Colorado AI Act in · EU AI Act (High-Risk) in · ISO 42001 + NIST AI RMF + Agentic AI — unified in one toolkit

AI Controls Starter: Unified Cross-Framework Controls Matrix

One 11-tab Excel workbook mapping 120–150 controls across ISO 42001, NIST AI RMF, NIST GenAI Profile, and Colorado AI Act. Assess governance posture across all four frameworks in a single implementation view.

$399 One-time purchase · Instant download
Get AI Controls Starter

Payments processed by Lemon Squeezy (Merchant of Record). Price increases to $499 after initial launch period.

What’s Inside

An 11-tab Excel workbook plus an AI Acceptable Use Policy template. Delivered as a ZIP file via instant download.

Tab 1

Instructions & Navigation

Step-by-step workflow guide, terminology key (shall/should/must), tab descriptions with hyperlinks, and FAQ.

Tab 2 — Core IP

Unified Controls Matrix

The master crosswalk. 120–150 rows mapping all four frameworks into 10 columns with evidence requirements, priority ratings, and implementation notes.

120–150 rows · 12 control domains · auto-filtered
Tab 3

ISO 42001 Crosswalk

Pre-filtered view for certification-focused teams. All Clauses 4–10 and Annex A controls, sorted by ISO clause number.

~80–100 rows
Tab 4

NIST AI RMF Crosswalk

Pre-filtered view sorted by GOVERN, MAP, MEASURE, and MANAGE. All 72 subcategories with ISO and Colorado cross-references.

72+ rows
Tab 5

Colorado Safe Harbor Crosswalk

Every deployer and developer obligation with C.R.S. section-level statutory citations. Affirmative defense evidence mapping.

~25–35 rows
Tab 6

Framework Gaps & Conflicts

Where ISO 42001, NIST AI RMF, and Colorado AI Act diverge. Conflict descriptions with recommended reconciliation approaches.

20–25 documented divergences
Tab 7

AI System Inventory

Register for cataloguing all AI systems. Pre-configured drop-downs for deployment status, risk classification, and Colorado high-risk determination.

5 example rows + 50 empty
Tab 8

Gap Analysis Checklist

Domain-by-domain compliance assessment. Drop-down severity ratings with conditional formatting. Summary dashboard with gap counts and bar chart.

~60–80 assessment items
Tab 9

AI Risk Register

Structured risk register with 20+ pre-loaded AI risks. 5×5 heat map. Likelihood, impact, risk score formulas, treatment plans, and residual risk tracking.

20+ pre-loaded risks + 30 empty
Tab 10

Maturity Assessment Dashboard

Single-page visual scorecard. Traffic-light by control domain, overall maturity score, compliance percentage. Auto-populates from Gap Analysis. Screenshot-ready for board reporting.

Tab 11

Sources & Disclaimer

Complete list of primary sources with version and date. Full legal disclaimer. Every reference in the workbook is traceable to a verified source document.

Bonus

AI Acceptable Use Policy (Lite)

2-page Word template with red placeholders for organization-specific customization. Covers scope, acceptable/prohibited uses, data handling, and oversight requirements.

Framework Coverage

Four frameworks reconciled into one controls matrix. Every reference verified against primary source documents.

FrameworkSourceCoverage
ISO/IEC 42001:2023Purchased standard PDFEvery clause (4.1–10.2) and Annex A control (A.2–A.10)
NIST AI RMF 1.0NIST AI 100-1 (Jan 2023)All 72 subcategories across GOVERN, MAP, MEASURE, MANAGE
NIST AI 600-1 GenAI ProfilePublished profile (Jul 2024)200+ actions mapped to corresponding RMF subcategories
Colorado AI Act (SB 24-205)Enacted text as amended by SB 25B-004All developer and deployer obligations with C.R.S. citations

Cost Comparison

Cross-framework reconciliation is expensive. ACT eliminates 80–120 hours of manual mapping.

Manual reconciliation
$16K–$60K
80–120 hours at $200–$500/hour. Internal team maps frameworks independently, reconciles conflicts, builds templates from scratch.
GRC consultant
$20K–$80K
External engagement for cross-framework gap analysis and remediation roadmap. 4–12 week timeline. Vendor-locked deliverables.
ACT Tier 1 Starter
$399
Pre-reconciled unified matrix. Instant download. No subscription. No platform dependency. Estimated 8–12 hours to complete initial assessment.

Who This Is For

CTOs, CISOs, DPOs, and compliance leads at technology-centric SMEs (10–250 employees) who need to assess AI governance posture across multiple frameworks without enterprise-scale budgets or 6-month consulting engagements.

ACT Tier 1 is the right starting point for organizations that need to understand their obligations, identify gaps, and build a remediation roadmap — but are not yet ready for full policy formalization and implementation documentation.

Upgrade path. When gap analysis reveals documentation gaps, ACT Tier 2 Professional provides the policy templates, board reporting pack, implementation project plan, FRIA template, and agentic AI governance module needed to close them. Learn more.

Assess Your AI Governance Posture

One workbook. Four frameworks. 120–150 pre-reconciled controls. Instant download.

Get AI Controls Starter — $399

Not sure yet? Take the free 15-question readiness assessment first.