment efforts easier through structured guidance.

Organisations must also consider certification. The first UKAS-accredited certification body for AI management systems was BSI, which became accredited on 15 January 2026. The certification process involves demonstrating compliance with ISO/IEC 42001:2023. The AI RMF Playbook and crosswalks support this by providing frameworks for documenting AI governance. These documents help auditors understand how AI systems are managed, monitored, and reviewed. The crosswalks ensure that these documents align with regulatory expectations, such as those from the EU AI Act or the Digital Omnibus.