NIST AI 100-1
NIST AI RMF 1.0
- Published by NIST in January 2023
- Voluntary: no certificate, no penalties
- Four functions: GOVERN, MAP, MEASURE, MANAGE
- Free to use, principles-based, flexible
- NIST states version 1.0 is being revised
ISO/IEC 42001:2023
ISO/IEC 42001
- Published by ISO and IEC in December 2023
- Certifiable through accredited third-party audit
- Management system structure, like ISO 27001
- Accredited certification available since late 2024
- Used for enterprise procurement and EU market work
Detailed comparison
| Attribute | NIST AI RMF 1.0 | ISO/IEC 42001 |
|---|---|---|
| Published by | US National Institute of Standards and Technology (NIST) | International Organization for Standardization (ISO) and IEC |
| Published | January 2023 (AI RMF 1.0), with the Playbook alongside | December 2023 (ISO/IEC 42001:2023) |
| Type | Voluntary framework, not certifiable | International standard with third-party certification |
| Core structure | Four functions: GOVERN, MAP, MEASURE, MANAGE | Plan-do-check-act management system, same shape as ISO 27001 and ISO 9001 |
| Certification available | No. It is a reference framework only | Yes. Accredited certification bodies issue ISO 42001 certificates |
| Typical cost | The framework is free; implementation cost varies with consultant use | Audit and certification run in the tens of thousands of dollars, plus annual surveillance audits |
| Implementation timeline | 3 to 12 months depending on your starting maturity | 6 to 18 months to certification readiness from scratch |
| Prescriptiveness | Principles-based, with flexible guidance in the Playbook | Requirements-based. Mandatory clauses must be satisfied to certify |
| Geographic focus | US-primary, widely used internationally | International, used across the EU, UK, and Asia-Pacific |
| EU AI Act alignment | Supports gap analysis; not a harmonized European standard | Adjacent to the European AI management standard EN 18286:2026, published in July 2026 and awaiting citation in the Official Journal, which is what confers presumption of conformity |
| Colorado AI Act alignment | SB 26-189 removed the framework-based affirmative defense; NIST alignment is now practice, not a legal safe harbor | Not referenced in Colorado's statute; the management system still supports the notice and records duties |
| NYC LL 144 alignment | Not referenced; bias testing practice maps to the MEASURE function | Not referenced; ISO 42001 bias-management controls address the same concepts |
| Current status | AI RMF 1.0 is the current version and NIST states it is being revised | ISO/IEC 42001:2023 is current; accredited certification has been available since late 2024 |
| Best for | US teams building an internal AI governance program from scratch | Teams that need certifiable proof of AI governance for customers, regulators, or EU market access |
| Auditable by regulators | No formal audit mechanism; used as a self-assessment reference | Yes. Certificates and surveillance audit reports can be shown to third parties |
Choose NIST AI RMF if
- You are US-based and preparing for state laws like Colorado's ADMT regime
- You are early in AI governance and need a flexible starting structure
- Your team needs shared language for AI risk without certification overhead
- You want internal governance in place before pursuing certification
- Budget is tight: the NIST AI RMF is free and widely understood
Choose ISO/IEC 42001 if
- You need a certificate to satisfy enterprise procurement requirements
- You sell AI products into the EU and want standards-aligned evidence
- You already run ISO 27001 or ISO 9001 and want the same management structure
- You must demonstrate AI governance to regulators, investors, or an acquirer
- You are preparing for EU AI Act conformity work and want third-party validation
Most mature programs use both
The common path is to build the governance program on the NIST AI RMF, then add ISO/IEC 42001 certification when external validation becomes a business requirement. The four NIST functions map cleanly onto ISO 42001 clauses, so the second step reuses most of the first.
1
Start with NIST AI RMF
Build your AI inventory, governance structure, and risk processes using GOVERN, MAP, MEASURE, and MANAGE.
2
Run a gap analysis
Map your NIST-aligned controls onto ISO 42001 clauses and close what is missing. A large share is usually already covered.
3
Certify
Engage an accredited certification body, pass the stage 1 documentation review and the stage 2 audit, and maintain surveillance.