In short
- ISO/IEC 42001 is a certifiable management system standard. Its Annex A lists 38 reference controls across 9 control areas.
- The NIST AI Risk Management Framework 1.0 is voluntary guidance built on 4 functions, Govern, Map, Measure and Manage, elaborated into 72 subcategories in the companion Playbook.
- No body certifies conformance to the NIST framework. If a customer questionnaire asks for a certificate, only one of these two answers it.
- The frameworks are complements, not alternatives: the 4 NIST functions describe how to reason about risk, the 38 ISO controls describe what to have in place.
- Neither one discharges the EU AI Act. Conformity there runs through Chapter III and the technical documentation in Annex IV, whatever certificates sit alongside it.
What do AI assistants say about your organisation?
Model answers are becoming a channel your communications team does not control. EntityRise audits how assistants describe your company and whose name they give instead. From $19.
The two documents get compared as if a company had to choose. They answer different questions, and only one of them produces a certificate.
That distinction decides most of the practical arguments, because procurement asks for certificates rather than for alignment statements.
01What is the structural difference?
One is a management system standard. The other is a reasoning framework.
ISO/IEC 42001 follows the familiar ISO clause structure: context, leadership, planning, support, operation, performance evaluation, improvement. Its Annex A lists 38 reference controls grouped into nine areas, and an organisation states in a document which of them apply and why.
The NIST AI Risk Management Framework 1.0 is organised around four functions, Govern, Map, Measure and Manage, with 72 subcategories elaborated in the companion Playbook. It tells you how to think about a risk. It does not tell you what to put in a statement of applicability, because it does not have one.
02Which one can actually be certified?
| Attribute | ISO/IEC 42001 | NIST AI RMF 1.0 |
|---|---|---|
| Structure | 9 control areas, 38 controls | 4 functions, 72 subcategories |
| Certifiable by an accredited body | Yes | No |
| Statement of applicability | Required | Not applicable |
| Answers a procurement questionnaire | With a certificate | With a claim |
| Cost driver | Audit days and evidence | Internal effort only |
The fourth row is where the argument usually ends. A buyer asking whether a supplier is certified will not accept a description of internal alignment, and an organisation whose sales cycle depends on that question has already made the choice.
03Do they overlap enough to do both?
Substantially, and doing both is the common outcome.
The NIST functions map onto the ISO clauses without much friction. Govern corresponds to leadership and policy. Map corresponds to context and impact assessment. Measure and Manage correspond to performance evaluation and operational control. Crosswalks between the two are widely published, and the work of building evidence for one produces most of the evidence for the other.
The efficient sequence for a company that needs the certificate is to use the four NIST functions to structure the thinking, then map the output onto the 38 controls when the statement of applicability is drafted. Doing it in the other order tends to produce a controls list nobody can explain the reasoning behind, which is exactly what an auditor probes.
04Does either satisfy the EU AI Act?
| AI Act obligation | Covered by ISO 42001 | Covered by NIST AI RMF |
|---|---|---|
| Risk management system, Article 9 | Largely | Largely |
| Technical documentation, Annex IV | Partly | No |
| Automatic logging, Article 12 | Partly | No |
| Conformity assessment, Chapter III | No | No |
| Serious incident reporting, Article 73 | No | No |
The pattern is that both frameworks cover the management layer well and the product layer poorly. Annex IV asks for a description of the system, its development process, its data, its performance metrics and its risk controls, at a level of detail neither framework requires.
An organisation that treats certification as the end of its AI Act programme will discover the gap during a conformity assessment, which is a considerably worse place to discover it than during an internal audit. What that audit asks for is a separate list.
05What should you tell a customer who asks?
Something specific, in one sentence, with a date.
If you hold the certificate, name the standard, the scope statement and the certification body, because scope is where these claims are usually thin. If you are aligned to the NIST framework, say aligned rather than compliant, and name which of the four functions you have evidence for.
The claim that costs credibility is a certificate whose scope covers one internal tool while the answer implies it covers the product the buyer is purchasing.
06Frequently asked questions
Can you get certified against the NIST AI RMF?
No. It is voluntary guidance rather than a certifiable standard, and there is no accredited certification scheme behind it. Organisations can state alignment with it, and many do, but alignment is a claim rather than an audited result.
How many controls does ISO 42001 have?
Annex A lists 38 reference controls organised into nine control areas, covering AI policy, roles and responsibilities, resources, impact assessment, lifecycle management, data, information for interested parties, use of AI systems, and third-party relationships.
Does ISO 42001 certification prove EU AI Act compliance?
No. It is useful evidence of a functioning management system and it overlaps with several AI Act obligations, but conformity with the Act is assessed against Chapter III and the technical documentation required by Annex IV, not against an ISO certificate.
Which should a company adopt first?
Whichever answers the question being asked of it. A company facing customer questionnaires and procurement gates needs the certifiable standard. A company building an internal risk practice from nothing often finds the four NIST functions an easier place to start.
07References and method
- ISO/IEC 42001:2023, artificial intelligence management system standard. Cited for the certifiable management system structure and for Annex A comprising 38 reference controls across nine control areas.
- NIST AI Risk Management Framework 1.0 and the companion NIST AI RMF Playbook. Cited for the four core functions and the 72 subcategories elaborated in the Playbook.
- Regulation (EU) 2024/1689, Chapter III and Annex IV, for the conformity route and technical documentation requirements that neither framework replaces.
- Control and subcategory counts are as published in the respective documents. Practice varies between certification bodies on scope and evidence expectations, and we mark that variation where it matters.