ISO 42001 vs NIST AI RMF

ISO 42001 vs NIST AI RMF:
a certificate and a method.

The two AI governance frameworks buyers mention most, compared on what they are, who checks them, what they require and how they fit together, so you can decide whether you need one, the other or both.

Last updated Published by TryTrustableNot legal advice

01

What is the difference between ISO 42001 and the NIST AI RMF?

ISO/IEC 42001 is a certifiable international standard that sets requirements for an AI management system, audited by accredited certification bodies. The NIST AI RMF is voluntary US guidance offering a risk method in four functions, with no certification. ISO 42001 says what the system must contain; the RMF shows one way to do the risk work.

ISO/IEC 42001:2023NIST AI RMF 1.0
What it isInternational management system standardVoluntary framework from a US federal agency
PublishedDecember 202326 January 2023; Generative AI Profile (AI 600-1) 26 July 2024
StructureClauses 4–10 in the harmonized structure; Annex A with 38 controls in nine areasFour functions, Govern, Map, Measure, Manage; 19 categories and 72 subcategories
Language"Shall" requirementsSuggested outcomes and actions
CertificationYes, by accredited certification bodies under ISO/IEC 17021-1 and 42006None
Cost to readPaid standardFree
UnitThe organisation's AI management system, within its scopeAI systems and the organisation's practices around them
Risk methodRequires AI risk and impact assessments; does not prescribe howIs a risk method, in detail
CycleThree-year certificate, surveillance audits, internal audit and management reviewContinuous and iterative; no external check
Where it is asked forEnterprise procurement worldwide, including Europe and IndiaUS federal context and US enterprises; widely used as guidance elsewhere
EU AI Act effectNo presumption of conformityNo presumption of conformity

Checked September 2026. NIST says AI RMF 1.0 is being revised; version 1.0 was current at the time of writing.

02

How ISO 42001 and the NIST AI RMF fit together

ISO 42001 and the NIST AI RMF fit together because 42001 requires an AI risk assessment and an AI system impact assessment without prescribing how to do them, and the RMF's Map and Measure functions are a detailed way of doing exactly that. The RMF's Govern function lines up with 42001's leadership, policy and roles clauses.

NIST AI RMFClosest ISO/IEC 42001 home
Govern: policy, accountability, culture, third partiesClause 5 leadership and policy; A.2, A.3; A.10 third-party relationships
Map: context, purpose, impactsClause 4 context; 6.1.4 AI system impact assessment; A.5
Measure: metrics, evaluation, trackingClause 9.1 monitoring and measurement; A.6 verification and validation, operation and monitoring
Manage: treatment, response, recovery6.1.3 risk treatment and Statement of Applicability; clause 8 operation; clause 10 improvement; A.8 incident communication

An orientation, not a control-level mapping. NIST's crosswalk maps subcategories to the final draft of 42001.

03

Which one does an Indian company need?

An Indian company selling AI features usually needs ISO 42001 when a buyer asks for a certificate, and the NIST AI RMF when it wants a free, detailed method for the risk work or sells to US public-sector buyers. Neither is legally required in India. A company that sells into the EU also has AI Act duties that neither replaces.

The practical order for most: build the inventory and run the risk and impact work using the RMF's Map and Measure functions, wrap it in the 42001 management system, then certify when a buyer asks. The guides go deeper: ISO 42001, NIST AI RMF, and EU AI Act vs ISO 42001 for the legal side. The AI governance engine keeps one inventory and one set of evaluation records that both frameworks can read. TryTrustable does not hold ISO 42001 certification itself.

Questions

The things people ask us

What is the difference between ISO 42001 and the NIST AI RMF?

ISO/IEC 42001 is a certifiable international standard that sets requirements for an AI management system, audited by accredited certification bodies. The NIST AI RMF is voluntary US guidance offering a risk method in four functions, with no certification. ISO 42001 says what the system must contain; the RMF shows one way to do the risk work.

Should we use ISO 42001 or the NIST AI RMF?

Use ISO 42001 if a customer or market wants a certificate. Use the NIST AI RMF if you want a detailed, free risk method, or if US federal buyers expect it. Many organisations use both: the RMF as the method inside the ISO 42001 risk and impact assessments, and the certificate as the proof that the whole system runs.

Is there a crosswalk between ISO 42001 and the NIST AI RMF?

Yes. NIST publishes crosswalks from the AI RMF to other frameworks, including one to the final draft of ISO/IEC 42001. It maps RMF functions and subcategories to 42001 clauses and controls. Treat it as a starting point: it predates the published standard, and your auditor decides what evidence satisfies a clause.

Which is more widely recognised in India?

ISO 42001, for commercial purposes, because it is an international standard with accredited certification that buyers can verify. The NIST AI RMF is widely read and respected as guidance, but it produces no certificate. Neither is required by Indian law; India's AI governance guidelines are also voluntary.

Do either of them satisfy the EU AI Act?

No. The EU AI Act regulates individual AI systems, with risk classification, technical documentation and conformity assessment. Neither ISO 42001 nor the NIST AI RMF is a harmonised standard under the Act, so neither gives a presumption of conformity, though both build governance the Act assumes.

Book a walkthrough

One AI inventory, two frameworks.

We register a model, run an evaluation and show the same record answering a NIST AI RMF subcategory and an ISO 42001 control.