Guide

AI Governance Guide: EU AI Act vs ISO 42001 vs NIST AI RMF

Three frameworks, three purposes — a binding law, a certifiable management-system standard and a voluntary US framework. Here's what each one actually covers, how they compare side by side, and a practical roadmap to build AI governance starting from zero.

General information, not legal advice. Regulatory dates and thresholds evolve — verify current obligations with official EU, ISO and NIST sources and, where the AI Act may apply to you, consult qualified legal counsel before relying on anything here.

If you're building an AI governance program, you'll run into the same three names almost immediately: the EU AI Act, ISO/IEC 42001 and the NIST AI RMF. They get talked about interchangeably, but they are not the same kind of thing. One is a binding law with fines attached. One is a certifiable management-system standard, structured like the ISO standards many organizations already know. One is voluntary US guidance with no certification at all. This guide explains what each actually requires, compares them side by side, and lays out a step-by-step roadmap for standing up AI governance when you're starting from nothing.

The one-line difference

EU AI Act (Regulation (EU) 2024/1689) — the risk-tiered law

The EU AI Act is the world's first comprehensive, horizontal AI law. Rather than regulating AI as a single category, it sorts AI systems into risk tiers and attaches obligations that scale with the risk:

The Act's obligations are being phased in over time rather than applying all at once. Broadly speaking: the prohibited-practices provisions were the first to take effect, from around February 2025; GPAI model obligations followed from around August 2025; the bulk of high-risk system obligations are generally understood to apply from around August 2026; and obligations for high-risk AI that is embedded in already-regulated products (such as certain machinery or medical devices) follow later still, broadly around August 2027. Treat these as general, approximate milestones rather than exact legal dates for your situation — the Act includes transitional provisions and sector-specific nuances, so confirm the precise timeline that applies to your systems against the official text or with counsel.

Crucially, the AI Act has extraterritorial reach: it can apply to providers and deployers outside the EU whenever an AI system is placed on the EU market or its output is used within the EU. "We're not an EU company" does not automatically mean "out of scope."

ISO/IEC 42001:2023 — the certifiable AI management system

ISO/IEC 42001 is the first international standard for an AI Management System (AIMS). It doesn't tell you which AI risk tier you're in — it tells you how to run the governance program around your AI systems, using the same Harmonized Structure as ISO 9001 (quality) and ISO 27001 (information security): a Plan-Do-Check-Act cycle across clauses 4 through 10 — context of the organization, leadership, planning, support, operation, performance evaluation and improvement.

On top of that shared skeleton, ISO 42001 adds an AI-specific Annex A control set covering things like AI policy, roles and responsibilities, resources for AI systems, AI system impact assessment, data quality, third-party and supplier management for AI, and incident response for AI-related issues — the same "clause body + Annex A controls" pattern that ISO 27001 uses for information security.

Because it shares its structure with ISO 9001 and ISO 27001, an organization that already runs one of those systems can extend its existing document control, internal audit and management-review processes to cover AI rather than starting over. And because it's certifiable by an accredited certification body, ISO 42001 gives you something the AI Act and NIST AI RMF don't: a third-party badge you can show customers, regulators and partners as objective evidence that your AI governance program actually works.

NIST AI RMF 1.0 — the voluntary US risk framework

The NIST AI RMF 1.0, published by the U.S. National Institute of Standards and Technology, is voluntary guidance, not law and not a certifiable standard — there is no NIST AI RMF certificate to earn. What it offers instead is a clear, practical way to think about AI risk, organized around four core functions:

Despite being voluntary, the NIST AI RMF is widely referenced — including by companies outside the US — because it is well-structured, sector-agnostic and pairs with a practical Playbook and a Generative AI Profile. Many organizations use it as the "how do we think about this" layer underneath a more formal system like ISO 42001, or as their primary framework when neither EU AI Act scope nor certification is a priority.

Side-by-side comparison

 EU AI ActISO/IEC 42001:2023NIST AI RMF 1.0
What it isBinding EU regulation (2024/1689)International management-system standardVoluntary US framework / guidance
Scope / jurisdictionEU market; extraterritorial reach to non-EU providers & deployers affecting the EUGlobal — any organization, any sectorPrimarily US-oriented, used globally as best-practice guidance
Mandatory or voluntaryMandatory for in-scope systems, with fines for non-complianceVoluntary to adopt or certifyVoluntary; no general legal mandate
CertifiableNo certificate — conformity assessment for high-risk systems insteadYes — accredited third-party certificationNo — self-assessment / attestation only
Core structureRisk tiers: prohibited / high-risk / GPAI / limited / minimalClauses 4–10 (PDCA) + AI-specific Annex A controls4 functions: Govern, Map, Measure, Manage
Key requirementsRisk management, data governance, technical documentation, human oversight, transparency, conformity assessment for high-risk systemsDocumented AIMS, leadership commitment, AI risk assessment, resource & supplier controls, internal audit, management review, continual improvementStructured risk identification, measurement and mitigation across the AI lifecycle; organizational accountability
TimelinePhased entry into force, roughly Feb 2025 → Aug 2027 by obligation type (see above)Available now; certification timeline depends on your audit cyclePublished 2023; adopt at your own pace

A roadmap for starting from zero

If your organization has no formal AI governance today, these five steps roughly reflect the order that works in practice:

  1. Step 1 — Inventory your AI systems. You can't govern what you haven't found. Build a register of every AI system, model and AI-powered vendor tool in use — including the ones individual teams adopted without IT or compliance ever signing off. Capture purpose, data used, deployment context and who owns it.
  2. Step 2 — Classify EU AI Act risk tier, if you operate in or serve the EU. For every system on your inventory, work out whether the AI Act applies at all, and if so, which risk tier (prohibited, high-risk, GPAI, limited or minimal) it falls into. This determines your legal obligations and their deadlines.
  3. Step 3 — Stand up an AI governance policy and AIMS foundations. Even before pursuing ISO 42001 certification, adopt its structure: a short AI policy, a named accountable owner, defined roles, and an initial AI risk assessment aligned to clauses 4–6. This gives you a documented foundation that both regulators and auditors recognize.
  4. Step 4 — Run a NIST AI RMF risk assessment. Use the Govern / Map / Measure / Manage functions to systematically assess risk across your inventoried systems — this is a practical way to turn Step 1's inventory into a prioritized action list, independent of whether any given system is EU AI Act in-scope.
  5. Step 5 — Put ongoing monitoring in place. AI governance isn't a one-time project. Schedule periodic re-assessment as models change and new systems are adopted, define an AI incident-response process, track regulatory updates (new EU guidance, NIST updates), and report status to leadership — the same "Check-Act" discipline ISO management systems already require.

Put it into practice — free AI governance tools

These free, no-signup tools run in your browser and map directly onto the frameworks above:

Frequently asked questions

What's the actual difference between the EU AI Act, ISO 42001 and NIST AI RMF?
The EU AI Act is binding law that classifies AI systems by risk and sets mandatory obligations, mainly in and around the EU market. ISO 42001 is a certifiable management-system standard for how you run AI governance, without setting legal risk tiers itself. NIST AI RMF is voluntary US guidance organized around four functions, with no certification. The AI Act is what you're legally required to do; ISO 42001 is a certifiable system for organizing how you do it; NIST AI RMF is a widely referenced way to think about and manage AI risk.

Is the EU AI Act mandatory if my company isn't based in the EU?
Often yes. Like the GDPR, the Act has extraterritorial reach — it can apply to providers and deployers placing AI systems on the EU market or whose output is used in the EU, regardless of where they're established. Any company with EU customers, users or operations should run a scope assessment rather than assume it doesn't apply.

Can ISO 42001 be certified, and is it legally required?
Yes, it's certifiable by an accredited certification body, similar to ISO 27001 or ISO 9001. Certification is not a legal requirement under any current law — organizations pursue it voluntarily to demonstrate governance maturity, and because a working AIMS makes EU AI Act compliance considerably easier to evidence.

Is the NIST AI RMF mandatory for US companies?
No. It's voluntary guidance from NIST with no general federal mandate for private organizations. It's increasingly referenced in federal agency guidance and procurement, and many organizations adopt it as a practical baseline even without a legal requirement.

Do we need all three, or can we just pick one?
Most organizations end up using more than one — they serve different purposes and overlap. EU AI Act compliance isn't optional if it legally applies to you. ISO 42001 and NIST AI RMF are voluntary but complementary: many organizations use NIST AI RMF's four functions to structure risk thinking and ISO 42001 to build a certifiable system, with the AI Act's risk classification layered on top wherever it applies.

What are the EU AI Act's risk tiers?
Unacceptable-risk practices are prohibited outright. High-risk systems (employment, credit scoring, critical infrastructure, law enforcement, etc.) face the strictest obligations — risk management, data governance, technical documentation, human oversight, conformity assessment. Limited-risk systems mainly carry transparency duties. Minimal-risk systems have no extra obligations. General-purpose AI (GPAI) models are regulated separately, with added systemic-risk duties for the most capable models.

How does ISO 42001 relate to ISO 27001 or ISO 9001?
It shares ISO's Harmonized Structure — the same clause 4–10 skeleton used by ISO 9001 and ISO 27001. An organization already certified to one of those can extend its existing document control, internal audit and management-review processes to cover AI, adding the AI-specific Annex A controls and AI risk assessment (clause 6) rather than building a separate system from scratch.

Where should an organization with zero AI governance start?
Start with an honest inventory of every AI system in use, including tools individual teams adopted on their own. If you operate in or serve the EU, classify each system's AI Act risk tier. In parallel, stand up baseline AI governance — a short policy, a named owner, an initial risk assessment — following the ISO 42001 clause structure even before pursuing certification, then run a NIST AI RMF risk assessment and put ongoing monitoring in place.

General information, not legal advice. AMAADOR Workshop is an independent EHS & compliance resource, not a law firm, and does not provide legal opinions on AI Act scope or classification. Regulatory dates, thresholds and requirements evolve — verify current obligations directly against the official EU AI Act text, ISO/IEC 42001:2023 and NIST AI RMF 1.0 publications, and consult qualified legal counsel for your specific situation.

← Back to home · Open the AI Governance toolkit →