Framework overlap

Does OECD AI Principles cover ISO/IEC 27003:2017?

You hold OECD AI Principles and have been told to do ISO/IEC 27003:2017. Here is how much overlaps, control by control.

24% of ISO/IEC 27003:2017 you already have

OECD AI Principles already covers about 24% of ISO/IEC 27003:2017, leaving 55 of 72 controls as genuinely new work.

Already covered 4 Likely covered 13 New work 55

What is genuinely new work

Nothing in OECD AI Principles reaches these. This is the list to scope.

27003-10.1
Nonconformity and Corrective Action
27003-10.2
Continual Improvement
27003-4.1
Understanding the Organization and Its Context
27003-4.2
Interested Parties and Their Requirements
27003-4.3
Determining ISMS Scope
27003-5.2
Information Security Policy
27003-5.3
Roles, Responsibilities, Authorities
27003-6.1.1
Actions to Address Risks and Opportunities
27003-6.1.2
Information Security Risk Assessment
27003-6.1.3
Information Security Risk Treatment
27003-6.2
Information Security Objectives
27003-7.1
Resources
27003-7.2
Competence
27003-7.3
Awareness
27003-7.4
Communication
27003-7.5
Documented Information
27003-8.1
Operational Planning and Control
27003-8.2
Risk Assessment Performance
27003-8.3
Risk Treatment Implementation
27003-9.1
Monitoring, Measurement, Analysis, Evaluation
27003-9.2
Internal Audit
27003-9.3
Management Review
AS9100D-10.1
General Improvement
AS9100D-10.3
Continual Improvement
AS9100D-4.1
Understanding the Organization and Its Context
AS9100D-4.2
Understanding Needs and Expectations of Interested Parties
AS9100D-4.3
Determining the Scope of the QMS
AS9100D-4.4
Quality Management System and Its Processes
AS9100D-5.2
Quality Policy
AS9100D-5.3
Organizational Roles, Responsibilities, and Authorities
AS9100D-6.1
Risk-Based Thinking and Operational Risk
AS9100D-6.2
Quality Objectives and Planning to Achieve Them
AS9100D-6.3
Planning of Changes
AS9100D-7.1
Resources
AS9100D-7.2
Competence
AS9100D-7.3
Awareness
AS9100D-7.5
Documented Information
AS9100D-8.3
Design and Development of Products
AS9100D-8.7
Control of Nonconforming Outputs
AS9100D-9.1
Monitoring, Measurement, Analysis, Evaluation
AS9100D-9.2
Internal Audit
AS9100D-9.3
Management Review
ISO27003-4.1
Understanding the Organization and Its Context
ISO27003-4.4
Information Security Management System
ISO27003-5.2
Information Security Policy
ISO27003-5.3
Organizational Roles, Responsibilities, and Authorities
ISO27003-6.2
Information Security Objectives and Planning to Achieve Them
ISO27003-7.1
Resources
ISO27003-7.2
Competence
ISO27003-7.3
Awareness
ISO27003-7.4
Communication
ISO27003-7.5
Documented Information
ISO27003-9.1
Monitoring, Measurement, Analysis and Evaluation
ISO27003-9.2
Internal Audit
ISO27003-9.3
Management Review
Show the 17 you already have
AS9100D-8.1
Operational Planning and Control
ISO27003-6.1
Actions to Address Risks and Opportunities
ISO27003-8.2
Information Security Risk Assessment
ISO27003-8.3
Information Security Risk Treatment
27003-5.1
Leadership and Commitment
8.3
Statement of Applicability linkage
8.5
Control effectiveness review
AS9100D-10.2
Nonconformity and Corrective Action
AS9100D-5.1
Leadership and Commitment
AS9100D-8.4
Control of Externally Provided Processes, Products, Services
AS9100D-8.5
Production and Service Provision
ISO27003-10.1
Continual Improvement
ISO27003-10.2
Nonconformity and Corrective Action
ISO27003-4.2
Understanding Needs and Expectations of Interested Parties
ISO27003-4.3
Determining the Scope of the ISMS
ISO27003-5.1
Leadership and Commitment
ISO27003-8.1
Operational Planning and Control

How this is calculated

Already covered means a mapping runs from a control in OECD AI Principles to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition