Skip to main content
AI Governance

ISO 42001 vs NIST AI RMF: Which AI Governance Framework Your Buyers Actually Want

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

9 min read

Contents

    A CTO at a UK AI company asked me last year which framework to adopt, having been told by one advisor to follow NIST and by another to certify ISO 42001. Both advisors were right for the buyer they had in mind, and neither had asked which buyers the company was actually selling to.

    That question settles it in most cases. These are not competing answers to the same problem. They are different instruments serving different audiences, and the choice follows from where your revenue comes from.

    One is certifiable and one is not

    The single most consequential difference: ISO 42001 can be certified by an accredited certification body. NIST AI RMF cannot.

    ISO 42001 certification produces a certificate from a body accredited by a national accreditation authority, recognised internationally, and verifiable by anyone who asks. It is the artefact you attach to a security questionnaire.

    NIST AI RMF is a voluntary framework published by the US National Institute of Standards and Technology. There is no accredited certification scheme. Organisations self-attest alignment, or engage a consultancy to assess alignment and produce a report. That report carries whatever weight the reader gives it.

    For an organisation whose problem is proving something to a buyer, this difference is often decisive on its own.

    What NIST AI RMF is for

    NIST AI RMF 1.0 was published in January 2023. It organises AI risk management into four functions.

    GOVERN establishes the culture, structures, policies, and accountability for AI risk across the organisation. It is cross-cutting and applies to the other three.

    MAP establishes context: what the AI system is for, who it affects, what the intended and unintended uses are, and what risks arise.

    MEASURE covers the analysis, assessment, benchmarking, and monitoring of identified risks, including the metrics and testing that make risk tractable.

    MANAGE covers the prioritisation of risks and the response to them, including risk treatment, third-party risk, and incident response.

    NIST subsequently published a Generative AI Profile providing specific guidance for generative systems.

    The framework's strength is as a risk vocabulary and an analytical structure. It is thoughtful about the ways AI systems fail and it gives teams a shared language for discussing those failures. It is deliberately not prescriptive, which makes it adaptable and makes it hard to audit against.

    What ISO 42001 is for

    ISO 42001 specifies a management system. Its structure follows the harmonised ISO management system architecture: scope, leadership, planning, support, operation, performance evaluation, and improvement, with 38 Annex A controls covering AI policy, organisation, resources, impact assessment, lifecycle, data, transparency, use, and third parties.

    Its strength is that it produces an auditable, certifiable system with defined evidence requirements. Its structure is familiar to anyone who has operated ISO 27001 or ISO 9001, which makes it easier to integrate with existing governance.

    The trade-off is the reverse of NIST's. ISO 42001 tells you what management system to operate. It is lighter than NIST on the technical substance of AI risk measurement.

    How the two map onto each other

    The two are complementary rather than contradictory, and crosswalks between them exist.

    NIST GOVERN maps closely onto ISO 42001 clauses 4, 5, and 7, covering context, leadership, policy, roles, and competence.

    NIST MAP maps onto the AI system inventory, the impact assessment controls, and the context and scoping work in clause 4.

    NIST MEASURE maps onto the risk assessment process in clause 6 and the performance evaluation requirements in clause 9, and it is the area where NIST offers more practical substance than the standard.

    NIST MANAGE maps onto risk treatment in clause 6, operational control in clause 8, third-party controls, and the improvement requirements in clause 10.

    An organisation implementing ISO 42001 that uses NIST AI RMF as the methodological reference for the measurement and analysis work ends up with a stronger system than one using either alone. That combination is, in my view, the correct approach for organisations with the capacity for it.

    Which your buyers recognise

    This is the question that usually decides it.

    ISO 42001 is recognised in UK and EU enterprise procurement, in international supply chains, and increasingly in investor diligence. It travels because ISO certification is a globally understood currency. For a UK organisation selling into UK, EU, or international enterprise, it is the artefact procurement teams ask for.

    NIST AI RMF is recognised in US federal procurement and in US enterprise buying, particularly among organisations that have aligned their own governance to NIST frameworks. Where a buyer's own security programme is built on NIST CSF, they will often ask suppliers about NIST AI RMF alignment as a matter of institutional habit.

    The practical test: look at your last ten enterprise security questionnaires and see which framework was named. If the answer is neither, look at where your pipeline is going next.

    When to hold both

    Three situations make both worthwhile.

    Transatlantic sales. An organisation selling into both US and European enterprise will meet both expectations, and the marginal cost of documenting NIST alignment on top of an ISO 42001 implementation is modest.

    US federal or federal supply chain exposure. NIST frameworks carry particular weight in and around US government procurement.

    Technical depth requirements. Where an organisation's AI systems carry material risk and the internal team needs a rigorous methodology for measuring it, NIST's substance is genuinely useful regardless of what buyers ask for.

    For most UK organisations, the sequence is ISO 42001 as the certified management system, with NIST AI RMF adopted as the internal methodology where the technical depth is needed. That gives you the certificate for procurement and the rigour for the work.

    The practical sequence

    Establish which buyers are asking and what they are asking for. This determines everything downstream and it takes an afternoon of looking at actual questionnaires rather than assumptions.

    Implement ISO 42001 as the management system if the answer points to UK, EU, or international enterprise. Use NIST AI RMF as the reference methodology for the risk measurement and analysis work inside that implementation.

    Document NIST alignment separately where US buyers require it. This is a mapping exercise against an implemented management system, not a second programme.

    The failure mode to avoid is running both as parallel programmes. They share too much substance for that to be efficient, and the result is two sets of documentation describing the same controls in different vocabularies.

    If you are deciding between frameworks or need to establish which your buyers actually require, a scoping call establishes the position in thirty minutes. Book a scoping call.

    Alfred Obeng

    Founder of Goldline Consultancy. ISO 42001 Lead Implementer (PECB), ISO 42001 Lead Auditor (PECB), ISO 27001 Senior Lead Implementer (PECB), ISO 27001 Lead Auditor (PECB), CISSP, PMP.

    Related reading

    AI Governance

    12 min read

    ISO 42001 and the EU AI Act: What the Standard Covers and What It Does Not

    By Alfred Obeng, Founder and Principal Consultant

    CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

    Where ISO 42001 supports EU AI Act readiness, which obligations the standard does not reach, and how to sequence a compliance programme against the enforcement timetable.

    • AI Governance
    • ISO 42001
    • EU AI Act
    ISO 42001

    11 min read

    ISO 27001 vs ISO 42001: What Each Standard Actually Governs

    By Alfred Obeng, Founder and Principal Consultant

    CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

    The practical difference between an information security management system and an AI management system, where the controls overlap, and which one to implement first.

    • ISO 42001
    • ISO 27001
    • AI Governance
    ISO 42001

    9 min read

    Why a GRC Platform Is Not an AI Management System

    By Alfred Obeng, Founder and Principal Consultant

    CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

    What compliance platforms do well for ISO 42001, what they cannot do, and where the practitioner work actually sits.

    • ISO 42001
    • AI Governance
    • GRC
    AI Governance

    10 min read

    ISO 42001 for UK Public Sector Suppliers: Transparency Records, Procurement, and the Accountability Question

    By Alfred Obeng, Founder and Principal Consultant

    CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

    What central government AI transparency obligations mean for suppliers, how AI governance appears in public procurement, and where SC-cleared delivery matters.

    • ISO 42001
    • AI Governance
    • Public Sector

    We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.