Reference Guide
AI Governance Frameworks Compared: NIST AI RMF, ISO/IEC 42001, and the EU AI Act
Enterprise leaders searching for an AI governance framework face a crowded field: voluntary risk frameworks, certifiable management standards, and binding regulation. This guide compares the frameworks that matter most for enterprise AI governance — what each one requires, whether it is binding, and how to combine them in a single implementation program.
Comparison at a Glance
| Framework | Type | Binding? | Best For |
|---|---|---|---|
| NIST AI Risk Management Framework (AI RMF 1.0) | Voluntary framework | No — voluntary, though referenced by U.S. policy | U.S.-based organizations building an internal AI risk program from scratch |
| ISO/IEC 42001:2023 | Certifiable management-system standard | No — voluntary, but certifiable by accredited auditors | Enterprises that want third-party certification to demonstrate AI governance to customers and regulators |
| EU AI Act (Regulation 2024/1689) | Binding regulation | Yes — legally enforceable in the EU, with extraterritorial reach; fines up to €35M or 7% of global turnover | Any organization placing AI systems on the EU market or whose AI outputs are used in the EU |
| OECD AI Principles | Intergovernmental principles | No — soft law, but the foundation for many national frameworks | Boards and policymakers setting directional principles before selecting an operational framework |
| NIST Generative AI Profile (AI 600-1) | Voluntary framework profile | No — voluntary companion to the AI RMF | Organizations extending an existing AI RMF program to cover generative AI deployments |
NIST AI Risk Management Framework (AI RMF 1.0)
Issuer: U.S. National Institute of Standards and Technology
Released: January 2023
Legally binding: No — voluntary, though referenced by U.S. policy
Scope: Risk management across the AI lifecycle: Govern, Map, Measure, Manage
Best for: U.S.-based organizations building an internal AI risk program from scratch
ISO/IEC 42001:2023
Issuer: International Organization for Standardization / IEC
Released: December 2023
Legally binding: No — voluntary, but certifiable by accredited auditors
Scope: AI management system (AIMS): policies, roles, controls, continuous improvement
Best for: Enterprises that want third-party certification to demonstrate AI governance to customers and regulators
EU AI Act (Regulation 2024/1689)
Issuer: European Union
Released: Entered into force August 2024; obligations phase in 2025–2027
Legally binding: Yes — legally enforceable in the EU, with extraterritorial reach; fines up to €35M or 7% of global turnover
Scope: Risk-tiered obligations: prohibited practices, high-risk system requirements, GPAI model rules, transparency duties
Best for: Any organization placing AI systems on the EU market or whose AI outputs are used in the EU
OECD AI Principles
Issuer: Organisation for Economic Co-operation and Development
Released: 2019; updated May 2024
Legally binding: No — soft law, but the foundation for many national frameworks
Scope: High-level values: inclusive growth, human rights, transparency, robustness, accountability
Best for: Boards and policymakers setting directional principles before selecting an operational framework
NIST Generative AI Profile (AI 600-1)
Issuer: U.S. National Institute of Standards and Technology
Released: July 2024
Legally binding: No — voluntary companion to the AI RMF
Scope: Generative-AI-specific risks: hallucination, data leakage, CBRN uplift, information integrity
Best for: Organizations extending an existing AI RMF program to cover generative AI deployments
How Enterprises Implement Them Together
These frameworks are complementary, not competing. A common enterprise pattern is:
- Adopt OECD AI Principles at the board level to set values and accountability expectations.
- Stand up an ISO/IEC 42001 management system to assign ownership, controls, and audit cadence — and to gain a certifiable artifact customers and regulators recognize.
- Run the NIST AI RMF (Govern, Map, Measure, Manage) as the operating process inside that management system, with the Generative AI Profile for LLM deployments.
- Overlay EU AI Act obligations wherever systems or outputs touch the EU market — classifying systems by risk tier and meeting conformity, transparency, and GPAI requirements on the regulatory timeline.
Key Takeaway
The EU AI Act tells you what you must do; ISO/IEC 42001 gives you a certifiable management system to organize it; NIST AI RMF gives you the day-to-day risk process. Enterprises that treat AI governance as one integrated program — rather than four separate compliance projects — reduce duplicated effort and close the gaps where AI risk actually escapes.
This guide is for general orientation, not legal advice. Follow our weekly briefing for continuing coverage of AI governance, or read more about Airunamok.ai.