NIST AI RMF, ISO/IEC 42001 and the OECD AI Principles: how they compare
The NIST AI RMF, ISO/IEC 42001, and the OECD AI Principles are complementary, not competing: a voluntary risk-management process, a certifiable management system, and a values baseline. None replaces the EU AI Act's legal obligations; they help you operationalize them.
The EU AI ActEU AI ActRegulation (EU) 2024/1689, the European Union's law on artificial intelligence. It takes a risk-based approach: prohibited practices, requirements for high-risk AI systems, transparency obligations for specific uses, and a separate regime for general-purpose AI models. Obligations are divided between providers and deployers. See general-purpose AI, conformity assessment.Open full entry → obliges deployersdeployerAn organization using an AI system under its own authority in its activities. It carries the operator duties: use per instructions, oversight, input relevance, monitoring, notices.Open full entry → of high-risk AI systemshigh-risk AI systemAn AI system that falls under the EU AI Act's strictest requirements, following Article 6. There are two routes in: a system that is a product or safety component covered by the Union harmonization legislation in Annex I and subject to third-party conformity assessment, or a system used in one of the areas listed in Annex III, such as employment, education, or access to essential services. Article 6(3) contains a filter: an Annex III system is not high-risk if it does not pose a significant risk of harm to health, safety, or fundamental rights, although a system that profiles natural persons is always high-risk. See EU AI Act, Annex III, conformity assessment.Open full entry → to demonstrable governancegovernanceThe system through which an organization steers itself: corporate governance, risk management, compliance, lines of accountability, risk appetite, and the operating model. It exists across everything the organization does, before and beyond AI. AI governance is this same system extended for AI. See AI governance, governance design, execution level.Open full entry →, but the law does not prescribe how you organize that governance. That is a deliberate choice by the European legislator: room for international standards and existing management frameworks. In practice, that space leads to a recurring question: which framework do you choose as your foundation?
This article compares the three most widely used international AI governance frameworks, NIST AI RMFNIST AI RMFThe AI Risk Management Framework of the US National Institute of Standards and Technology, published as version 1.0 in 2023. It is a voluntary framework built around four functions: govern, map, measure, and manage. In a layered setup, it serves as the risk method inside a management system such as ISO/IEC 42001. See ISO/IEC 42001, ISO/IEC 23894.Open full entry →, ISO 42001 and the OECD AI PrinciplesOECD AI PrinciplesThe intergovernmental principles for trustworthy AI adopted by the OECD in 2019 and updated in 2024. They set value-based expectations such as transparency, accountability, and human-centered values, and have shaped later frameworks and legislation. See responsible AI.Open full entry →, and explains how each relates to the concrete obligations of the EU AI Act. No abstract principlesprincipleOne of the seven responsible-AI values a governed system should live up to (fairness, safety and reliability, privacy, security and robustness, transparency and explainability, accountability, human oversight). A principle is abstract: it states an outcome, not a lever you can pull. It becomes governable by naming the harm that would breach it, assessing the risk that harm carries, and placing controls against that risk. Held this way, a principle becomes a pillar. See pillar, harm, risk.Open full entry →, but a practical analysis for the compliance professional who must make a choice today.
Why frameworks are necessary at all
The EU AI Act is legislation: it defines obligations, prohibitions and sanctions. What it does not provide is a working method. How do you inventory AI systemsAI systemA machine-based system that, for explicit or implicit objectives, infers from input how to generate outputs (predictions, content, recommendations or decisions) that can influence physical or virtual environments. The OECD-style definition followed by the EU AI Act.Open full entry →? How do you weigh risksriskIn the EU AI Act's terms, the combination of the likelihood that a harm occurs and the severity of it if it does. The link between a principle (via the harm that would breach it) and a control (the measure that reduces it). Naming the harm and assessing its risk is required by Art. 9 before any mitigation measure is chosen. See harm, control, residual risk.Open full entry →? How do you embed oversight in the practice of your organization? That is precisely what governance frameworks provide, a structured method for moving from legal obligation to demonstrable practice.
