Phase 7 · AI Security Landscape + Governance Frameworks · Lesson 2 of 4
Article
·
25 min
·
+10 pts
When a company says "we need to govern our AI," three names come up — and a GRC engineer is expected to know which is which. They are not competitors; they sit at different altitudes. One is a voluntary playbook for managing AI risk (NIST AI RMF). One is a certifiable management system you can be audited against (ISO 42001). One is binding law with tiered obligations and real fines (the EU AI Act). You will often use all three at once: the framework to organize the work, the standard to certify it, and the law to know what is mandatory. This lesson puts them side by side so you can tell, for any AI system, which applies and what evidence each expects.
The NIST AI Risk Management Framework (AI RMF 1.0, 2023) is the US, voluntary, no-fee framework for managing AI risk across a system's lifecycle. If you know the NIST Cybersecurity Framework, the shape is familiar: four core functions, meant to be run continuously rather than once.
NIST AI RMF gives you no certificate and no auditor. Its value is as a common structure — a way to organize AI risk work and show you have a deliberate process. It is the framework you reach for to answer "how do we approach this at all?"
ISO/IEC 42001:2023 is the world's first certifiable AI Management System (AIMS) standard. If NIST AI RMF is the playbook, ISO 42001 is the system of record that a third party can audit and certify — exactly the role ISO 27001 plays for information security. It follows the same management-system pattern: leadership commitment, a risk and impact assessment process, documented controls (its Annex A lists AI-specific controls — data quality, transparency, human oversight, lifecycle management), and a continual-improvement loop.
The reason it matters commercially is the same reason ISO 27001 matters: a customer or regulator can ask "are you ISO 42001 certified?" and a third party's certificate answers it. It is the AI counterpart to the certification a GRC engineer already shepherds — and it interlocks cleanly with an existing ISO 27001 program.
The EU AI Act is not a framework you adopt; it is law that applies if you build or deploy AI affecting people in the EU — regardless of where your company is. Its defining move is to regulate AI by risk tier, with obligations that scale to the tier:
The Act carries GDPR-scale fines (a percentage of global turnover), which is why classifying a system's tier — the next exercise — is a real, consequential judgement, not an academic one.
NIST AI RMF ISO/IEC 42001 EU AI Act
------------------ ---------------------- ----------------------------
WHAT IT IS Voluntary risk Certifiable AI mgmt Binding law (EU market)
framework (playbook) system standard (AIMS)
ORIGIN / FORCE US NIST; voluntary ISO/IEC; certifiable EU regulation; mandatory
STRUCTURE Govern/Map/ Mgmt system + Annex A Risk tiers: unacceptable /
Measure/Manage AI controls high / limited / minimal
ANALOGOUS TO NIST CSF ISO 27001 GDPR (tiered, fineable)
CERTIFIABLE? No (self-use) Yes (3rd-party audit) N/A — conformity assessment
for high-risk systems
PENALTY None (voluntary) Loss of certification Fines up to % of global
turnover
EVIDENCE EXPECTED Documented risk AIMS docs, control set, Risk mgmt file, data
process across the audit trail, continual governance, logs, human-
four functions improvement records oversight + conformity docs
USE IT TO Organize the work Certify the program Know what is mandatoryThe three AI governance regimes — what each is, who mandates it, and the evidence it expects
In practice they stack. You use NIST AI RMF to structure how the organization thinks about AI risk — the Govern/Map/Measure/Manage loop becomes the shape of your AI risk program. You pursue ISO 42001 when you need a certificate a customer trusts, reusing much of your existing ISO 27001 machinery. And you check the EU AI Act first for anything touching EU users, because it sets the floor: it tells you which obligations are not optional and which tier a system falls into. The frameworks tell you how; the law tells you what you must.
That last decision — which tier a system falls into — is where the rest of this module goes. First a short video walking the tiers against real systems, then an exercise where you classify eight AI use cases yourself.