Skip to content
Notice AIAC/NOT/2026/03

Certification schemes are in development. Syllabi and examination standards will be published ahead of the first cohorts in October 2026.

AI Assurance Council

ISO/IEC 42001 vs NIST AI RMF: which framework, when

§ 1 — Guide

The question is usually posed as a choice: should we adopt ISO/IEC 42001 or the NIST AI RMF? It is the wrong question, and the framing causes real waste — organisations run selection exercises between two instruments that do different jobs.

What each one actually is

ISO/IEC 42001 is a management system standard. It specifies requirements for establishing, implementing, maintaining, and improving an AI management system. It has the familiar ISO structure — context, leadership, planning, support, operation, performance evaluation, improvement — and, critically, it is certifiable: an accredited body can audit an organisation against it and issue a certificate.

The NIST AI RMF is a voluntary framework. It organises AI risk management into four functions — Govern, Map, Measure, Manage — and describes outcomes to work toward. It is not certifiable, deliberately. There is no NIST audit and no NIST certificate, and any vendor claiming to be “NIST AI RMF certified” is misrepresenting it.

The distinction that matters

42001 is largely about whether you have a system: are roles defined, are risks assessed on a defined basis, is performance evaluated, do improvements get made. An auditor checks that the machinery exists and operates.

The RMF is largely about what good risk management looks like for a specific AI system: how to characterise context, what to measure, what “measure” even means when the property is fairness or robustness.

Put crudely: 42001 tells you to have a process for measuring risk. The RMF has more to say about how to measure it. This is why mature programmes use both — 42001 as the organisational skeleton, the RMF as the technical content that fills it.

Choosing, when you must choose first

Start with 42001 when:

  • A customer, procurement process, or regulator is asking for a certificate. Only 42001 can produce one.
  • The problem is organisational: nobody owns AI risk, there is no inventory, decisions are not recorded.
  • You already run ISO management systems (27001, 9001). The structure is familiar and the audit cycle can be shared, which is a substantial practical saving.

Start with the RMF when:

  • The problem is technical rather than organisational: you have governance on paper but no idea how to evaluate the systems in front of you.
  • You operate in or sell to the US federal ecosystem, where the RMF is the common reference.
  • You need to move now. There is no certification to schedule and no auditor to book, so adoption can begin immediately and incrementally.

Where they overlap and where they do not

Both expect an inventory, risk assessment proportionate to impact, defined accountability, and monitoring after deployment. Work done for one counts substantially toward the other, and mapping between them is well-trodden.

The gaps are more instructive:

  • 42001 does not tell you how to test a model. It requires that you assess risk; it does not specify evaluation methodology. The RMF’s Measure function has more to offer, though it too stops short of prescribing metrics.
  • The RMF gives you no external signal. After a year of good RMF-aligned work you have better practice and nothing a customer can verify. That is not a flaw — it is the design — but it matters when procurement is the driver.
  • Neither is a compliance shortcut. Conforming to either does not establish compliance with the EU AI Act, sectoral financial regulation, or data protection law. They are tools for organising work, not substitutes for legal analysis.

The failure mode to avoid

The characteristic failure is adopting a framework as a document exercise: a policy set written to satisfy an auditor, disconnected from the teams shipping models. It passes the audit and changes nothing, and it is worse than doing nothing because it manufactures false confidence and consumes the budget that real work needed.

A useful test after six months: has any deployment decision changed because of the framework? If nothing has been delayed, re-scoped, or rejected, the framework is decorative.

Practical sequence

  1. Inventory what you actually run, including systems bought rather than built.
  2. Triage by consequence of failure, not by technical sophistication.
  3. Take the highest-consequence system and do a real risk assessment on it, using the RMF’s Map and Measure functions for structure.
  4. Extract the organisational gaps that exercise reveals — undefined ownership, missing monitoring, absent documentation.
  5. If certification is needed, build the 42001 management system around what those gaps taught you.

Doing it in that order produces a management system shaped by real findings. Doing it in reverse produces a manual.

Framework selection and application is assessed directly in the Certified AI Assurance Practitioner track.

§ 2 — Certification

Related certification track

AIAC-01 · Foundation

Certified AI Assurance Practitioner

The baseline credential for professionals entering AI assurance: risk identification, testing concepts, governance frameworks, and evidence-based assessment across any industry.

§ 3 — Related guides

Continue reading