By William Price, Founder of Bastion Cyber Group·Published ·Updated
Teams standing up AI governance often ask whether they should follow ISO/IEC 42001 or the NIST AI Risk Management Framework. The short answer: they're complementary, and most programs use both.
NIST AI RMF
A voluntary US framework built around four functions — Govern, Map, Measure, and Manage. It's a practical way to structure how you identify and reduce AI risk, and it's flexible about implementation.
ISO/IEC 42001
A certifiable management-system standard for AI (an AIMS), with defined requirements and Annex A controls. It's what you point an auditor or customer to when they ask for evidence of governance.
Using them together
We typically map AI risk with NIST AI RMF while building the management system ISO 42001 requires — an AI use inventory, a risk register, and a Statement of Applicability. One drives the thinking; the other makes it auditable. See our AI governance approach.