A CTO at a UK AI company asked me last year which framework to adopt, having been told by one advisor to follow NIST and by another to certify ISO 42001. Both advisors were right for the buyer they had in mind, and neither had asked which buyers the company was actually selling to.
That question settles it in most cases. These are not competing answers to the same problem. They are different instruments serving different audiences, and the choice follows from where your revenue comes from.
One is certifiable and one is not
The single most consequential difference: ISO 42001 can be certified by an accredited certification body. NIST AI RMF cannot.
ISO 42001 certification produces a certificate from a body accredited by a national accreditation authority, recognised internationally, and verifiable by anyone who asks. It is the artefact you attach to a security questionnaire.
NIST AI RMF is a voluntary framework published by the US National Institute of Standards and Technology. There is no accredited certification scheme. Organisations self-attest alignment, or engage a consultancy to assess alignment and produce a report. That report carries whatever weight the reader gives it.
For an organisation whose problem is proving something to a buyer, this difference is often decisive on its own.
What NIST AI RMF is for
NIST AI RMF 1.0 was published in January 2023. It organises AI risk management into four functions.
GOVERN establishes the culture, structures, policies, and accountability for AI risk across the organisation. It is cross-cutting and applies to the other three.
MAP establishes context: what the AI system is for, who it affects, what the intended and unintended uses are, and what risks arise.
MEASURE covers the analysis, assessment, benchmarking, and monitoring of identified risks, including the metrics and testing that make risk tractable.
MANAGE covers the prioritisation of risks and the response to them, including risk treatment, third-party risk, and incident response.
NIST subsequently published a Generative AI Profile providing specific guidance for generative systems.
The framework's strength is as a risk vocabulary and an analytical structure. It is thoughtful about the ways AI systems fail and it gives teams a shared language for discussing those failures. It is deliberately not prescriptive, which makes it adaptable and makes it hard to audit against.
What ISO 42001 is for
ISO 42001 specifies a management system. Its structure follows the harmonised ISO management system architecture: scope, leadership, planning, support, operation, performance evaluation, and improvement, with 38 Annex A controls covering AI policy, organisation, resources, impact assessment, lifecycle, data, transparency, use, and third parties.
Its strength is that it produces an auditable, certifiable system with defined evidence requirements. Its structure is familiar to anyone who has operated ISO 27001 or ISO 9001, which makes it easier to integrate with existing governance.
The trade-off is the reverse of NIST's. ISO 42001 tells you what management system to operate. It is lighter than NIST on the technical substance of AI risk measurement.
How the two map onto each other
The two are complementary rather than contradictory, and crosswalks between them exist.
NIST GOVERN maps closely onto ISO 42001 clauses 4, 5, and 7, covering context, leadership, policy, roles, and competence.
NIST MAP maps onto the AI system inventory, the impact assessment controls, and the context and scoping work in clause 4.
NIST MEASURE maps onto the risk assessment process in clause 6 and the performance evaluation requirements in clause 9, and it is the area where NIST offers more practical substance than the standard.
NIST MANAGE maps onto risk treatment in clause 6, operational control in clause 8, third-party controls, and the improvement requirements in clause 10.
An organisation implementing ISO 42001 that uses NIST AI RMF as the methodological reference for the measurement and analysis work ends up with a stronger system than one using either alone. That combination is, in my view, the correct approach for organisations with the capacity for it.
Which your buyers recognise
This is the question that usually decides it.
ISO 42001 is recognised in UK and EU enterprise procurement, in international supply chains, and increasingly in investor diligence. It travels because ISO certification is a globally understood currency. For a UK organisation selling into UK, EU, or international enterprise, it is the artefact procurement teams ask for.
NIST AI RMF is recognised in US federal procurement and in US enterprise buying, particularly among organisations that have aligned their own governance to NIST frameworks. Where a buyer's own security programme is built on NIST CSF, they will often ask suppliers about NIST AI RMF alignment as a matter of institutional habit.
The practical test: look at your last ten enterprise security questionnaires and see which framework was named. If the answer is neither, look at where your pipeline is going next.
When to hold both
Three situations make both worthwhile.
Transatlantic sales. An organisation selling into both US and European enterprise will meet both expectations, and the marginal cost of documenting NIST alignment on top of an ISO 42001 implementation is modest.
US federal or federal supply chain exposure. NIST frameworks carry particular weight in and around US government procurement.
Technical depth requirements. Where an organisation's AI systems carry material risk and the internal team needs a rigorous methodology for measuring it, NIST's substance is genuinely useful regardless of what buyers ask for.
For most UK organisations, the sequence is ISO 42001 as the certified management system, with NIST AI RMF adopted as the internal methodology where the technical depth is needed. That gives you the certificate for procurement and the rigour for the work.
The practical sequence
Establish which buyers are asking and what they are asking for. This determines everything downstream and it takes an afternoon of looking at actual questionnaires rather than assumptions.
Implement ISO 42001 as the management system if the answer points to UK, EU, or international enterprise. Use NIST AI RMF as the reference methodology for the risk measurement and analysis work inside that implementation.
Document NIST alignment separately where US buyers require it. This is a mapping exercise against an implemented management system, not a second programme.
The failure mode to avoid is running both as parallel programmes. They share too much substance for that to be efficient, and the result is two sets of documentation describing the same controls in different vocabularies.
If you are deciding between frameworks or need to establish which your buyers actually require, a scoping call establishes the position in thirty minutes. Book a scoping call.
