
Blog Post
Evidence for One AI Framework Does Not Count for the Next
September 14, 2026
An organization assembles an evidence package for one AI framework, passes, and discovers that almost none of it transfers to the next instrument applying to the same system. The frameworks agree on the principles and disagree on what proves them. Three frameworks defining risk differently is the same problem one layer earlier.
The common response is to look for a crosswalk and treat the mapping as a reuse plan. Crosswalks are useful for something narrower than that, and understanding why non-recognition exists explains what to do instead.
Why Is There No Mutual Recognition?
Because no body has standing to grant it, which makes this a structural feature rather than an oversight somebody will correct.
Mutual recognition requires an authority with jurisdiction over both instruments. An international management standard is published by a standards organization. A risk management framework is issued by a national agency as voluntary guidance. European AI legislation is law. No entity sits above all three with the power to declare that satisfying one satisfies another, so there is no mechanism through which recognition could arrive.
Which Makes Waiting the Wrong Strategy
Programs sometimes defer evidence work on the expectation that harmonization is coming. Convergence on vocabulary is happening and recognition of conformity is not, and those are different things. The absence of cited harmonized standards is a related and separate problem with the same practical consequence.
Where Does the Evidence Diverge?
At the precision layer rather than at the principle layer, which is why crosswalks read as encouraging and deliver so little.

Take data governance, which every AI framework addresses. European legislation requires explicit evaluation of training data for bias with stated metrics on dataset balance. A management system standard addresses the same topic as an organizational objective with documented policy and responsibility. A risk framework describes measurement as a function without prescribing the statistical test.
All three are about data governance, so a crosswalk maps them to one another correctly. Only one tells you which statistic to compute, so evidence assembled for the management standard does not answer the legislative requirement.
Which Direction Does Transfer Work?
Upward only. Evidence produced to the most specific requirement can be summarized to satisfy a general one, and evidence produced to a general requirement cannot be decomposed into a specific one that was never measured. The asymmetry determines everything about how the evidence should be stored.
What Should Be Stored, Then?
The underlying observation rather than the document, at the finest granularity any applicable regime demands.
A document is assembled for an audience. An observation is a fact about the system, recorded once with its date, method and result, and it can be assembled into any number of documents afterward. Storing the bias evaluation as a dated measurement with its metric and outcome serves the legislative requirement directly and the management standard by summary. Storing it as a completed section of one framework's report serves that framework only.
Which Regime Sets the Schema?
Whichever demands the most specific evidence for a given topic, and the answer differs by topic rather than being one framework throughout. Legislation may be most specific on data and testing while a management standard is most specific on organizational responsibility and competence. Building the record to the strictest requirement per topic, rather than to the strictest framework overall, produces a store that serves all of them, and normalizing one control set across frameworks is the same principle on the cyber side.
What Is a Crosswalk Legitimately For?
Two things, and neither is evidence reuse.

Scoping is the first. Knowing that a clause in one instrument relates to an article in another tells you which teams and which systems are in scope for both, which prevents the second exercise starting from nothing. Identifying what is missing is the second, since a topic appearing in one framework and not another is a genuine finding about coverage.
What a Crosswalk Cannot Support
A claim that satisfying one requirement satisfies another. A certificate under a management standard carries no legal weight under European AI legislation, where conformity depends on assessment against standards the legislation itself recognizes, along with registration, technical documentation and marking obligations that no certificate replaces.
What Is the Certification Trap?
Believing that a certification establishes regulatory readiness, which is the most expensive version of this misunderstanding and a common one.
An organization achieving certification under a management standard has demonstrated that it operates a governance system, which is genuinely valuable and frequently a commercial requirement. It has not demonstrated conformity with legislation, produced the technical documentation a conformity assessment requires, or registered anything. Discovering that after the certification budget was spent is a poor sequence, and what a management system standard covers is worth reading against what the legislation demands separately.
Does the Certification Help at All?
Substantially, in the right frame. The governance scaffolding it requires produces the ownership, policy and review records the legislation also expects, so the organizational half transfers well. What does not transfer is the technical evidence per system, which is where the specific requirements live.
What Does the Storage Look Like in Practice?
A record per observation with five fields, which is a schema decision rather than a tooling one.
- What was assessed: The system or dataset, identified consistently so the same object can be referenced by several frameworks.
- What was measured: The specific metric or test, named rather than described, since the name is what a specific requirement asks for.
- The result and the date: Both, because a requirement asking whether something was assessed needs the second as much as the first.
