Governance · 12 min read · Rody Nigel, PhD

The PMAIS Regulatory Crosswalk: Mapping EU, Canadian, and US Obligations to Implementation Controls

PMAIS does not treat compliance as a checklist bolted onto a finished system. It treats it as a structured input to the design of the system itself.

Ask most AI vendors which regulations their product complies with, and you will get a list of laws. Ask what that compliance actually consists of at the level of a specific deployment, in a specific jurisdiction, touching a specific category of data, and the conversation usually stops. That gap is where regulated deployments fail, and it is the problem the PMAIS regulatory crosswalk is built to solve.

What a crosswalk actually is

A crosswalk is a structured mapping exercise, performed at the start of every engagement and repeated at defined governance intervals, that runs through: the AI use case, the jurisdiction(s) it touches, the sector, the specific obligations that combination creates, the resulting risk classification, the controls required, the accountable role for each control, and the evidence that demonstrates it was met. Every step is a named PMAIS artefact, not a paragraph of narrative.

European Union: the EU AI Act and GDPR

The EU AI Act became fully applicable on August 2, 2026, subject to transition periods for specific high-risk categories. Its high-risk regime centers on risk management, data quality, logging, documentation, human oversight, robustness, cybersecurity, and accuracy — requirements that map closely onto PMAIS's Risk Classification & Regulatory Crosswalk, Human Oversight Plan, Data Governance Record, and Test & Validation Evidence Package. We are deliberate about our claim here: PMAIS provides a structured implementation and evidence framework for addressing applicable EU AI Act obligations. We do not claim automatic compliance — that determination depends on the specific system and legal analysis.

Canada: a fragmented but navigable landscape

Canada's AI-relevant regulation combines federal privacy law, provincial privacy regimes, and a federal directive for public-sector work — and it continues to evolve through active enforcement. At the federal level, PIPEDA governs collection, use, and disclosure of personal information and requires consent, accountability, and safeguards that apply directly to AI systems. Because RN Consultants is based in Quebec, Quebec's Law 25 receives particular attention: privacy impact assessments in defined circumstances, governance-of-personal-information obligations, and transparency requirements around automated decision-making. Depending on the client, Alberta's and British Columbia's privacy regimes may also apply. For public-sector engagements, the Treasury Board Directive on Automated Decision-Making sets algorithmic impact assessment and transparency requirements that most teams have not fully operationalized.

United States: a regulatory landscape, not a single law

There is no single US federal statute equivalent to the EU AI Act. Obligations arise from federal requirements and FTC enforcement, sector-specific regulation (financial services, healthcare, employment), a growing patchwork of state privacy and AI laws, and the NIST AI Risk Management Framework — which operationalizes AI risk management through four functions (Govern, Map, Measure, Manage) and is designed to apply across sectors.

Standards, above and alongside law

Regulated enterprises operate on a combination of legislation, regulation, standards, contractual obligation, and internal policy. Depending on the engagement, PMAIS references the NIST AI RMF, ISO/IEC 42001, ISO/IEC 23894, ISO/IEC 27001, and ISO/IEC 27701. RN Consultants does not claim certification against any standard unless a corresponding assessment service is explicitly part of the engagement.

PMAIS sits above and around these specific legal regimes: use case, jurisdiction, and sector feed into a crosswalk, which determines controls, which produce evidence, reviewed at each stage gate — a living framework built to absorb regulatory change rather than be invalidated by it.

If you need to know exactly which obligations apply to your specific AI deployment, that mapping is the first deliverable of a PMAIS engagement. Book a discovery call to start.

Book a discovery call →