32% of ASEAN Guide on AI Governance and Ethics you already have
NIST SP 800-53 Rev 5 already covers about 32% of ASEAN Guide on AI Governance and Ethics, leaving
25 of 37 controls as genuinely new work.
Already covered 0
Likely covered 12
New work 25
No control in NIST SP 800-53 Rev 5
maps directly to one in ASEAN Guide on AI Governance and Ethics. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in NIST SP 800-53 Rev 5 reaches these. This is the list to scope.
AIGE-HI-3Determine the level of human involvement
AIGE-HI-5Mitigate automation bias and protect affected groups
AIGE-IG-2Define roles and responsibilities for AI oversight
AIGE-IG-4Training, awareness and capability building
AIGE-IG-5Periodic review of the governance model
AIGE-IG-6Apply risk-based proportionality
AIGE-NR-1Nurture AI talent and upskill the workforce
AIGE-NR-2Invest in AI research and development
AIGE-NR-3Support the AI innovation ecosystem and investment
AIGE-OM-10Third-party and vendor AI governance
AIGE-OM-2Data quality and representativeness
AIGE-OM-3Bias identification and mitigation
AIGE-OM-6Repeatability and reproducibility
AIGE-OM-7Robustness and security testing
AIGE-OM-8Traceability and auditability
AIGE-OM-9Deployment, monitoring and review
AIGE-P2Fairness and Equity
AIGE-P6Accountability and Integrity
AIGE-RR-1Establish an ASEAN Working Group on AI Governance
AIGE-RR-2Foster regional alignment, cooperation and interoperability
AIGE-SI-1Stakeholder communication policy and AI-use disclosure
AIGE-SI-2Feedback channels
AIGE-SI-3Decision review and recourse channels
AIGE-SI-4Acceptable use policies
Show the 12 you already have
AIGE-HI-1Establish AI objectives and assess against principles and risks
AIGE-HI-2Assess probability and severity of harm
AIGE-HI-4Document risk impact assessments
AIGE-IG-1Establish internal AI governance structures and oversight body
AIGE-IG-3AI ethics policies, standards and code of conduct
AIGE-OM-1Project governance and problem statement definition
AIGE-OM-4Data provenance, minimisation and protection
AIGE-OM-5Model explainability
AIGE-P1Transparency and Explainability
AIGE-P3Security and Safety
AIGE-P5Privacy and Data Governance
AIGE-P7Robustness and Reliability
How this is calculated
Already covered means a mapping runs from a control in NIST SP 800-53 Rev 5 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition