# AI Regulatory Mapping Template and Jurisdiction Register

One structure for obligations across every jurisdiction you operate in: a regulatory inventory, a unified control mapping showing which internal control satisfies which obligation where, a conflict register for genuine incompatibilities, and monitoring assignments.

**Who this is for:** The compliance owner keeping several jurisdictions coherent without a separate programme per country.

Source playbook: https://aigovernance.com/playbook/multi-jurisdiction-ai-compliance-mapping

---

## Multi-jurisdiction regulatory inventory

_Every jurisdiction, its applicable AI frameworks, the key obligations, and when they bite._

### Template

| Jurisdiction | Applicable frameworks | Key obligations | Effective / applicability date | Our exposure |
|---|---|---|---|---|
| <jurisdiction> | | | YYYY-MM-DD | systems / users / entities in scope |

### Worked example

| Jurisdiction | Applicable frameworks | Key obligations | Effective date | Our exposure |
|---|---|---|---|---|
| EU | EU AI Act; GDPR | high-risk obligations; transparency; FRIA | high-risk 2027-12-02 | Resume Screener, Support Copilot |
| US-CO | Colorado AI Act SB205 | risk mgmt; impact assessment; disclosure | 2026-06-30 (as amended) | Fraud Scoring, Resume Screener |
| US-NYC | Local Law 144 | annual bias audit; notice | in force | Resume Screener |
| China | Generative AI Measures; Deep Synthesis | security assessment; labeling; filing | in force | none (no China offering) |
| UK | pro-innovation framework; sector regulators | regulator guidance | ongoing | all UK-facing |

### Acceptance criteria

- Every jurisdiction with users, staff, or entities is listed, including those where exposure is currently none.
- Each row names the specific systems in scope.
- Applicability dates are tracked and updated as they move.

---

## Unified control mapping

_Which internal control satisfies which obligation, across jurisdictions, so one control does multiple jobs._

### Template

| Internal control | Obligations satisfied (jurisdiction: reference) | Systems covered | Owner | Status |
|---|---|---|---|---|
| <control name / ID> | EU: <ref>; CO: <ref>; NYC: <ref> | | | |

### Worked example

| Internal control | Obligations satisfied | Systems covered | Owner | Status |
|---|---|---|---|---|
| Bias testing program (MON-003) | EU AI Act Art. 10; CO SB205 impact assessment; NYC LL144 audit; EEOC adverse impact | Resume Screener, Fraud Scoring | DS + Compliance | operating |
| Decision logging (ALC-001/002) | EU AI Act Art. 12; GDPR Art. 22 traceability; FCRA record-keeping | all consequential-decision systems | Platform | operating |
| Human oversight design (HOC-002) | EU AI Act Art. 14; CO SB205; GDPR Art. 22 | Resume Screener | Talent | gap: low-score review |

### Acceptance criteria

- Each control lists every obligation it satisfies with a specific reference per jurisdiction.
- Obligations with no control mapped are visible and become gaps.
- A control gap flags every jurisdiction it affects, not just one.

---

## Conflict register

_Genuine incompatibilities between jurisdictions, with the documented legal resolution._

### Template

| Conflict | Jurisdiction A requirement | Jurisdiction B requirement | Why they conflict | Resolution | Signed off by |
|---|---|---|---|---|---|
| <id> | | | | e.g. run separate instances; apply stricter globally; geofence | Legal |

### Worked example

| Conflict | A requirement | B requirement | Why they conflict | Resolution | Signed off by |
|---|---|---|---|---|---|
| C-1 | EU: retain human-review logs with personal data for audit | Jurisdiction X: data localization forbids exporting those logs | logs cannot sit in one global store | separate regional log stores; no cross-border replication of review logs | GC, 2026-08-30 |
| C-2 | Jurisdiction Y: mandatory algorithm disclosure to regulator | Trade-secret protection expectations elsewhere | disclosure scope | disclose under the regulator's confidentiality regime; documented scope limit | GC, 2026-09-05 |

### Acceptance criteria

- Only genuine legal incompatibilities are logged, not mere differences in stringency.
- Each conflict has a resolution and a named legal sign-off.
- Where the resolution is "apply the stricter rule globally", that is recorded so it is not re-litigated.

---

## Regulatory monitoring assignments

_Who watches which jurisdiction, and how a finding enters the process._

### Template

| Jurisdiction | Monitored sources | Owner | Cadence | Where findings go |
|---|---|---|---|---|
| <jurisdiction> | | <name> | weekly / monthly | inventory + calendar + review task |

### Worked example

| Jurisdiction | Sources | Owner | Cadence | Findings route |
|---|---|---|---|---|
| EU | EUR-Lex; AI Office; EDPB | EU Compliance | weekly | update inventory; add calendar entry; open review task if guidance changes interpretation |
| US states | legislature trackers; NCSL; state AG actions | US Compliance | weekly | same |
| China | CAC bulletins; national standards | APAC Compliance (external counsel support) | monthly | same |

### Acceptance criteria

- Every jurisdiction in the inventory has a named monitoring owner.
- Findings have a defined route into the inventory, calendar, and review queue.
- Coverage of jurisdictions with thin internal expertise is backed by external counsel.

---

## Governance controls this kit produces evidence for

- **CMP-001**: The inventory and control mapping are the multi-jurisdiction regulatory compliance mapping.
- **CMP-003**: Voluntary frameworks in the inventory are mapped alongside binding obligations.
- **BRD-009**: The unified control mapping feeds the multi-framework risk register with control coverage per obligation.
- **CMP-002**: The monitoring assignments are the regulatory and standards monitoring workflow across jurisdictions.
- **MGV-003**: Gaps surfaced by the control mapping become governance-program milestones.
