Compyl
GRC Your Way

ISO 42001 vs EU AI Act vs NIST AI RMF: How the Three Fit Together

Last updated: September 10, 2026

ISO 42001, the EU AI Act, and the NIST AI RMF are not competing options. ISO/IEC 42001:2023 is a certifiable management system standard, the EU AI Act is a binding law with fines attached, and the NIST AI Risk Management Framework is voluntary guidance for structuring how you think about AI risk. Most organizations that build or deploy AI at scale end up using all three: NIST AI RMF to organize the work, ISO 42001 to prove it to customers, and the EU AI Act as the legal floor they cannot fall below if they touch the EU market.

This three-way comparison is part of our AI governance guide. If you want the pairwise versions, we also cover NIST AI RMF vs ISO 42001 and EU AI Act vs ISO 42001 separately.

Key takeaways

  • Only the EU AI Act is mandatory. ISO 42001 is voluntary but certifiable. NIST AI RMF is voluntary and has no certification.
  • ISO 42001 tells you how to run an AI management system. The EU AI Act tells you which AI systems are restricted and what obligations attach to them. NIST AI RMF tells you how to reason about AI risk.
  • The frameworks overlap heavily on risk assessment, documentation, human oversight, data governance, and monitoring, which is why a single set of controls can serve all three.
  • Following the Digital Omnibus on AI (Regulation (EU) 2026/1744), Annex III high-risk obligations under the EU AI Act now apply from December 2, 2027, and Annex I product-embedded high-risk systems from August 2, 2028.
  • The practical sequence for most companies: adopt NIST AI RMF vocabulary, build an ISO 42001 management system, and map EU AI Act obligations into it as legal requirements.

What is each framework, in one paragraph?

ISO/IEC 42001:2023

ISO 42001 is the first international standard for an artificial intelligence management system (AIMS). It was published by ISO and IEC in December 2023 and follows the same harmonized structure as ISO 27001 and ISO 9001: Clauses 4 through 10 cover context, leadership, planning, support, operation, performance evaluation, and improvement. Annex A lists 38 controls grouped under nine control objectives, and Annex B provides implementation guidance for each. Accredited certification bodies audit against it, and a certificate is valid for three years with annual surveillance audits. We cover the details in our guide to ISO 42001 requirements.

The EU AI Act

The EU AI Act (Regulation (EU) 2024/1689) is the world’s first comprehensive AI law. It entered into force on August 1, 2024, and applies to providers, deployers, importers, and distributors of AI systems placed on the EU market or whose output is used in the EU, regardless of where the company is based. It classifies AI systems by risk (unacceptable, high, limited, minimal) and adds a separate regime for general-purpose AI models. Non-compliance can cost up to EUR 35 million or 7 percent of global annual turnover for prohibited practices, and up to EUR 15 million or 3 percent for most other violations. Our post on EU AI Act compliance in 2026 walks through the obligations by role.

NIST AI RMF 1.0

The NIST AI Risk Management Framework was released by the US National Institute of Standards and Technology in January 2023. It is voluntary, sector-agnostic, and organized into four functions: Govern, Map, Measure, and Manage, which break down into 19 categories and 72 subcategories. NIST also publishes a companion Playbook with suggested actions and, in July 2024, released the Generative AI Profile (NIST AI 600-1) covering 12 risks specific to generative models. There is no certification and no auditor, but US federal procurement, state laws, and many enterprise vendor questionnaires reference it. See our NIST AI RMF explainer for the full structure.

How do ISO 42001, the EU AI Act, and NIST AI RMF compare side by side?

