Skip to main content
Regulome
Search the register
For ProvidersRun the free checker

NIST AI RMF vs. ISO/IEC 42001

One is a free reference framework, the other is a certifiable management standard. What each covers, what each costs, and which regulations they help with.

NIST AI 100-1

NIST AI RMF 1.0

  • Published by NIST in January 2023
  • Voluntary: no certificate, no penalties
  • Four functions: GOVERN, MAP, MEASURE, MANAGE
  • Free to use, principles-based, flexible
  • NIST states version 1.0 is being revised
ISO/IEC 42001:2023

ISO/IEC 42001

  • Published by ISO and IEC in December 2023
  • Certifiable through accredited third-party audit
  • Management system structure, like ISO 27001
  • Accredited certification available since late 2024
  • Used for enterprise procurement and EU market work

Detailed comparison

AttributeNIST AI RMF 1.0ISO/IEC 42001
Published byUS National Institute of Standards and Technology (NIST)International Organization for Standardization (ISO) and IEC
PublishedJanuary 2023 (AI RMF 1.0), with the Playbook alongsideDecember 2023 (ISO/IEC 42001:2023)
TypeVoluntary framework, not certifiableInternational standard with third-party certification
Core structureFour functions: GOVERN, MAP, MEASURE, MANAGEPlan-do-check-act management system, same shape as ISO 27001 and ISO 9001
Certification availableNo. It is a reference framework onlyYes. Accredited certification bodies issue ISO 42001 certificates
Typical costThe framework is free; implementation cost varies with consultant useAudit and certification run in the tens of thousands of dollars, plus annual surveillance audits
Implementation timeline3 to 12 months depending on your starting maturity6 to 18 months to certification readiness from scratch
PrescriptivenessPrinciples-based, with flexible guidance in the PlaybookRequirements-based. Mandatory clauses must be satisfied to certify
Geographic focusUS-primary, widely used internationallyInternational, used across the EU, UK, and Asia-Pacific
EU AI Act alignmentSupports gap analysis; not a harmonized European standardAdjacent to the European AI management standard EN 18286:2026, published in July 2026 and awaiting citation in the Official Journal, which is what confers presumption of conformity
Colorado AI Act alignmentSB 26-189 removed the framework-based affirmative defense; NIST alignment is now practice, not a legal safe harborNot referenced in Colorado's statute; the management system still supports the notice and records duties
NYC LL 144 alignmentNot referenced; bias testing practice maps to the MEASURE functionNot referenced; ISO 42001 bias-management controls address the same concepts
Current statusAI RMF 1.0 is the current version and NIST states it is being revisedISO/IEC 42001:2023 is current; accredited certification has been available since late 2024
Best forUS teams building an internal AI governance program from scratchTeams that need certifiable proof of AI governance for customers, regulators, or EU market access
Auditable by regulatorsNo formal audit mechanism; used as a self-assessment referenceYes. Certificates and surveillance audit reports can be shown to third parties

Choose NIST AI RMF if

  • You are US-based and preparing for state laws like Colorado's ADMT regime
  • You are early in AI governance and need a flexible starting structure
  • Your team needs shared language for AI risk without certification overhead
  • You want internal governance in place before pursuing certification
  • Budget is tight: the NIST AI RMF is free and widely understood

Choose ISO/IEC 42001 if

  • You need a certificate to satisfy enterprise procurement requirements
  • You sell AI products into the EU and want standards-aligned evidence
  • You already run ISO 27001 or ISO 9001 and want the same management structure
  • You must demonstrate AI governance to regulators, investors, or an acquirer
  • You are preparing for EU AI Act conformity work and want third-party validation

Most mature programs use both

The common path is to build the governance program on the NIST AI RMF, then add ISO/IEC 42001 certification when external validation becomes a business requirement. The four NIST functions map cleanly onto ISO 42001 clauses, so the second step reuses most of the first.

1

Start with NIST AI RMF

Build your AI inventory, governance structure, and risk processes using GOVERN, MAP, MEASURE, and MANAGE.

2

Run a gap analysis

Map your NIST-aligned controls onto ISO 42001 clauses and close what is missing. A large share is usually already covered.

3

Certify

Engage an accredited certification body, pass the stage 1 documentation review and the stage 2 audit, and maintain surveillance.