AI Procurement Framework Crosswalks

A structured hub for mapping AI procurement evidence across government guidance, security, privacy, risk management, regulation and management-system assurance.

AI buyers are often asked to work across several frameworks at once. The same underlying evidence may answer parts of multiple requirements, but the frameworks are not interchangeable and a mapping is not the same as certification or legal compliance.

Use this hub to understand where evidence themes overlap and where a specialist or organisation-specific crosswalk is needed.

Start with the procurement lifecycle

The main AI Procurement Knowledge Base follows six stages: Plan → Specify → Evaluate → Contract → Deploy → Monitor. Framework guidance should be applied inside that lifecycle rather than added as a separate questionnaire at the end.

If you do not yet know which workstream you need, use the AI Procurement Route Finder.

UK Government AI Playbook

The AI Playbook for the UK Government covers safe, effective and secure use of AI in government and explicitly includes selecting, buying and deploying AI. It is especially useful for intended use, human control, lifecycle management, commercial involvement, skills and assurance.

Read: UK Government AI Playbook procurement crosswalk.

Related lifecycle guides:

PPN 017 — AI-use transparency in procurement

PPN 017 helps public-sector buyers identify AI use in procurements and service delivery. It is a transparency trigger, not a complete due-diligence framework.

Read: PPN 017 explained for AI procurement.

DSIT AI Risk Management Toolkit

The 2026 toolkit supports teams designing, operating, procuring and delivering AI-enabled products. It helps connect risk identification to evidence requirements, treatment, ownership and monitoring.

Read: Using the UK AI Risk Management Toolkit in procurement.

NCSC secure AI guidance

The NCSC organises secure AI development around secure design, development, deployment, and operation and maintenance. Procurement can use those lifecycle areas to structure security evidence and contract controls.

Read: NCSC Secure AI Guidance for Procurement and AI security due diligence.

ICO AI and data protection guidance

The ICO guidance addresses accountability, lawfulness, fairness, transparency, data minimisation, security, individual rights and meaningful oversight when personal data is involved.

Read: ICO AI and Data Protection for Procurement.

NIST AI Risk Management Framework

NIST AI RMF is a useful risk-management reference for governing, mapping, measuring and managing AI risk. It can help buyers structure risk evidence, but it does not replace UK legal or public-procurement requirements.

Read: NIST AI RMF procurement crosswalk.

For supplier evidence, start with the AI Supplier Due-Diligence Checklist.

EU AI Act

For EU exposure, procurement should first establish applicability, intended use and the roles of provider and deployer. The evidence needed can change materially depending on classification and use.

Read: EU AI Act Procurement Evidence Guide.

ISO/IEC 42001

ISO/IEC 42001 is an AI management-system standard. A relevant certificate can provide useful organisational governance evidence, but it does not by itself prove product performance, security, privacy or suitability for a buyer's use case.

Read: ISO/IEC 42001 Evidence in AI Procurement.

Evidence themes that recur across frameworks

Common themes include:

  • intended purpose and system boundaries;
  • governance and accountable ownership;
  • risk identification and treatment;
  • data and privacy;
  • security and supply-chain dependencies;
  • testing, evaluation and known limitations;
  • human oversight;
  • transparency and documentation;
  • incident response;
  • change control;
  • monitoring and evidence currency.

A reusable evidence record can reduce duplication, but each framework still needs its own applicability judgement and requirement mapping.

Public mapping versus tailored crosswalks

This public hub explains the relationships and evidence themes. It intentionally does not publish a complete organisation-specific tender matrix or legal compliance schedule.

Professional work can include:

  • organisation-specific framework crosswalks;
  • tailored RFI/RFP/ITT question sets;
  • requirement and evaluation matrices;
  • supplier evidence collection and gap analysis;
  • independent verification;
  • contract schedule and control mapping;
  • remediation plans;
  • reusable procurement evidence packs;
  • post-award monitoring and reassessment.

AI TrustMark provides an independent verification layer; it does not create government endorsement, legal advice, ISO certification, NCSC accreditation or an automatic procurement award.