What AI Governance Means: NIST AI RMF And ISO/IEC 42001
AI governance is how an organisation decides who owns AI risk and how it is managed. Here is how two widely cited frameworks, NIST AI RMF and ISO/IEC 42001, approach it.
Checked against primary sources and independently reviewed on . Sources are listed at the end.
AI governance is the set of decisions, roles and routines an organisation uses to make sure its AI systems do what they should, and to catch them when they do not. It covers who may approve a new AI use case, how risks are assessed before launch, what gets monitored afterwards and who answers for the result.
Two frameworks come up often in this work. The NIST AI Risk Management Framework is a free US framework that describes what good AI risk management looks like. ISO/IEC 42001 is a separate international standard that sets requirements for an AI management system, which an accredited body can certify. This article explains both, how they differ and how they relate to binding law. Laws such as the EU AI Act are covered in the next article, and technical attacks on AI systems are covered in AI Security.
Why AI Needs Its Own Governance
Most organisations already have security, privacy and quality processes. AI strains them in a few specific ways. A model’s behaviour is learned from data rather than written line by line, so it can be wrong in ways nobody coded. Its output can shift when the data it sees in production drifts away from the data it was trained on. Generative models can produce confident but false answers, and they can be steered by inputs nobody anticipated.
These problems cut across teams. Data scientists build the model, product owners decide where it is used, legal teams worry about liability and security teams worry about misuse. Governance gives these groups a shared process so that risk decisions are made deliberately and recorded, rather than left to whoever ships first.
The NIST AI Risk Management Framework
NIST published version 1.0 of the AI Risk Management Framework, also known as NIST AI 100-1, in January 2023.1 NIST designed it for voluntary use by any organisation, in any sector. As of October 2026, NIST’s own page states that version 1.0 is being revised under the White House AI Action Plan, so readers should expect a new edition.2
The framework is built around four functions. Govern sits across the other three, because without accountable owners and a risk culture the rest does not hold together.
- Govern
Set policies, roles and accountability for AI risk, and build a culture where people raise problems early.
- Map
Understand the context: what the system is for, who it affects, what could go wrong and which laws apply.
- Measure
Test and track the risks you mapped, using quantitative and qualitative methods, before and after release.
- Manage
Decide what to do about each risk, put controls in place, respond to incidents and retire systems when needed.
The framework also lists the qualities of a trustworthy AI system: valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed.1 These work as a checklist of what “good” means when you assess a system.
In July 2024 NIST added a Generative AI Profile, NIST AI 600-1, which applies the framework to systems such as chatbots and image generators.3 It names 12 risks that generative AI creates or makes worse. They include confabulation (confidently stated false output), data privacy, information security, information integrity, intellectual property, harmful bias, and risks in the value chain of third-party models and components. For each, the profile suggests actions mapped to the four functions.
ISO/IEC 42001: A Management System You Can Certify
ISO/IEC 42001:2023 was published in December 2023 by ISO and IEC.4 It specifies requirements for an AI management system: the policies, objectives, processes and records an organisation keeps to run AI responsibly and to improve that over time. ISO describes it as the first AI management system standard.
Because it states requirements rather than suggestions, a certification body can audit an organisation against it and issue a certificate. A companion standard, ISO/IEC 42006:2025, published in July 2025, sets the requirements for bodies that audit and certify AI management systems.5 That is the practical difference from the NIST framework. An organisation that already holds an ISO/IEC 27001 certificate for information security can reuse the audit and review routines it built for that standard when it adds AI.
Two companion standards are worth knowing. ISO/IEC 23894:2023 gives guidance on managing AI risk and is not certifiable.6 ISO/IEC 42005:2025, published in May 2025, gives guidance on assessing how an AI system may affect individuals, groups and society.7
How The Two Fit Together
The frameworks are complementary rather than competing. NIST tells you what good AI risk management involves and gives detailed suggested actions. ISO/IEC 42001 tells you how to embed that in a management system and lets you prove it to customers and partners through an audit.
| NIST AI RMF 1.0 | ISO/IEC 42001:2023 | |
|---|---|---|
| Publisher | US National Institute of Standards and Technology | ISO and IEC (international) |
| Legal Force | Voluntary framework | Voluntary standard; becomes contractual if a customer requires it |
| Form | Four functions with categories and suggested actions | Requirements for a management system that can be audited |
| Certification | None; you self-assess | Third-party certification available (certification bodies follow ISO/IEC 42006) |
| Cost To Read | Free | Paid standard |
| Generative AI Detail | Generative AI Profile (AI 600-1) with 12 named risks | Applies to any AI system, generative or not |
| Status | Version 1.0 under revision | First edition, published |
A common pattern is to use the NIST functions and the generative AI risk list to design controls, then run them inside a 42001 management system. How these map onto the EU AI Act clause by clause is the subject of the crosswalk article.
Where To Start
Begin with an inventory. List every AI system you build, buy or embed, who owns it, what it decides or produces, and whose data it uses. That single list feeds every framework above; NIST’s GOVERN 1.6 asks for exactly this kind of inventory, and an auditor or regulator is likely to want to see it early.1 From there, rank systems by the harm they could cause and focus your first risk assessments on the top of the list.
Footnotes
-
NIST, “Artificial Intelligence Risk Management Framework (AI RMF 1.0)”, NIST AI 100-1, January 2023. nvlpubs.nist.gov ↩ ↩2 ↩3
-
NIST, “AI Risk Management Framework”, accessed 7 October 2026. nist.gov ↩
-
NIST, “Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile”, NIST AI 600-1, July 2024. nvlpubs.nist.gov ↩
-
ISO, “ISO/IEC 42001:2023 Information technology, Artificial intelligence, Management system”, December 2023. iso.org ↩
-
ISO, “ISO/IEC 42006:2025 Artificial intelligence, Requirements for bodies providing audit and certification of artificial intelligence management systems”, July 2025. iso.org ↩
-
ISO, “ISO/IEC 23894:2023 Information technology, Artificial intelligence, Guidance on risk management”, February 2023. iso.org ↩
-
ISO, “ISO/IEC 42005:2025 Information technology, Artificial intelligence, AI system impact assessment”, May 2025. iso.org ↩
Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.