NIST AI RMF vs ISO 42001
Last reviewed: · By Victor Humenhuk (AIGP certified)
The NIST AI Risk Management Framework is a free, voluntary US framework for identifying and managing AI risk across the lifecycle, organised around four functions (Govern, Map, Measure and Manage) and seven characteristics of trustworthy AI. ISO/IEC 42001 is an international management system standard that specifies requirements for an AI management system and can be certified by a third-party certification body. Put simply, NIST tells you how to reason about AI risk, while ISO/IEC 42001 tells you what management system to build around it and gives you a certificate you can show a customer. Neither confers a presumption of conformity with the EU AI Act, because only harmonised European standards can do that, but both map usefully onto its requirements.
NIST AI RMF vs ISO/IEC 42001 side by side
| NIST AI RMF 1.0 | ISO/IEC 42001:2023 | |
|---|---|---|
| Type | Voluntary guidance framework | Certifiable management system standard |
| Publisher and date | US National Institute of Standards and Technology, January 2023 | ISO and IEC, December 2023 |
| Cost | Free to download and use | The standard must be purchased, and certification and audit are chargeable |
| Structure | Four core functions (Govern, Map, Measure, Manage) plus seven trustworthiness characteristics | Common management system clauses 4 to 10, plus Annex A controls and Annex B implementation guidance |
| Unit of focus | The AI system and its risks to people, organisations and society | The organisation and its management system |
| Certification | None available; self-assessment or third-party readiness reviews only | Yes, by certification bodies, whose own requirements are set out in ISO/IEC 42006 |
| Companion material | AI RMF Playbook, Generative AI Profile (NIST AI 600-1), crosswalks to other frameworks | ISO/IEC 23894 on AI risk management, ISO/IEC 42005 on impact assessment, ISO/IEC 22989 on terminology |
| Best evidence of | Sound risk reasoning and measurement | Repeatable governance with independent assurance |
What is in the NIST AI RMF?
The framework is built for use across the whole lifecycle and by any actor in it. Its four core functions are:
- Govern, the cross-cutting function: policies, accountability, culture, workforce and third-party risk. It runs through the other three rather than sitting before them.
- Map, which establishes context: intended purpose, deployment setting, affected people, benefits and costs, and whether the system should exist at all.
- Measure, which analyses and tracks risk using quantitative and qualitative methods, including TEVV and red teaming.
- Manage, which allocates resources to prioritised risks, responds, recovers and communicates, and includes decommissioning.
Underneath sit seven characteristics of trustworthy AI: valid and reliable; safe; secure and resilient; accountable and transparent; explainable and interpretable; privacy-enhanced; and fair, with harmful bias managed. The Playbook turns each subcategory into suggested actions, and the Generative AI Profile adapts the framework to generative systems. Nothing in it is binding, but it is referenced in US federal AI guidance and turns up regularly in vendor due diligence questionnaires. See the full NIST AI RMF topic.
What is in ISO/IEC 42001?
ISO/IEC 42001 follows the same high-level structure as ISO/IEC 27001 and ISO 9001, so an organisation that already runs a certified management system will recognise the shape: context of the organisation, leadership, planning, support, operation, performance evaluation and improvement, driven by a plan-do-check-act cycle. On top of the clauses sits Annex A, a set of controls covering matters such as AI policy, internal organisation and roles, resources for AI systems, impact assessment, lifecycle management, data for AI systems, information for interested parties, use of AI systems, and third-party and customer relationships.
The point of difference is auditability. Because 42001 states its requirements in shall form, a certification body can certify against it, which is why it is starting to appear in RFPs and vendor questionnaires as shorthand for AI governance maturity. It does not tell you what a good risk decision looks like. For that you go to ISO/IEC 23894 for risk management guidance and ISO/IEC 42005 for AI system impact assessment.
Does either one satisfy the EU AI Act?
No, and this is a frequent misconception. Under Article 40 of the AI Act, a presumption of conformity comes only from harmonised European standards whose references have been published in the Official Journal, the ones being developed by CEN-CENELEC JTC 21. Common specifications adopted by the Commission under Article 41 are the fallback. A NIST alignment claim or an ISO/IEC 42001 certificate is neither.
That said, both are useful evidence and reduce the delta:
- ISO/IEC 42001 maps closely onto the quality management system required of high-risk providers by Article 17, and its documentation discipline supports Articles 11, 12 and 18.
- The NIST functions map onto the Article 9 risk management system and the Article 15 accuracy, robustness and cybersecurity requirements, and the Generative AI Profile is a practical starting point for general-purpose model work.
- Neither covers conformity assessment, CE marking, registration or serious incident reporting, which are AI Act-specific mechanics.
The Council of Europe's HUDERIA methodology is a third animal again: a risk and impact assessment methodology for human rights, democracy and the rule of law, developed alongside the Framework Convention on AI, rather than a management system. See ISO 42001 and HUDERIA.
Which should your organisation adopt?
- Start with NIST if you need a common language for risk quickly, you have no budget, you are US-based or sell into US federal supply chains, or your immediate problem is that nobody agrees what risk means for your models.
- Go to ISO/IEC 42001 if customers or procurement teams are asking for independent assurance, you already run certified management systems, or you need one auditable governance backbone across many AI systems.
- Run both if you are subject to the EU AI Act: use 42001 as the management system of record and NIST, particularly Measure and the Generative AI Profile, as the technical risk method inside it. The two are complementary, and NIST publishes crosswalks precisely because organisations combine them.
- Whichever you pick, track CEN-CENELEC JTC 21 output separately. That is where AI Act conformity will actually be evidenced.
Related study notes
- NIST AI RMF: the full kit
- ISO 42001 and HUDERIA
- Aligning risk strategies
- The three-tier guardrail framework
Frequently asked questions
Can you get certified against the NIST AI RMF?
No. The framework is voluntary and NIST does not operate a certification scheme. Firms sometimes obtain third-party readiness assessments or attestations describing alignment with the framework, but that is not certification against a management system standard in the way ISO/IEC 42001 allows.
Does ISO/IEC 42001 certification prove EU AI Act compliance?
No. Only harmonised European standards published in the Official Journal give a presumption of conformity under Article 40. A 42001 certificate is useful evidence of governance maturity and covers much of the ground needed for the Article 17 quality management system, but it does not discharge conformity assessment, CE marking, registration or incident reporting duties.
Is ISO/IEC 42001 the same as ISO 27001 for AI?
They share the common management system structure and the certification model, and an existing 27001 programme makes 42001 much easier. The content differs: 27001 addresses information security, while 42001 addresses AI-specific concerns such as impact on individuals and society, data for AI systems, lifecycle management and responsible use.
Do you need to understand both?
For most AI governance work, yes, and above all how they differ in nature. Be able to name the four NIST core functions and the seven trustworthiness characteristics, and to distinguish a voluntary framework from a certifiable management system standard and from a binding legal requirement such as the EU AI Act.
Test yourself
Try the free AIGP practice questions, or read the full AIGP study guide - free.