What is the difference between NIST AI RMF and ISO 42001?
The NIST AI RMF is a free framework "intended for voluntary use", organised around four functions (Govern, Map, Measure, Manage); ISO/IEC 42001 is a paid international standard that "specifies requirements" for an AI management system, and organisations can be audited and certified against it under ISO/IEC 42006. A bank can use the RMF to structure AI risk work and 42001 to prove a management system to third parties. Neither is named in SR 26-2 or the EU AI Act.[1][2][3][4][5][6]
| NIST AI RMF | ISO/IEC 42001 | |
|---|---|---|
| Instrument | NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0, January 2023), with the Generative AI Profile (NIST AI 600-1, July 2024) | ISO/IEC 42001:2023, Information technology — Artificial intelligence — Management system (Edition 1, December 2023) |
| Status | Published; being revised under the White House AI Action Plan | Published Dec 18, 2023; certification bodies governed by ISO/IEC 42006 |
| In the tracker | NIST AI RMF 1.0 · NIST AI 600-1 (Generative AI Profile) · NIST AI RMF Playbook Authority: NIST | Not a tracked regulatory document — see the sources below |
How do the NIST AI RMF and ISO/IEC 42001 differ?
| Dimension | NIST AI RMF | ISO/IEC 42001 |
|---|---|---|
| What it is | A framework to "better manage risks to individuals, organizations, and society associated with artificial intelligence", released January 26, 2023.[1] | "The world's first AI management system standard"; it "specifies requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System (AIMS)".[3] |
| Nature | "Intended to be voluntary, rights-preserving, non-sector-specific, and use-case agnostic".[2] | A "management system standard (MSS)": implementing it "means putting in place policies and procedures for the sound governance of an organization in relation to AI, using the Plan‐Do‐Check‐Act methodology".[3] |
| Structure | Four functions, GOVERN, MAP, MEASURE and MANAGE; "Governance is designed to be a cross-cutting function to inform and be infused throughout the other three functions."[2] | Management-system clauses (for example 4.1 understanding the organization and its context, 6.1.2 AI risk assessment, 6.1.3 AI risk treatment, 8.4 AI system impact assessment) and Annex B items such as B.2.2 AI policy, as mapped in the NIST-listed crosswalk.[7] |
| Certification | No certification scheme: a voluntary framework organisations adapt to their context.[2] | ISO/IEC 42006 "sets out the additional requirements for bodies that audit and certify artificial intelligence management systems (AIMS) according to ISO/IEC 42001".[4] |
| Cost and access | "This publication is available free of charge" from NIST.[2] | Sold by ISO: 51 pages, listed at CHF 225.[3] |
| Who it is for | Organizations "designing, developing, deploying, or using AI systems", of all sizes and in all sectors.[2] | "Organizations of any size involved in developing, providing, or using AI-based products or services", across all industries.[3] |
| Generative AI | NIST AI 600-1 (July 2024) is "a cross-sectoral profile of and companion resource for" the AI RMF for generative AI, listing twelve risks from CBRN information to value chain and component integration, including "Confabulation".[8] | The standard is designed to be applicable "across various AI applications and contexts".[3] |
| How the two connect | NIST's AI Resource Center lists a crosswalk from the AI RMF to ISO/IEC 42001, submitted by the user community; listing "does not imply NIST endorsement".[9] | The crosswalk maps RMF subcategories to 42001 clauses, e.g. Govern 1.1 (legal and regulatory requirements) to 4.1 and 6.2, and Govern 1.3 to 6.1.2 AI risk assessment.[7] |
| Status | "The AI RMF 1.0 is being revised as part of the White House AI Action Plan."[1] | Published December 18, 2023, Edition 1, by ISO/IEC JTC 1/SC 42.[3] |
| Named in bank-relevant law | Colorado SB 24-205 required a deployer's risk management policy and program to be reasonable considering "the latest version" of the NIST AI RMF, ISO/IEC 42001 or another recognized framework; SB 26-189, which repealed and reenacted it, names neither framework.[10][11] | SB 24-205 named "standard ISO/IEC 42001" alongside the RMF. SR 26-2 and the EU AI Act name neither; the AI Act presumes conformity only for harmonised standards published in the Official Journal (Article 40).[10][5][6] |
How should a bank use the two together?
