UprootSecurityUprootSecurity

Phase 7 · AI Security Landscape + Governance Frameworks · Lesson 2 of 4

The Three AI Governance Frameworks: NIST AI RMF, ISO 42001, EU AI Act

Article

·

25 min

·

+10 pts

When a company says "we need to govern our AI," three names come up — and a GRC engineer is expected to know which is which. They are not competitors; they sit at different altitudes. One is a voluntary playbook for managing AI risk (NIST AI RMF). One is a certifiable management system you can be audited against (ISO 42001). One is binding law with tiered obligations and real fines (the EU AI Act). You will often use all three at once: the framework to organize the work, the standard to certify it, and the law to know what is mandatory. This lesson puts them side by side so you can tell, for any AI system, which applies and what evidence each expects.

NIST AI RMF — the playbook

The NIST AI Risk Management Framework (AI RMF 1.0, 2023) is the US, voluntary, no-fee framework for managing AI risk across a system's lifecycle. If you know the NIST Cybersecurity Framework, the shape is familiar: four core functions, meant to be run continuously rather than once.

  • Govern — the culture and accountability layer that runs through the other three: policies, roles, risk tolerance, and oversight for AI.
  • Map — establish context: what is this AI system for, who does it affect, what could go wrong, what are its dependencies.
  • Measure — analyze and track the risks: test for bias, robustness, security, and reliability; quantify what you can.
  • Manage — act on the risks: prioritize, treat, monitor, and respond to incidents over time.

NIST AI RMF gives you no certificate and no auditor. Its value is as a common structure — a way to organize AI risk work and show you have a deliberate process. It is the framework you reach for to answer "how do we approach this at all?"

ISO 42001 — the certifiable management system

ISO/IEC 42001:2023 is the world's first certifiable AI Management System (AIMS) standard. If NIST AI RMF is the playbook, ISO 42001 is the system of record that a third party can audit and certify — exactly the role ISO 27001 plays for information security. It follows the same management-system pattern: leadership commitment, a risk and impact assessment process, documented controls (its Annex A lists AI-specific controls — data quality, transparency, human oversight, lifecycle management), and a continual-improvement loop.

The reason it matters commercially is the same reason ISO 27001 matters: a customer or regulator can ask "are you ISO 42001 certified?" and a third party's certificate answers it. It is the AI counterpart to the certification a GRC engineer already shepherds — and it interlocks cleanly with an existing ISO 27001 program.

EU AI Act — the binding law

The EU AI Act is not a framework you adopt; it is law that applies if you build or deploy AI affecting people in the EU — regardless of where your company is. Its defining move is to regulate AI by risk tier, with obligations that scale to the tier:

  • Unacceptable risk — prohibited outright (e.g. social scoring, manipulative systems, most real-time public biometric identification).
  • High risk — permitted but heavily regulated: risk management, data governance, logging/traceability, human oversight, transparency, and a conformity assessment before going to market. This is where most of the compliance weight lives (think AI in hiring, credit, medical devices, critical infrastructure).
  • Limited risk — transparency obligations: tell people they are interacting with an AI, and label AI-generated or manipulated content (deepfakes, synthetic media).
  • Minimal risk — the vast majority (spam filters, recommendation engines, AI in games): no specific obligations, voluntary codes of conduct.

The Act carries GDPR-scale fines (a percentage of global turnover), which is why classifying a system's tier — the next exercise — is a real, consequential judgement, not an academic one.

Side by side

NIST AI RMF            ISO/IEC 42001              EU AI Act
                  ------------------     ----------------------     ----------------------------
WHAT IT IS          Voluntary risk         Certifiable AI mgmt        Binding law (EU market)
                  framework (playbook)   system standard (AIMS)
ORIGIN / FORCE      US NIST; voluntary     ISO/IEC; certifiable       EU regulation; mandatory
STRUCTURE           Govern/Map/            Mgmt system + Annex A      Risk tiers: unacceptable /
                  Measure/Manage         AI controls                high / limited / minimal
ANALOGOUS TO        NIST CSF               ISO 27001                  GDPR (tiered, fineable)
CERTIFIABLE?        No (self-use)          Yes (3rd-party audit)      N/A — conformity assessment
                                                                    for high-risk systems
PENALTY             None (voluntary)       Loss of certification      Fines up to % of global
                                                                    turnover
EVIDENCE EXPECTED   Documented risk        AIMS docs, control set,    Risk mgmt file, data
                  process across the     audit trail, continual     governance, logs, human-
                  four functions         improvement records        oversight + conformity docs
USE IT TO           Organize the work      Certify the program        Know what is mandatory

The three AI governance regimes — what each is, who mandates it, and the evidence it expects

How a GRC engineer uses all three

In practice they stack. You use NIST AI RMF to structure how the organization thinks about AI risk — the Govern/Map/Measure/Manage loop becomes the shape of your AI risk program. You pursue ISO 42001 when you need a certificate a customer trusts, reusing much of your existing ISO 27001 machinery. And you check the EU AI Act first for anything touching EU users, because it sets the floor: it tells you which obligations are not optional and which tier a system falls into. The frameworks tell you how; the law tells you what you must.

That last decision — which tier a system falls into — is where the rest of this module goes. First a short video walking the tiers against real systems, then an exercise where you classify eight AI use cases yourself.

The Three AI Governance Frameworks: NIST AI RMF, ISO 42001, EU AI Act — UprootSecurity Bootcamp