AI Governance Institute
All governance templates →How do we map AI compliance obligations across multiple jurisdictions?

Implementation Kit

AI Regulatory Mapping Template and Jurisdiction Register

One structure for obligations across every jurisdiction you operate in: a regulatory inventory, a unified control mapping showing which internal control satisfies which obligation where, a conflict register for genuine incompatibilities, and monitoring assignments.

Who this is for: The compliance owner keeping several jurisdictions coherent without a separate programme per country.

Download the kit (Markdown) ↓4 artifacts. Every table also copies as CSV.

1. Multi-jurisdiction regulatory inventory

Spreadsheet

Every jurisdiction, its applicable AI frameworks, the key obligations, and when they bite.

Template

JurisdictionApplicable frameworksKey obligationsEffective / applicability dateOur exposure
<jurisdiction>YYYY-MM-DDsystems / users / entities in scope

Worked example

JurisdictionApplicable frameworksKey obligationsEffective dateOur exposure
EUEU AI Act; GDPRhigh-risk obligations; transparency; FRIAhigh-risk 2027-12-02Resume Screener, Support Copilot
US-COColorado AI Act SB205risk mgmt; impact assessment; disclosure2026-06-30 (as amended)Fraud Scoring, Resume Screener
US-NYCLocal Law 144annual bias audit; noticein forceResume Screener
ChinaGenerative AI Measures; Deep Synthesissecurity assessment; labeling; filingin forcenone (no China offering)
UKpro-innovation framework; sector regulatorsregulator guidanceongoingall UK-facing

Acceptance criteria

  • Every jurisdiction with users, staff, or entities is listed, including those where exposure is currently none.
  • Each row names the specific systems in scope.
  • Applicability dates are tracked and updated as they move.

2. Unified control mapping

Spreadsheet

Which internal control satisfies which obligation, across jurisdictions, so one control does multiple jobs.

Template

Internal controlObligations satisfied (jurisdiction: reference)Systems coveredOwnerStatus
<control name / ID>EU: <ref>; CO: <ref>; NYC: <ref>

Worked example

Internal controlObligations satisfiedSystems coveredOwnerStatus
Bias testing program (MON-003)EU AI Act Art. 10; CO SB205 impact assessment; NYC LL144 audit; EEOC adverse impactResume Screener, Fraud ScoringDS + Complianceoperating
Decision logging (ALC-001/002)EU AI Act Art. 12; GDPR Art. 22 traceability; FCRA record-keepingall consequential-decision systemsPlatformoperating
Human oversight design (HOC-002)EU AI Act Art. 14; CO SB205; GDPR Art. 22Resume ScreenerTalentgap: low-score review

Acceptance criteria

  • Each control lists every obligation it satisfies with a specific reference per jurisdiction.
  • Obligations with no control mapped are visible and become gaps.
  • A control gap flags every jurisdiction it affects, not just one.

3. Conflict register

Spreadsheet

Genuine incompatibilities between jurisdictions, with the documented legal resolution.

Template

ConflictJurisdiction A requirementJurisdiction B requirementWhy they conflictResolutionSigned off by
<id>e.g. run separate instances; apply stricter globally; geofenceLegal

Worked example

ConflictA requirementB requirementWhy they conflictResolutionSigned off by
C-1EU: retain human-review logs with personal data for auditJurisdiction X: data localization forbids exporting those logslogs cannot sit in one global storeseparate regional log stores; no cross-border replication of review logsGC, 2026-08-30
C-2Jurisdiction Y: mandatory algorithm disclosure to regulatorTrade-secret protection expectations elsewheredisclosure scopedisclose under the regulator's confidentiality regime; documented scope limitGC, 2026-09-05

Acceptance criteria

  • Only genuine legal incompatibilities are logged, not mere differences in stringency.
  • Each conflict has a resolution and a named legal sign-off.
  • Where the resolution is "apply the stricter rule globally", that is recorded so it is not re-litigated.

4. Regulatory monitoring assignments

Spreadsheet

Who watches which jurisdiction, and how a finding enters the process.

Template

JurisdictionMonitored sourcesOwnerCadenceWhere findings go
<jurisdiction><name>weekly / monthlyinventory + calendar + review task

Worked example

JurisdictionSourcesOwnerCadenceFindings route
EUEUR-Lex; AI Office; EDPBEU Complianceweeklyupdate inventory; add calendar entry; open review task if guidance changes interpretation
US stateslegislature trackers; NCSL; state AG actionsUS Complianceweeklysame
ChinaCAC bulletins; national standardsAPAC Compliance (external counsel support)monthlysame

Acceptance criteria

  • Every jurisdiction in the inventory has a named monitoring owner.
  • Findings have a defined route into the inventory, calendar, and review queue.
  • Coverage of jurisdictions with thin internal expertise is backed by external counsel.

Governance controls this kit produces evidence for

Completing the artifacts above gives you a head start on the evidence requirements for these controls.

CMP-001
CMP-001

The inventory and control mapping are the multi-jurisdiction regulatory compliance mapping.

CMP-003
CMP-003

Voluntary frameworks in the inventory are mapped alongside binding obligations.

BRD-009
BRD-009

The unified control mapping feeds the multi-framework risk register with control coverage per obligation.

CMP-002
CMP-002

The monitoring assignments are the regulatory and standards monitoring workflow across jurisdictions.

MGV-003
MGV-003

Gaps surfaced by the control mapping become governance-program milestones.

This kit backs one playbook. Read the full guidance for the reasoning behind each artifact.

Decide what to implement next

Assess your governance gaps, then create an action plan with owners and target dates. Build and export without an account; sign in when you want to save your plan.

Start the AI governance assessment →