---
title: "NIST AI RMF vs ISO 42001: differences, overlap and mapping"
description: "NIST AI RMF vs ISO/IEC 42001: a voluntary framework and a certifiable standard, compared on scope and artefacts, with a topic-by-topic clause mapping."
canonical: https://aigovernanceengineer.com/resources/crosswalk/nist-ai-rmf-vs-iso-42001
author: "Jorge García Aibar"
license: "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)"
doi: https://doi.org/10.5281/zenodo.22956197
version: "0.5.0"
updated: 2026-09-27
---

# NIST AI RMF vs ISO 42001: differences, overlap and mapping

> Both are voluntary, and only ISO/IEC 42001 is certifiable. The NIST AI RMF 1.0 is a US-origin risk framework, non-sector-specific and use-case agnostic, organised in four functions: Govern, Map, Measure and Manage. ISO/IEC 42001 is the international AI management-system standard; certification bodies audit organisations against it, with their own competence set by ISO/IEC 42006.

**In short**

The NIST AI RMF and ISO/IEC 42001 are both voluntary, and only ISO/IEC 42001 is certifiable. The NIST AI RMF 1.0 (NIST AI 100-1, 26 January 2023) is a US-origin risk framework, non-sector-specific and use-case agnostic, organised in four functions (Govern, Map, Measure and Manage) and 19 categories. There is no 2.0; NIST states that 1.0 is being revised. ISO/IEC 42001 is the international AI management-system standard: certification bodies audit organisations against clauses 4 to 10 and a Statement of Applicability over the Annex A controls, under ISO/IEC 42006. NIST hosts a crosswalk from the RMF to ISO/IEC 42001, and in this crosswalk both file clauses under 20 of 25 topics, 11 of them strongly. A common route is to organise risk work with the RMF, tag controls with its category and subcategory identifiers, and move to ISO/IEC 42001 when a certificate is needed as proof of a working management system.

## At a glance

The two instruments side by side, as the Body of Knowledge states them, each cell with the primary source it rests on.

| Attribute | NIST AI RMF | ISO/IEC 42001 |
|---|---|---|
| Type | Framework: NIST AI Risk Management Framework 1.0 (NIST AI 100-1). Its companion Generative AI Profile (NIST AI 600-1, 2024) is not mapped on these pages. (Sources: [NIST AI 100-1](https://doi.org/10.6028/NIST.AI.100-1), [NIST AI 600-1](https://doi.org/10.6028/NIST.AI.600-1)) | Standard: ISO/IEC 42001:2023, the AI management-system (AIMS) standard (Source: [ISO/IEC 42001:2023](https://www.iso.org/standard/42001)) |
| Issuer | NIST (United States) (Source: [NIST AI 100-1](https://doi.org/10.6028/NIST.AI.100-1)) | ISO/IEC (JTC 1/SC 42) (Source: [ISO/IEC 42001:2023](https://www.iso.org/standard/42001)) |
| Legal force | Voluntary and US-origin. It describes itself as voluntary, rights-preserving, non-sector-specific and use-case agnostic. (Source: [NIST AI 100-1](https://doi.org/10.6028/NIST.AI.100-1)) | Voluntary. It is a management-system standard, not the Article 17 QMS, and its European adoption confers no presumption of conformity with the AI Act. (Sources: [ISO/IEC 42001:2023](https://www.iso.org/standard/42001), [AI Act Art. 17](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_17), [AI Act Art. 40](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_40)) |
| Scope and reach | Any organisation, in any sector and for any use case. GOVERN applies across the whole process; MAP, MEASURE and MANAGE apply per system and per lifecycle stage. (Source: [NIST AI 100-1](https://doi.org/10.6028/NIST.AI.100-1)) | Any organisation that develops, provides or uses AI. It specifies requirements for establishing, implementing, maintaining and continually improving an AI management system. (Source: [ISO/IEC 42001:2023](https://www.iso.org/standard/42001)) |
| Certifiable | No. There is no certification scheme for it: NIST AI 100-1 presents the RMF as voluntary guidance. (Source: [NIST AI 100-1](https://doi.org/10.6028/NIST.AI.100-1)) | Yes. Certification bodies audit organisations against it; ISO/IEC 42006:2025 sets their additional requirements on top of ISO/IEC 17021-1. The certificate evidences a management system; it does not make a system compliant. (Source: [ISO/IEC 42006:2025](https://www.iso.org/standard/44546.html)) |
| Key artefacts | Four functions (Govern, Map, Measure, Manage) in 19 categories and their subcategories, used as control metadata; a current and a target profile, with the gap between them as the action plan. (Source: [NIST AI 100-1](https://doi.org/10.6028/NIST.AI.100-1)) | Clauses 4 to 10 in the Harmonized Structure: AI policy, roles, AI risk assessment (6.1.2), risk treatment (6.1.3) and system impact assessment (6.1.4), internal audit, management review. Annex A control objectives in nine areas (A.2 to A.10), justified in a Statement of Applicability. (Source: [ISO/IEC 42001:2023](https://www.iso.org/standard/42001)) |
| Dates | 1.0 published 2023-01-26; there is no 2.0. A formal review was foreseen by 2028, and as of 2026-09-24 NIST states that 1.0 is being revised, with no revised version published. (Sources: [NIST AI 100-1](https://doi.org/10.6028/NIST.AI.100-1), [NIST: AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework)) | Published 2023. No application date: it applies to an organisation from the day it adopts the standard. (Source: [ISO/IEC 42001:2023](https://www.iso.org/standard/42001)) |
| In the Body of Knowledge | [22. NIST AI RMF 1.0 in depth](https://aigovernanceengineer.com/bok/principles-and-standards#nist-ai-rmf-10-in-depth) · [13. NIST AI RMF and ISO/IEC 23894 on the stack](https://aigovernanceengineer.com/bok/risk-management#nist-ai-rmf-and-isoiec-23894-on-the-stack) | [22. The ISO/IEC management-system trio](https://aigovernanceengineer.com/bok/principles-and-standards#the-management-system-trio) · [13. ISO 31000, ISO/IEC 23894 and ISO/IEC 42001](https://aigovernanceengineer.com/bok/risk-management#iso-31000-isoiec-23894-and-isoiec-42001) |

