NIST AI RMF vs ISO 42001: what they share and how they differ
NIST AI RMF and ISO 42001 share 11 of 24 control themes and 16 checks. 92% of ISO 42001 requirements can be proven with checks NIST AI RMF already uses, 47% the other way round.
Voluntary
NIST AI RMF
How to apply the NIST AI RMF to your AI systems
72 requirementsNext Dec 2026
Voluntary
ISO 42001
How to prepare for ISO/IEC 42001 certification
13 requirementsNext Dec 2026
11/24shared control themes
16shared checks
92%of ISO 42001 requirements covered by NIST AI RMF evidence
47%of NIST AI RMF requirements covered by ISO 42001 evidence
At a glance
| NIST AI RMF | ISO 42001 | |
|---|---|---|
| Jurisdiction | United States (federal) | International |
| Kind | Voluntary framework | Certifiable standard |
| Status | Voluntary same | Voluntary same |
| Binding | No same | No same |
| Object analysed | AI system | Organisation |
| Scope | Any organisation designing, deploying or using AI. | Organisations providing or using AI systems. |
| Territorial reach | No territorial scope; de facto reference for US public buyers. | International. |
| Penalties | None (voluntary). Leverage: safe harbour in state laws. | None; certification lost or refused. |
| Qualification axes | Internal risk tier (organisation-defined) | System impact level (Cl. 6.1.4) |
| Roles | AI actor | Provider, User, Producer |
| Requirements | 72 | 13 |
| Next milestone | Dec 2026, Expected RMF revision | Dec 2026, CEN-CENELEC JTC 21 harmonised standards for the AI Act (prEN 18286 QMS) |
Theme by theme
requirements per theme
NIST AI RMFISO 42001
Governance
Assessment
Build
People & use
Lifecycle & third parties
What they share: one piece of evidence, two frameworks
16
| Code | Check | Requirements NIST AI RMF | Requirements ISO 42001 |
|---|---|---|---|
| CHK-LEGAL-MAP | Applicable legal and regulatory requirements for AI are identified, mapped and monitored | ||
| CHK-POL-TRUST | Trustworthy-AI characteristics are embedded in organizational policies and a safety-first culture | ||
| CHK-POL-RISK | An AI risk-management policy and process are established through transparent, documented controls | ||
| CHK-ROLES-CLARIFIED | Roles, responsibilities and delegated authorities are documented and clear to relevant stakeholders | ||
| CHK-REVIEW-PLAN | Ongoing monitoring and periodic review of the risk-management process are planned, with defined roles and review frequency | ||
| VER-022-F-01 | Risk and incident response procedure | ||
| CHK-TRAINING | Personnel and partners receive AI risk-management training | ||
| CHK-EXEC-ACCOUNT | Executive leadership is accountable for AI risk decisions (board committee, risk appetite) | ||
| VER-008-03 | Competent overseers assigned to the system | ||
| CHK-IMPACT-ASSESS | An impact assessment is performed, documented and used in go/no-go and risk decisions | ||
| CHK-THIRDPARTY-POL | Policies address third-party AI/data risks, incl. IP, transparency and testing | ||
| CHK-TEVV | TEVV plan, test sets, metrics and data considerations are documented | ||
| VER-021-F-01 | Operational monitoring plan | ||
| VER-003-01 | Documented and up-to-date risk register | ||
| CHK-RISK-RESPONSE | Risk treatment is prioritized and high-priority responses are planned and documented | ||
| CHK-CONTINUAL-IMPROVE | Continual-improvement activities are integrated with stakeholder engagement |
Differences: requirements specific to each framework
Requirements with no check serving the other framework: the extra work.
NIST AI RMF
38
GOVERN-1.6
MAP-1.3
MAP-3.1
MEASURE-2.2
MEASURE-2.7
MEASURE-2.8
MEASURE-2.10
MEASURE-2.11
MEASURE-2.12
MEASURE-3.3
MANAGE-3.1
ISO 42001
1
Timelines
PastSet in the textPotentialTo verify
Jan 26, 2023NIST AI RMF · AI RMF 1.0
Dec 18, 2023ISO 42001 · ISO/IEC 42001 published
Jul 26, 2024NIST AI RMF · Generative AI Profile (NIST AI 600-1)
May 2025ISO 42001 · ISO/IEC 42005 (impact assessment)
Jul 2025ISO 42001 · ISO/IEC 42006 (certification bodies)
Jul 23, 2025NIST AI RMF · AI Action Plan asks for a revision of the framework
Dec 2026NIST AI RMF · Expected RMF revision
Dec 2026ISO 42001 · CEN-CENELEC JTC 21 harmonised standards for the AI Act (prEN 18286 QMS)
Run these requirements across all your AI systems
TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.