With continued advancement in artificial intelligence (AI), organizations that rely on AI must face a choice: which AI governance programs to implement.
The National Institute of Standards and Technology (NIST) provides a voluntary day-to-day methodology. Additionally, ISO/IEC 42001 offers a path to certification. However, the certification and certificate issuance comes from an accredited external certification body, not from the International Organization for Standardization (ISO).
Choosing between the two means understanding what your organization requires.
In this guide, learn what each framework requires, where the overlaps lie, and the differences in cost, certification and EU AI Act alignment.
What Is the NIST AI Risk Management Framework?
The NIST AI Risk Management Framework (AI RMF) is a set of guidelines that help organizations manage the risks associated with AI systems. NIST released this framework on January 26, 2023, and it is intended for voluntary use.
Info: The National Artificial Intelligence Initiative Act of 2020 (P.L. 116-283) instructed NIST to develop the framework. NIST established AI RMF 1.0 as a voluntary, rights-preserving framework that applies across industries and AI use cases, while recognizing it as a “living document” that will continue to evolve over time..
The AI RMF Core is composed of four functions:
- GOVERN: The overarching function that cultivates a culture of risk management across teams responsible for designing, developing, deploying, evaluating or acquiring AI systems
- MAP: Establishes the context organizations need to frame risk for specific systems
- MEASURE: Applies a combination of quantitative and qualitative methods to analyze, benchmark, and monitor risks
- MANAGE: Allocates resources to risks the MAP and MEASURE functions identify in accordance with the GOVERN function
Across those four functions, NIST identifies 19 categories and 72 subcategories. MEASURE holds the most subcategories, showing where a lot of the real work is needed.
In 2024, NIST extended the AI RMF with AI 600-1, a generative AI profile that incorporates risk guidance specific to various models. As of August 2026, AI RMF 1.0 is the only finalized version of the core framework.
What Is ISO/IEC 42001?
ISO/IEC 42001:2023 is an international standard that specifies requirements for establishing, implementing, maintaining and continually improving an AI management system (AIMS) within an organization. An AIMS encompasses the interrelated policies, objectives and processes an organization uses to govern its use of AI systems.
ISO and the International Electrotechnical Commission (IEC) published the standard in 2023.
Where the NIST AI RMF outlines a voluntary framework, ISO/IEC 42001 follows a set of auditable clauses plus an annex of AI-specific controls. This annex, Annex A, organizes those controls into nine controls, covering policies related to:
- AI management
- Internal organization
- Resources for AI systems
- Assessing AI system impacts
- AI system lifecycle
- Data for AI systems
- Information and reporting for interested parties
- Responsible use and human oversight
- Third-party and customer relationships
- These controls are auditable, and a third party can verify conformance and issue a certificate to complying organizations.
See your security gap before attackers do.
See continuous trust in action on a platform that includes RADIUS, PKI and AI security.
NIST AI RMF vs. ISO/IEC 42001: Key Differences
To compare ISO/IEC 42001 and the NIST AI RMF, we’ve identified differences across several dimensions in the table below.
| Dimension | NIST AI RMF | ISO/IEC 42001 |
| Type | Voluntary framework | Certifiable management-system standard |
| Governing body | NIST, a U.S. federal agency | ISO/IEC, an international standards body |
| Cost to access | Free to download and use | Requires certification audit fees |
| Structure | Four functions, 19 categories, 72 subcategories | Clauses plus nine Annex A controls (A.2 through A.10) |
| Certification | Not certifiable | Certifiable through accredited bodies |
| Primary audience | Federal agencies, contractors, voluntary adopters | Any organization needing third-party proof of an AIMS |
| Geographic reach | Primarily U.S., referenced elsewhere | International, referenced in EU and Asia-Pacific markets |
Organizations should treat the NIST AI RMF as a risk-management guide and ISO/IEC 42001 as auditable proof that they follow this guidance.
The largest differences between the two frameworks can be broken down across these four dimensions: objective, structure, certification and implementation.
Objective and Scope
The NIST AI RMF guides organizations through AI risk, regardless of sector or use case. NIST built its framework to be non-sector-specific.
ISO/IEC 42001 has a narrower scope. It specifies requirements for a defined management system within one organization.
Structure
The AI RMF organizes a set of Core functions and categories to guide its reasoning. It also incorporates profiles that tailor guidance to a specific use case, such as a generative AI profile.
ISO/IEC 42001 organizes its structure across numbered management-system clauses to cover context, leadership, planning, support, operation, performance, evaluation and improvement, along with its Annex A control set.
