
This is the final revised edition (March 2026) of my paper, "Passporting Compliance for AI: Operationalising Governance via a Clause-Level Crosswalk across EU, ISO/IEC, NIST, and CoE Frameworks." Originally submitted in July 2025, this version reflects a year of thoughtful refinement: incorporating reviewer critiques, practitioner feedback, and the evolving AI governance landscape that has seen new national implementations, CoE ratifications, and ISO updates since the initial draft.
At its heart, the paper confronts a core paradox in AI regulation: an abundance of frameworks sharing conceptual foundations, yet imposing redundant compliance burdens on organizations. I operationalize "compliance passporting"—the evidence-based transfer of assurance artefacts across regimes—as a practical solution, distinguished from broader mutual recognition as its operational instrument. Through a mixed-method approach (expert interviews n=10, survey n=27, clause-level coding of 847 units), I map alignment zones: high in risk management and transparency, partial in human rights assessments, and absent in environmental governance—a gap I address with a proposed ISO/IEC 42001-E module including concrete KPIs.
Key revisions elevate the work beyond technical mapping:
This isn't merely a compliance tool for assurance teams—it's a plea for governance humility, acknowledging that interoperability risks deepening inequalities unless built with Global South voices at the core. As an independent researcher, I offer this as a conversation starter, grounded in honesty about its promises and limits.