The frameworks: NIST, ISO 42001, and the EU AI Act
A plain-English tour of the three frameworks that shape AI governance.
You don't need to be a compliance expert, but any leader governing AI should know the three frameworks that shape the field. They're complementary: one gives you a risk process, one a management system to certify, and one is law with teeth.
NIST AI Risk Management Framework (AI RMF). A voluntary US framework (released 2023) that's become the common language for managing AI risk. Its structure is four functions worth knowing by name:
- GOVERN — the cross-cutting foundation: policies, accountability, roles, culture. (It runs through the other three.)
- MAP — understand context; inventory and categorize your AI use cases and their risks.
- MEASURE — assess and test those risks (accuracy, bias, security, privacy).
- MANAGE — prioritize, respond to, and monitor risks over time.
There's also a Generative AI Profile adding GenAI-specific risks (hallucination, data privacy, and more). Think of NIST as the process for how you handle AI risk — practical and non-certifiable.
ISO/IEC 42001. The first certifiable AI management system standard (2023) — the "ISO 27001 of AI." It specifies requirements for an AI Management System (governance, risk and impact assessments, controls, continual improvement) that a third-party auditor can certify. Major clouds and AI labs have certified (AWS, Anthropic, Microsoft). Think of ISO 42001 as the certifiable management system — increasingly a way to prove good governance to customers and regulators.
The EU AI Act. The world's most significant AI law (Regulation 2024/1689), and the one with real penalties (up to €35M or 7% of global turnover). It's risk-tiered:
- Unacceptable — banned outright (social scoring, certain manipulation).
- High-risk — heavy obligations (risk management, data governance, human oversight, documentation) for AI in sensitive areas like employment, credit, essential services, law enforcement.
- Limited — transparency duties (tell people they're talking to AI; label deepfakes).
- Minimal — most AI, unregulated.
Crucially, its extraterritorial reach means it can apply to organizations outside the EU that serve the EU market. Its timeline recently shifted (covered in detail in the regulatory-landscape lesson) — the dates changed in 2026, and a lot of stale material gets them wrong.
How they fit together: use NIST as your practical risk-management process, pursue ISO 42001 if you need to certify your governance to the market, and treat the EU AI Act (plus sector and local laws) as the legal floor you must meet. You don't adopt all three mechanically — you build a governance program (the rest of this course) informed by them. Knowing these three by name and purpose is enough to speak the language and know where to look.
Note which framework matters most for you right now: NIST (you need a risk process), ISO 42001 (you need to prove governance to customers), or EU AI Act (you serve the EU / regulated markets). That's your anchor.
Enjoying the free lessons? Get an email when we publish new courses and updates — no spam, unsubscribe anytime.
Discussion (0)
Ask a question or share what worked for you. Comments are reviewed before they appear.
No comments yet. Be the first to start the discussion!