Certification and Assurance
The NIST AI RMF does not offer a certification path. Organizations may self-assess against it or use it to produce alignment evidence for a customer’s due diligence request.
ISO/IEC 42001 is the only certifiable program of the two. An accredited third-party certification body must audit an organization’s AIMS against the standard’s clauses and Annex A controls. Then, if the organization conforms, the auditor issues a certificate.
Implementation Effort
The NIST AI RMF has no associated fees to adopt its framework, though it does take staff time to implement. Teams read the framework and map existing AI risk practices to its functions and categories, then they document any gaps.
ISO/IEC 42001 has a higher implementation cost. Organizations must build the management system, run internal audits and pay an accredited certification body for the external audit.
Note: Timelines may vary across each framework. Reported ISO/IEC 42001 implementations run roughly five to nine months for those starting from scratch. Organizations that already hold ISO/IEC 27001 may only take three to five months because they can reuse their existing management-system infrastructure.
Certification, Accreditation and What an ISO/IEC 42001 Certificate Actually Proves
An organization’s ISO/IEC 42001 certificate is only as credible as the body that issues it. That credibility runs through a separate standard.
ISO/IEC 42006:2025 specifies requirements that certification bodies must meet before they can audit and certify organizations against ISO/IEC 42001. It supplements the general certification-body requirements in ISO/IEC 17021-1 to add AI-specific layers, such as:
- Auditor competence
- Risk-based auditing
- Audit-time estimation
- Rules on impartiality and independence
Accreditation bodies use this standard to determine whether a certification body can issue AIMS certificates customers can trust.
In January 2026, the United Kingdom Accreditation Service (UKAS) announced BSI as the first certification body it has accredited to issue ISO/IEC 42001 certificates.
“Accreditation to ISO/IEC 42001 represents a ground-breaking step in building confidence in the use of artificial intelligence…As organizations look for trusted ways to demonstrate responsible and well-governed AI, accredited certification will play an essential role in strengthening confidence across industry, public services and wider society.”
Matt Gantley, Chief Executive of UKAS
The ANSI National Accreditation Board (ANAB) accredited Schellman as the first certification body to issue ISO/IEC 42001 certificates in the United States.
Before purchasing an ISO/IEC 42001 certificate, make sure the issuing body is accredited by a body like UKAS or ANAB. Certifications from unaccredited bodies do not carry the same weight.
ISO/IEC 42001 and EU AI Act Compliance
The European Union’s AI Act has requirements that go beyond ISO/IEC 42001 obligations. Organizations should understand these differences before creating a full AI governance and compliance plan.
ISO/IEC 42001 was not fully aligned with the final text of the EU AI Act. While it is an international standard, it is not formally recognized by the EU as part of its harmonization process. So, an ISO/IEC 42001 certificate alone does not prove that an organization meets the AI Act’s requirements.
A newer European standard, EN 18286: 2026, was published in July 2026 to address this gap. The standard was designed specifically for AI Act regulatory purposes and includes mapping to the controls in ISO/IEC 42001 Annex A. Organizations that already use ISO/IEC 42001 will be able to build on their existing controls, rather than starting from scratch.
ISO/IEC 42001 is a foundation for EU AI Act compliance, not proof of compliance. EN 18286: 2026 provides a more direct framework for aligning a quality management system with the Act.
However, EN 18286 has not yet been cited in the Official Journal of the European Union (OJEU). Until this happens, the standard does not provide the AI Act’s legal presumption of conformity. Organizations can, and should, use the standard to guide their compliance efforts, but they still must demonstrate that their quality management system meets the AI Act’s requirements.
For organizations doing business in the EU, ISO/IEC 42001 is a useful foundation, and EN 18286 provides a more direct framework for aligning with the AI Act.
Do NIST AI RMF and ISO/IEC 42001 Work Together?
NIST designed the AI RMF to work with international standards like ISO/IEC 42001, so most organizations do not have to choose between them.
NIST’s AI standards roadmap identifies alignment with international standards as a priority, and an existing crosswalk maps AI RMF subcategories to relevant ISO/IEC 42001 clauses and Annex A controls.
The crosswalk can help organizations identify overlapping requirements and avoid duplicate work, but it is not proof of conformance or evidence for audits.
Note: Use the AI RMF to establish and manage AI risk practices. Use ISO/IEC 42001 when you need a formal, certifiable AI management system.
For organizations using both, the AI RMF can provide the internal risk management framework while ISO/IEC 42001 provides the management-system structure and documentation needed for formal assessment.
The security plan that scales with you.
Our solutions can scale from mid-market to global enterprises. Compare options and see how our solutions protect you from costly breaches and ensure peace of mind.
Which Framework Should You Choose?
Which framework to use depends on who is asking you to demonstrate compliance.
The NIST AI RMF may be a better starting point when:
- You work with U.S. federal agencies or contractors that commonly use the framework as a reference.
- Your AI governance program is still developing, and you need a common way for teams to identify and discuss AI risks before formalizing controls.
- Customers or regulators want to see that you have a risk-management process, but have not specifically requested certification.
ISO/IEC 42001 certification may make more sense when:
- Enterprise or EU customers are looking for a recognized certification as part of their procurement process (remember for EU customers to also pay attention to EU AI Act requirements).
- Your organization already follows ISO/IEC 27001 or another management-system standard and can build on established audit processes.
- Your sales or legal teams need independent, third-party validation that can address customer requirements more directly than an internal policy can.
For organizations with more mature AI governance programs, using both frameworks together is often the practical answer.
The right starting point depends less on the framework itself and more on who is asking you to prove something. The AI RMF can serve as the foundation for internal risk management, while ISO/IEC 42001 provides a formal management system and third-party certification. The existing crosswalk between the frameworks can also help reduce duplicated work.
Where Identity Controls Fit AI Governance
AI governance also depends on knowing which people, services, devices and AI agents can access AI systems. Both the NIST AI RMF and ISO/IEC 42001 address governance, accountability, resources, and risk management, all of which become harder to manage when AI workloads rely on shared credentials or unmanaged access.
Certificate-based identity provides a way to give each user, device, service or AI agent a unique credential rather than relying on shared API keys or passwords. With a public key infrastructure (PKI), organizations can issue, manage and revoke credentials at scale to create a clearer record of who or what is authorized to access a system.
For organizations looking to strengthen this layer of AI governance, agentic AI security and enterprise risk frameworks provide more detail on how identity controls fit into broader AI security.
SecureW2 offers several solutions to strengthen identity and authentication for AI environments:
- JoinNow Dynamic PKI can automate certificate issuance and associate certificates with non-human identities.
- JoinNow Cloud RADIUS can then use certificate-based authentication to enforce those identities when devices and workloads connect to protected resources.
- SecureW2 also supports mutual TLS for AI agent authentication.
Strong identity controls are an important part of building a secure, accountable AI environment. Schedule a demo to see how SecureW2 can help put those controls in place.
Key Takeaways
- The NIST AI RMF provides voluntary guidance for managing AI risk, while ISO/IEC 42001 establishes a certifiable AI management system.
- An ISO/IEC 42001 certificate is most meaningful when issued by an accredited certification body meeting ISO/IEC 42006 requirements.
- ISO/IEC 42001 certification alone does not establish conformity with the EU AI Act.
Frequently Asked Questions
Do I need ISO 42001 if I already have ISO 27001?
ISO/IEC 27001 addresses information security, while ISO/IEC 42001 focuses specifically on AI management. Having ISO/IEC 27001 does not eliminate the need for ISO/IEC 42001 if you need an AI-specific management system or certification. However, organizations with an existing ISO/IEC 27001 management system may be able to reuse established processes for areas such as leadership, documentation, internal audits and management review.
How long is an ISO 42001 certificate valid?
ISO/IEC 42001 certification generally follows a three-year certification cycle. Surveillance audits take place during the cycle to confirm that the management system continues to meet certification requirements, followed by a recertification audit at the end of the cycle. Certification can be affected if required surveillance audits are not completed or significant nonconformities are not addressed.
Who is required to follow the NIST AI RMF?
The NIST AI RMF is voluntary, so it does not impose a general legal requirement on organizations to use it. NIST designed it to be flexible across industries, use cases and organization sizes. However, the framework can still become a practical expectation when government requirements, contracts, customers or internal governance policies reference it.
Which framework should I prioritize first, ISO 42001 or the NIST AI RMF?
If no customer or regulator is asking for certification, the NIST AI RMF can be a practical starting point. It is voluntary and provides a structured way to identify, assess and manage AI risks. If customers, procurement teams or other stakeholders specifically want third-party certification, ISO/IEC 42001 may be the better priority. Organizations seeking certification should also consider whether the certification body is accredited under the applicable requirements for ISO/IEC 42001 certification.
Does ISO 42001 certification satisfy EU AI Act requirements?
Not by itself. ISO/IEC 42001 provides a useful foundation for AI governance, but certification does not automatically establish conformity with the EU AI Act. EN 18286 was developed specifically to support AI Act compliance and maps to ISO/IEC 42001 controls. However, until it is cited in the EU’s Official Journal, it does not provide a formal presumption of conformity.