If your board, a customer's procurement team, or a regulator has asked "what's your AI governance framework," you've probably hit the same fork in the road: NIST's AI Risk Management Framework, or ISO/IEC 42001. Vendors selling audits will tell you ISO 42001 is the serious choice. Vendors selling risk software will tell you NIST AI RMF is all you need. Both answers are incomplete. The honest answer is that these are two different kinds of document solving two different problems, and most organizations that get this right end up using both — just not at the same time, and not for the same reason.
This comparison lays out what each one actually is, what it costs, what it covers, and who should reach for which first, so you can make the call without paying for a sales pitch dressed up as guidance.
Quick verdict: They are complementary, not competing. NIST AI RMF (NIST.AI.100-1, published 2023-01-26) is a free, voluntary US framework that gives you the risk-management vocabulary and process — GOVERN, MAP, MEASURE, MANAGE — but it is not certifiable; there is no official NIST AI RMF certificate. ISO/IEC 42001:2023 (published 2023-12-18) is a certifiable management-system standard, audited by accredited third parties much like ISO 27001. Many organizations use NIST AI RMF to structure their internal risk process first, then formalize and certify that process against ISO/IEC 42001 once they need external proof for customers, partners, or regulators. If you need a marketing- and procurement-grade certificate, you need ISO 42001. If you need a starting vocabulary and a free internal process, you start with NIST AI RMF. Many mature programs need both, at different points in their maturity.
What is the NIST AI RMF?
The NIST AI Risk Management Framework (AI RMF 1.0, formally NIST.AI.100-1) was released by the US National Institute of Standards and Technology on January 26, 2023. It is voluntary — there is no law requiring private-sector adoption — and it is free to download and use. It was built through a multi-stakeholder process and is organized around four functions:
- GOVERN — culture, accountability, and policy that cut across the other three functions.
- MAP — understanding context, use cases, and the risks a given AI system actually poses.
- MEASURE — analyzing, tracking, and benchmarking identified risks.
- MANAGE — allocating resources and acting on measured risks, including monitoring and response.
NIST paired the framework with a companion AI RMF Playbook — practical, suggested actions mapped to each function and subcategory — and later published a Generative AI Profile (NIST-AI-600-1, released July 26, 2024) that applies the same four functions specifically to generative AI risks such as confabulation, data memorization, and content provenance. NIST has continued revising and extending the RMF ecosystem through 2025–2026 as the technology and threat landscape shift.
Because it's a framework rather than a certifiable standard, there's no accredited body that will audit you against the AI RMF and hand you a certificate. What you get instead is a shared vocabulary and a structured way to think about AI risk — genuinely useful groundwork for what responsible AI means in practice inside your organization, and a natural first artifact for an AI governance committee to build its charter around.
What is ISO/IEC 42001?
ISO/IEC 42001:2023, published December 18, 2023, is the first international standard for an AI management system (AIMS) — the AI-specific counterpart to ISO 27001 for information security or ISO 9001 for quality. It follows the same Plan-Do-Check-Act (PDCA) structure used across ISO management-system standards: you define an AI policy and objectives, implement controls, monitor and evaluate performance, and continually improve.
Critically, ISO/IEC 42001 certifies your organization's management system — not a specific model, algorithm, or dataset. An accredited certification body audits how you govern the lifecycle of AI systems you build or use: roles and responsibilities, risk assessment, data governance, third-party/supplier AI, incident handling, and continual improvement. The audit path mirrors ISO 27001's: a Stage 1 documentation review, a Stage 2 implementation audit, annual surveillance audits, and full recertification roughly every three years.
Two companion documents matter here. ISO/IEC 42006:2025 sets the requirements for the certification bodies themselves, which is what allows an accredited ISO 42001 certificate (versus a self-declared "we follow ISO 42001" claim with no independent audit behind it). And ISO/IEC 23894:2023 (AI risk management guidance) and ISO/IEC 42005:2025 (AI system impact assessment) provide supporting detail that organizations often use alongside 42001 during implementation. Unlike NIST's framework, ISO standards are paid documents, and certification itself carries real cost and calendar time — typically months of preparation plus the audit fees themselves.
NIST AI RMF vs ISO 42001 at a glance
| Dimension | NIST AI RMF | ISO/IEC 42001 |
|---|---|---|
| Legal status | Voluntary US framework | Voluntary international standard |
| Certifiable? | No — no official certificate exists | Yes — accredited third-party certification |
| Cost | Free to access and use | Paid standard; certification adds audit fees and staff time |
| What it covers | A risk-management process (GOVERN/MAP/MEASURE/MANAGE) plus a Generative AI Profile | A full management system (policy, roles, controls, continual improvement) under PDCA |
| Geography / recognition | Strongest recognition in the US; referenced globally as a risk-language baseline | Globally recognized certification, widely requested in EU and enterprise procurement |
| Best for | Building internal risk vocabulary and process quickly, at low cost | Proving governance maturity externally to customers, partners, or regulators |
Which should you choose?
The right starting point depends less on which document reads better and more on who is asking and why.
Small and mid-size businesses (SMBs)
Start with NIST AI RMF. It costs nothing, gives you a defensible internal structure fast, and lets you demonstrate a real process to customers or insurers without committing to an audit budget you may not have yet. Use the Playbook to turn the four functions into a checklist your team can actually run. If a specific enterprise customer later requires certified proof, you can layer ISO 42001 on top of the process you've already built rather than starting from zero.
Enterprises with AI products or heavy AI-vendor exposure
Plan for both, likely NIST first internally, ISO 42001 for external assurance. At enterprise scale, procurement teams, insurers, and boards increasingly expect a certificate, not just a policy document. ISO 42001 certification also gives you a structure that maps cleanly onto other management-system certifications you may already hold (ISO 27001, ISO 9001), which lowers the incremental audit burden.
Organizations selling into the EU or otherwise EU-facing
Lean toward ISO/IEC 42001. It is the certification EU customers, distributors, and regulators most readily recognize, and its management-system structure maps reasonably well onto the documentation and risk-management obligations emerging under the EU AI Act. Certification won't by itself guarantee AI Act compliance, but it gives you an audited paper trail that's far easier to extend into EU-specific obligations than an informal internal process would be.
US-facing organizations, especially those selling to US federal or state government
NIST AI RMF is usually the expected reference point, since it's the framework US agencies and many US enterprise buyers already cite. That said, a growing share of US enterprise procurement now asks for ISO 42001 too, particularly for vendors handling sensitive data or safety-relevant use cases — so treat NIST as your floor, not your ceiling.
The bottom line
Neither framework is a shortcut to "we're compliant." NIST AI RMF gives you the shared language and process discipline to run AI risk management well; ISO/IEC 42001 gives you an audited, certifiable way to prove that discipline exists to people outside your organization. Treat the choice as sequencing, not exclusivity: build the process with NIST AI RMF, then decide — based on what your customers, regulators, or board actually demand — whether the ISO 42001 certificate is worth the cost and calendar time to obtain.
For a broader look at how governance frameworks like these translate into day-to-day accountability structures, see our ranking methodology and how we evaluate companies across AI company rankings for their governance practices.