DimensionISO/IEC 42001EU AI ActNIST AI RMF
TypeInternational management system standardBinding EU regulationVoluntary US framework
PublisherISO and IECEuropean Parliament and CouncilNIST (US Department of Commerce)
Published / in forceDecember 2023In force August 1, 2024; phased application through 2028January 2023 (Generative AI Profile July 2024)
Mandatory?No, unless required by contractYes, for in-scope systems on the EU marketNo, except where referenced by law or contract
Certification available?Yes, via accredited certification bodiesConformity assessment and CE marking for high-risk systems; no general certificateNo
ScopeThe organization’s whole AI management systemSpecific AI systems and GPAI models by risk classAI risk across the lifecycle of any system
Core structureClauses 4 to 10 plus 38 Annex A controlsRisk tiers, provider and deployer obligations, GPAI obligations, governance and enforcement chaptersGovern, Map, Measure, Manage; 72 subcategories
Risk approachOrganization defines risk criteria and runs AI risk and impact assessmentsLegislator predefines risk categories; high-risk systems need a risk management systemOrganization maps context, measures risk, manages response
PenaltiesNone (loss of certificate)Up to EUR 35M or 7% of global turnoverNone
Best forProving governance to customers and auditorsLegal compliance for EU market accessInternal vocabulary, US federal and state alignment
Typical ownerCompliance, security, or GRC leadLegal and product, with compliance supportRisk, data science, or AI governance lead

Where do the three frameworks overlap?

The overlap is larger than most teams expect. All three require you to know what AI systems you have, understand their intended purpose and context, assess and treat risk, keep documentation, provide for human oversight, govern data quality, monitor performance after deployment, and handle incidents. The differences are mostly in framing and rigor, not in substance.

A few concrete mappings illustrate the point. ISO 42001 Clause 6.1 (actions to address risks and opportunities) and controls A.5 (AI system impact assessment) and A.6 (AI system lifecycle) line up with NIST AI RMF Map and Measure, and with EU AI Act Article 9 (risk management system) and Article 27 (fundamental rights impact assessment for certain deployers). ISO 42001 A.4 (resources) and A.7 (data for AI systems) map to NIST Govern and Map subcategories on data provenance and to EU AI Act Article 10 (data and data governance). ISO 42001 Clause 9 (performance evaluation) and A.6.2.6 (operation and monitoring) correspond to NIST Measure and Manage and to EU AI Act Article 72 (post-market monitoring).

Because of this, organizations that treat the three as separate projects end up with three inventories, three risk registers, and three sets of evidence. The better pattern is one control library with each control tagged to the clause, article, or subcategory it satisfies. Our ISO 42001 vs ISO 27001 comparison shows how the same approach works when you add security frameworks to the mix.

Where do they diverge?

Legal force

The EU AI Act is the only one of the three that can fine you. It also imposes obligations that no voluntary framework does: registration of high-risk systems in the EU database, CE marking, appointment of an EU authorized representative for non-EU providers, transparency notices for chatbots and synthetic media, and AI literacy obligations for staff under Article 4. ISO 42001 and NIST AI RMF will help you build the evidence, but they do not replace a legal gap analysis.

Proof

Only ISO 42001 produces an independent certificate. When a customer’s procurement team asks for evidence of AI governance, “we follow NIST AI RMF” is a statement; an ISO 42001 certificate is a verified fact. The EU AI Act’s conformity assessment for high-risk systems is proof of a different kind: it demonstrates that a specific system meets legal requirements, not that your organization manages AI well overall.

Granularity

NIST AI RMF is the most granular in its treatment of risk concepts (trustworthiness characteristics, socio-technical context, measurement approaches) and the least prescriptive about organizational machinery. ISO 42001 is the opposite: highly prescriptive about management system mechanics (scope, policy, roles, internal audit, management review) and comparatively light on technical detail. The EU AI Act sits between them, prescriptive on outcomes for high-risk systems and silent on how to organize.

Geography

The EU AI Act applies based on market, not headquarters. A US SaaS company with EU customers is in scope. NIST AI RMF carries the most weight in the US, where it is referenced in federal guidance, the Colorado AI Act’s affirmative defense provisions, and many state-level proposals. ISO 42001 is recognized globally and is the most portable of the three across jurisdictions.

What are the current EU AI Act deadlines that affect this decision?

Timing matters because it determines how urgent the legal track is relative to the voluntary ones. The prohibitions on unacceptable-risk practices and the AI literacy obligation have applied since February 2, 2025. General-purpose AI model obligations have applied since August 2, 2025. The Digital Omnibus on AI, published in the Official Journal on July 24, 2026 and in force since July 27, 2026, moved the Annex III standalone high-risk deadline from August 2, 2026 to December 2, 2027, and the Annex I product-embedded high-risk deadline from August 2, 2027 to August 2, 2028. If you deploy high-risk systems, that is your outer bound; if you use only limited-risk or minimal-risk systems, your obligations are already live and are mostly about transparency and literacy. Our EU AI Act compliance timeline tracks these dates.

Which framework should you start with?

The honest answer depends on three questions: who is asking, where you sell, and how mature your program is.

If customers or regulators are asking for proof, start with ISO 42001. It gives you a defensible structure, an auditable evidence trail, and a certificate. You will find that building the management system forces you to answer most NIST AI RMF questions anyway, and its risk and impact assessment controls give you the scaffolding for EU AI Act Article 9 and Article 27 work.

If you sell into the EU and any of your systems could plausibly be high-risk (employment, credit, education, critical infrastructure, biometrics, essential services, law enforcement, migration, justice), start with an EU AI Act classification exercise. You need to know your legal exposure before you design a management system around it. Then build ISO 42001 with those obligations baked in.

If you are early, US-focused, and mostly trying to get engineering, legal, and risk speaking the same language, start with NIST AI RMF. It is free, readable, and fast to adopt. Use the Govern function to stand up basic policy and roles, use Map to build your AI system inventory, and graduate to ISO 42001 when someone asks for a certificate. Our NIST AI RMF implementation guide lays out that path.

How do you run all three without tripling the work?

Treat ISO 42001 as the operating system and the other two as requirement sets that plug into it. In practice this looks like: one AI system inventory with fields for EU AI Act risk classification and NIST Map context; one risk assessment methodology that satisfies ISO 42001 Clause 6.1, EU AI Act Article 9, and NIST Measure; one impact assessment template that serves ISO 42001 A.5 and EU AI Act Article 27; one control library with crosswalk tags; and one evidence repository that your ISO auditor, your EU conformity assessment, and your customer questionnaires all draw from. The cost of doing this well up front is far lower than reconciling three parallel programs later.

Frequently asked questions

Does ISO 42001 certification mean you comply with the EU AI Act?

No. ISO 42001 is not a harmonized standard under the AI Act and a certificate does not create a presumption of conformity. It does, however, provide most of the organizational evidence the Act expects, such as risk management, documentation, and monitoring. You still need a legal gap analysis for the system-specific obligations.

Is the NIST AI RMF legally required anywhere?

Not directly. It is voluntary, but it is referenced in US federal guidance and in some state laws. The Colorado AI Act, for example, allows use of the NIST AI RMF as part of an affirmative defense. Contracts with US federal agencies and large enterprises increasingly ask for alignment with it.

Can a US company ignore the EU AI Act?

Only if it has no AI systems on the EU market and no system output used in the EU. The Act applies extraterritorially. If you have EU customers, users, or partners, assume you are in scope and classify your systems.

Which is cheaper: ISO 42001 or NIST AI RMF?

NIST AI RMF is free to adopt and has no audit. ISO 42001 involves implementation effort plus certification fees, which for most mid-sized organizations land in the tens of thousands of dollars over the three-year cycle. See our post on ISO 42001 certification cost for ranges.

Do the three frameworks conflict anywhere?

Rarely. They use different vocabulary (NIST’s “trustworthiness characteristics” versus ISO’s “AI system impact” versus the Act’s “fundamental rights”), but the underlying expectations are compatible. The main friction is scope: the EU AI Act is system-specific, ISO 42001 is organization-wide, and NIST AI RMF can be applied at either level.

Should a startup bother with any of this?

Yes, at least at the inventory and policy level. The AI literacy and transparency obligations under the EU AI Act already apply, enterprise buyers are asking about AI governance in security reviews, and building an inventory and risk process early is far cheaper than retrofitting one after you have fifty models in production.

Bringing it together

ISO 42001, the EU AI Act, and the NIST AI RMF answer three different questions: how to run AI governance, what the law requires, and how to reason about AI risk. The organizations that handle this well pick one operating model and map the rest into it. Compyl gives you a single platform to inventory AI systems, run risk and impact assessments, manage a crosswalked control library, and collect evidence once for ISO 42001, the EU AI Act, and NIST AI RMF. If you are deciding where to start, our team can help you map your current position against all three.

By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies