Framework overlap

Does Iowa Consumer Data Protection Act cover NIST AI Risk Management Framework (AI RMF 1.0)?

You hold Iowa Consumer Data Protection Act and have been told to do NIST AI Risk Management Framework (AI RMF 1.0). Here is how much overlaps, control by control.

35% of NIST AI Risk Management Framework (AI RMF 1.0) you already have

Iowa Consumer Data Protection Act already covers about 35% of NIST AI Risk Management Framework (AI RMF 1.0), leaving 34 of 52 controls as genuinely new work.

Already covered 3 Likely covered 15 New work 34

What is genuinely new work

Nothing in Iowa Consumer Data Protection Act reaches these. This is the list to scope.

AIRMF-GOV-03
AI Compliance and Legal
AIRMF-GOV-04
Third-Party AI Risk
AIRMF-GV-1.1
Legal and regulatory requirements involving AI are understood, managed, and documented
AIRMF-GV-1.2
Trustworthy AI characteristics are integrated into organisational policies, processes, and procedures
AIRMF-GV-2.1
Roles and responsibilities related to AI risk management are documented and clear
AIRMF-GV-3.1
Decision making related to mapping, measuring, and managing AI risks is informed by diverse perspectives
AIRMF-GV-4.1
Organisational culture and incentives prioritise AI risk management
AIRMF-MAN-02
AI Monitoring and Maintenance
AIRMF-MEA-02
Bias and Fairness Assessment
AIRMF-MN-1.1
AI risks are prioritised and resources are allocated to manage them
AIRMF-MN-2.1
Mechanisms for tracking identified risks over time are in place
AIRMF-MN-3.1
AI risks and benefits from third party resources are managed
AIRMF-MN-4.1
AI risk management documentation and processes are improved continuously
AIRMF-MN-4.3
Incidents and errors are communicated to relevant AI actors
AIRMF-MP-1.1
Context of AI system use is established and understood
AIRMF-MP-2.1
Categorisation of AI systems is performed
AIRMF-MP-3.1
AI capabilities, targeted usage, goals, and expected benefits and costs are understood
AIRMF-MP-4.1
Approaches and metrics for risk identification are established
AIRMF-MP-5.1
Risks and benefits are characterised for components, including third party components
AIRMF-MS-1.1
Appropriate methods and metrics for measuring AI risk are identified and applied
AIRMF-MS-2.1
Test sets, evaluation criteria, and ongoing tracking are documented
AIRMF-MS-2.11
Fairness and bias are evaluated and results documented
AIRMF-MS-2.7
AI system security and resilience are evaluated
AIRMF-MS-2.8
AI system explainability and interpretability are evaluated
AIRMF-MS-3.1
Approaches and metrics for risk measurement are validated by stakeholders
NIST-AI600-GOV-2
Safety-First Culture
NIST-AI600-GOV-3
Content Provenance Governance
NIST-AI600-GOV-4
Pre-Deployment Testing Governance
NIST-AI600-GOV-5
Incident Disclosure Governance
NIST-AI600-MAP-3
Third-Party Risk Mapping
NIST-AI600-MEA-1
Confabulation Testing
NIST-AI600-MEA-2
Bias and Fairness Evaluation
NIST-AI600-MEA-5
Red-Teaming and Adversarial Testing
NIST-AI600-MGT-2
Human Oversight Integration
Show the 18 you already have
AIRMF-MAN-03
AI Incident Response
AIRMF-MAP-02
AI Risk Identification
AIRMF-MAP-03
AI Impact Assessment
AIRMF-GOV-01
AI Risk Management Policies
AIRMF-GOV-02
AI Risk Culture
AIRMF-MAN-01
AI Risk Treatment
AIRMF-MAP-01
AI System Context
AIRMF-MEA-01
AI Performance Metrics
AIRMF-MEA-03
AI Transparency and Explainability
NIST-AI600-GOV-1
Legal and Regulatory Compliance
NIST-AI600-MAP-1
GAI Risk Identification
NIST-AI600-MAP-2
Stakeholder Impact Assessment
NIST-AI600-MEA-3
Privacy Leak Assessment
NIST-AI600-MEA-4
Environmental Impact Measurement
NIST-AI600-MGT-1
Content Provenance Implementation
NIST-AI600-MGT-3
Third-Party Dependency Management
NIST-AI600-MGT-4
Incident Response for GAI
NIST-AI600-MGT-5
Decommissioning Procedures

How this is calculated

Already covered means a mapping runs from a control in Iowa Consumer Data Protection Act to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition