Research · AI Governance, Risk & Compliance
Frameworks & Standards: NIST AI RMF and ISO/IEC 42001
Voluntary frameworks and international standards give organizations a common structure for AI governance. The NIST AI Risk Management Framework and ISO/IEC 42001 are the two most widely referenced.
NIST AI Risk Management Framework
The NIST AI Risk Management Framework (AI RMF 1.0), released in January 2023, is a voluntary framework from the US National Institute of Standards and Technology. It organizes AI risk management into four functions: Govern, which sets culture, policies and accountability; Map, which establishes context and identifies risks; Measure, which analyzes and tracks them; and Manage, which prioritizes and acts on them. NIST has also published a Generative AI Profile (NIST AI 600-1) that applies the framework to generative AI risks.
ISO/IEC 42001
ISO/IEC 42001:2023 specifies requirements for an AI management system (AIMS). Like ISO/IEC 27001 for information security, it follows a management system structure: context, leadership, planning, support, operation, performance evaluation and improvement. Organizations can be independently certified against it. Related standards include ISO/IEC 23894, which gives guidance on AI risk management.
How they fit together
- NIST AI RMF is flexible guidance for identifying and managing AI risks.
- ISO/IEC 42001 provides a certifiable management system that shows governance is in place and operating.
- Many organizations use NIST AI RMF to design risk practices and ISO/IEC 42001 to formalize and certify the program.
- Both can support compliance with regulations such as the EU AI Act, although neither guarantees it.
Common pitfalls
- Adopting a framework on paper without changing how decisions are made.
- Treating certification as the goal rather than evidence of good practice.
- Running AI governance separately from existing security, privacy and risk programs.
How to get started
- Use the NIST AI RMF functions to assess current practices and gaps.
- If you already run ISO/IEC 27001, extend that management system to cover ISO/IEC 42001.
- Map framework controls to your regulatory obligations.
- Decide whether external certification adds value for your customers.
Questions leaders should ask
- Which framework will we use as our common vocabulary for AI risk?
- Do customers or regulators expect ISO/IEC 42001 certification from us?
- Can we integrate AI governance into our existing ISO or risk programs?
- How do our framework controls map to the laws that apply to us?