## Where they overlap, topic by topic

The crosswalk maps 25 AI governance topics. Both instruments file clauses under 20 of them, 11 strongly (a core clause on each side). 2 topics have a core clause only in the NIST AI RMF and 0 only in ISO 42001; 1 more is touched by one side only in passing (a related clause, not a core one); 2 are reached by neither. A shared topic means the two deal with the same thing, not that meeting one meets the other.

Strong: both file a core clause. Partial: both file a clause, at least one only in passing. Only, in passing: one side files a related clause and the other none. The last column names a pattern only where it serves a core clause on both sides: the register entry of that clause lists it and the pattern's own "Maps to" line names the clause.

| Topic | What NIST AI RMF asks for | What ISO 42001 asks for | Overlap | Patterns for both |
|---|---|---|---|---|
| [Risk management](https://aigovernanceengineer.com/resources/crosswalk#topic-risk-management) | [MAP 1](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-map) Context is established and understood; [MAP 5](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-map) Impacts to individuals, groups, communities, organizations, and society are characterized; [MANAGE 1](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage) AI risks based on assessments and other analytical output are prioritized, responded to, and managed; [GOVERN 1.3](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-govern) Processes, procedures, and practices are in place to determine the needed level of risk management activities based on the organization's risk tolerance; [MAP 1.5](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-map) Organizational risk tolerances are determined and documented; [MANAGE 1.3](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage) Responses to the AI risks deemed high priority, as identified by the MAP function, are developed, planned, and documented; [MANAGE 1.4](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage) Negative residual risks to both downstream acquirers of AI systems and end users are documented; [MEASURE 3](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure) Mechanisms for tracking identified AI risks over time are in place; [MEASURE 2](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure) AI systems are evaluated for trustworthy characteristics | 6.1.2 AI risk assessment; 6.1.3 AI risk treatment; 8.2 AI risk assessment (operation); 8.3 AI risk treatment (operation); [A.6](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a6) AI system life cycle; 6.1.4 AI system impact assessment | Strong |  |
| [Governance and accountability](https://aigovernanceengineer.com/resources/crosswalk#topic-governance-accountability) | [GOVERN 1](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-govern) Policies, processes, procedures, and practices across the organization related to the mapping, measuring, and managing of AI risks are in place, transparent, and implemented effectively; [GOVERN 2](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-govern) Accountability structures are in place so that the appropriate teams and individuals are empowered, responsible, and trained; [GOVERN 4](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-govern) Organizational teams are committed to a culture that considers and communicates AI risk; [GOVERN 5](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-govern) Processes are in place for robust engagement with relevant AI actors | 5.1 Leadership and commitment; 5.2 AI policy; 5.3 Roles, responsibilities and authorities; [A.2](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a2) Policies related to AI; [A.3](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a3) Internal organization; 9.3 Management review (not yet verified against the source); 7.2 Competence (not yet verified against the source); 9.2 Internal audit (not yet verified against the source); 10.1 Continual improvement (not yet verified against the source) | Strong |  |
| [Impact assessment](https://aigovernanceengineer.com/resources/crosswalk#topic-impact-assessment) | [MAP 3](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-map) AI capabilities, targeted usage, goals, and expected benefits and costs are understood; [MAP 5](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-map) Impacts to individuals, groups, communities, organizations, and society are characterized | 6.1.4 AI system impact assessment; 8.4 AI system impact assessment (operation); [A.5](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a5) Assessing impacts of AI systems | Strong |  |
| [Data governance](https://aigovernanceengineer.com/resources/crosswalk#topic-data-governance) | [MAP 2](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-map) Categorization of the AI system is performed; [MEASURE 2.10](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure) Privacy risk of the AI system is examined and documented; [MEASURE 2.11](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure) Fairness and bias are evaluated and results are documented | [A.7](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a7) Data for AI systems; [A.7.3](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a7) Acquisition of data (not yet verified against the source); [A.4](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a4) Resources for AI systems | Partial |  |
| [Documentation and transparency](https://aigovernanceengineer.com/resources/crosswalk#topic-documentation-transparency) | [MAP 1](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-map) Context is established and understood; [MEASURE 2.8](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure) Risks associated with transparency and accountability are examined and documented; [MAP 1.6](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-map) System requirements are elicited from and understood by relevant AI actors. Design decisions take socio-technical implications into account to address AI risks; [MEASURE 2.9](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure) The AI model is explained, validated, and documented, and AI system output is interpreted within its context as identified in the MAP function to inform responsible use and governance | 7.5 Documented information; [A.6](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a6) AI system life cycle; [A.8](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a8) Information for interested parties | Partial |  |
