ISO 42001 vs NIST AI RMF:
a certificate and a method.
The two AI governance frameworks buyers mention most, compared on what they are, who checks them, what they require and how they fit together, so you can decide whether you need one, the other or both.
Last updated Published by TryTrustableNot legal advice
What is the difference between ISO 42001 and the NIST AI RMF?
ISO/IEC 42001 is a certifiable international standard that sets requirements for an AI management system, audited by accredited certification bodies. The NIST AI RMF is voluntary US guidance offering a risk method in four functions, with no certification. ISO 42001 says what the system must contain; the RMF shows one way to do the risk work.
| ISO/IEC 42001:2023 | NIST AI RMF 1.0 | |
|---|---|---|
| What it is | International management system standard | Voluntary framework from a US federal agency |
| Published | December 2023 | 26 January 2023; Generative AI Profile (AI 600-1) 26 July 2024 |
| Structure | Clauses 4–10 in the harmonized structure; Annex A with 38 controls in nine areas | Four functions, Govern, Map, Measure, Manage; 19 categories and 72 subcategories |
| Language | "Shall" requirements | Suggested outcomes and actions |
| Certification | Yes, by accredited certification bodies under ISO/IEC 17021-1 and 42006 | None |
| Cost to read | Paid standard | Free |
| Unit | The organisation's AI management system, within its scope | AI systems and the organisation's practices around them |
| Risk method | Requires AI risk and impact assessments; does not prescribe how | Is a risk method, in detail |
| Cycle | Three-year certificate, surveillance audits, internal audit and management review | Continuous and iterative; no external check |
| Where it is asked for | Enterprise procurement worldwide, including Europe and India | US federal context and US enterprises; widely used as guidance elsewhere |
| EU AI Act effect | No presumption of conformity | No presumption of conformity |
Checked September 2026. NIST says AI RMF 1.0 is being revised; version 1.0 was current at the time of writing.
How ISO 42001 and the NIST AI RMF fit together
ISO 42001 and the NIST AI RMF fit together because 42001 requires an AI risk assessment and an AI system impact assessment without prescribing how to do them, and the RMF's Map and Measure functions are a detailed way of doing exactly that. The RMF's Govern function lines up with 42001's leadership, policy and roles clauses.
| NIST AI RMF | Closest ISO/IEC 42001 home |
|---|---|
| Govern: policy, accountability, culture, third parties | Clause 5 leadership and policy; A.2, A.3; A.10 third-party relationships |
| Map: context, purpose, impacts | Clause 4 context; 6.1.4 AI system impact assessment; A.5 |
| Measure: metrics, evaluation, tracking | Clause 9.1 monitoring and measurement; A.6 verification and validation, operation and monitoring |
| Manage: treatment, response, recovery | 6.1.3 risk treatment and Statement of Applicability; clause 8 operation; clause 10 improvement; A.8 incident communication |
An orientation, not a control-level mapping. NIST's crosswalk maps subcategories to the final draft of 42001.
Which one does an Indian company need?
An Indian company selling AI features usually needs ISO 42001 when a buyer asks for a certificate, and the NIST AI RMF when it wants a free, detailed method for the risk work or sells to US public-sector buyers. Neither is legally required in India. A company that sells into the EU also has AI Act duties that neither replaces.
The practical order for most: build the inventory and run the risk and impact work using the RMF's Map and Measure functions, wrap it in the 42001 management system, then certify when a buyer asks. The guides go deeper: ISO 42001, NIST AI RMF, and EU AI Act vs ISO 42001 for the legal side. The AI governance engine keeps one inventory and one set of evaluation records that both frameworks can read. TryTrustable does not hold ISO 42001 certification itself.
The things people ask us
What is the difference between ISO 42001 and the NIST AI RMF?
ISO/IEC 42001 is a certifiable international standard that sets requirements for an AI management system, audited by accredited certification bodies. The NIST AI RMF is voluntary US guidance offering a risk method in four functions, with no certification. ISO 42001 says what the system must contain; the RMF shows one way to do the risk work.
Should we use ISO 42001 or the NIST AI RMF?
Use ISO 42001 if a customer or market wants a certificate. Use the NIST AI RMF if you want a detailed, free risk method, or if US federal buyers expect it. Many organisations use both: the RMF as the method inside the ISO 42001 risk and impact assessments, and the certificate as the proof that the whole system runs.
Is there a crosswalk between ISO 42001 and the NIST AI RMF?
Yes. NIST publishes crosswalks from the AI RMF to other frameworks, including one to the final draft of ISO/IEC 42001. It maps RMF functions and subcategories to 42001 clauses and controls. Treat it as a starting point: it predates the published standard, and your auditor decides what evidence satisfies a clause.
Which is more widely recognised in India?
ISO 42001, for commercial purposes, because it is an international standard with accredited certification that buyers can verify. The NIST AI RMF is widely read and respected as guidance, but it produces no certificate. Neither is required by Indian law; India's AI governance guidelines are also voluntary.
Do either of them satisfy the EU AI Act?
No. The EU AI Act regulates individual AI systems, with risk classification, technical documentation and conformity assessment. Neither ISO 42001 nor the NIST AI RMF is a harmonised standard under the Act, so neither gives a presumption of conformity, though both build governance the Act assumes.
One AI inventory, two frameworks.
We register a model, run an evaluation and show the same record answering a NIST AI RMF subcategory and an ISO 42001 control.