AI Governance Framework Comparison: NIST AI RMF vs. ISO 42001 vs. EU AI Act

Compare NIST AI RMF, ISO 42001, and the EU AI Act - what's binding vs. voluntary, where they overlap, and how enterprises should sequence adoption.

Rushali

Rushali

AI Governance Framework Comparison
AI Governance Framework Comparison

The security team completes red-teaming its new customer support guy and documents the outcomes. Three different stakeholders ask three different questions of the same report in a week and are all correct. Three different stakeholders pose three different questions of the same report within a week, and all are correct. Which one wins is essentially the question when it comes to NIST AI RMF vs ISO 42001 vs EU AI Act, but that is the wrong way to think of it at the outset. One is voluntary, another is a certified management level, and another has fine consequences. This guide explains what each needs and where they share enough to allow for re-use of work, where they really differ, and the logical sequence once you understand your footprint.

The 30-Second Answer

For the reader who found this article through a search engine, who will want to know the answer before they even make it to the meeting, here is the short version – this is not a competition for the same position. NIST AI RMF is a risk management approach that is done voluntarily. Only one of the three is an ISO standard that you can certify to, namely ISO/IEC 42001. The EU AI Act is mandatory, and regardless of your adoption of either of the two, it will not care.

At some point, most companies, regardless of their size, will be using all three for various tasks: NIST for the day-to-day risk words, ISO 42001 for the structure that they can be audited against to show the words are being used, and the EU AI Act as a minimum requirement for any business that deals with the EU market. The choice of one and ignoring the others typically corresponds to finding out six months into an audit or regulatory investigation that you developed a program that meets internal stakeholders but no one else. That is the place where the majority of AI governance programs fail: in the gap between we've got a policy, and we can prove it.

What Each Framework Actually Is

The three of these documents are drafted by three different types of people for three different types of people, and that is why they are different from each other in all aspects of this question. It is crucial that one knows what each of them is in itself before making any comparison.

NIST AI RMF vs. ISO 42001 vs. EU AI Act

NIST AI RMF: A Voluntary Risk Management Method

On January 26, 2023, NIST released AI RMF 1.0, which was the result of a public comment process that garnered approximately 400 sets of formal comments from over 240 organizations. It was created within the framework of the National AI Initiative Act of 2020, and the document itself makes it clear that it is voluntary: NIST doesn't audit anyone against it, and there is no certificate to be earned.

The framework is broken down into four functions: Govern, Map, Measure, and Manage. Govern is over the policies, accountability arrangements, and culture that must be in place before the other three functions come into existence. Map sets the context of a particular AI system, both for whom it impacts and what could go wrong. Measure evaluates trustworthiness properties of the system, such as validity, safety, and fairness, according to NIST. What gets prioritized, what gets a kill switch, and what gets disclosed is all in the hands of Manage. Map, Measure, and Manage do not occur in sequence, as stated by NIST; Govern is the only place that updates based on the output of Map, Measure, and Manage.

You can find a companion AI RMF Playbook, more than 140 pages of suggested actions that correspond to each subcategory, with the base framework running about 40 pages. NIST expanded the framework in July 2024 with the Generative AI Profile (AI 600-1), establishing the same four functions over the same twelve risk categories, but including new ones that apply to generative systems, such as confabulation, information security, intellectual property exposure, and CBRN information risk. That profile alone has over 200 suggested actions under what appears, at a glance, to be four simple words.

ISO/IEC 42001: A Certifiable Management System

As of this writing, ISO/IEC 42001 is the first international standard for an AI management system, and the “management system” is probably the part of the standard that is most often overlooked in the summary. It does not offer direction on how to create a fair model or a safe agent. It outlines how to operate the organization with AI systems: it explains who makes decisions about risk, how the risk decisions are documented, how the organization discovers its own failures, and how it becomes better.

The structure of the standard is harmonized with ISO's Annex SL structure; this structure is also followed by ISO 27001 for information security and ISO 9001 for quality. That's intentional: Companies with an existing ISMS can merely integrate an AI management system with the existing infrastructure, which is why certification timelines are being reduced for companies with an existing ISMS. There are 38 controls outlined in 9 areas, all based on the Plan-Do-Check-Act cycle: Plan the AI management system, Do it, Check it using internal audits and management review, Act based on what you have found when you check.

