ISO 42001 vs NIST AI RMF

Two frameworks dominate the AI-governance conversation. One is a certifiable management-system standard; the other is a voluntary risk framework. Here is how they actually compare — and why most serious AI programmes use them together.

Michael McCarroll 14 min read Updated June 2026

What each framework actually is

ISO/IEC 42001:2023 is an international management-system standard for Artificial Intelligence Management Systems (AIMS). It follows the same Annex SL structure as ISO 27001 and ISO 9001, and — critically — it is certifiable. An accredited certification body can issue a formal certificate against it.

The NIST AI Risk Management Framework (AI RMF 1.0) is a voluntary framework published by the US National Institute of Standards and Technology. It is organised around four functions — Govern, Map, Measure, Manage — and provides a rich vocabulary for AI risk work. There is no certification and no attestation.

Side-by-side comparison

DimensionISO/IEC 42001NIST AI RMF
TypeCertifiable management systemVoluntary risk framework
PublisherISO / IECNIST (US)
CertificationYes — accredited third partiesNone
StructureAnnex SL clauses 4–10 + Annex A controlsGovern, Map, Measure, Manage
Best forProving governance to buyers and regulatorsStructuring internal AI risk practice
EU AI Act fitFrontrunner for harmonised standardUseful vocabulary; not a legal shortcut

How to run them together

Step 1

Adopt ISO 42001 as the operating system

Establish the AIMS: scope, policy, roles, risk methodology, objectives, internal audit, management review. This becomes the certifiable spine.
Step 2

Use NIST AI RMF to shape the risk work inside

Structure impact assessments and model reviews around Govern / Map / Measure / Manage. The vocabulary maps cleanly onto ISO 42001's Annex A controls.
Step 3

Run one evidence set

Every model card, DPIA, bias test and monitoring log satisfies both. Do not maintain two libraries; tag evidence to both frameworks and store once.
Step 4

Certify against ISO 42001

Stage 1 and Stage 2 audits from an accredited body. NIST AI RMF alignment becomes a talking point in the sales cycle — the certificate becomes the trust anchor.
Step 5

Publish a joint statement

Trust-centre page: "Our AI management system is certified to ISO/IEC 42001 and aligned to the NIST AI Risk Management Framework." That single line closes most AI-governance questions on procurement checklists.

Which to lead with

If the buying market is North American enterprise, lead with NIST AI RMF alignment while you work toward ISO 42001 certification. If the buying market is European, regulated, or global, lead with ISO 42001 — it is the standard buyers, insurers and regulators are converging on. Either way, plan for both.

Run ISO 42001 and NIST AI RMF in one workspace

ISO-STANDARD.app maps AI controls to both frameworks so a single evidence library satisfies buyers, auditors and regulators — without duplicating the work.

ISO-STANDARD.app ships a ready-to-adopt ISO 42001 workspace with the risk register, controls catalogue, policies and audit-ready exports already wired together — no spreadsheet sprawl, no consultant lock-in.

Free downloads for this topic

Prefer a conversation? Email hello@iso-standard.app — a real human responds within one business day.

Frequently asked questions

Is NIST AI RMF certifiable?
No. NIST AI RMF is a voluntary framework. There is no certification body and no attestation report. ISO/IEC 42001 is a certifiable management-system standard — an accredited certification body can issue a certificate against it.
Do we need both?
Most mature AI programmes end up using both. NIST AI RMF gives you a rich vocabulary and function model (Govern, Map, Measure, Manage) for risk work. ISO 42001 gives you the certifiable management system buyers and regulators recognise. The control overlap is significant.
Which does the EU AI Act reference?
The EU AI Act does not mandate either, but ISO/IEC 42001 is the frontrunner for a harmonised standard because it is a certifiable management system aligned to the Act's obligations for providers and deployers of high-risk AI systems.
What's the fastest path?
Adopt ISO 42001 as the operating system. Use NIST AI RMF functions to structure risk workshops, model impact assessments and metrics inside it. That way one programme satisfies buyers who ask for either.
Related guides
Trust & security
ISO 27001 aligned
Controls mapped to Annex A
Encryption in transit & at rest
TLS 1.3 · AES-256
MFA enforced
TOTP required for all admins
GDPR & UK GDPR
DPA on request · EU/UK data
SOC 2 ready posture
Audit-grade logging
RLS-isolated tenants
Row-level data separation
← All guidesHome →