Last updated: September 22, 2026
The main AI governance frameworks in 2026 are ISO/IEC 42001 (the certifiable AI management system standard), the NIST AI Risk Management Framework (the leading voluntary risk framework), and the EU AI Act (the first comprehensive binding AI law), supported by a second tier of guidance standards such as ISO/IEC 23894 and ISO/IEC 42005, the OECD AI Principles, Singapore’s Model AI Governance Framework, and a growing set of US state laws. They differ in three ways that matter: whether compliance is mandatory, whether you can be certified against them, and whether they govern the organization, the individual AI system, or the AI-affected decision. Most organizations end up using ISO 42001 as the operating structure, the NIST AI RMF as the risk method, and the EU AI Act (or a state law) as the legal requirement the first two are mapped to.
This comparison is part of our AI governance guide. For a deeper look at the three headline frameworks alone, see ISO 42001 vs EU AI Act vs NIST AI RMF; this post widens the lens to the frameworks that sit around them.
Key takeaways
- Only one of the major frameworks is certifiable (ISO 42001), only one is binding law with fines (the EU AI Act, alongside narrower US state laws), and only one is free, US-government backed, and designed as a risk method (the NIST AI RMF). They are complements, not rivals.
- The frameworks operate at different levels. ISO 42001 governs the organization; the NIST AI RMF governs the lifecycle of each system; the EU AI Act governs specific uses by risk tier. A complete program needs all three levels.
- Second-tier standards fill specific gaps: ISO/IEC 23894 for AI risk management technique, ISO/IEC 42005 for AI impact assessments, ISO/IEC 42006 for how certification bodies audit ISO 42001.
- Regulatory timelines shifted in 2026. The EU’s Digital Omnibus on AI, in force since July 27, 2026, deferred the Annex III high-risk obligations to December 2, 2027 and the Annex I product-embedded obligations to August 2, 2028, while the Article 50 transparency duties applied on August 2, 2026 as planned.
- Pick one control library, map it to every framework you care about, and collect each piece of evidence once. Organizations that run a separate spreadsheet per framework do the same work three times.
Which AI governance frameworks should you compare?
The list below is limited to frameworks that a company can realistically adopt or be held to. Vendor-specific responsible AI principles, academic frameworks, and industry codes of conduct are useful reading but are not what a customer, auditor, or regulator will ask about. Each entry is scored on the same six attributes: who issues it, whether it is mandatory, whether it is certifiable, what it governs, what it produces, and who it is for.
AI governance framework comparison table
| Framework | Issuer and date | Mandatory? | Certifiable? | What it governs | Primary output | Best fit |
|---|---|---|---|---|---|---|
| ISO/IEC 42001 | ISO/IEC, December 2023 | No (voluntary, but increasingly demanded by customers) | Yes, accredited third-party certification | The organization: an AI management system covering policy, roles, risk, lifecycle, suppliers, and improvement | Certificate; AIMS documentation; Statement of Applicability against 38 Annex A controls | Organizations that build or deploy AI at scale and need a provable, auditable program |
| NIST AI RMF 1.0 | US NIST, January 2023; Generative AI Profile (NIST AI 600-1) July 2024 | No (voluntary; referenced in US federal procurement and state law) | No | Each AI system across its lifecycle through four functions: Govern, Map, Measure, Manage | Risk profiles, measurement plans, documented risk treatment per system | Teams that need a practical risk method, especially in the US market |
| EU AI Act | European Union, in force August 1, 2024; amended by the Digital Omnibus on AI, July 2026 | Yes, for any provider or deployer whose AI reaches the EU market or affects people in the EU | Not as such; high-risk systems need conformity assessment and CE marking | Specific AI uses by risk tier: prohibited, high-risk, transparency-limited, general-purpose models | Conformity assessment, technical documentation, EU database registration, transparency notices | Any organization in scope; legally required |
| ISO/IEC 23894 | ISO/IEC, February 2023 | No | No (guidance standard) | AI risk management technique, adapting ISO 31000 to AI | Risk management process and AI-specific risk sources and controls | Risk teams building the method behind ISO 42001 clause 6 or the NIST Map and Measure functions |
| ISO/IEC 42005 | ISO/IEC, 2025 | No | No (guidance standard) | AI system impact assessment on individuals, groups, and society | Documented impact assessments per system | Organizations that need a structured impact assessment for ISO 42001 control A.5 or EU AI Act fundamental rights impact assessments |
| OECD AI Principles | OECD, 2019, updated May 2024 | No (intergovernmental recommendation) | No | High-level values: inclusive growth, human rights, transparency, robustness, accountability | Principles adopted by 47 jurisdictions; the source definitions used by the EU AI Act and G7 | Board-level principles; policy alignment across countries |
| Singapore Model AI Governance Framework | IMDA and PDPC, 2019 and 2020; Generative AI edition May 2024 | No | No (AI Verify testing toolkit available) | Internal governance, human oversight, operations management, stakeholder communication | Self-assessment and AI Verify test reports | APAC organizations and teams that want a practical, tool-backed self-assessment |
| US state AI laws (Colorado, and sector rules such as NYC Local Law 144) | State legislatures; Colorado’s revised law effective January 1, 2027 | Yes, within each state’s scope | No | Automated decisions affecting consumers, employees, or candidates; disclosure and, in some cases, impact assessment or bias audit | Notices, bias audits, disclosures, records | Any organization using AI in hiring, lending, housing, insurance, or similar decisions in those states |
How do the three major frameworks differ?
ISO/IEC 42001: the certifiable management system
ISO 42001 follows the same harmonized structure as ISO 27001, with clauses 4 through 10 covering context, leadership, planning, support, operation, performance evaluation, and improvement, plus an Annex A of 38 controls grouped under nine objectives (A.2 through A.10) covering AI policy, roles, resources, impact assessment, the system lifecycle, data, information for interested parties, use of AI systems, and third-party relationships. Its defining feature is certification: an accredited body audits your AI management system and issues a certificate that customers accept in place of their own due diligence. It tells you what a governed organization looks like, but it leaves the risk assessment method to you, which is why it is usually paired with ISO/IEC 23894 or the NIST AI RMF.
NIST AI RMF: the risk method
The NIST AI RMF is a voluntary framework organized around four functions. Govern establishes culture, roles, and policy; Map sets context and identifies risks for a given system; Measure tests and tracks them; Manage prioritizes and treats them. It defines seven trustworthiness characteristics (valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, fair with harmful bias managed) that give teams a shared vocabulary. The Generative AI Profile adds more than 200 suggested actions for generative systems. There is no certification and no auditor, which makes it fast to adopt and hard to prove; most organizations use it as the engine inside an ISO 42001 program rather than as a standalone claim. The NIST AI RMF vs ISO 42001 comparison covers the pairing in detail.
EU AI Act: the binding law
The EU AI Act is the only entry in the table with fines: up to EUR 35 million or 7 percent of global annual turnover for prohibited practices, up to EUR 15 million or 3 percent for most other violations, and up to EUR 7.5 million or 1 percent for supplying incorrect information. It regulates uses rather than organizations, sorting systems into prohibited practices (banned since February 2, 2025), high-risk systems listed in Annex III and Annex I, systems with transparency duties under Article 50, and general-purpose AI models (obligations since August 2, 2025). Following the Digital Omnibus on AI, the high-risk obligations for Annex III systems now apply from December 2, 2027 and for Annex I product-embedded systems from August 2, 2028, while the Article 50 transparency obligations took effect on August 2, 2026. The Act does not tell you how to run a governance program; it tells you what evidence a high-risk system must have. That is why Article 17 (quality management system for providers) maps so directly onto ISO 42001, and why the EU AI Act compliance overview recommends building the management system first and treating the Act’s annexes as the control targets.
What do the second-tier frameworks add?
ISO/IEC 23894 is the AI-specific adaptation of ISO 31000. It does not add requirements; it supplies the method for the risk clauses in ISO 42001 and a catalogue of AI risk sources (data quality, model opacity, automation bias, environmental impact, and so on) that teams otherwise have to invent. ISO/IEC 42005 does the same for impact assessments, giving a structure for assessing effects on individuals, groups, and society that satisfies ISO 42001’s Annex A.5 controls and provides a credible base for the fundamental rights impact assessment some deployers owe under Article 27 of the EU AI Act. ISO/IEC 42006 matters indirectly: it sets the requirements for bodies that certify against ISO 42001, so it determines how rigorous your audit will be. The OECD AI Principles are where the definitions come from; the EU AI Act’s definition of an AI system was aligned to the OECD’s 2023 revision, so reading the OECD text explains why the Act’s scope is drawn the way it is. Singapore’s framework and the AI Verify toolkit are the most practical of the group for teams that want a self-assessment with tests they can actually run.
How do US state laws fit in?
US state activity has been volatile. Colorado’s Artificial Intelligence Act, originally due February 1, 2026, was delayed to June 30, 2026 and then repealed and replaced in May 2026 by a narrower law focused on disclosure and transparency around automated decision-making, now effective January 1, 2027. New York City’s Local Law 144 has required bias audits of automated employment decision tools since 2023, and several states apply existing consumer protection and anti-discrimination law to AI outcomes. The practical lesson is that state laws target the decision (hiring, lending, housing, insurance, healthcare) rather than the technology, so an AI system inventory that records which systems make or inform decisions about people is the control that keeps you ready regardless of which statute lands next. None of these laws is certifiable, and most reference the NIST AI RMF as a safe harbor or reasonable-care benchmark, which is another reason to adopt it.
How do you choose which frameworks to adopt?
Start from obligation, then reputation, then method. If you place AI systems on the EU market or your outputs affect people in the EU, the EU AI Act is not optional; classify your systems first and use the EU AI Act compliance checklist to scope the work. If you sell to enterprises, expect ISO 42001 to appear in security questionnaires the way ISO 27001 and SOC 2 did, and plan for certification within 12 to 18 months. If you need a way to actually assess risk per system, adopt the NIST AI RMF (with ISO/IEC 23894 as the technique reference) and run it inside the ISO 42001 structure. Add ISO/IEC 42005 when you deploy systems that affect people materially, and add state-law controls to the systems that make covered decisions. The AI risk assessment guide shows how one assessment can serve all of these at once.
How do you avoid doing the work three times?
Every framework in the table asks for the same underlying artifacts under different names: an inventory of AI systems, a risk or impact assessment per system, defined roles and oversight, data governance for training and inference, documentation and transparency for users, supplier controls, monitoring, and incident handling. Build one control library around those artifacts, map each control to the ISO 42001 clause or Annex A control, the NIST AI RMF subcategory, and the EU AI Act article it satisfies, and collect evidence against the control rather than the framework. When the next framework or state law arrives, you add a column to the mapping rather than a new program.
Frequently asked questions
Which AI governance framework is best?
There is no single best. ISO 42001 is best for proving governance to others, the NIST AI RMF is best for managing risk internally, and the EU AI Act is best because you have no choice if you are in scope. Most mature programs use all three.
Is the NIST AI RMF mandatory in the United States?
No. It is voluntary, but it is referenced in federal procurement guidance and in several state laws as a reasonable-care benchmark, so adopting it reduces legal exposure even where nothing requires it.
Does ISO 42001 certification prove EU AI Act compliance?
Not by itself. Certification shows you run a governed AI program, and it covers much of Article 17’s quality management requirements for providers, but high-risk systems still need conformity assessment against the Act’s specific requirements. Harmonised standards, once adopted, will give a presumption of conformity; ISO 42001 is not one of them. See EU AI Act vs ISO 42001 for the gap analysis.
Can a small company use these frameworks?
Yes. ISO 42001 scales with the size of the AI footprint, the NIST AI RMF can be applied to a single system, and the EU AI Act includes lighter obligations for SMEs. The minimum for any company is an inventory, a policy, and a risk assessment for each system that affects people.
How does SOC 2 relate to these frameworks?
SOC 2 is a security, availability, and privacy attestation, not an AI governance framework, although auditors increasingly ask about AI use under the existing criteria. It complements ISO 42001 rather than replacing it; see ISO 42001 vs SOC 2.
Where do ISO/IEC 23894 and 42005 fit if we already follow ISO 42001?
They are guidance, not requirements, and they fill the “how” that ISO 42001 leaves open: 23894 for the risk assessment method and 42005 for impact assessments. Adopting them is the easiest way to show an auditor that your clause 6 and Annex A.5 processes are grounded in a recognized method.
Running every framework from one program
The comparison table is useful for choosing; the mapping is what makes the choice sustainable. Compyl ships a control library that is pre-mapped across ISO 42001, the NIST AI RMF, and the EU AI Act, alongside ISO 27001 and SOC 2, so each policy, risk assessment, and piece of evidence is collected once and reported against every framework that cites it. Your AI system inventory, risk register, and vendor reviews live in the same place as the rest of your compliance program, and adding a new framework is a mapping exercise rather than a rebuild. Request a demo to see the cross-framework mapping in action.