Free security assessment — no obligation Get a Proposal
← All insights
Governance

ISO 42001 vs NIST AI RMF: how they fit together

Published Updated

Teams standing up AI governance often ask whether they should follow ISO/IEC 42001 or the NIST AI Risk Management Framework. The short answer: they're complementary, and most programs use both.

NIST AI RMF

A voluntary US framework built around four functions — Govern, Map, Measure, and Manage. It's a practical way to structure how you identify and reduce AI risk, and it's flexible about implementation.

ISO/IEC 42001

A certifiable management-system standard for AI (an AIMS), with defined requirements and Annex A controls. It's what you point an auditor or customer to when they ask for evidence of governance.

Using them together

We typically map AI risk with NIST AI RMF while building the management system ISO 42001 requires — an AI use inventory, a risk register, and a Statement of Applicability. One drives the thinking; the other makes it auditable. See our AI governance approach.

More insights