NIST AI RMF vs ISO 42001: what they share and how they differ

NIST AI RMF and ISO 42001 share 11 of 24 control themes and 16 checks. 92% of ISO 42001 requirements can be proven with checks NIST AI RMF already uses, 47% the other way round.

USVoluntary frameworkVoluntary

NIST AI RMF

How to apply the NIST AI RMF to your AI systems

72 requirementsNext Dec 2026
INTLCertifiable standardVoluntary

ISO 42001

How to prepare for ISO/IEC 42001 certification

13 requirementsNext Dec 2026
11/24shared control themes
16shared checks
92%of ISO 42001 requirements covered by NIST AI RMF evidence
47%of NIST AI RMF requirements covered by ISO 42001 evidence

At a glance

NIST AI RMF ISO 42001
JurisdictionUnited States (federal)International
KindVoluntary frameworkCertifiable standard
StatusVoluntary sameVoluntary same
BindingNo sameNo same
Object analysedAI systemOrganisation
ScopeAny organisation designing, deploying or using AI.Organisations providing or using AI systems.
Territorial reachNo territorial scope; de facto reference for US public buyers.International.
PenaltiesNone (voluntary). Leverage: safe harbour in state laws.None; certification lost or refused.
Qualification axesInternal risk tier (organisation-defined)System impact level (Cl. 6.1.4)
RolesAI actorProvider, User, Producer
Requirements7213
Next milestoneDec 2026, Expected RMF revisionDec 2026, CEN-CENELEC JTC 21 harmonised standards for the AI Act (prEN 18286 QMS)

Theme by theme

requirements per theme

What they share: one piece of evidence, two frameworks

16

CodeCheckRequirements NIST AI RMFRequirements ISO 42001
CHK-LEGAL-MAPApplicable legal and regulatory requirements for AI are identified, mapped and monitored
CHK-POL-TRUSTTrustworthy-AI characteristics are embedded in organizational policies and a safety-first culture
CHK-POL-RISKAn AI risk-management policy and process are established through transparent, documented controls
CHK-ROLES-CLARIFIEDRoles, responsibilities and delegated authorities are documented and clear to relevant stakeholders
CHK-REVIEW-PLANOngoing monitoring and periodic review of the risk-management process are planned, with defined roles and review frequency
VER-022-F-01Risk and incident response procedure
CHK-TRAININGPersonnel and partners receive AI risk-management training
CHK-EXEC-ACCOUNTExecutive leadership is accountable for AI risk decisions (board committee, risk appetite)
VER-008-03Competent overseers assigned to the system
CHK-IMPACT-ASSESSAn impact assessment is performed, documented and used in go/no-go and risk decisions
CHK-THIRDPARTY-POLPolicies address third-party AI/data risks, incl. IP, transparency and testing
CHK-TEVVTEVV plan, test sets, metrics and data considerations are documented
VER-021-F-01Operational monitoring plan
VER-003-01Documented and up-to-date risk register
CHK-RISK-RESPONSERisk treatment is prioritized and high-priority responses are planned and documented
CHK-CONTINUAL-IMPROVEContinual-improvement activities are integrated with stakeholder engagement

Differences: requirements specific to each framework

Requirements with no check serving the other framework: the extra work.

NIST AI RMF

38

Timelines

PastSet in the textPotentialTo verify
Jan 26, 2023NIST AI RMF · AI RMF 1.0
Dec 18, 2023ISO 42001 · ISO/IEC 42001 published
Jul 26, 2024NIST AI RMF · Generative AI Profile (NIST AI 600-1)
May 2025ISO 42001 · ISO/IEC 42005 (impact assessment)
Jul 2025ISO 42001 · ISO/IEC 42006 (certification bodies)
Jul 23, 2025NIST AI RMF · AI Action Plan asks for a revision of the framework
Dec 2026NIST AI RMF · Expected RMF revision
Dec 2026ISO 42001 · CEN-CENELEC JTC 21 harmonised standards for the AI Act (prEN 18286 QMS)

Run these requirements across all your AI systems

TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.

Request a demo