ISO 42001 is certifiable, while NIST AI RMF is not. It is certified through Stage 1 and 2 audits by an approved body, is valid for three years, and requires annual surveillance audits to retain certification. Generally $20,000 – $60,000, and takes 4- 9 months to complete – this can be significantly reduced if an organization runs an ISO 27001 program. It's what security questionnaires and procurement teams are really asking for when they ask, “How do you govern your AI?

EU AI Act: Binding Law with Financial Penalties

All three of the EU Acts are binding for anyone they apply to, but the EU AI Act ( Regulation (EU) 2024/1689) becomes lawfully binding in August 2024, while the other two are optional. It sets four levels of risk for AI systems. Some of the practices were banned outright under Article 5, which was initially adopted for eight practices, such as the creation of facial image recognition databases through untargeted collection and the social scoring of citizens by public authorities; the ban took effect on 2 February 2025, with further bans being added to Article 5 through the Digital Omnibus amendments adopted in 2026, which include the ban on AI systems creating non-consensual intimate imagery or child sexual abuse material, which will enter into force on 2 December 2026. High-risk systems, those systems listed in Annex III (hiring, credit scoring, biometric identification, critical infrastructure) or systems built as safety components in accordance with Annex I, have the highest requirements: There is a requirement for a documented risk management system, data governance controls, technical documentation, human oversight, and a conformity assessment prior to the system being put to market. With limited-risk systems, primarily chatbots and content generators, it is just a matter of writing a disclaimer that the individual is communicating with AI. The minimum-risk systems do not have any obligations whatsoever.

The dates in this timeline have changed since the Act was originally written, and the only point that a comparison-type article would bother with is the current ones, so it's more important than most. The Digital Omnibus on AI took effect on 27th of July 2026 and extended the high-risk compliance deadline for Annex III systems from 2nd August 2026 to 2nd December 2027, while that for Annex I embedded systems was postponed to 2nd August 2028. The obligations for watermarking generative AI output under Article 50(2) were independently postponed to 2 December 2026. None of these affect any costs or duties generally imposed on AI model providers from Article 51 to Article 56, which have been in force since 2 August 2025, or on the Article 5 prohibitions, which are already live. If you're planning around the original August 2026 high-risk deadline, you're planning around a date that is no longer relevant.

Master Comparison Table

It's easier to remember the differences in practice when you see the three next to each other than when you read them one after another.


NIST AI RMF

ISO/IEC 42001

EU AI Act

Nature

Voluntary risk management method

Certifiable AI management system standard

Binding, risk-tiered regulation

Issuing Body

NIST (U.S. Department of Commerce)

ISO/IEC (international standards bodies)

European Union

Binding?

No

No (market-driven, not legally required)

Yes

Certifiable?

No

Yes, via accredited third-party audit

No certification; conformity assessment and CE marking instead

Year Published

2023 (AI RMF 1.0); GenAI Profile 2024

2023

2024 (Regulation (EU) 2024/1689), timeline amended 2026

Geographic Scope

U.S.-origin, adopted globally as a de facto method

Global

EU market, applies extraterritorially to any provider or deployer reaching EU users

Enforcement / Penalties

None directly; referenced in some U.S. state laws and federal procurement

None regulatory; losing certification can mean losing contracts

Up to €35 million or 7% of global annual turnover, whichever is higher

Best For

Building an internal, day-to-day risk methodology

Proving governance maturity to customers, auditors, and regulators

Anyone placing or deploying AI that reaches the EU market

Where the Three Frameworks Overlap

The overlap in these three is larger than comparison content would suggest, and it is measurable in terms of specificity instead of a general statement. Legalithm's analysis of the standards indicates that ISO 42001 certification addresses about 70 - 80% of the EU AI Act's high-risk systems organizational and process requirements, mainly focusing on the requirements of the risk management system contained in Article 9 and the quality management system requirements of Article 17 of the EU AI Act. That number is the most important number in this entire comparison, since it tells one something: If you build the ISO 42001 management system correctly, you've already done most of the structural work required by the AI Act, even if you have not actually obtained the certificate.

Shared Ground: Risk Management, Documentation, Human Oversight, Transparency

Although they arrive at four similar points with slightly different terms, all three focus on the same four pillars. The same expectation lies beneath the assignment of Risk management to NIST's Map and Measure functions, ISO 42001's Clause 6 risk assessment, and the EU AI Act's Article 9 risk management system, and in each case it requires that the risk is anticipated before it can actually occur.

