NIST AI RMF vs ISO 42001
Both are voluntary, and only ISO/IEC 42001 is certifiable. The NIST AI RMF 1.0 is a US-origin risk framework, non-sector-specific and use-case agnostic, organised in four functions: Govern, Map, Measure and Manage. ISO/IEC 42001 is the international AI management-system standard; certification bodies audit organisations against it, with their own competence set by ISO/IEC 42006.
At a glance
The two instruments side by side, as the Body of Knowledge states them. Each cell names the primary source it rests on; the last row links the chapter sections each line comes from.
| Attribute | NIST AI RMF | ISO/IEC 42001 |
|---|---|---|
| Type | Framework: NIST AI Risk Management Framework 1.0 (NIST AI 100-1). Its companion Generative AI Profile (NIST AI 600-1, 2024) is not mapped on these pages. Sources: NIST AI 100-1, NIST AI 600-1 | Standard: ISO/IEC 42001:2023, the AI management-system (AIMS) standard Source: ISO/IEC 42001:2023 |
| Issuer | NIST (United States) Source: NIST AI 100-1 | ISO/IEC (JTC 1/SC 42) Source: ISO/IEC 42001:2023 |
| Legal force | Voluntary and US-origin. It describes itself as voluntary, rights-preserving, non-sector-specific and use-case agnostic. Source: NIST AI 100-1 | Voluntary. It is a management-system standard, not the Article 17 QMS, and its European adoption confers no presumption of conformity with the AI Act. Sources: ISO/IEC 42001:2023, AI Act Art. 17, AI Act Art. 40 |
| Scope and reach | Any organisation, in any sector and for any use case. GOVERN applies across the whole process; MAP, MEASURE and MANAGE apply per system and per lifecycle stage. Source: NIST AI 100-1 | Any organisation that develops, provides or uses AI. It specifies requirements for establishing, implementing, maintaining and continually improving an AI management system. Source: ISO/IEC 42001:2023 |
| Certifiable | No. There is no certification scheme for it: NIST AI 100-1 presents the RMF as voluntary guidance. Source: NIST AI 100-1 | Yes. Certification bodies audit organisations against it; ISO/IEC 42006:2025 sets their additional requirements on top of ISO/IEC 17021-1. The certificate evidences a management system; it does not make a system compliant. Source: ISO/IEC 42006:2025 |
| Key artefacts | Four functions (Govern, Map, Measure, Manage) in 19 categories and their subcategories, used as control metadata; a current and a target profile, with the gap between them as the action plan. Source: NIST AI 100-1 | Clauses 4 to 10 in the Harmonized Structure: AI policy, roles, AI risk assessment (6.1.2), risk treatment (6.1.3) and system impact assessment (6.1.4), internal audit, management review. Annex A control objectives in nine areas (A.2 to A.10), justified in a Statement of Applicability. Source: ISO/IEC 42001:2023 |
| Dates | 1.0 published 2023-01-26; there is no 2.0. A formal review was foreseen by 2028, and as of 2026-09-24 NIST states that 1.0 is being revised, with no revised version published. Sources: NIST AI 100-1, NIST: AI Risk Management Framework | Published 2023. No application date: it applies to an organisation from the day it adopts the standard. Source: ISO/IEC 42001:2023 |
| In the Body of Knowledge |
Where they overlap, topic by topic
The crosswalk maps 25 AI governance topics. Both instruments file clauses under 20 of them, 11 strongly (a core clause on each side). 2 topics have a core clause only in the NIST AI RMF and 0 only in ISO 42001; 1 more is touched by one side only in passing (a related clause, not a core one); 2 are reached by neither. A shared topic means the two deal with the same thing, not that meeting one meets the other.
Strong: both file a core clause. Partial: both file a clause, at least one only in passing. Only, in passing: one side files a related clause and the other none. Clause ids link to their page in the obligation register where one exists. The last column names a pattern only where it serves a core clause on both sides: the crosswalk row's register entry lists it and the pattern's own "Maps to" line names that clause. Otherwise the cell is empty.
| Topic | What NIST AI RMF asks for | What ISO 42001 asks for | Overlap | Patterns for both |
|---|---|---|---|---|
| Risk management |
|
| Strong | |
| Governance and accountability |
|
| Strong | |
| Impact assessment |
| Strong | ||
| Data governance |
| Partial | ||
| Documentation and transparency |
| Partial | ||
| Inventory and registration |
|
| Strong | |
| Logging and traceability | Partial | |||
| Human oversight |
|
| Strong | |
| Runtime guardrails |
| Strong | ||
| Robustness, security and evaluations |
|
| Strong | |
| Incident response and monitoring |
|
| Strong | |
| Supply chain and third parties |
|
| Strong | |
| Prohibited practices |
|
| Partial | |
| Fairness and non-discrimination |
|
| Partial | |
| Privacy and data protection |
|
| Partial | |
| Explainability and right to explanation |
|
| Partial | |
| AI literacy and competence |
|
| Strong | |
| Conformity assessment and certification |
|
| Partial | |
| IP and copyright |
| Not mapped | NIST AI RMF only | |
| Agent identity and autonomy |
| Not mapped | NIST AI RMF only, in passing | |
| Sandboxes and real-world testing |
|
| Partial | |
| Environmental impact |
| Not mapped | NIST AI RMF only | |
| Deployment, change and decommissioning |
| Strong |
Can the NIST AI RMF help you certify to ISO/IEC 42001?
Partly. NIST itself hosts a crosswalk from the AI RMF to ISO/IEC 42001. But certification needs the management system itself, clauses 4 to 10 and a Statement of Applicability over the Annex A controls, which the RMF does not ask for. Its category and subcategory identifiers still serve as control metadata inside the AIMS.
Which should you start with?
Start with the NIST AI RMF to organise risk work: it is voluntary, non-sector-specific, and its four functions and 19 categories give you identifiers to tag controls with. Move to ISO/IEC 42001 when you need a certificate as proof of a working management system; the same identifiers then feed its Statement of Applicability.
Next step
Put the comparison to work on your own systems, in the browser.
Frequently asked questions
Is there an official crosswalk between the NIST AI RMF and ISO 42001?
NIST's AI Resource Center hosts crosswalks from the RMF to other frameworks, including ISO/IEC 42001, and dated 14 August 2025 a revised ISO/IEC 23894 crosswalk and a new ISO/IEC 42005 one. They are a sound starting point for a crosswalk file, not a substitute for mapping your own controls.
Source: NIST AIRC: crosswalks
Is there a NIST AI RMF 2.0?
No. AI RMF 1.0 (NIST AI 100-1, 26 January 2023) remains the citable text. As of 2026-09-24 NIST's framework page states that 1.0 is being revised as part of the White House AI Action Plan, but no revised version is published. Pin the version in control metadata.
How do ISO/IEC 23894 and ISO 42001 relate to the NIST AI RMF?
ISO/IEC 23894 applies ISO 31000 risk management to AI; ISO/IEC 42001 is the certifiable management-system standard whose risk clauses (6.1.2 to 6.1.4, operated in 8.2 to 8.4) require the risk loop to exist and run. NIST's crosswalk shows that its functions and the 23894 clauses describe one process.
Sources: ISO/IEC 23894:2023, ISO/IEC 42001:2023, NIST AIRC: crosswalks
What does the NIST AI RMF cover that ISO 42001 does not?
In this crosswalk, 2 of the 25 topics have a core NIST AI RMF clause and no ISO 42001 clause mapped: IP and copyright; Environmental impact. Agent identity and autonomy is touched only in passing: the NIST AI RMF files a related clause there, not a core one, and ISO 42001 none. A topic with no ISO 42001 clause here is one this mapping does not reach, not one ISO 42001 is shown to leave out. The overlap table on this page lists the clauses; mappings are illustrative, not a claim of conformity.
Both instruments sit inside a wider field: AI governance, explained, from the laws and standards to the engineering practice.
Sources
- NIST AI RMF: https://www.nist.gov/itl/ai-risk-management-framework
- NIST AI RMF: https://airc.nist.gov/airmf-resources/airmf/
- ISO/IEC 42001: https://www.iso.org/standard/42001
- NIST AI 100-1: https://doi.org/10.6028/NIST.AI.100-1
- NIST AI 600-1: https://doi.org/10.6028/NIST.AI.600-1
- Regulation (EU) 2024/1689, consolidated text: https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng
- ISO/IEC 42006:2025: https://www.iso.org/standard/44546.html
- NIST AIRC: crosswalks: https://airc.nist.gov/airmf-resources/crosswalks/
- ISO/IEC 23894:2023: https://www.iso.org/standard/77304.html
Every clause on this page, with its note and verification status, is in the topic × framework crosswalk and its JSON download.
Other comparisons: ISO 42001 vs EU AI Act · NIST AI RMF vs EU AI Act