| [Inventory and registration](https://aigovernanceengineer.com/resources/crosswalk#topic-inventory-registration) | [GOVERN 1.6](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-govern) Mechanisms are in place to inventory AI systems and are resourced according to organizational risk priorities; [GOVERN 1.7](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-govern) Processes and procedures are in place for decommissioning and phasing out AI systems safely and in a manner that does not increase risks or decrease the organization's trustworthiness | [A.4](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a4) Resources for AI systems | Strong |  |
| [Logging and traceability](https://aigovernanceengineer.com/resources/crosswalk#topic-logging-traceability) | [MANAGE 4](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage) Risk treatments, including response and recovery, and communication plans for the identified and measured AI risks are documented and monitored; [MEASURE 3](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure) Mechanisms for tracking identified AI risks over time are in place | [A.6](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a6) AI system life cycle; [A.6.2.8](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a6) AI system recording of event logs (not yet verified against the source) | Partial |  |
| [Human oversight](https://aigovernanceengineer.com/resources/crosswalk#topic-human-oversight) | [MANAGE 2.4](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage) Mechanisms are in place and applied, and responsibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use; [MAP 3.5](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-map) Processes for human oversight are defined, assessed, and documented in accordance with organizational policies from the GOVERN function; [GOVERN 3.2](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-govern) Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight of AI systems | [A.9](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a9) Use of AI systems | Strong |  |
| [Runtime guardrails](https://aigovernanceengineer.com/resources/crosswalk#topic-runtime-guardrails) | [MANAGE 2](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage) Strategies to maximize AI benefits and minimize negative impacts are planned, prepared, implemented, documented, and informed by relevant AI actors | [A.9](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a9) Use of AI systems; [A.6](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a6) AI system life cycle | Strong |  |
| [Robustness, security and evaluations](https://aigovernanceengineer.com/resources/crosswalk#topic-robustness-security-evals) | [MEASURE 2](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure) AI systems are evaluated for trustworthy characteristics; [MEASURE 2.7](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure) AI system security and resilience as identified in the MAP function are evaluated and documented; [MEASURE 2.1](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure) Test sets, metrics, and details about the tools used during TEVV are documented; [MEASURE 1](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure) Appropriate methods and metrics are identified and applied | [A.6](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a6) AI system life cycle; 9.1 Monitoring, measurement, analysis and evaluation | Strong |  |
| [Incident response and monitoring](https://aigovernanceengineer.com/resources/crosswalk#topic-incident-monitoring) | [MANAGE 4](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage) Risk treatments, including response and recovery, and communication plans for the identified and measured AI risks are documented and monitored; [MANAGE 4.3](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage) Incidents and errors are communicated to relevant AI actors, including affected communities. Processes for tracking, responding to, and recovering from incidents and errors are followed and documented; [MANAGE 2.4](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage) Mechanisms are in place and applied, and responsibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use; [GOVERN 4.3](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-govern) Organizational practices are in place to enable AI testing, identification of incidents, and information sharing | [A.8](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a8) Information for interested parties; 10.2 Nonconformity and corrective action | Strong |  |
| [Supply chain and third parties](https://aigovernanceengineer.com/resources/crosswalk#topic-supply-chain) | [GOVERN 6](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-govern) Policies and procedures are in place to address AI risks and benefits arising from third-party software and data and other supply chain issues; [MAP 4](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-map) Risks and benefits are mapped for all AI system components including third-party software and data; [MANAGE 3](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage) AI risks and benefits from third-party entities are managed; [MANAGE 3.1](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage) AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented; [GOVERN 6.2](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-govern) Contingency processes are in place to handle failures or incidents in third-party data or AI systems deemed to be high-risk | [A.10](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a10) Third-party and customer relationships | Strong |  |
| [Prohibited practices](https://aigovernanceengineer.com/resources/crosswalk#topic-prohibited-practices) | [GOVERN 1.1](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-govern) Legal and regulatory requirements involving AI are understood, managed, and documented | [A.9.4](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a9) Intended use of the AI system (not yet verified against the source) | Partial |  |
