Microsoft Teams

AI Governance · Framework Comparison

ISO 42001, NIST AI RMF and the EU AI Act aren't three competing choices.

One is a legally binding regulation. One is a voluntary risk-management methodology. One is a certifiable management-system standard you can actually be audited against. Used together, they cover each other's gaps — and ISO 42001 is built to sit at the centre.

  • Clause-level crosswalk
  • Article 40 presumption of conformity
  • Updated for the 2026 EU AI Act timeline
ISO 42001 Services Free AI Governance Checklist

What each one actually is

ISO/IEC 42001 — the standard

The first international AI Management System standard. Certifiable via a two-stage external audit, the same shape as ISO 27001 — a management system covering policy, risk, resourcing, and continual improvement, with a full Annex A control set. It's the only one of the three you can actually be certified against.

NIST AI RMF — the methodology

A voluntary, program-level risk management framework from the US National Institute of Standards and Technology, built around four functions: Govern, Map, Measure, Manage. No certification exists for it — it's a way of thinking about AI risk, not an audit you pass. ISO 42001 explicitly references it as a normative source.

EU AI Act — the regulation

A binding law with real enforcement teeth, not a voluntary standard. It applies based on where your AI system's output is used, not where you're headquartered. Obligations scale with risk tier, and Article 40 lets harmonised standards — ISO 42001 among the leading candidates — create a presumption of conformity for the parts they cover.

The clause-level crosswalk

NIST's own published guidance maps its four functions directly onto specific ISO 42001 clauses. This is the practical version — what building each ISO 42001 clause actually gets you toward the other two.

ISO 42001 clause NIST AI RMF function EU AI Act relevance
Clauses 5–6 — Leadership, planning, AI policy Govern Risk management system, Art. 9
Clause 6.1.2 — AI system impact assessment Map High-risk classification, Annex III
Clause 9 — Monitoring, measurement, internal audit Measure Post-market monitoring, Art. 72
Clause 8, 10 — Operational controls, nonconformity & improvement Manage Human oversight & corrective action, Art. 14, 26

This is a practical mapping to help scope work, not a legal equivalence table — a harmonised-standard presumption of conformity under Article 40 only applies to the specific requirements a standard actually covers, and every EU AI Act obligation still needs its own compliance check.

The EU AI Act's four risk tiers, and how each one is actually decided

"High-risk" isn't a vibe — it's a specific list. The Act sorts every AI system into one of four tiers, and which tier a system lands in is decided by matching it against Article 5's banned practices, Annex III's named use-case categories, and Article 50's transparency triggers — not by how sophisticated the model is or how nervous it makes your legal team.

Prohibited — Article 5

Eight specific practices banned outright: subliminal/manipulative techniques that cause harm, exploiting a group's vulnerabilities, social scoring, predicting criminal risk from profiling alone, untargeted facial-image scraping, emotion inference in workplaces/education, biometric categorisation of sensitive attributes, and real-time remote biometric ID by law enforcement in public. One match here means the system cannot lawfully be deployed in the EU — full stop, no obligations checklist, no path to compliance.

High-risk — Annex III

Eight named categories: biometric ID, critical infrastructure, education/vocational access, employment and worker management, access to essential services (credit, insurance, benefits), law enforcement, migration/border control, and administration of justice or democratic processes. A match here triggers the Act's full Title III obligations — risk management, data governance, technical documentation, logging, human oversight, conformity assessment, EU database registration.

Limited risk — Article 50

Systems that talk directly to people (chatbots), generate synthetic content (deepfakes, AI-written text), or do non-prohibited emotion recognition/biometric categorisation owe transparency obligations — disclose it's AI, label the content — on top of whatever else applies. These stack with High-risk obligations rather than replacing them: a high-risk system that's also a chatbot owes both checklists.

Minimal risk

Everything else. No mandatory obligations under the Act as things stand — though the voluntary codes of conduct under Article 95 are worth adopting anyway, since "minimal risk today" isn't a permanent classification as the Act's annexes get amended.

365 Free tool · No sign-up

Is your AI system high-risk under the EU AI Act?

Tick everything that applies. Every question maps to one specific clause of Article 5, Annex III or Article 50 — nothing here is a vague judgement call. Instant tier, plain-English obligations.

Suggested tier: Minimal

Screening aid based on our reading of the EU AI Act — not legal advice. Confirm borderline or high-stakes classifications with counsel.

This exact engine tracks every AI system in your inventory automatically, tied straight to ISO 42001 evidence, inside Checkpoint. See Checkpoint in action

Why build on ISO 42001 rather than starting with the others

It's the only one that's certifiable

NIST AI RMF has no certificate to hold up in a procurement conversation, and the EU AI Act is a legal obligation, not something you get "certified" against. ISO 42001 is the one you can point to with third-party evidence — an auditor's sign-off, not a self-declaration.

It absorbs the other two as you build it

Because ISO 42001 references NIST AI RMF directly and maps closely onto EU AI Act risk-management requirements, building the ISO 42001 management system captures most of the substance of the other two along the way — you're not running three parallel programmes.

The EU AI Act timeline just moved — again

Per the May 2026 Digital Omnibus, GPAI obligations activate 2 August 2026, but high-risk Annex III obligations have been deferred to 2 December 2027. That's more runway, not less urgency — the organisations ready when enforcement actually lands are the ones who started the management system now.

It's the one enterprise buyers are already asking for

"Are you ISO 42001 certified?" is already showing up in roughly 40% of enterprise AI vendor RFPs in the EU and around 25% in North America. Procurement teams are asking for the certificate specifically, not "do you have an AI risk framework."

Common questions

Do I need all three?

Not as three separate programmes. If you're EU-exposed, the EU AI Act's obligations apply regardless of what else you do — but ISO 42001 gets you most of the way to demonstrating compliance with the management-system parts of it, and NIST AI RMF's vocabulary is already built into ISO 42001's structure.

Does ISO 42001 replace GDPR or the Privacy Act for AI?

No — privacy obligations for personal data used in AI systems still apply separately (see ISO 27701 for that layer). ISO 42001 governs the AI management system itself: what AI you run, who's accountable, and how you'd catch it going wrong.

We're US-only — does the EU AI Act even matter?

The EU AI Act applies based on where your AI system's output is used, not where you're headquartered — so a US company with EU customers or users is very likely in scope regardless. Worth checking before assuming it doesn't apply.

Related

ISO 42001 Full AI governance certification AI Vendor Risk Assessment A faster answer than full certification Free AI Governance Checklist Score your readiness in 12 minutes

Not sure which of the three actually applies to you?

A 30-minute scoping call maps your actual exposure across all three, not just the one you asked about.

Book a Scoping Call

Free monthly digest

Get the monthly Australian compliance digest

Practical updates on ISO 27001, Essential Eight, Privacy Act and AI governance — delivered once a month. No spam, unsubscribe any time.

No spam. Unsubscribe any time. We never share your email.