- SR 26-2 references neither framework, and it leaves generative and agentic AI to a bank's broader risk management and governance practices.[5]
- Use the RMF and the Generative AI Profile as the risk vocabulary for AI outside the model risk perimeter, such as generative assistants, since AI 600-1 was written for generative AI risks.[8][5]
- Consider 42001 certification where a third party needs evidence of an AI management system, for example vendors assuring a bank or a bank assuring clients; certification bodies work to ISO/IEC 42006.[4]
- Do not treat 42001 certification as EU AI Act conformity: presumption of conformity attaches to harmonised standards whose references are published in the Official Journal.[6]
- Map once: the crosswalk listed by NIST links RMF subcategories to 42001 clauses, but NIST says listing implies neither endorsement nor that either resource comprehensively covers the other.[9][7]
- Expect change on the NIST side: the RMF is being revised under the White House AI Action Plan.[1]
When did each happen?
| Date | Instrument | Event |
|---|---|---|
| Jan 26, 2023 | NIST AI RMF | NIST releases AI RMF 1.0 (NIST AI 100-1).[1] |
| Dec 18, 2023 | ISO/IEC 42001 | ISO/IEC 42001:2023 published.[3] |
| May 17, 2024 | Both | Colorado SB 24-205 signed, referencing both the NIST AI RMF and ISO/IEC 42001 (later repealed and reenacted by SB 26-189).[10] |
| Jul 26, 2024 | NIST AI RMF | NIST AI 600-1, the Generative AI Profile, published.[1][8] |
| Jul 7, 2025 | ISO/IEC 42001 | ISO/IEC 42006 published: requirements for bodies certifying AI management systems to ISO/IEC 42001.[4] |
| May 14, 2026 | Both | Colorado SB 26-189 replaces SB 24-205 without naming either framework.[11] |
What is still open?
- NIST is revising the AI RMF 1.0; the revised text, and how it lines up with ISO/IEC 42001, is not yet published.[1]
Is the NIST AI RMF mandatory for banks?
No. NIST says the framework is intended for voluntary use, and the US interagency model risk guidance (SR 26-2) does not reference it.[1][5]
Can a bank be certified to ISO/IEC 42001?
Yes: ISO/IEC 42001 specifies requirements for an AI management system, and ISO/IEC 42006 sets the requirements for bodies that audit and certify organisations against it.[3][4]
Is there a crosswalk between the NIST AI RMF and ISO/IEC 42001?
Yes. NIST's AI Resource Center lists a community-submitted crosswalk mapping AI RMF subcategories to ISO/IEC 42001 clauses; NIST notes listing does not imply endorsement or that either resource fully covers the other.[9][7]
Does ISO/IEC 42001 certification satisfy the EU AI Act?
Not by itself. The AI Act gives a presumption of conformity to high-risk systems that conform to harmonised standards published in the Official Journal; the Act does not name ISO/IEC 42001.[6]
Which covers generative AI?
NIST has a dedicated Generative AI Profile (AI 600-1) that lists twelve generative-AI risks; ISO/IEC 42001 is designed to apply across various AI applications and contexts.[8][3]
What are the four functions of the NIST AI RMF?
Govern, Map, Measure and Manage, with governance designed as a cross-cutting function that informs the other three.[2]
- AI Risk Management Framework — National Institute of Standards and Technology, Jan 26, 2023 · tracker page
- NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0) — National Institute of Standards and Technology, Jan 26, 2023
- ISO/IEC 42001:2023, Information technology — Artificial intelligence — Management system — International Organization for Standardization, Dec 18, 2023
- ISO/IEC 42006:2025, requirements for bodies providing audit and certification of AI management systems — International Organization for Standardization, Jul 7, 2025
- Supervisory Guidance on Model Risk Management (SR 26-2 attachment) — Federal Reserve Board, FDIC and OCC, Apr 17, 2026
- Regulation (EU) 2024/1689 (Artificial Intelligence Act) — Official Journal of the European Union (EUR-Lex), Jul 12, 2024 · tracker page
- NIST AI RMF to ISO/IEC FDIS 42001 AI Management System Crosswalk — NIST AI Resource Center (community-submitted crosswalk), May 23, 2023
- NIST AI 600-1, Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile — National Institute of Standards and Technology, Jul 26, 2024 · tracker page
- Crosswalk Documents (AI RMF resources) — NIST Trustworthy and Responsible AI Resource Center, Apr 15, 2026
- Colorado SB 24-205, Consumer Protections for Artificial Intelligence (signed act) — Colorado General Assembly, May 17, 2024 · tracker page
- Colorado SB 26-189, Concerning the Use of Automated Decision-Making Technology in Consequential Decisions (signed act) — Colorado General Assembly, May 14, 2026 · tracker page
Every cell and answer on this page cites the official text it comes from; quotations are verbatim. Last reviewed Sep 24, 2026.
When either side of this comparison moves, the next morning's brief says so.
when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free
plus every tracker, bank and agent page update, the morning after · leave any morning