All articles

Standards

ISO/IEC 42001 and the NIST AI RMF are not competitors

One is a certifiable management system standard. The other is voluntary US guidance. Procurement teams increasingly ask for the first and assume the second.

SkillHat Editorial Team5 min read
ISO/IEC 42001 and the NIST AI RMF are not competitors

What is the difference between ISO/IEC 42001 and the NIST AI RMF?

ISO/IEC 42001 is a certifiable management system standard for AI, so an organisation can be audited and certified against it. The NIST AI Risk Management Framework is voluntary US guidance that structures how risk is identified and managed, with no certification. They are complementary: procurement teams increasingly ask for 42001 certification and assume AI RMF style risk practice underneath it.

Key facts

NIST AI RMF 1.0 was published in January 2023 and is voluntary, with no certificate and no auditor.

ISO/IEC 42001:2023 was published in December 2023 and is certifiable by accredited bodies.

Certification is becoming a procurement question, not just a governance exercise.

What each one is

ISO/IEC 42001 specifies requirements for establishing, implementing, maintaining and improving an AI management system: policies, roles, risk and impact assessments, Annex A controls and continual improvement. It follows the usual ISO certification model.

The NIST AI Risk Management Framework organises AI risk work into four functions and gives teams a shared vocabulary. It is guidance, not a certification scheme.

How they fit together

The practical pattern is to use the AI RMF for internal substance and ISO/IEC 42001 for external proof. Major vendors including Microsoft have published their ISO/IEC 42001 positions for AI services.

Both map usefully onto EU AI Act obligations, but neither is a substitute for the Act's specific documentation and oversight requirements.

Career angle

AI governance roles are being written by people who already know ISO 27001. If you can run a management system, adding AI scope is a smaller step than it sounds.

The differentiator is having done an AI impact assessment on a real system, not naming the standard.

What it means for you

Start with the AI RMF to think clearly. Move to ISO/IEC 42001 when a customer asks for proof you cannot give them with a policy document.

Regulation only pays you if you can show the work.

The GRC Experience Program builds practical project experience, interview-ready stories and the positioning to prove it.

Turn This Into Something You Can Prove.

Short fit call. Clear next step. If neither program is right for you, we'll tell you.

Build Experience You Can Explain.

Explore SkillHat’s practical programs for GRC careers and expertise-led businesses.