Research · AI Governance, Risk & Compliance

Frameworks & Standards: NIST AI RMF and ISO/IEC 42001

Voluntary frameworks and international standards give organizations a common structure for AI governance. The NIST AI Risk Management Framework and ISO/IEC 42001 are the two most widely referenced.

NIST AI Risk Management Framework

The NIST AI Risk Management Framework (AI RMF 1.0), released in January 2023, is a voluntary framework from the US National Institute of Standards and Technology. It organizes AI risk management into four functions: Govern, which sets culture, policies and accountability; Map, which establishes context and identifies risks; Measure, which analyzes and tracks them; and Manage, which prioritizes and acts on them. NIST has also published a Generative AI Profile (NIST AI 600-1) that applies the framework to generative AI risks.

ISO/IEC 42001

ISO/IEC 42001:2023 specifies requirements for an AI management system (AIMS). Like ISO/IEC 27001 for information security, it follows a management system structure: context, leadership, planning, support, operation, performance evaluation and improvement. Organizations can be independently certified against it. Related standards include ISO/IEC 23894, which gives guidance on AI risk management.

How they fit together

  • NIST AI RMF is flexible guidance for identifying and managing AI risks.
  • ISO/IEC 42001 provides a certifiable management system that shows governance is in place and operating.
  • Many organizations use NIST AI RMF to design risk practices and ISO/IEC 42001 to formalize and certify the program.
  • Both can support compliance with regulations such as the EU AI Act, although neither guarantees it.

Common pitfalls

  • Adopting a framework on paper without changing how decisions are made.
  • Treating certification as the goal rather than evidence of good practice.
  • Running AI governance separately from existing security, privacy and risk programs.

How to get started

  • Use the NIST AI RMF functions to assess current practices and gaps.
  • If you already run ISO/IEC 27001, extend that management system to cover ISO/IEC 42001.
  • Map framework controls to your regulatory obligations.
  • Decide whether external certification adds value for your customers.

Questions leaders should ask

  • Which framework will we use as our common vocabulary for AI risk?
  • Do customers or regulators expect ISO/IEC 42001 certification from us?
  • Can we integrate AI governance into our existing ISO or risk programs?
  • How do our framework controls map to the laws that apply to us?

Research Reports

In-depth guides, ebooks and certification prep.

Browse all reports →