Two AI governance frameworks come up in every compliance conversation, and almost always framed wrongly: as if they were alternatives, and as if they were mandatory. They are neither.
What each one is
ISO/IEC 42001:2023 is the first AI management system (AIMS) standard, published in December 2023. It is certifiable: an accredited body audits you and issues a certificate. Its structure mirrors ISO 27001 or ISO 9001 — policy, roles, risk assessment, controls, internal audit, continual improvement.
The NIST AI Risk Management Framework is a voluntary US framework organised around four functions: Govern, Map, Measure, Manage. It is not certified. It is guidance on how to think about risk, not a badge.
Neither is legally required, in the United States or internationally.
They don’t compete, they overlap
This is the most common misunderstanding. The NIST AI RMF’s functions map onto ISO 42001’s requirements, so work done for one carries directly into the other’s audit. Published crosswalks exist for exactly this purpose.
The practical way to see it:
| NIST AI RMF | ISO/IEC 42001 | |
|---|---|---|
| Nature | Risk management framework | Certifiable management system |
| Entry cost | Low — documentation and method | High — external audit and upkeep |
| What you get | A structured way to think | A certificate to show |
| When to start | Always, from the first project | When somebody asks for it |
And where does the EU AI Act fit?
Separately. The AI Act is law, with concrete obligations and penalties. The other two are voluntary.
The good news is that the work carries over almost entirely: the system inventory, risk classification, traceability, human oversight and staff training are inputs to all three. Doing it once, properly, serves everything.
When to actually certify
Not out of conviction. Out of demand.
Corporate procurement processes increasingly list ISO 42001 in due-diligence questionnaires, and public sector contractors are starting to face expectations to demonstrate NIST-aligned governance. That is the moment: when a specific contract depends on it.
Certifying earlier usually means spending five or six figures on something nobody asked for. It is a commercial decision, not an ethical one.
What you should do now regardless
Independent of certification, at any company using AI in processes that matter:
- A living inventory of AI systems, with purpose, owner and the data they touch.
- A risk assessment per system, even if it fits on one page.
- Traceability: model, version, prompt, data, who approved what.
- Documented human oversight at the points where the system decides something affecting people.
- A periodic review with a date in the calendar, not whenever someone remembers.
That is 80% of the effort of any of the three frameworks. If you have it, certifying later is paperwork. If you don’t, no certificate will save you from an incident.