Pick what your AI system is made of. The mapper selects the risks that come with those parts, the ISO/IEC 42001 Annex A controls that apply, and where each control lands in the NIST AI Risk Management Framework, with the reason for every hop. At the end you get a draft Statement of Applicability, a control checklist, and an evidence list you can download.
Select every part of your AI system that exists. If you only have a chat box in front of a model, that is: system prompt, user prompt, output, and logging.
These risks were selected because of the parts you chose. Each one names the parts that triggered it and the matching entry in the OWASP GenAI LLM Top 10 (2026) where one exists. Untick anything that does not apply to you.
Only Annex A controls triggered by your parts and risks are shown. Open a control to read how it applies to an LLM or prompt interface and what triggered it. Control names are paraphrased; the standard's text is not reproduced here.
Each applicable control is placed under a NIST AI RMF function with the categories it supports and the reason for the placement, plus the risk categories from the NIST Generative AI Profile (AI 600-1) it addresses. This is a practical crosswalk, not an official ISO or NIST publication.
Generated from selections only. The Statement of Applicability is a draft for review by the people accountable for the system; justifications must be confirmed, and controls not triggered here should be reviewed before being excluded. Not legal or certification advice.