Second is documentation. Policies and accountability structures need to be “transparent and implemented effectively” for NIST's Govern function. Documenting information throughout the entire AI lifecycle is a prerequisite to earn the ISO 42001 certification. The EU AI Act requires that for high-risk systems, the technical documentation be available under Article 11, such that a regulator could be able to "reconstruct the development and testing of the system. The third is human oversight, which is the subject of the NIST's Manage function and the NIST's trustworthiness characteristics incorporated into AI 600-1, as well as Article 14 of the AI Act's oversight requirements, which requires the imposition of oversight measures "commensurate with the risks, level of autonomy and context of use" of the system. The final piece of the puzzle comes from transparency, which is referenced in NIST's information-integrity risk category, ISO 42010's stakeholder communication demands, and Articles 13 and 50 of the AI Act.

The bottom line: A sound, properly constructed AI risk program yields the same underlying evidence, inventory, risk assessments, evidence of tests and monitoring, and evidence of oversight, regardless of the framework the particular auditor is evaluating it against. The paper format is altered. The work below generally does not.

Where They Genuinely Diverge

It is a real overlap, but it is not a complete one; that is, these three are not the same, and a governance program that considers them to be is in trouble. The key differences that make the most significant impact are enforcement, certification, and some requirements from the EU AI Act that have no NIST/ISO equivalent.

Enforcement and Consequences

NIST AI RMF does not impose any penalties. An organization that doesn't choose to follow it will be unaffected by NIST, but the framework is increasingly mentioned in U.S. state laws, federal procurement language, and as a minimum standard for "reasonable" AI risk management. There is no government agency that is fining companies for not complying with ISO 42001, but the absence of certification or failing to gain it in the first place can result in lost enterprise contracts, as procurement increasingly sees it as a checkbox.

The EU AI Act is the exception, as it has a three-level penalty regime under Article 99. A fine of up to €35 million or 7% of worldwide annual turnover, whichever is higher, is the maximum for infringing Article 5 prohibited practices, which is higher than the maximum set by GDPR. The European AI Office, within the European Commission, has direct enforcement powers regarding the general-purpose AI (GPAI) model providers, while national market surveillance authorities in each member state are responsible for the rest, with a cap of €15 million or 3% of turnover. A third level, up to €7.5 million or 1.5%, is for minor breaches, such as providing false data to a regulator. For small and medium-sized enterprises (SMEs) and start-ups, the fine is capped at the lowest of the fixed amount or the percentage, not the highest, meaning a startup earning €2 million in turnover is liable to a maximum of €140,000 rather than the maximum of €35 million.

Certification vs. No Certification vs. Conformity Assessment

In the case of these three, they employ three distinct mechanisms to demonstrate compliance, which is one of the more popular pitfalls in governance planning with AI.

Framework

Proof Mechanism

Who Verifies It

NIST AI RMF

Self-attestation; no formal process

No external party; internal audit at most

ISO/IEC 42001

Third-party certification, Stage 1 and Stage 2 audits

Accredited certification body

EU AI Act

Conformity assessment (self-assessment or third-party, depending on system category), CE marking, EU database registration

Internal control (Annex VI) or a notified body (Annex VII), depending on the high-risk category

Only ISO 42001 of the three is a standard that is formally validated by a third party. Unlike the voluntary badges of conformity found in most other standards, the EU AI Act's conformity assessment is a legal requirement for placing a high-risk system on the market, and may be achieved by internal control or require external notified body involvement depending on the category. Neither does NIST AI RMF have an equivalent to it. An organization can claim to be with it, but no other party is able to substantiate that claim without a third-party audit to some other benchmark.

EU AI Act's Unique Requirements with No NIST/ISO Equivalent

There are a few aspects of the EU AI Act that do not have any true analog in NIST AI RMF, or in ISO 42001, and most comparison articles sidestep this point because it is easier to write about areas where there is agreement.

Article 5's prohibited practices shouldn't be treated as a risk category to be managed; rather, they are a bright line. Both NIST and ISO are based on the premise that risk can be mitigated through controls and documentation. Article 5, point by point, denies the above explanation on the basis of eight current (and in the future, more) specific practices: No control set, no documentation, no risk assessment that would allow real-time biometric surveillance in public spaces for law-enforcement purposes to be accepted under the Act. It is not permitted, no matter how well-constructed the system is.

