Frameworks

AI governance frameworks compared: NIST, ISO/IEC 42001 and the EU AI Act

Ask three people for "an AI governance framework" and you will get three different objects: a voluntary risk method, a certifiable management standard, and a binding law. NIST's AI RMF, ISO/IEC 42001, and the EU AI Act each answer a different question, and treating them as interchangeable is the fastest way to build the wrong program. This guide separates them, shows the one real legal bridge between a standard and the Act, and gives you a defensible order of work.

Why the word "framework" is the problem

The word covers anything with structure. A method you may ignore, a standard you can be audited against, and a regulation that binds you are all called frameworks in vendor decks and job postings. The distinctions that matter are narrower. Is the instrument voluntary? Can a third party certify you against it? Does it create legal obligations? Answer those three questions for each instrument and the confusion disappears.

NIST AI RMF: a voluntary method built on four functions

The NIST AI Risk Management Framework, published as NIST AI 100-1 (AI RMF 1.0), is a voluntary approach to managing AI risk. Its Core is built from four functions: GOVERN, MAP, MEASURE, and MANAGE. Each function breaks down into categories and subcategories, which subdivide into specific actions and outcomes. NIST is explicit that these actions "do not constitute a checklist, nor are they necessarily an ordered set of steps."

GOVERN is different from the other three. It is a cross-cutting function, designed to inform and be infused throughout MAP, MEASURE, and MANAGE. It cultivates a risk management culture, sets policies and organizational schemes, incorporates impact assessment processes, and connects technical design decisions to organizational values. It also covers the full product lifecycle, including legal issues around third-party software, hardware, and data.

NIST does suggest a working order. Assuming a governance structure is in place, functions may be performed in any order that adds value. But the framework itself says:

After instituting the outcomes in GOVERN, most users of the AI RMF would start with the MAP function and continue to MEASURE or MANAGE.

The process should be iterative, with cross-referencing between functions. Risk management should be continuous and run throughout the AI system lifecycle. NIST also publishes a companion Playbook, itself voluntary, with suggested tactical actions organizations can adapt to their own context.

What the AI RMF is not: certifiable. No body audits you against it and issues a certificate. You adopt it, tailor it, and use as much or as little as your capacity allows. NIST says framework users may select from among the categories and subcategories or apply all of them.

ISO/IEC 42001: a certifiable management system standard

ISO/IEC 42001, "Information technology - Artificial intelligence - Management system," edition 1.0, published December 18, 2023, is a different animal. It specifies requirements and guidance for establishing, implementing, maintaining, and continually improving an AI management system, abbreviated AIMS.

The word "requirements" is what separates it from the AI RMF. A standard with requirements can be audited. A conformant organization can hold a certificate. The infrastructure for that now exists: ISO/IEC 42006:2025 specifies, in its own words, "additional requirements to ISO/IEC 17021-1... performing auditing and certification of an artificial intelligence management system (AIMS) according to ISO/IEC 42001." In plain terms, 42006 governs the bodies that certify you against 42001.

The standard sits inside a small family. ISO/IEC 22989:2022 supplies AI concepts and terminology. ISO/IEC 42005:2025 gives guidance for organizations performing AI system impact assessments for individuals and societies. Together they give you vocabulary, an impact assessment method, and a certifiable management system.

Adopting 42001 is still voluntary. No law forces you to certify. But once you seek certification, its requirements bind you contractually and operationally in a way the AI RMF never does.

The EU AI Act: law, with obligations you do not choose

The EU AI Act, Regulation (EU) 2024/1689, published in the Official Journal on July 12, 2024, is not a framework you adopt. It is law that applies to you or does not, based on what you build, deploy, or place on the Union market.

Article 9 shows what a legal obligation looks like next to a voluntary function. For high-risk AI systems, a risk management system "shall be established, implemented, documented and maintained." It must be a continuous iterative process, planned and run throughout the entire lifecycle, with regular systematic review and updating. The Article specifies the steps: identify and analyze known and reasonably foreseeable risks to health, safety, or fundamental rights under the intended purpose; estimate and evaluate risks under intended use and reasonably foreseeable misuse; evaluate other risks based on post-market monitoring data under Article 72; and adopt appropriate and targeted risk management measures.

The Act goes further into engineering territory than either voluntary instrument. Residual risk for each hazard, and overall residual risk, must be judged acceptable. Risks must be eliminated or reduced as far as technically feasible through design and development. Mitigation and control measures must address risks that cannot be eliminated. High-risk systems must be tested to identify the most appropriate risk management measures, and testing may include real-world conditions under Article 60. Deployers must receive the information required under Article 13 and, where appropriate, training.

None of this is optional, none of it is a maturity model, and no certificate substitutes for it.

