# NIST AI RMF vs ISO/IEC 42001: Which Should a Bank Use?

Source: https://www.bankingnewsai.com/ai-regulation/compare/nist-ai-rmf-vs-iso-42001
Last updated: Sep 24, 2026

## What is the difference between NIST AI RMF and ISO 42001?

The NIST AI RMF is a free framework "intended for voluntary use", organised around four functions (Govern, Map, Measure, Manage); ISO/IEC 42001 is a paid international standard that "specifies requirements" for an AI management system, and organisations can be audited and certified against it under ISO/IEC 42006. A bank can use the RMF to structure AI risk work and 42001 to prove a management system to third parties. Neither is named in SR 26-2 or the EU AI Act. [1][2][3][4][5][6]

## At a glance

|  | NIST AI RMF | ISO/IEC 42001 |
| --- | --- | --- |
| Instrument | NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0, January 2023), with the Generative AI Profile (NIST AI 600-1, July 2024) | ISO/IEC 42001:2023, Information technology — Artificial intelligence — Management system (Edition 1, December 2023) |
| Status | Published; being revised under the White House AI Action Plan | Published Dec 18, 2023; certification bodies governed by ISO/IEC 42006 |
| In the tracker | [NIST AI RMF 1.0](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-100-1), [NIST AI 600-1 (Generative AI Profile)](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-600-1), [NIST AI RMF Playbook](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-rmf-playbook) ([NIST](https://www.bankingnewsai.com/ai-regulation/nist)) | Not a tracked regulatory document (see sources) |

## How do the NIST AI RMF and ISO/IEC 42001 differ?

| Dimension | NIST AI RMF | ISO/IEC 42001 |
| --- | --- | --- |
| What it is | A framework to "better manage risks to individuals, organizations, and society associated with artificial intelligence", released January 26, 2023. [1] | "The world's first AI management system standard"; it "specifies requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System (AIMS)". [3] |
| Nature | "Intended to be voluntary, rights-preserving, non-sector-specific, and use-case agnostic". [2] | A "management system standard (MSS)": implementing it "means putting in place policies and procedures for the sound governance of an organization in relation to AI, using the Plan‐Do‐Check‐Act methodology". [3] |
| Structure | Four functions, GOVERN, MAP, MEASURE and MANAGE; "Governance is designed to be a cross-cutting function to inform and be infused throughout the other three functions." [2] | Management-system clauses (for example 4.1 understanding the organization and its context, 6.1.2 AI risk assessment, 6.1.3 AI risk treatment, 8.4 AI system impact assessment) and Annex B items such as B.2.2 AI policy, as mapped in the NIST-listed crosswalk. [7] |
| Certification | No certification scheme: a voluntary framework organisations adapt to their context. [2] | ISO/IEC 42006 "sets out the additional requirements for bodies that audit and certify artificial intelligence management systems (AIMS) according to ISO/IEC 42001". [4] |
| Cost and access | "This publication is available free of charge" from NIST. [2] | Sold by ISO: 51 pages, listed at CHF 225. [3] |
| Who it is for | Organizations "designing, developing, deploying, or using AI systems", of all sizes and in all sectors. [2] | "Organizations of any size involved in developing, providing, or using AI-based products or services", across all industries. [3] |
| Generative AI | NIST AI 600-1 (July 2024) is "a cross-sectoral profile of and companion resource for" the AI RMF for generative AI, listing twelve risks from CBRN information to value chain and component integration, including "Confabulation". [8] | The standard is designed to be applicable "across various AI applications and contexts". [3] |
| How the two connect | NIST's AI Resource Center lists a crosswalk from the AI RMF to ISO/IEC 42001, submitted by the user community; listing "does not imply NIST endorsement". [9] | The crosswalk maps RMF subcategories to 42001 clauses, e.g. Govern 1.1 (legal and regulatory requirements) to 4.1 and 6.2, and Govern 1.3 to 6.1.2 AI risk assessment. [7] |
| Status | "The AI RMF 1.0 is being revised as part of the White House AI Action Plan." [1] | Published December 18, 2023, Edition 1, by ISO/IEC JTC 1/SC 42. [3] |
| Named in bank-relevant law | Colorado SB 24-205 required a deployer's risk management policy and program to be reasonable considering "the latest version" of the NIST AI RMF, ISO/IEC 42001 or another recognized framework; SB 26-189, which repealed and reenacted it, names neither framework. [10][11] | SB 24-205 named "standard ISO/IEC 42001" alongside the RMF. SR 26-2 and the EU AI Act name neither; the AI Act presumes conformity only for harmonised standards published in the Official Journal (Article 40). [10][5][6] |

## How should a bank use the two together?

- SR 26-2 references neither framework, and it leaves generative and agentic AI to a bank's broader risk management and governance practices. [5]
- Use the RMF and the Generative AI Profile as the risk vocabulary for AI outside the model risk perimeter, such as generative assistants, since AI 600-1 was written for generative AI risks. [8][5]
- Consider 42001 certification where a third party needs evidence of an AI management system, for example vendors assuring a bank or a bank assuring clients; certification bodies work to ISO/IEC 42006. [4]
- Do not treat 42001 certification as EU AI Act conformity: presumption of conformity attaches to harmonised standards whose references are published in the Official Journal. [6]
- Map once: the crosswalk listed by NIST links RMF subcategories to 42001 clauses, but NIST says listing implies neither endorsement nor that either resource comprehensively covers the other. [9][7]
- Expect change on the NIST side: the RMF is being revised under the White House AI Action Plan. [1]

## Timeline

- Jan 26, 2023 — NIST AI RMF: NIST releases AI RMF 1.0 (NIST AI 100-1). [1]
- Dec 18, 2023 — ISO/IEC 42001: ISO/IEC 42001:2023 published. [3]
- May 17, 2024 — Both: Colorado SB 24-205 signed, referencing both the NIST AI RMF and ISO/IEC 42001 (later repealed and reenacted by SB 26-189). [10]
- Jul 26, 2024 — NIST AI RMF: NIST AI 600-1, the Generative AI Profile, published. [1][8]
- Jul 7, 2025 — ISO/IEC 42001: ISO/IEC 42006 published: requirements for bodies certifying AI management systems to ISO/IEC 42001. [4]
- May 14, 2026 — Both: Colorado SB 26-189 replaces SB 24-205 without naming either framework. [11]

## What is still open?

- NIST is revising the AI RMF 1.0; the revised text, and how it lines up with ISO/IEC 42001, is not yet published. [1]

## FAQ

### Is the NIST AI RMF mandatory for banks?

No. NIST says the framework is intended for voluntary use, and the US interagency model risk guidance (SR 26-2) does not reference it. [1][5]

### Can a bank be certified to ISO/IEC 42001?

Yes: ISO/IEC 42001 specifies requirements for an AI management system, and ISO/IEC 42006 sets the requirements for bodies that audit and certify organisations against it. [3][4]

### Is there a crosswalk between the NIST AI RMF and ISO/IEC 42001?

Yes. NIST's AI Resource Center lists a community-submitted crosswalk mapping AI RMF subcategories to ISO/IEC 42001 clauses; NIST notes listing does not imply endorsement or that either resource fully covers the other. [9][7]

### Does ISO/IEC 42001 certification satisfy the EU AI Act?

Not by itself. The AI Act gives a presumption of conformity to high-risk systems that conform to harmonised standards published in the Official Journal; the Act does not name ISO/IEC 42001. [6]

### Which covers generative AI?

NIST has a dedicated Generative AI Profile (AI 600-1) that lists twelve generative-AI risks; ISO/IEC 42001 is designed to apply across various AI applications and contexts. [8][3]

### What are the four functions of the NIST AI RMF?

Govern, Map, Measure and Manage, with governance designed as a cross-cutting function that informs the other three. [2]

## Sources

1. [AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework) — National Institute of Standards and Technology, Jan 26, 2023
2. [NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0)](https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf) — National Institute of Standards and Technology, Jan 26, 2023
3. [ISO/IEC 42001:2023, Information technology — Artificial intelligence — Management system](https://www.iso.org/standard/42001) — International Organization for Standardization, Dec 18, 2023
4. [ISO/IEC 42006:2025, requirements for bodies providing audit and certification of AI management systems](https://www.iso.org/standard/42006) — International Organization for Standardization, Jul 7, 2025
5. [Supervisory Guidance on Model Risk Management (SR 26-2 attachment)](https://www.federalreserve.gov/supervisionreg/srletters/SR2602a1.pdf) — Federal Reserve Board, FDIC and OCC, Apr 17, 2026
6. [Regulation (EU) 2024/1689 (Artificial Intelligence Act)](https://eur-lex.europa.eu/eli/reg/2024/1689/oj) — Official Journal of the European Union (EUR-Lex), Jul 12, 2024
7. [NIST AI RMF to ISO/IEC FDIS 42001 AI Management System Crosswalk](https://airc.nist.gov/docs/NIST_AI_RMF_to_ISO_IEC_42001_Crosswalk.pdf) — NIST AI Resource Center (community-submitted crosswalk), May 23, 2023
8. [NIST AI 600-1, Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile](https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf) — National Institute of Standards and Technology, Jul 26, 2024
9. [Crosswalk Documents (AI RMF resources)](https://airc.nist.gov/airmf-resources/crosswalks) — NIST Trustworthy and Responsible AI Resource Center, Apr 15, 2026
10. [Colorado SB 24-205, Consumer Protections for Artificial Intelligence (signed act)](https://leg.colorado.gov/bill_files/47770/download) — Colorado General Assembly, May 17, 2024
11. [Colorado SB 26-189, Concerning the Use of Automated Decision-Making Technology in Consequential Decisions (signed act)](https://leg.colorado.gov/bill_files/116489/download) — Colorado General Assembly, May 14, 2026

Other comparisons: [SR 11-7 vs SR 26-2](https://www.bankingnewsai.com/ai-regulation/compare/sr-11-7-vs-sr-26-2), [OCC vs CFPB on AI lending](https://www.bankingnewsai.com/ai-regulation/compare/occ-vs-cfpb-ai-lending), [EU AI Act vs Colorado AI Act](https://www.bankingnewsai.com/ai-regulation/compare/eu-ai-act-vs-colorado-ai-act), [PRA SS1/23 vs SR 26-2](https://www.bankingnewsai.com/ai-regulation/compare/pra-ss1-23-vs-sr-26-2). [All comparisons](https://www.bankingnewsai.com/ai-regulation/compare).

---

Canonical page: https://www.bankingnewsai.com/ai-regulation/compare/nist-ai-rmf-vs-iso-42001
Part of [BankingNewsAI](https://www.bankingnewsai.com/) — a free daily brief on AI in banking, an AI regulation tracker (19 authorities, 167 documents) and AI-strategy profiles of the 100 largest US banks. Markdown versions of every reference page: append `.md` to the page URL; index at https://www.bankingnewsai.com/llms.txt.