A second reason is robustnessrobustnessA system's ability to perform reliably under realistic conditions including noise, edge cases and adversarial pressure, the engineering core of the safety-and-reliability principle.Open full entry →. Organizations that structure governance solely on the basis of statutory text build a compliance structure that is vulnerable to changes in interpretation, case law and legislative amendments. Frameworks are broader, deeper and, in the case of ISO 42001, internationally audited and certified. They offer a foundation that is more than the minimum legal requirement.
Framework 1: NIST AI Risk Management Framework (AI RMF)
The NIST AI RMF, published by the American National Institute of Standards and Technology, is built around four functions that form a cyclical process: Govern, Map, Measure and Manage. The framework is not prescriptive, it does not dictate which specific measures you must take, but provides a structured language and method for identifying, quantifying and managing AI risks.
The four functions in practice
- Govern, Establish the organizational context: who is responsible for AI risk management, which values and risk appetiterisk appetiteThe level of risk an organization's leadership is willing to accept in pursuit of its objectives, set at the governance design level. It is the benchmark against which residual risk is judged acceptable or not, inherited from the organization's broader governance and applied to AI. A concept from enterprise risk management (COSO ERM) before it is an AI one. See residual risk, governance design.Open full entry → does your organization maintain, how is oversight arranged?
- Map, Identify and categorize AI systems and their risks. Which systems does your organization deploy, for what purpose, and what risks do they carry for those affected?
- Measure, Quantify and prioritize identified risks. This includes performing impact assessmentsimpact assessmentA structured evaluation, carried out in the plan-and-design stage, of the harms an AI system could cause and the risk those harms carry, before the system is built. The first place the governance chain is run, and the cheapest point in the life cycle to reduce risk. The anchor artifact of the planning stage; under the EU AI Act, a fundamental-rights impact assessment is required for certain high-risk deployers. See harm, risk, life cycle.Open full entry →, biasbiasA systematic skew in data, model behavior, or outcomes that treats one group differently from another without justification. Bias usually enters through training data that reflects historical patterns. For high-risk AI systems, Article 10 of the EU AI Act requires examination of datasets for possible biases and measures to detect, prevent, and mitigate them. See fairness, proxy discrimination.Open full entry → analyses and reliability tests.
- Manage, Implement measures, monitor operation and document decisions. This is the operational domain: incident response, oversight processes, periodic reviews.
Alignment with the EU AI Act
NIST AI RMF aligns well with the systematics of Art. 9 EU AI Act (risk management system) and Art. 26 (deployer obligations). The 'Map' function corresponds to the required inventory and classification; 'Manage' covers the monitoring and oversight obligations of Art. 26.5. However, the framework offers no certification pathway, it is a methodology, not a standard that is audited.
Suitable for whom
NIST AI RMF is particularly suitable for organizations that want to structure governance from an IT or security background, for organizations already working with the NIST Cybersecurity Framework (the approach is closely related), and for teams looking for a pragmatic, stepwise method without certification ambition.
Framework 2: ISO/IEC 42001, AI management system
ISO 42001 is the international management standard for artificial intelligence, published in December 2023. It is the AI equivalent of ISO 27001 (information security) and ISO 9001 (quality management), and like those standards, it leads to a certifiable AI Management SystemAI management systemThe organizational structure, policies and processes for governing AI across its life cycle, as formalized in ISO/IEC 42001.Open full entry → (AIMS). The structure follows the High Level Structure (HLS) shared by all ISO management systems, which simplifies integration with existing ISO certifications.
Core requirements
ISO 42001 requires organizations to establish, implement, maintain and continually improve a documented AIMS. This includes:
- An AI policy established by management;
- A system for identifying and assessing AI-related risks and opportunities;
- Documented objectives and measurable indicators;
- Internal auditsinternal auditThe third line of defense: independent assurance that AI assessments, controls and documentation actually operate, reporting to the board, never to the builders.Open full entry → and management reviews;
- Corrective actions in response to deviations.
Alignment with the EU AI Act
ISO 42001 is the framework with the strongest direct alignment with the EU AI Act. Art. 17 of the AI Act, which mandates a quality management system for providersproviderThe actor who develops an AI system (or has it developed) and places it on the market or into service under its own name. It carries manufacturer-style duties: design controls, documentation, conformity.Open full entry → of high-risk AI, is closely aligned in content with the AIMS requirements of ISO 42001. For deployers, an ISO 42001 certification provides a powerful means of evidenceevidenceThe concrete proof that a control is designed, implemented, and working: a test report, an audit trail, an impact assessment, a monitoring log. Each link in the governance chain produces an artifact, and together they are what an organization hands to its own board, a regulator, a customer, or an affected person to show, not say, that a system is governed. Its absence is itself the failure: a risk register without test results, or a mitigation claimed without validation, is a governance gap, not a paperwork one. The closing link of the governance chain. See control, governance.Open full entry → for the supervisory authority: it demonstrates not only that you have a system, but that an independent auditor has assessed and approved that system.
Suitable for whom
ISO 42001 is suitable for organizations with a serious certification ambition, for organizations that have already implemented ISO 27001 or ISO 9001 (HLS integration significantly reduces the implementation burden), and for organizations where clients or contracting authorities require a demonstrable management framework. The implementation burden is substantial, plan a minimum of six to twelve months for a full implementation including gap analysis, documentation and internal audit cycle.
Framework 3: OECD principles on artificial intelligence
The OECD AI Principles, first established in 2019 and updated since, are five principles at policy level: inclusive growth and wellbeing, human-centered values and fairnessfairnessThe responsible-AI principle that systems should not create or reinforce unjust discrimination; operationalized through bias testing, representative data and per-group thresholds. It has multiple, mutually incompatible mathematical definitions. Under the EU AI Act, providers of high-risk AI systems must examine their data sets for possible biases (Article 10), and several discriminatory uses are prohibited outright (Article 5). See bias, proxy discrimination, high-risk AI system, responsible AI.Open full entry →, transparency and explainabilitytransparency and explainabilityThe principle that people can know an AI system is involved and can be told why it produced a given outcome. The failure is concrete rather than abstract: it arrives on the day a customer, a supervisor, or a court asks for the reasoning, and "the model decided" turns out to be the absence of an explanation rather than one. The EU AI Act separates the two directions: Article 13 requires high-risk systems to be transparent enough for the deployer to interpret and use their output, and Article 50 requires people to be informed when they interact with AI or receive AI-generated content. See model card, responsible AI.Open full entry →, robustness and safety, and accountabilityaccountabilityThe principle that a named human or organization answers for an AI system's outcomes, through ownership, documentation, audit trails and redress; never the system itself. The EU AI Act attaches obligations to the role rather than the technology, with provider duties in Article 16 and deployer duties in Article 26, supported by technical documentation (Article 11) and record-keeping (Article 12). See provider, deployer, record-keeping, responsible AI.Open full entry →. The OECD Principles are not an implementation framework, they provide no processes, controlcontrolThe concrete, testable measure that reduces a specific risk, and through that risk protects the principle behind it. Also called a risk management measure, risk response, or risk treatment. Always traceable to the risk it addresses: under EU AI Act Art. 9 every control must map back to a specific risk, and controls recorded separately from their risks is a recognized compliance failure. It works in one of three types: preventive, detective, or corrective. See risk, control types, evidence.Open full entry → points or documentation requirements.
Alignment with the EU AI Act
The EU AI Act is substantially influenced in content by the OECD Principles: the principles can be found in the recitals of the law. For compliance purposes, however, the OECD Principles are a starting point, not an endpoint. They help in formulating AI policy at board level and in articulating your organization's values around AI, but they do not in themselves produce demonstrable compliance with concrete legal obligations.
Suitable for whom
The OECD Principles are suitable as a policy compass for boards and management, as a basis for an organization-wide AI ethics policy, and as a supplement to one of the other frameworks, not as a standalone compliance approach. Those who rely solely on the OECD Principles for EU AI Act compliance have a gap in practical implementation.
Comparison matrix: three frameworks side by side
| Criterion | NIST AI RMF | ISO 42001 | OECD Principles |
|---|---|---|---|
| Type | Methodology | Management standard (certifiable) | Policy principles |
| Certification | No | Yes (independent audit) | No |
| EU AI Act alignment | Good (Art. 9, Art. 26) | Strong (Art. 17, Art. 26) | Indirect (recitals) |
| Implementation burden | Medium | High | Low |
| Suitable for SMEs | Yes | Limited (unless already ISO-certified) | Yes (as supplement) |
| Audit evidence for supervisor | Indirect | Strong (third-party certificate) | Weak |
How does this relate to your EU AI Act obligations?
A widely held misconception is that one framework replaces the EU AI Act. It does not. The AI Act is legislation with legally enforceable obligations; frameworks are methodologies that help fulfill those obligations in practice. The relationship is complementary, not substitutable.
Concretely: Art. 9 requires a risk management system for high-risk AI, and compliance with it rests on the provider (Art. 16(a)). As a deployer your obligations sit in Art. 26, which call for a risk-based approachrisk-based approachRegulating or governing AI in proportion to the risk of the use case rather than the technology itself, the organizing principle of the EU AI Act and most frameworks.Open full entry → but are a distinct set of duties from the Art. 9 system itself. NIST AI RMF and ISO 42001 both offer a methodology for setting up that system, but you still need to determine the specific risk class per system (Art. 6), retain the correct documents (Art. 26.6), and report incidents (Art. 73). No framework replaces those specific obligations.
The smartest approach for most deployers is a combination: ISO 42001 as management framework for the governance structure, supplemented by the NIST AI RMF methodology for operational risk analysis per system, and the EU AI Act as legal assessment framework determining which obligations are concretely applicable.
Own framework: when is it useful?
Some organizations choose their own, tailored governance framework, a combination of elements from existing standards, supplemented by sector-specific requirements. This is a legitimate approach, but requires more internal expertise and is harder to communicate to external supervisory authorities. An own framework offers no certification pathway and requires you to demonstrate at an audit that your approach is equivalent to the legal requirements.
For organizations in heavily regulated sectors, financial services, healthcare, government, a standardized framework is preferable due to its recognizability with sector supervisory authorities (DNB, NZa, ACM).
Practical recommendations by organization type
Starting compliance teams (0–6 months)
Start with the NIST AI RMF as a methodological compass. The four functions (Govern, Map, Measure, Manage) provide structure without certification pressure. Use the 'Map' phase to build a complete AI register; use 'Govern' to assign ownership and responsibilities. Document everything, every decision, every review.
Organizations with ISO certification (e.g. 27001 or 9001)
Add ISO 42001 as an extension to your existing management system. The High Level Structure makes integration relatively straightforward. Plan a gap analysis as the first step: which elements of ISO 42001 does your current management system already cover, and where are the gaps?
Organizations with certification ambition
Choose ISO 42001 as the primary standard and plan the implementation in two phases: internal implementation and first internal audit (phase 1), followed by certification audit by an accredited body (phase 2). Reserve sufficient budget and time, a full ISO 42001 implementation typically takes six to twelve months.
Boards and management
The OECD Principles offer an accessible framework for placing AI governanceAI governanceGovernance extended for AI: the same organizational steering at the highest level, widened to cover what makes AI different (it works in probabilities rather than fixed rules, learns from data, and can act at a speed and scale no human reviewer can match). It inherits the existing governance structure and brings AI inside the disciplines the organization already runs, rather than creating a parallel system in a silo. It operates on two levels, design and execution. See governance, governance design, execution level, responsible AI.Open full entry → on the agenda at board level. Combine them with a concrete implementation approach (NIST or ISO 42001) and ensure a clear mandate for the internal AI Officer or Governance Professional.
Conclusion: choose deliberately, document your choice
There is no universally 'best' framework, the right choice depends on the size of your organization, your existing governance structures, your sector regulatory context and your certification ambitions. What does apply universally: make a deliberate choice and document why you chose that framework. A supervisory authority reviewing your dossier wants to see not only what you have done, but also why you chose that approach and how that approach demonstrably works in the practice of your organization.
The EU AI Act makes room for international standards and own management frameworks. Use that space, but fill it with the disciplined structure that only a deliberately chosen framework can provide.