If you are standing up AI governance, someone has probably already asked you the question: are we following NIST or ISO? It sounds like a fork in the road. It is not really. The two were built for different jobs, and treating them as rivals leads to a weaker program than using each for what it does well.
Here is the plain version of what each one is, where it helps, and how to run both without doubling your work.
What NIST AI RMF actually is
The NIST AI Risk Management Framework is a voluntary framework from the U.S. National Institute of Standards and Technology. Its job is to give you a shared way to think and talk about AI risk. It organizes the work into a handful of functions, the familiar shape of which is govern, map, measure, and manage. Govern sets the culture and accountability. Map figures out the context and what could go wrong. Measure analyzes and tracks it. Manage acts on it.
What you get from NIST is vocabulary and structure for reasoning about risk. What you do not get is a certificate. It is guidance, not a standard you pass or fail. That is a feature, not a gap. It keeps it flexible and easy to adopt, and it maps cleanly onto risk processes you already run.
What ISO/IEC 42001 actually is
ISO/IEC 42001 is an international standard for an AI management system. If you have lived through ISO 27001 for information security, the shape will feel familiar. It defines the requirements for a management system, the ongoing set of policies, roles, processes, and controls that an organization operates and improves over time. The key word is system. It is not a one-time checklist. It is a way of running the function that can be audited and, importantly, certified by an accredited body.
What you get from ISO 42001 is a structure an auditor recognizes and a certification you can show a customer, a regulator, or a board. What it does not hand you is the detailed risk vocabulary for reasoning through a specific AI system. That is the part NIST is good at.
Why the "versus" framing is the wrong one
Read those two descriptions back to back and the answer becomes obvious. One gives you the language and method for handling AI risk. The other gives you the management structure and the certifiable proof that you are handling it. They meet in the middle rather than competing.
NIST tells you how to think about the risk. ISO tells you how to run the program that manages it. A serious operation needs both halves.
In practice, a strong program uses NIST AI RMF to drive the actual risk work, the classifying, assessing, and deciding, and organizes all of it inside the management-system structure that ISO 42001 expects. When the auditor arrives, the structure is there. When your team needs to reason through whether a new agent is safe to deploy, the risk vocabulary is there too.
How to run both without doubling the work
The fear people have is that adopting two frameworks means twice the effort. It does not, if you set it up right. The trick is a single control set that carries both mappings.
Build or adopt one library of controls. For each control, note which NIST function it supports and which ISO 42001 clause it satisfies. Now you have one program that answers both conversations. When someone asks how you align to NIST, you filter by the NIST column. When the ISO auditor asks about a clause, you filter by the ISO column. You did the work once.
One honest caution on mappings. Any crosswalk between frameworks is directional. It points you to the right neighborhood, but you still have to verify each mapping against the exact versions your organization has adopted, because the frameworks evolve and the fit is rarely one to one. Treat a mapping as a starting point that saves you weeks, not as a finished answer you can assert to an auditor without checking.
So which do you start with?
If you need a certificate to satisfy a customer or a regulator, ISO 42001 is the one that gets you there, and you should build toward it. If you just need to get a credible risk program running quickly and internally, NIST AI RMF is the faster on-ramp because there is nothing to certify and nothing to fail. Most mid-market teams start with the NIST-shaped risk work because it delivers value on day one, then grow it into the ISO structure as the certification need becomes real.
Either way, you are not choosing a side. You are choosing an order.
One control set, both frameworks
The AI Governance Accelerator includes a 71-control library where every control carries both its NIST AI RMF and ISO/IEC 42001 mapping, so one program answers both conversations. Do the work once.
Get the Toolkit →