The requirements in Article 10 for data governance are more specific than those found in NIST or ISO. It demands relevance, proper sampling of training, validation, and test sets, and, as much as possible, that there be no errors and that errors be detected and corrected in an appropriate manner, providing specific provisions for the detection and correction of bias. Neither NIST AI RMF nor ISO 42001 prescribes the type of data you need to put into a model; it only tells you to manage your data-related risk, not to meet the dataset-quality criteria which a regulator can examine.

The Act also contains characteristics of CE marking, which is different from other acts, and the EU declaration of conformity. The provider has to go through the conformity assessment, prepare the declaration, attach the CE mark to the system physically, and register the system in the public database of the EU before it can be sold in the EU market. That is a product-safety compliance system that has been used for decades in the EU on hardware and is not found in either voluntary system.

How the Frameworks Map to Each Other (Crosswalks)

None of this means you need to have to rebuild your governance program three times. Since the underpinning of each is very similar, you may use the same text for each framework as long as you make sure you know which piece refers to which.

AI governance program

NIST AI RMF to EU AI Act (MAP/MEASURE as Article 9 & 11 Evidence)

The typical comparison of an EU AI Act with NIST's AI RMF is limited to "one is law, one is not law", but a more practical comparison is that NIST's own activities create evidence the AI Act is looking for. The Map function from NIST contributes to the majority of the material for Article 11's technical documentation requirement because it documents the context of the system, stakeholders, and potential harms. The testing evidence produced by Measure forms the basis for the accuracy, robustness, and cybersecurity requirements in Article 15 and the risk management system in Article 9. That's because NIST's output is not necessarily in the format required by the Act, and NIST is voluntary, so an organization can just do Map and Measure loosely and be "aligned" with the Act; the Act's technical documentation requirements do not allow that kind of looseness for a system being placed on the EU market.

ISO 42001 to EU AI Act (Certification Supporting Conformity Assessment)

Don't assume that ISO 42001 certification guarantees conformance with the EU AI Act – no accredited body will claim this as a given. What it does do is provide most of the organizational support that a conformity assessment would expect to have in place: a documented risk management process; an internal audit program; management review cycles; and a quality management system that is very similar to the mandatory element of Article 17 of the Act. This is why the figure of 70-80% overlap was given. Having an active ISO 42001 certification, an organization enters a conformity assessment with half the work done, but with some issues related to data governance, CE marking, and the prohibited-practices check, which ISO 42001 was never intended to address, that it has to address.

NIST AI RMF to ISO 42001 (Risk Model Running Inside the Management System)

A NIST AI RMF vs ISO 42001 comparison is actually a comparison between a method and the container that it runs in. ISO 42001 provides the certificate structure, the Plan-Do-Check-Act cycle, the Annex A controls, the audit schedule, and intentionally does not prescribe the methodology for managing risks. Those NIST functions (Govern, Map, Measure, Manage) fit nicely into that structure: Govern provides ISO's Plan phase, Map and Measure provide ISO's Do and Check phases, and Manage provides ISO's Act phase, where decisions are made on corrective actions. The mapping to ISO 42001 is also based on the same logic as the formal crosswalk between the AI RMF and the related AI system impact assessment standard (ISO/IEC 42005), and several GRC vendors have created their own subcategory-to-Annex-A crosswalks from ISO 42005. Most advanced AI governance programs actually operate as a part of ISO 42001. Most of the advanced programs of AI governance run within ISO 42001 and not as standalone programs.

Do You Need All Three?

With these three AI compliance frameworks compared side-by-side, the clear conclusion is most organizations don't need all three on day one, and the best approach to get started will depend more on where your AI systems run than on the framework that is getting the most attention this quarter.

If You Only Operate in the US

NIST AI RMF is the reasonable minimum, and it's interesting to note that the legal terrain below it just changed. Colorado's initial AI Act (SB 24-205) provided an affirmative defense as well as a rebuttable presumption of reasonable care to organizations that had a risk management program consistent with NIST AI RMF or ISO 42001 in place. The requirement for a risk-management program was eliminated from SB 24-205, and a disclosure-based framework, with automated decision-making technology as its sole focus, was created in its place, with the change taking effect on January 1, 2027, after the governor's signature on May 14, 2026, in SB 26-189. NIST AI RMF is still the “workbench” benchmark for reasonable care overall; it's still referenced in federal procurement, but the attention-getting statutory safe harbor of 2024 is no longer here.