Side by side

NIST AI RMF ISO/IEC 42001 EU AI Act
What it is Voluntary risk management framework (NIST AI 100-1) Management system standard with requirements and guidance Binding EU regulation (2024/1689)
Voluntary? Yes, explicitly Yes, unless you commit to certification No, applies as law where in scope
Can you be certified? No Yes, by bodies operating under ISO/IEC 42006:2025 No; it imposes obligations rather than offering certification
What it obliges Nothing; it offers outcomes and actions to select and tailor Its requirements, if you pursue or hold certification Legal duties, such as the Article 9 risk management system for high-risk AI systems
Core structure Four functions: GOVERN, MAP, MEASURE, MANAGE An AIMS to establish, implement, maintain, and continually improve Articles setting requirements and obligations

How they stack: Article 40 is the bridge

The three instruments are not rivals. They operate at different layers, and the AI Act itself builds the connection point. Article 40(1) creates a presumption of conformity:

High-risk AI systems or general-purpose AI models which are in conformity with harmonized standards or parts thereof the references of which have been published in the Official Journal of the European Union in accordance with Regulation (EU) No 1025/2012 shall be presumed to be in conformity with the requirements set out in Section 2 of this Chapter or, as applicable, with the obligations set out in of Chapter V, Sections 2 and 3, of this Regulation, to the extent that those standards cover those requirements or obligations.

Read the conditions carefully. The presumption attaches to harmonized standards whose references have been published in the Official Journal, and only to the extent those standards cover the relevant requirements or obligations. Under Article 40(2), the Commission issues standardisation requests to European standardisation organisations to produce those standards, covering all the Section 2 requirements and, as applicable, general-purpose AI model obligations.

That means an ISO/IEC 42001 certificate does not, by itself, buy you the presumption. Article 40(3) directs participants in the standardisation process to take into account existing international standards in the field of AI that are consistent with Union values, fundamental rights, and interests. International standards feed the process; the presumption flows only from harmonized standards cited in the Official Journal. Whether and how far any given harmonized standard will track 42001 is a question the published citations will answer, not one you should assume.

The stacking logic, then: the Act sets the obligations, harmonized standards will offer a presumed route to meeting some of them, and voluntary instruments give you the method and the management system to get there.

What order to do the work in

The sources themselves suggest a sequence.

First, establish where the law binds you, because law is the one layer you do not choose. If you have high-risk systems in scope, Article 9's risk management system is mandatory, continuous, and lifecycle-long. That obligation defines the floor.

Second, stand up governance before anything else. NIST's own guidance assumes a governance structure is in place before the other functions run, and states that most users would then start with MAP and continue to MEASURE or MANAGE. GOVERN 1.1 puts legal and regulatory requirements first among its subcategories: understood, managed, and documented. That ordering supports doing the legal scoping and the governance build together.

Third, formalize. If you need to demonstrate your management system to customers, auditors, or your own board, ISO/IEC 42001 is the instrument that supports third-party certification, with 42006:2025 governing the certifying bodies and 42005:2025 guiding impact assessments along the way.

Throughout, watch the Official Journal for harmonized standard citations under Article 40, because those citations are what convert standards work into a presumption of conformity.

The exam will press exactly on the distinctions this article draws. You need to be able to classify each instrument correctly, name the four AI RMF functions and GOVERN's cross-cutting role, state what makes 42001 certifiable where the RMF is not, and explain the conditions under which Article 40's presumption of conformity actually applies. Get those separations firm and the rest of the governance domain gets much easier to hold.

Common questions

Is ISO/IEC 42001 the same as the EU AI Act?

No. ISO/IEC 42001 is a voluntary management system standard you can be certified against. The EU AI Act is law and applies whether or not you hold any certification. Article 40 links them only in one direction: conformity with a harmonized standard whose reference is published in the Official Journal gives a presumption of conformity, to the extent that standard covers the requirement.

Is the NIST AI Risk Management Framework mandatory?

No. NIST describes it as intended to be voluntary, rights-preserving, non-sector specific and use-case agnostic.

Which should we adopt first?

They answer different questions. NIST gives you a risk method, ISO/IEC 42001 gives you a management system you can certify, and the EU AI Act tells you what is legally required if you are in scope. Establish whether the Act reaches you before choosing between the voluntary instruments.

Sources

Every figure, date and quotation above was read from the document itself, not from a summary of it.

Credential Press is not affiliated with, endorsed by or authorized by the IAPP, ISO, the IEC, NIST or any other body. This is not legal advice.

We are writing the book on this. The AIGP Exam Guide covers all 4 domains and all 13 competencies, in proportion to the published item weights. Join the first-reader list and you get it free before it goes on sale.