Method and assessor complete it. Which procedure was followed and who performed it, since several regimes ask about independence and none can be answered retrospectively, which producing evidence on somebody else's timeline makes concrete. An AI Interaction Data Fabric supplies the operational half of that record continuously rather than at assessment time.
How Many Regimes Will Apply?
More than the two or three most programs plan for, and counting them is the exercise that determines whether the storage approach matters or is over-engineering.
A single AI system in a mid-sized organization can attract a management standard for commercial reasons, a risk framework because a customer requires alignment, regional AI legislation on the strength of where its users are, sector regulation on the strength of what it decides, and data protection law on the strength of what it processes. Five instruments with five evidence expectations and no recognition between any pair of them.
Which Ones Are Discovered Late?
The sector and territorial ones, since the first two arrive through a deliberate decision and the others attach without anybody choosing. A system built for one market that acquires users elsewhere has picked up obligations nobody assessed, and obligations following where affected people live is how that happens.
Does the Count Change the Approach?
It changes whether the approach is worth the effort. An organization facing one instrument can reasonably assemble evidence for it directly, and one facing five cannot sustain five packages assembled separately. The observation store pays for itself somewhere around the second or third regime, which is where most organizations already are without having counted.
What Should Change Before the Next Assessment?
Three things, and the first is the one that compounds.
Record observations rather than framework sections, so the next instrument draws on the same store. Identify per topic which applicable regime is most specific, and build the record to that level rather than to the average. Then keep the crosswalk for scoping and stop treating it as a reuse claim. An AI data fabric holds the operational evidence in one place, which is what makes assembling several packages from one store possible rather than aspirational.
Store Observations, Assemble Documents
No body has authority over an international standard, a national framework and European legislation simultaneously, so mutual recognition has no mechanism to arrive and waiting for it is not a plan. The frameworks agree on principles and diverge on the precision of evidence, which is why a crosswalk maps cleanly and reuses badly. Transfer works upward only, since a specific measurement summarizes to a general requirement and a general one cannot be decomposed. So the record should hold observations at the finest granularity any applicable regime demands, with documents assembled from it per audience. Kovrr's AI compliance readiness assesses per requirement rather than per framework, which is the structure this problem requires.
To see one evidence set assessed against several AI regimes rather than repeated per framework, book a demo mapped to your own systems.
AI Evidence Portability FAQs
Speak to an ExpertWhy is there no mutual recognition between AI frameworks?
Because no body has standing to grant it, which makes this structural rather than an oversight. Mutual recognition requires an authority with jurisdiction over both instruments, and an international management standard is published by a standards organization, a risk management framework is issued by a national agency as voluntary guidance, and European AI legislation is law. No entity sits above all three with power to declare that satisfying one satisfies another, so there is no mechanism through which recognition could arrive.
Where does the evidence diverge?
At the precision layer rather than the principle layer, which is why crosswalks read as encouraging and deliver little. Every AI framework addresses data governance, so a crosswalk maps them correctly. European legislation requires explicit evaluation of training data for bias with stated metrics on dataset balance, a management system standard addresses the topic as an organizational objective with documented policy, and a risk framework describes measurement without prescribing the statistical test.
Which direction does evidence transfer work in?
Upward only. Evidence produced to the most specific requirement can be summarized to satisfy a general one, and evidence produced to a general requirement cannot be decomposed into a specific one that was never measured. That asymmetry determines how evidence should be stored, since building to the strictest requirement per topic produces a record serving all applicable regimes while building to the average produces one serving none of the demanding ones.
What is a crosswalk legitimately for?
Two things, neither of which is evidence reuse. Scoping, since knowing that a clause in one instrument relates to an article in another tells you which teams and systems are in scope for both. And identifying what is missing, since a topic appearing in one framework and not another is a genuine coverage finding. What it cannot support is a claim that satisfying one requirement satisfies another, since a certificate carries no legal weight where conformity depends on assessment against recognized standards.
What is the certification trap?
Believing a certification establishes regulatory readiness. An organization certified under a management standard has demonstrated it operates a governance system, which is genuinely valuable and frequently a commercial requirement, and has not demonstrated conformity with legislation, produced the technical documentation a conformity assessment requires, or registered anything. The governance scaffolding does transfer well on the organizational half, while the technical evidence per system does not, and that is where specific requirements live.
What should be stored instead of framework sections?
Observations, with five fields per record. What was assessed, identified consistently so the same object can be referenced by several frameworks. What was measured, named rather than described, since the name is what a specific requirement asks for. The result and the date, since a requirement asking whether something was assessed needs both. And the method and assessor, since several regimes ask about independence and none can be answered retrospectively.