If You Sell Into or Operate in the EU

The EU AI Act is not optional and does not discriminate based on the location of your headquarters. It has an extraterritorial reach, so any provider or deployer whose AI system is used by EU users will be in scope, even if the company is based solely in the US and sells software to customers in the EU. Make sure to first sort all AI systems into the four risk categories as this determines all obligations that follow, and then work towards whichever compliance date is relevant to your systems based on the 2026 Digital Omnibus timeline.

If You Need Vendor/Customer Assurance (Procurement-Driven)

When it's your customer's security question, rather than a regulator, ISO 42001 is the answer. AI-focused questions are now being introduced to vendor evaluations, including how models are trained, the data that feeds into them, and who is responsible when things go wrong. An ISO 42001 certificate is an accepted certificate that responds to those questions rather than a custom essay for each deal, as it is in the format that procurement accepts. For now at least, the certified population remains small enough that it's a competitive differentiator to have the certificate.

Recommended Sequencing for Enterprises

The choice of an AI governance framework to implement first is indeed a sequencing issue, and it's a place where practitioners can actually differ from one another, so let's be honest about it instead of taking a stand and claiming it is a settled issue.

Recommended Sequencing for Enterprises

Start with ISO 42001 as the Management Backbone, or NIST AI RMF as the Faster On-Ramp

One way of thinking is to begin with ISO 42001 since it provides the certified structure on top of which all else can be built; and for those organizations already certified to ISO 27001, it points out that they can go up the ladder of certification with minimal effort, in as little time as four months. In the guidance itself, Legalithm takes this stance explicitly: build AIMS first, and then add NIST's risk methodology on top, and then fill the gaps at the end that are specific to the EU AI Act.

The other school begins with NIST AI RMF, as they don't need an audit, an accredited body, or a $20,000-$60,000 certification budget to start. This Playbook outlines actions that an organization can take to begin to apply Govern, Map, Measure, and Manage this quarter, without waiting for a certification cycle to clear. While NIST may not be the most robust on-ramp for achieving an AI certification, it's also the lower-friction one, given the pressure for a business to demonstrate progress with their board, or the uncertainty in achieving an AI certification in the first place.

Both are defensible. The wrong choice is to spend months debating which one it is to start, but still do nothing.

Layer EU AI Act Requirements Continuously, Not as a Final Step

The EU AI Act does not need to be considered a compliance endpoint at the end of a program, whichever internal framework arises first. Its obligations are to be continuous, not one-off: Article 9's risk management system must be an "iterative process" and not a one-off at launch; Article 12's logging requirements must be "operational" for the duration the system is in production; Article 14's human oversight must be "operational" at runtime, not just on paper at launch. When it comes to Bolting Act compliance, it typically follows NIST and ISO work, and involves rebuilding the logging and monitoring components that should have been installed from the start. Develop the EU-specific technical documentation, data governance audits, and human oversight structures in parallel with the NIST/ISO work, not after.

Extending These Frameworks to Agentic AI

All of the above explanations have focused on AI systems that create content or make a recommendation. The agentic systems – those that plan, call up tools, remember the context across sessions, and act without human eyes looking over their shoulder – challenge three or four of the assumptions on which these frameworks are built, and that’s where practitioners are creating new guidance more rapidly than any individual regulator can formalize it.

What None of the Three Frameworks Were Built For

NIST AI RMF's trustworthiness characteristics, ISO 42001's Annex A controls, and the EU AI Act's Article 14 human oversight requirements all implicitly rely on the premise that a human will review the outputs before they have downstream impacts. Agents that call a payment API, edit a production database, or approve a refund without any involvement on the part of the customer do not fit in the above-mentioned model neatly. NIST's own Generative AI Profile is partially correct: Twelve of its risk categories (such as 'confabulation' and 'information security') do still apply to generative model-based agents, but the profile was created with the potential for a model to speak rather than for an autonomous system to act using tools. The base frameworks were not designed to fill this gap, which is why NIST is also working on an AI Agent Standards Initiative.

The same gap is being noticed by regulators. On January 22, 2026, Singapore’s Infocomm Media Development Authority released a Model AI Governance Framework for Agentic AI, the first governance document developed for the behavior of autonomous agents, not an adaptation of the guidelines for generative AI, and was updated to version 1.5 in May 2026. It's optional, but it's an indicator of the direction formal guidance is heading in the future, and it's an area that cannot be covered with generic risk management terms in NIST, ISO or the AI Act alone.

The IAPP Tiered Guardrail Model as a Starting Point

With a regulatory solution not yet on the horizon, IAPP's Three-Tiered Guardrail Framework has emerged as one of the more commonly referenced places to begin governing agentic systems in the space these frameworks create. It categorizes guardrails into three groups: universal guardrails, which define requirements for privacy, transparency, security, and safety that are applicable to all agents, irrespective of their purpose; organization guardrails, which set the guardrails for the company, depending on the risk appetite and the industry context; and societal guardrails, which are expectations set by the regulatory authorities and general ethical values as they manifest. Here, the model is somewhat like the EU AI Act, where the level of governance is scaled to the actual risk and/or potential impact of the agent, but the Act does not specify a type of system to which this applies. The same graduated logic underlies Singapore's own agentic framework, which classifies its guidance in the same way: by the extent of risk that it can bound up front, by the human accountability accorded to an agent, and by the extent of technical controls that it can specify that are proportional to what it allows that agent to do.

Other Frameworks Worth Knowing (Briefly)

NIST, ISO and the EU AI Act are not in isolation. There are two other benchmarks that appear frequently in the same discussions, but are not the subject of this comparison.

OECD AI Principles

The OECD Principles on AI were agreed in May 2019 and amended in May 2024, and form the ethical foundation underlying all three frameworks discussed here. They are five values - people and planet, human rights and democratic values, transparency and explainability, robustness and safety and accountability - along with five policy recommendations directed at government, not individual organizations. They are followed by 47 countries and jurisdictions, including all OECD member countries and the European Union (EU) itself; and they are used almost as literally as they are written in NIST's trustworthiness characteristics and in the EU Act on AI in the description of the EU's goals in the recitals of the EU Act. No one is directly audited on the OECD Principles; these are the common terms used when the NIST, ISO, and EU AI Act requirements were written.

OWASP Top 10 for LLM/Agentic Applications

The NIST and ISO/AI Act are frameworks, and the OWASP Top 10 are security taxonomies, and they are used to solve different problems. The OWASP Top 10 for LLM Applications, this year's 2025 edition, identifies the top 10 risks for content generation systems, including prompt injection, insecure output handling, training data poisoning, and excessive agency. The OWASP Top 10 for Agentic Applications was released for the first time on December 9th, 2025, with over 100 contributors and a review board made up of NIST, Cisco, Microsoft, and AWS; it includes the risks related to autonomous action, such as goal hijacking, tool misuse, and memory poisoning. Neither list gives you instructions on how to conduct an AI governance program. Both of them will tell you what a security team should be testing for once the program is in place, so the two types of framework are usually used together and never in place of each other.

How Akto Helps Map Governance to Practice

The frameworks described above all require the same basic evidence: that risk was not only identified in policy, but it has been assessed, tested, and controlled. However, most AI governance programs come to a halt not because of the paperwork, but because they fail to produce actual evidence from systems that evolve much faster than the annual or quarterly audit cycle.

Continuous Risk Assessment Across LLMs, Agents, and MCP

NIST's Map function requires an understanding of the context and boundary of each AI system that an organization operates, while ISO 42001's Clause 6 requires a documented risk assessment, and the EU AI Act requires a risk management system throughout the AI system lifecycle. All three assume you actually know what AI systems are available in your environment, which is harder than it sounds when agents and MCP servers are begun by individual teams outside of a central inventory. Every one of these frameworks assumes an inventory step, namely finding and cataloging MCP servers, AI agents, tools, and attached resources, across infrastructure, cloud resources, and employee devices, which is often not performed in reality by agents. Then Akto's automated red teaming performs over 4,000 adversarial probes to create the test evidence that aligns directly with NIST's Measure function, plus the accuracy, robustness, and cybersecurity testing called for in the EU AI Act's Article 15.

Mapping Findings to NIST AI RMF, ISO 42001, and EU AI Act Controls

Discovery and testing can only be useful if the information discovered and tested is something that an auditor or the regulator can use. Akto's agentic posture management provides security teams with a real-time perspective of risk on all agents discovered and MCP tools, while its guardrails ensure that model behavior, tool access, and sensitive data flow is controlled by the rules and AI policies in real-time with human-in-the-loop override where needed. That combination creates exactly the kind of continuous record these frameworks require, but a point-in-time audit alone can't provide: an inventory that meets the Map function needs of NIST; red team results that meet the Measure function needs of NIST and Article 15 of ISO 42001; guardrail and override logs that meet the ongoing monitoring needs of ISO 42001's Check phase and the human oversight requirements of ISO 42001's Article 14. That does not take the place of the governance work of creating a written policy and holding people accountable, but rather that evidence layer will make a written policy defensible.

