TL;DR: Build the shared documentation core once. EU AI Act, NIST AI RMF, and Texas TRAIGA require the same five things at their foundation. Add framework-specific sections on top. The master table of contents is at the bottom of this article.
The problem with treating each framework separately
Organizations that have EU customers, US operations in Texas, or employees in states with AI employment laws are facing three overlapping compliance frameworks, each with its own documentation requirements. Most published guidance treats them in isolation. A consultant hired for EU AI Act compliance builds Annex IV technical documentation. A separate engagement for NIST AI RMF builds a risk register and playbook. The Texas TRAIGA team starts fresh with a governance program document.
The result is three partially overlapping documentation sets, maintained by different teams, telling slightly different stories about the same AI tools. Auditors and regulators are not impressed. Internal teams spend time reconciling documents that should never have been separate.
The better approach: identify the overlapping core requirements, build documentation that satisfies all of them once, and add framework-specific sections where the requirements actually diverge. This is not a shortcut; it is the architecturally correct way to build a compliance documentation program for an organization operating across multiple AI governance frameworks.
The shared core: what all three frameworks require
Approximately 60-70% of the documentation requirements across EU AI Act, NIST AI RMF, and Texas TRAIGA cover the same ground. The five shared core components are:
1. AI tool inventory
Every framework requires you to know what AI systems you are using and in what context.
- EU AI Act Article 11: Technical documentation must identify the AI system, its purpose, and its deployment context.
- NIST AI RMF (Govern/Map functions): The "Map" function begins with categorizing AI systems by risk profile and intended use.
- Texas TRAIGA: A governance program under TRAIGA must include documentation of AI systems subject to the act's requirements.
One inventory document, formatted to capture the fields required by each framework, satisfies all three. See AI tool register template for small teams for a base format to adapt.
2. Risk assessment for each AI tool
All three frameworks require documented risk assessment as the foundation for governance decisions.
- EU AI Act Article 9: A risk management system including risk identification, evaluation, and mitigation measures.
- NIST AI RMF (Measure function): Risk measurement processes, including identification of AI risks and their likelihood and severity.
- Texas TRAIGA: Risk documentation is required as part of the governance program and supports the NIST AI RMF safe harbor claim.
A single risk assessment template, completed for each AI tool in your inventory, can be structured to capture the fields each framework expects. The EU AI Act version will include fundamental rights impact assessment fields for high-risk systems. The NIST version will include playbook cross-references and core function mapping. The TRAIGA version will include the prohibited AI use check (see below).
3. Human oversight procedures
All three frameworks require evidence that humans are involved in consequential AI decisions.
- EU AI Act Article 14: High-risk AI systems must have human oversight measures. Deployers must assign oversight responsibility to individuals with the authority and ability to intervene.
- NIST AI RMF (Manage function): The Manage function covers accountability, including human roles in overseeing AI outputs and the ability to override or correct AI decisions.
- Texas TRAIGA: The act requires deployers to maintain human oversight over consequential AI decisions as part of a compliant governance program.
Document your oversight procedures once: who reviews AI outputs for which decisions, what override authority they have, how overrides are documented, and what escalation path exists when the AI output is disputed.
4. Incident log
All three frameworks require tracking of AI-related incidents and, in some cases, reporting to regulators or affected individuals.
- EU AI Act Article 73: Serious incidents involving high-risk AI systems must be reported to market surveillance authorities. Deployers must maintain records.
- NIST AI RMF (Manage function): Incident response and ongoing monitoring are part of the Manage function. Playbooks should address how AI incidents are identified, contained, and documented.
- Texas TRAIGA: Incident response documentation is part of the governance program. Organizations relying on the NIST safe harbor must have a functioning incident response process.
A single incident log covering all AI systems, with fields for incident type, affected AI system, affected parties, response taken, and regulatory reporting status, covers all three frameworks. The EU-specific column tracks whether the incident met the threshold for Article 73 reporting.
5. Vendor and supply chain records
All three frameworks require documentation of AI vendor relationships.
- EU AI Act Article 26: Deployers must obtain instructions for use from providers, review the provider's conformity documentation, and implement use within stated conditions.
- NIST AI RMF (Map/Govern functions): The supply chain risk management components of the framework require identifying AI vendors and assessing the risk they contribute.
- Texas TRAIGA: Vendor records are relevant to demonstrating that governance extends to third-party AI systems.
One vendor record per AI system: provider name, model or product version, date of last documentation review, data processing agreement status, any known limitations or restrictions from the provider's instructions for use.
Framework-specific additions
Once the shared core exists, the framework-specific additions are relatively contained.
EU AI Act additions
If any of your AI systems are classified as high-risk under Annex III of the EU AI Act, you need:
- Annex IV technical documentation: A structured document covering the AI system's purpose, development methodology, training data, performance metrics, and monitoring procedures. This goes beyond what NIST or TRAIGA require in specificity.
- Article 50 transparency notices: Written user notices required for chatbots and other AI systems that interact with individuals in ways that could be mistaken for human communication. These are brief, user-facing documents, not internal governance records.
- Fundamental rights impact assessment (FRIA): For deployers of high-risk AI systems, an assessment of the potential impact on fundamental rights. This includes reviewing the AI system's potential to produce discriminatory outcomes, privacy harms, and limitations on access to services.
For limited-risk AI systems (like chatbots covered by Article 50 disclosure requirements), the main EU-specific addition is the transparency notice itself, not the full Annex IV package.
See EU AI Act deployer evidence gaps SME August 2026 for common gaps in EU AI Act deployer documentation.
NIST AI RMF additions
If you are using NIST AI RMF as the primary framework (and relying on it for Texas TRAIGA safe harbor), structure your documentation with explicit NIST core function mapping:
- Govern: Add a governance policy document describing your organization's AI governance structure, roles, and accountability framework. The shared core covers many Govern requirements, but a standalone governance policy with executive sign-off is standard for NIST compliance programs.
- Map: Add a context characterization for each AI system, documenting the organizational context, user population, and potential impacts. This is the "why are we using this AI and for whom" document.
- Measure: Add a risk measurement playbook describing the methods you use to evaluate and test AI risk. For each AI system, this includes testing procedures, metrics tracked, and thresholds for escalation.
- Manage: Add explicit playbook cross-references in your risk assessment and incident response documentation so auditors can trace each risk management action to its NIST function.
See Texas TRAIGA safe harbor NIST AI RMF checklist for what TRAIGA specifically requires from the NIST documentation.
Texas TRAIGA additions
Beyond NIST AI RMF alignment, TRAIGA has two specific documentation requirements:
- Prohibited AI use declaration: TRAIGA prohibits certain uses of AI (including social scoring, real-time biometric surveillance, and other high-risk applications). Your documentation should include a written declaration, reviewed by legal counsel, confirming that your AI systems do not fall into the prohibited use categories.
- Substantial compliance evidence record: To claim the safe harbor, you need to be able to show that your NIST AI RMF implementation is operational, not just documented. This means evidence that governance processes actually run: meeting records, risk assessment dates, incident response tests, training records for AI oversight staff.
The master document table of contents
Copy this structure as the starting point for your master AI governance documentation set. Each numbered section maps to at least one shared core requirement plus framework-specific needs. Framework tags in brackets indicate which framework specifically requires that section: [ALL] means all three, [EU] means EU AI Act only, [NIST] means NIST AI RMF only, [TX] means Texas TRAIGA only.
AI Governance Master Documentation [Organization Name] | Version: [X.X] | Last reviewed: [Date]
PART 1: GOVERNANCE STRUCTURE [ALL] 1.1 AI governance policy (executive-approved) 1.2 AI governance roles and responsibilities matrix 1.3 AI governance review calendar
PART 2: AI SYSTEM INVENTORY [ALL] 2.1 AI system registry (master list) 2.2 Per-system context characterization sheets [NIST/MAP] 2.3 Risk tier classification for each system [EU/Art.9, NIST/Measure, TX] 2.4 Prohibited use compliance check [TX]
PART 3: RISK ASSESSMENTS [ALL] 3.1 Risk assessment methodology 3.2 Per-system risk assessment records 3.3 Fundamental rights impact assessment (high-risk systems) [EU/Art.9A] 3.4 Risk measurement playbook and metrics [NIST/Measure]
PART 4: HUMAN OVERSIGHT PROCEDURES [ALL] 4.1 Oversight role assignments per AI system 4.2 Override and escalation procedures 4.3 Training records for AI oversight staff 4.4 Override event log
PART 5: INCIDENT RESPONSE AND LOG [ALL] 5.1 AI incident response plan 5.2 Incident log (rolling) 5.3 Serious incident report tracker [EU/Art.73] 5.4 Post-incident review records
PART 6: VENDOR AND SUPPLY CHAIN RECORDS [ALL] 6.1 Vendor registry with documentation status 6.2 Data processing agreements (DPA) index [EU/Art.26, GDPR/Art.28] 6.3 Provider instructions-for-use records [EU/Art.26] 6.4 Vendor change notification log
PART 7: EU AI ACT SPECIFIC [EU] 7.1 Annex IV technical documentation (per high-risk system) 7.2 Article 50 transparency notices (per user-facing AI system) 7.3 EU market surveillance authority contact register
PART 8: NIST AI RMF SPECIFIC [NIST] 8.1 NIST AI RMF core function mapping table 8.2 AI RMF playbook cross-references by system 8.3 Govern function evidence (meeting records, policy sign-offs)
PART 9: TEXAS TRAIGA SPECIFIC [TX] 9.1 NIST AI RMF substantial compliance evidence record 9.2 Prohibited AI use declaration (signed) 9.3 TRAIGA governance program summary
Requirement-by-requirement mapping: one document, three frameworks
The table below maps each shared documentation artifact to the specific article, function, or requirement in each framework. Use this when an auditor or regulator asks which document satisfies a specific requirement.