| [Fairness and non-discrimination](https://aigovernanceengineer.com/resources/crosswalk#topic-fairness-non-discrimination) | [MEASURE 2.11](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure) Fairness and bias as identified in the MAP function are evaluated and results are documented; [GOVERN 3.1](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-govern) Decision-making related to mapping, measuring, and managing AI risks throughout the lifecycle is informed by a diverse team | [A.5.4](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a5) Assessing AI system impact on individuals or groups of individuals (not yet verified against the source) | Partial |  |
| [Privacy and data protection](https://aigovernanceengineer.com/resources/crosswalk#topic-privacy-data-protection) | [MEASURE 2.10](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure) Privacy risk of the AI system as identified in the MAP function is examined and documented | [A.7](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a7) Data for AI systems | Partial |  |
| [Explainability and right to explanation](https://aigovernanceengineer.com/resources/crosswalk#topic-explainability) | [MEASURE 2.9](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure) The AI model is explained, validated, and documented, and AI system output is interpreted within its context as identified in the MAP function to inform responsible use and governance; [MEASURE 2.8](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure) Risks associated with transparency and accountability as identified in the MAP function are examined and documented | [A.8.2](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a8) System documentation and information for users (not yet verified against the source) | Partial |  |
| [AI literacy and competence](https://aigovernanceengineer.com/resources/crosswalk#topic-ai-literacy) | [GOVERN 2.2](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-govern) The organization's personnel and partners receive AI risk management training to enable them to perform their duties and responsibilities consistent with related policies, procedures, and agreements; [MAP 3.4](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-map) Processes for operator and practitioner proficiency with AI system performance and trustworthiness, and relevant technical standards and certifications, are defined, assessed, and documented | 7.2 Competence (not yet verified against the source); 7.3 Awareness (not yet verified against the source) | Strong |  |
| [Conformity assessment and certification](https://aigovernanceengineer.com/resources/crosswalk#topic-conformity-assessment) | [MEASURE 1.3](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure) Internal experts who did not serve as front-line developers for the system and/or independent assessors are involved in regular assessments and updates | 9.2 Internal audit (not yet verified against the source) | Partial |  |
| [IP and copyright](https://aigovernanceengineer.com/resources/crosswalk#topic-ip-copyright) | [GOVERN 6.1](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-govern) Policies and procedures are in place that address AI risks associated with third-party entities, including risks of infringement of a third-party's intellectual property or other rights; [MAP 4.1](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-map) Approaches for mapping AI technology and legal risks of its components, including the use of third-party data or software, are in place, followed, and documented, as are risks of infringement of a third party's intellectual property or other rights | Not mapped | NIST AI RMF only |  |
| [Agent identity and autonomy](https://aigovernanceengineer.com/resources/crosswalk#topic-agent-identity-autonomy) | [GOVERN 3.2](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-govern) Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight of AI systems | Not mapped | NIST AI RMF only, in passing |  |
| [Sandboxes and real-world testing](https://aigovernanceengineer.com/resources/crosswalk#topic-sandboxes-real-world-testing) | [MEASURE 2.3](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure) AI system performance or assurance criteria are measured qualitatively or quantitatively and demonstrated for conditions similar to deployment setting(s) | [A.6.2.4](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a6) AI system verification and validation (not yet verified against the source) | Partial |  |
| [Environmental impact](https://aigovernanceengineer.com/resources/crosswalk#topic-environmental-impact) | [MEASURE 2.12](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure) Environmental impact and sustainability of AI model training and management activities as identified in the MAP function are assessed and documented | Not mapped | NIST AI RMF only |  |
| [Deployment, change and decommissioning](https://aigovernanceengineer.com/resources/crosswalk#topic-deployment-change-decommissioning) | [MANAGE 2.4](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage) Mechanisms are in place and applied, and responsibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use; [MANAGE 4.1](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage) Post-deployment AI system monitoring plans are implemented, including mechanisms for capturing and evaluating input from users and other relevant AI actors, appeal and override, decommissioning, incident response, recovery, and change management; [GOVERN 1.7](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-govern) Processes and procedures are in place for decommissioning and phasing out AI systems safely and in a manner that does not increase risks or decrease the organization's trustworthiness | [A.6.2.5](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a6) AI system deployment (not yet verified against the source); [A.6.2.6](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a6) AI system operation and monitoring (not yet verified against the source); [A.9](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a9) Use of AI systems | Strong | [Staged Rollout with Rollback Criteria](https://aigovernanceengineer.com/patterns/staged-rollout-rollback-criteria); [Drift & Fairness Monitor](https://aigovernanceengineer.com/patterns/drift-fairness-monitor); [Deactivation, Localisation & Retirement Runbook](https://aigovernanceengineer.com/patterns/deactivation-localisation-retirement-runbook) |

## Can the NIST AI RMF help you certify to ISO/IEC 42001?

Partly. NIST itself hosts a crosswalk from the AI RMF to ISO/IEC 42001. But certification needs the management system itself, clauses 4 to 10 and a Statement of Applicability over the Annex A controls, which the RMF does not ask for. Its category and subcategory identifiers still serve as control metadata inside the AIMS.

## Which should you start with?

Start with the NIST AI RMF to organise risk work: it is voluntary, non-sector-specific, and its four functions and 19 categories give you identifiers to tag controls with. Move to ISO/IEC 42001 when you need a certificate as proof of a working management system; the same identifiers then feed its Statement of Applicability.

## Next step

Put the comparison to work on your own systems, in the browser.

- [Read your governance maturity, layer by layer](https://aigovernanceengineer.com/toolkit/maturity-self-check): The maturity self-check: your profile across the five stack layers, the floor it sets and the one move that raises it.
- [Write an AI system impact assessment as one record](https://aigovernanceengineer.com/toolkit/impact-assessment): The impact assessment builder: every risk linked to the measure and pattern that mitigate it, and the triggers that reopen it.
- [Build the AI system inventory both frameworks start from](https://aigovernanceengineer.com/toolkit/ai-register-entry): The AI register entry builder: entries that validate against the published schemas, each field mapped to an ISO/IEC 42001 Statement of Applicability.

Indicative, not legal advice and not a conformity claim. Nothing you enter leaves your browser.

## Frequently asked questions

### Is there an official crosswalk between the NIST AI RMF and ISO 42001?

NIST's AI Resource Center hosts crosswalks from the RMF to other frameworks, including ISO/IEC 42001, and dated 14 August 2025 a revised ISO/IEC 23894 crosswalk and a new ISO/IEC 42005 one. They are a sound starting point for a crosswalk file, not a substitute for mapping your own controls.

Source: [NIST AIRC: crosswalks](https://airc.nist.gov/airmf-resources/crosswalks/)

### Is there a NIST AI RMF 2.0?

No. AI RMF 1.0 (NIST AI 100-1, 26 January 2023) remains the citable text. As of 2026-09-24 NIST's framework page states that 1.0 is being revised as part of the White House AI Action Plan, but no revised version is published. Pin the version in control metadata.

Sources: [NIST AI 100-1](https://doi.org/10.6028/NIST.AI.100-1), [NIST: AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework)

### How do ISO/IEC 23894 and ISO 42001 relate to the NIST AI RMF?

ISO/IEC 23894 applies ISO 31000 risk management to AI; ISO/IEC 42001 is the certifiable management-system standard whose risk clauses (6.1.2 to 6.1.4, operated in 8.2 to 8.4) require the risk loop to exist and run. NIST's crosswalk shows that its functions and the 23894 clauses describe one process.

Sources: [ISO/IEC 23894:2023](https://www.iso.org/standard/77304.html), [ISO/IEC 42001:2023](https://www.iso.org/standard/42001), [NIST AIRC: crosswalks](https://airc.nist.gov/airmf-resources/crosswalks/)

### What does the NIST AI RMF cover that ISO 42001 does not?

In this crosswalk, 2 of the 25 topics have a core NIST AI RMF clause and no ISO 42001 clause mapped: IP and copyright; Environmental impact. Agent identity and autonomy is touched only in passing: the NIST AI RMF files a related clause there, not a core one, and ISO 42001 none. A topic with no ISO 42001 clause here is one this mapping does not reach, not one ISO 42001 is shown to leave out. The overlap table on this page lists the clauses; mappings are illustrative, not a claim of conformity.

## Illustrative mapping, not a conformity assessment

Mappings are illustrative, not a claim of conformity. A mapping cell is not evidence; see the [Framework Crosswalk pattern](https://aigovernanceengineer.com/patterns/framework-crosswalk) for what turns a crosswalk into an auditable control.

## Sources

- NIST AI RMF: https://www.nist.gov/itl/ai-risk-management-framework
- NIST AI RMF: https://airc.nist.gov/airmf-resources/airmf/
- ISO/IEC 42001: https://www.iso.org/standard/42001
- NIST AI 100-1: https://doi.org/10.6028/NIST.AI.100-1
- NIST AI 600-1: https://doi.org/10.6028/NIST.AI.600-1
- Regulation (EU) 2024/1689, consolidated text: https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng
- ISO/IEC 42006:2025: https://www.iso.org/standard/44546.html
- NIST AIRC: crosswalks: https://airc.nist.gov/airmf-resources/crosswalks/
- ISO/IEC 23894:2023: https://www.iso.org/standard/77304.html

Every clause on this page, with its note and verification status, is in the [topic × framework crosswalk](https://aigovernanceengineer.com/resources/crosswalk) and its [JSON download](https://aigovernanceengineer.com/resources/crosswalk.json). Other comparisons: [ISO 42001 vs EU AI Act](https://aigovernanceengineer.com/resources/crosswalk/iso-42001-vs-eu-ai-act) · [NIST AI RMF vs EU AI Act](https://aigovernanceengineer.com/resources/crosswalk/nist-ai-rmf-vs-eu-ai-act). The wider field: [AI governance, explained](https://aigovernanceengineer.com/ai-governance).
