AI governance frameworks: which one, if you must pick
Shared methods · A shared method; linked tool guides explain the exact steps.
This page covers tools outside your selection. You can still read it. Find matching guides
NIST AI RMF and ISO/IEC 42001 are not rivals. One is a free way to think, the other a paid way to prove — pick by whether you need a certificate.
Someone eventually asks which framework you have "adopted", and the honest first answer is that the two most likely candidates are not competing. NIST's AI Risk Management Framework is a free, voluntary way to think about AI risk. ISO/IEC 42001 is a paid, certifiable way to prove you run a management system for it. Confusing them wastes money in one direction and credibility in the other.
NIST AI RMF: the free thinking tool
The AI RMF is exactly what it says on its own cover: "The Framework is intended to be voluntary, rights-preserving, non-sector-specific, and use-case agnostic", and "intended to be flexible and to augment existing risk practices". No one certifies you against it; its value is the shared vocabulary.
That vocabulary is four functions, and they are worth knowing because they double as a table of contents for the questions a rollout must answer:
- GOVERN: "GOVERN is a cross-cutting function that is infused throughout AI risk management and enables the other functions". The rollout owner and the policies sit here.
- MAP: "The MAP function establishes the context to frame risks related to an AI system". Which uses, which data, which stakes.
- MEASURE: "The MEASURE function employs quantitative, qualitative, or mixed-method tools, techniques, and methodologies to analyze, assess, benchmark, and monitor AI risk and related impacts". The honest metrics, measured not felt.
- MANAGE: "The MANAGE function entails allocating risk resources to mapped and measured risks". Deciding what to do, including the incident response after.
Most organisations already do fragments of all four. The framework's payoff is noticing which function you are weakest at (usually GOVERN, because no one owns it), a diagnosis you can get for the price of reading, today.
ISO/IEC 42001: the paid proving tool
ISO/IEC 42001:2023 is the first international standard for an AI management system, published in December 2023. Structurally it is a management-system standard in the ISO 9001 / 27001 family: you build a system for governing AI, and an accredited third party audits it in the usual two stages, with a certificate valid three years and annual surveillance audits between.
That shape tells you what it is for. Certification does not prove your AI is good; it proves you operate a documented, audited management system around it. The buyers of that proof are external: enterprise procurement, regulated partners, a customer's vendor-risk questionnaire. If nobody is asking for the certificate, you are paying real money, and four-to-nine months of effort, for a wall decoration.
The decision, in one question
Does someone external require proof? If a contract, a regulator, or a customer's vendor questionnaire demands a certificate, ISO/IEC 42001 is the instrument, and NIST AI RMF is how you organise the thinking underneath it. If nobody is demanding proof, run your governance using the AI RMF's four functions and spend the certification budget on the actual controls instead.
The two-step that fits most organisations: adopt the AI RMF's vocabulary now because it is free and clarifying; pursue 42001 only when a named external party makes the certificate worth its cost. Neither is the EU AI Act, which is law you comply with rather than a framework you choose, though a 42001 system is evidence you can point at when it asks.
What goes wrong
Certifying to impress yourselves. A 42001 audit with no external buyer is budget that bought a logo, and no risk reduction.
"We use NIST" as a governance claim. The AI RMF is a way to think; saying you have adopted it means nothing until the four functions have owners and outputs. It is a checklist of questions, not of achievements.
Framework instead of controls. Both documents organise governance; neither performs it. A perfect MAP of risks nobody then MANAGES is paperwork.
Ignoring the standard you cannot choose. A framework is optional; the AI Act, where it applies, is not. Do not let a governance-framework project crowd out actual legal obligations.
One-and-done. The AI RMF calls itself a living document and 42001 requires surveillance audits for a reason: an AI management system written once describes a company that no longer exists after the next model migration.
How to check it worked
Score yourself honestly on the four functions — for each of GOVERN, MAP, MEASURE, MANAGE, name the person who owns it and the last artefact it produced. Blanks are your real finding, and they cost nothing to discover. Only after the blanks are filled does the certification question even make sense: a 42001 audit of a system with three empty functions fails expensively, where the self-score failed for free.
Sources
Something wrong with this page?
Say what you expected and what you got. That is usually the shortest route to a correction, and it goes on the public issue tracker so the fix is visible.