Skip to content
AIAC AI ASSURANCE COUNCIL

ISO/IEC 42001 vs NIST AI RMF, and when each one applies

One is a certifiable management system standard, the other a voluntary risk framework. They are not alternatives, and treating them as such is a mistake.

The question usually arrives as a choice. Should we adopt ISO/IEC 42001 or the NIST AI RMF? It is the wrong question, and the framing causes real waste, because organisations run selection exercises between two instruments that do different jobs.

What each one actually is

ISO/IEC 42001:2023 is a management system standard. It specifies requirements for establishing, implementing, maintaining and improving an AI management system. It has the familiar ISO structure of context, leadership, planning, support, operation, performance evaluation and improvement. The part that matters commercially is that it is certifiable. An accredited body can audit an organisation against it and issue a certificate.

The NIST AI RMF (version 1.0, January 2023) is a voluntary framework. It organises AI risk management into four functions, which are Govern, Map, Measure and Manage, and it describes outcomes to work toward. It is not certifiable, and that is deliberate. There is no NIST audit and no NIST certificate.

The distinction that matters

42001 is largely about whether you have a system. Are roles defined, are risks assessed on a defined basis, is performance evaluated, do improvements get made. An auditor checks that the machinery exists and operates.

The RMF is largely about what good risk management looks like for a specific AI system. It covers how to characterise context, what to measure, and what the word measure even means when the property in question is fairness or robustness.

Put crudely, 42001 tells you to have a process for measuring risk, and the RMF has more to say about how to measure it. This is why mature programmes use both, with 42001 as the organisational skeleton and the RMF as the technical content that fills it.

Choosing, when you must choose first

Start with 42001 when:

  • A customer, procurement process, or regulator is asking for a certificate. Only 42001 can produce one.
  • The problem is organisational, which is to say nobody owns AI risk, there is no inventory, and decisions are not recorded.
  • You already run ISO management systems (ISO/IEC 27001, ISO 9001). The structure is familiar and the audit cycle can be shared, which is a substantial practical saving.

Start with the RMF when:

  • The problem is technical rather than organisational, because you have governance on paper but no idea how to evaluate the systems in front of you.
  • You operate in or sell to the US federal ecosystem, where the RMF is the common reference.
  • You need to move now. There is no certification to schedule and no auditor to book, so adoption can begin immediately and incrementally.

Where they overlap and where they do not

Both expect an inventory, risk assessment proportionate to impact, defined accountability, and monitoring after deployment. Work done for one counts substantially toward the other, and the mapping is not folklore, because NIST publishes crosswalks between the RMF and ISO/IEC 42001 for exactly this purpose.

The gaps are more instructive:

  • 42001 does not tell you how to test a model. It requires that you assess risk, and it does not specify evaluation methodology. The RMF’s Measure function goes further, though it too stops short of prescribing metrics.
  • The RMF gives you no external signal. After a year of good RMF-aligned work you have better practice and nothing a customer can verify. That is not a flaw but the design, and it still matters when procurement is the driver.
  • Neither is a compliance shortcut. Conforming to either does not establish compliance with the EU AI Act, sectoral financial regulation, or data protection law. They are tools for organising work, not substitutes for legal analysis.

The failure mode to avoid

Either instrument can be adopted as a document exercise, but they fail that way for different reasons. With 42001 the audit creates the incentive, because you can write a policy set that satisfies an auditor and reaches none of the teams shipping models. With the RMF there is no audit at all, so nothing external ever forces the question.

The same six-month test catches both. Has any deployment decision changed because of this work? That test is set out in our NIST AI RMF walkthrough.

Practical sequence

  1. Inventory what you actually run, including systems bought rather than built.
  2. Triage by consequence of failure, not by technical sophistication.
  3. Take the highest-consequence system and do a real risk assessment on it, using the RMF’s Map and Measure functions for structure.
  4. Extract the organisational gaps that exercise reveals, which are typically undefined ownership, missing monitoring and absent documentation.
  5. If certification is needed, build the 42001 management system around what those gaps taught you.

Doing it in that order produces a management system shaped by real findings. Doing it in reverse produces a manual.

§ 2 — Related guides

Continue reading