| Document | EU AI Act | NIST AI RMF | Texas TRAIGA |
|---|---|---|---|
| AI system registry | Article 11 (technical documentation basis); Article 49 (registration in EU database for high-risk) | Govern 1.1 (policies and accountability); Map 1.1 (context is established) | Section 5 governance program, system identification |
| Risk assessment per system | Article 9 (risk management system); Annex IV point 2 (intended purpose and risk) | Measure 2.1 (AI risks identified and evaluated); Map 2.1 (scientific and established methods for risk identification) | NIST AI RMF substantial compliance evidence (Map/Measure functions) |
| Fundamental rights impact | Article 9a / Article 27 (FRIA for deployers in public services, education, employment) | Not required, but Govern 6.1 (policies for human rights impacts) is analogous | Not required |
| Human oversight procedures | Article 14 (human oversight measures documented); Article 26 (deployer implements oversight per provider instructions) | Manage 4.2 (incident response includes human escalation); Govern 4.1 (oversight roles defined) | Governance program, human oversight element |
| Incident log | Article 73 (serious incident reporting records must be kept); Article 12 (logging obligation for high-risk systems) | Manage 2.4 (events documented in incident log); Manage 3.1 (responses to AI risks) | NIST AI RMF Manage function evidence |
| Vendor / DPA index | Article 26 (instructions for use and conformity documentation from provider); GDPR Article 28 (DPA with processors) | Map 5.1 (AI supply chain risks identified); Govern 6.2 (vendor risk management policies) | Governance program, supply chain element |
| Acceptable use policy | Article 13 (transparency to deployers and users); Article 50 (transparency to affected persons) | Govern 1.2 (accountability for AI decisions); Govern 2.2 (internal accountability policies) | Governance program, acceptable use policies |
| Training records for oversight staff | Article 4 (AI literacy, deployers must ensure staff have sufficient AI knowledge); Article 26(6) deployer obligations | Govern 5.2 (organizational teams committed to AI risk management); Govern 5.1 (roles defined) | NIST Govern function evidence |
| Post-incident review | Article 73 (follow-up notification after serious incident); Article 12 (logging for post-incident analysis) | Manage 3.2 (identified risks incorporated into governance); Manage 4.1 (response and recovery applied) | NIST Manage function evidence |
Three cells that auditors always check first:
- EU AI Act Article 73: Your incident log must show that for each serious incident, a notification was sent to the relevant national market surveillance authority within 15 days (or immediately for life-threatening events). The log entry should include the notification date and reference number.
- NIST AI RMF Govern 1.1: This function requires documented accountability, specifically, named individuals responsible for each AI system and their authority to intervene. A risk assessment without named owners does not satisfy this function.
- Texas TRAIGA substantial compliance: To claim the NIST safe harbor, you need evidence that you followed the NIST framework's core functions, not just that you are aware of them. The evidence is typically the documentation in Parts 8 and 9 of the master document structure above, plus meeting records and policy approvals showing the Govern function is operational.
How to implement this without a large team
For small and mid-size organizations, the full master document table of contents can look daunting. Here is how to sequence implementation:
Week 1-2: Complete Part 2 (AI system inventory). You cannot do anything else without knowing what AI systems you have and how they are classified.
Week 3-4: Complete Part 6 (vendor records). Pull your DPAs and vendor contracts. This surfaces gaps quickly.
Week 5-8: Complete Part 3 (risk assessments) for each AI system. Start with your highest-risk systems.
Week 9-10: Complete Part 4 (human oversight procedures) and Part 5 (incident response). These are process documents, not research projects.
Week 11-12: Add framework-specific sections. If you have EU customers, add Part 7. If you are relying on NIST safe harbor for Texas, flesh out Part 8 and complete Part 9.
Ongoing: Update Part 2 when new AI tools are adopted, update Part 5 on a rolling basis, review the rest annually or after major system changes.
For the AI system inventory format, start with the AI tool register template for small teams. For the broader governance program structure, see AI governance guide for small teams and the AI governance checklist 2026.
Related reading
For Texas TRAIGA requirements and the NIST safe harbor specifics, see Texas TRAIGA safe harbor NIST AI RMF checklist. For how NIST AI RMF compares to ISO 42001 for smaller organizations, see ISO 42001 vs NIST AI RMF for small teams. For common gaps in EU AI Act deployer documentation that auditors actually look for, see EU AI Act deployer evidence gaps SME August 2026. For the full EU AI Act compliance guide, see EU AI Act compliance guide for small teams. For Annex IV documentation specifics, see EU AI Act high-risk AI documentation templates August 2026. For Colorado's upcoming AI framework that may also require documentation overlap, see Colorado AI Act SB 189 2027 employer guide. The AI governance checklist 2026 covers the full governance program.
