ISO 42001 or the NIST AI RMF? Only one gives you a certificate

38 controls in nine areas against four functions and 72 subcategories. One is certifiable, one is not, and procurement asks for the certificate.

Reference GlobalUSEU

In short

  • ISO/IEC 42001 is a certifiable management system standard. Its Annex A lists 38 reference controls across 9 control areas.
  • The NIST AI Risk Management Framework 1.0 is voluntary guidance built on 4 functions, Govern, Map, Measure and Manage, elaborated into 72 subcategories in the companion Playbook.
  • No body certifies conformance to the NIST framework. If a customer questionnaire asks for a certificate, only one of these two answers it.
  • The frameworks are complements, not alternatives: the 4 NIST functions describe how to reason about risk, the 38 ISO controls describe what to have in place.
  • Neither one discharges the EU AI Act. Conformity there runs through Chapter III and the technical documentation in Annex IV, whatever certificates sit alongside it.
Advertisement

What do AI assistants say about your organisation?

Model answers are becoming a channel your communications team does not control. EntityRise audits how assistants describe your company and whose name they give instead. From $19.

Audit your AI visibility at EntityRise.ai →

The two documents get compared as if a company had to choose. They answer different questions, and only one of them produces a certificate.

That distinction decides most of the practical arguments, because procurement asks for certificates rather than for alignment statements.

01What is the structural difference?

One is a management system standard. The other is a reasoning framework.

ISO/IEC 42001 follows the familiar ISO clause structure: context, leadership, planning, support, operation, performance evaluation, improvement. Its Annex A lists 38 reference controls grouped into nine areas, and an organisation states in a document which of them apply and why.

The NIST AI Risk Management Framework 1.0 is organised around four functions, Govern, Map, Measure and Manage, with 72 subcategories elaborated in the companion Playbook. It tells you how to think about a risk. It does not tell you what to put in a statement of applicability, because it does not have one.

02Which one can actually be certified?

Comparison prepared by The Guardrail from the published documents. Counts are as stated in ISO/IEC 42001:2023 and the NIST AI RMF Playbook.
AttributeISO/IEC 42001NIST AI RMF 1.0
Structure9 control areas, 38 controls4 functions, 72 subcategories
Certifiable by an accredited bodyYesNo
Statement of applicabilityRequiredNot applicable
Answers a procurement questionnaireWith a certificateWith a claim
Cost driverAudit days and evidenceInternal effort only

The fourth row is where the argument usually ends. A buyer asking whether a supplier is certified will not accept a description of internal alignment, and an organisation whose sales cycle depends on that question has already made the choice.

03Do they overlap enough to do both?

Substantially, and doing both is the common outcome.

The NIST functions map onto the ISO clauses without much friction. Govern corresponds to leadership and policy. Map corresponds to context and impact assessment. Measure and Manage correspond to performance evaluation and operational control. Crosswalks between the two are widely published, and the work of building evidence for one produces most of the evidence for the other.

The efficient sequence for a company that needs the certificate is to use the four NIST functions to structure the thinking, then map the output onto the 38 controls when the statement of applicability is drafted. Doing it in the other order tends to produce a controls list nobody can explain the reasoning behind, which is exactly what an auditor probes.

04Does either satisfy the EU AI Act?

Coverage assessment prepared by The Guardrail. Editorial judgement based on the operative text of Regulation (EU) 2024/1689, not a legal opinion.
AI Act obligationCovered by ISO 42001Covered by NIST AI RMF
Risk management system, Article 9LargelyLargely
Technical documentation, Annex IVPartlyNo
Automatic logging, Article 12PartlyNo
Conformity assessment, Chapter IIINoNo
Serious incident reporting, Article 73NoNo

The pattern is that both frameworks cover the management layer well and the product layer poorly. Annex IV asks for a description of the system, its development process, its data, its performance metrics and its risk controls, at a level of detail neither framework requires.

An organisation that treats certification as the end of its AI Act programme will discover the gap during a conformity assessment, which is a considerably worse place to discover it than during an internal audit. What that audit asks for is a separate list.

05What should you tell a customer who asks?

Something specific, in one sentence, with a date.

If you hold the certificate, name the standard, the scope statement and the certification body, because scope is where these claims are usually thin. If you are aligned to the NIST framework, say aligned rather than compliant, and name which of the four functions you have evidence for.

The claim that costs credibility is a certificate whose scope covers one internal tool while the answer implies it covers the product the buyer is purchasing.

06Frequently asked questions

Can you get certified against the NIST AI RMF?

No. It is voluntary guidance rather than a certifiable standard, and there is no accredited certification scheme behind it. Organisations can state alignment with it, and many do, but alignment is a claim rather than an audited result.

How many controls does ISO 42001 have?

Annex A lists 38 reference controls organised into nine control areas, covering AI policy, roles and responsibilities, resources, impact assessment, lifecycle management, data, information for interested parties, use of AI systems, and third-party relationships.

Does ISO 42001 certification prove EU AI Act compliance?

No. It is useful evidence of a functioning management system and it overlaps with several AI Act obligations, but conformity with the Act is assessed against Chapter III and the technical documentation required by Annex IV, not against an ISO certificate.

Which should a company adopt first?

Whichever answers the question being asked of it. A company facing customer questionnaires and procurement gates needs the certifiable standard. A company building an internal risk practice from nothing often finds the four NIST functions an easier place to start.

07References and method

  1. ISO/IEC 42001:2023, artificial intelligence management system standard. Cited for the certifiable management system structure and for Annex A comprising 38 reference controls across nine control areas.
  2. NIST AI Risk Management Framework 1.0 and the companion NIST AI RMF Playbook. Cited for the four core functions and the 72 subcategories elaborated in the Playbook.
  3. Regulation (EU) 2024/1689, Chapter III and Annex IV, for the conformity route and technical documentation requirements that neither framework replaces.
  4. Control and subcategory counts are as published in the respective documents. Practice varies between certification bodies on scope and evidence expectations, and we mark that variation where it matters.
RA

, Assurance Correspondent

Covers assurance: management systems, audit evidence, and what certification bodies actually ask to see. Reach them at ruth@theguardrailreport.com.