← Back to all insights

Regulation Published · 17 July 2026

ISO 42001 and the NIST AI RMF: which one you need, and when

Neither is mandatory anywhere. And yet both are showing up in vendor due-diligence questionnaires, which is a far more effective way of becoming mandatory.

6 min read

Two AI governance frameworks come up in every compliance conversation, and almost always framed wrongly: as if they were alternatives, and as if they were mandatory. They are neither.

What each one is

ISO/IEC 42001:2023 is the first AI management system (AIMS) standard, published in December 2023. It is certifiable: an accredited body audits you and issues a certificate. Its structure mirrors ISO 27001 or ISO 9001 — policy, roles, risk assessment, controls, internal audit, continual improvement.

The NIST AI Risk Management Framework is a voluntary US framework organised around four functions: Govern, Map, Measure, Manage. It is not certified. It is guidance on how to think about risk, not a badge.

Neither is legally required, in the United States or internationally.

They don’t compete, they overlap

This is the most common misunderstanding. The NIST AI RMF’s functions map onto ISO 42001’s requirements, so work done for one carries directly into the other’s audit. Published crosswalks exist for exactly this purpose.

The practical way to see it:

NIST AI RMFISO/IEC 42001
NatureRisk management frameworkCertifiable management system
Entry costLow — documentation and methodHigh — external audit and upkeep
What you getA structured way to thinkA certificate to show
When to startAlways, from the first projectWhen somebody asks for it

And where does the EU AI Act fit?

Separately. The AI Act is law, with concrete obligations and penalties. The other two are voluntary.

The good news is that the work carries over almost entirely: the system inventory, risk classification, traceability, human oversight and staff training are inputs to all three. Doing it once, properly, serves everything.

When to actually certify

Not out of conviction. Out of demand.

Corporate procurement processes increasingly list ISO 42001 in due-diligence questionnaires, and public sector contractors are starting to face expectations to demonstrate NIST-aligned governance. That is the moment: when a specific contract depends on it.

Certifying earlier usually means spending five or six figures on something nobody asked for. It is a commercial decision, not an ethical one.

What you should do now regardless

Independent of certification, at any company using AI in processes that matter:

  • A living inventory of AI systems, with purpose, owner and the data they touch.
  • A risk assessment per system, even if it fits on one page.
  • Traceability: model, version, prompt, data, who approved what.
  • Documented human oversight at the points where the system decides something affecting people.
  • A periodic review with a date in the calendar, not whenever someone remembers.

That is 80% of the effort of any of the three frameworks. If you have it, certifying later is paperwork. If you don’t, no certificate will save you from an incident.

Sources

Next step

How ready is your business for AI?

Evaluate your AI maturity in 5 minutes and get free personalised recommendations.

Ready to move beyond the hype?