Final Thoughts on NIST AI RMF, ISO 42001, and the EU AI Act

Don't implement NIST AI RMF, ISO 42001 and EU AI Act as individual projects. Regardless of which of the three frameworks you are using to get started with AI risk assessment, remember that you need to choose a starting point based on where your AI systems are deployed, and then add the other two frameworks on top, not repeat the risk assessment exercise three times.

What these frameworks require is evidence, not policy: a true inventory of all models, agents, and MCP tools, with proof that there was a testing process, and logs documenting that guardrails were deployed when things went wrong. Akto's agentic discovery creates this inventory automatically, while the evidence it provides for NIST's Measure function and Article 15 of the EU AI Act is generated by the red teaming. Akto's guardrails and overrides with a human in the loop create the oversight evidence required by Article 14 of the EU AI Act and by ISO 42001's monitoring.

Schedule an Agentic security demo with Akto to ensure an audit can verify your AI governance policy.

FAQs on NIST AI RMF, ISO 42001, and the EU AI Act

What is the difference between NIST AI RMF, ISO 42001, and the EU AI Act?

NIST AI RMF is a voluntary Risk Management approach that focuses on four functions: Govern, Map, Measure, and Manage. The ISO/IEC 42001 is a certifiable management system standard that sets forth the process an organization should follow to structure, document, and audit its AI governance. EU AI Act is a legally binding document that establishes four risk categories for AI systems, with legal obligations and penalties for those in the highest risk category. There are three ways to do it: one is a method, one is certification, and one is a regulation.

Is the EU AI Act legally binding, while NIST AI RMF and ISO 42001 are not?

Yes. The EU AI Act is binding and punishable with fines of up to €35 million or 7% of global turnover for the most severe cases. There is no legal penalty for not adopting NIST AI RMF nor for not adopting ISO 42001, although there are commercial consequences if a customer demands it as a condition of doing business with ISO 42001.

Can you be certified against NIST AI RMF, or only ISO 42001?

The only formal third-party certification is ISO 42001, which is issued by an accredited body that carries out a Stage 1 and Stage 2 audit. There is no certification process for NIST AI RMF; organizations can only self-certify alignment, and there is no independent entity attesting to this.

How much overlap exists between these three frameworks?

There is a lot, and it can be calculated. Legalithm's analysis indicates that ISO 42001 contains approximately 70-80% of the process and organizational requirements of the EU AI Act for high-risk systems, which focus on the two key categories of the Act: the risk management system (under Article 9) and the quality management system (under Article 17). While the terminology varies, all three share in common risk management, documentation, human oversight, and transparency.

What does the EU AI Act require that NIST AI RMF and ISO 42001 don't cover?

Takes footprints into account. It is a good idea for a company servicing the US market to begin with the NIST AI RMF. Every business that puts and/or uses AI in the EU will be subject to the EU AI Act, regardless of where they are active. Many organizations that sell to enterprise customers who have a specific need for AI in their procurement process will also require ISO 42001, as it is becoming a standard request when entering into such customer relationships. Most organizations operating at scale invariably will employ a mix of the three.

Do organizations need to adopt all three frameworks, or just one?

Depends on footprint. The NIST AI RMF is sufficient for a US company to begin with, starting in the US. All companies, whether or not they are based in the EU, that are placing or deploying AI systems that affect consumers in the EU are subject to the EU AI Act. Many organizations that sell to enterprise customers who have special procurement needs for AI may require ISO 42001, as it is a growing requirement to do business. Most organizations that are running at scale at the end of the day use a mix of the three.

How does ISO 42001 map to or support EU AI Act conformity assessment?

While ISO 42001 does not directly fulfill the requirements of the EU AI Act, it provides most of the elements a conformity assessment would expect: a documented risk management process, internal audits, management review, and a quality management system that is very similar to the EU AI Act's Article 17 requirement. There are still some gaps to fill regarding data governance, CE marking, and checking prohibited practices by organizations in the context of the AI Act.

What are the penalties for EU AI Act non-compliance?

Three levels are available under Article 99. The fines for breaches of the Article 5 prohibited practices range up to €35 million or 7% of the annual global turnover of the company, whichever is higher. The maximum amounts for violations of high-risk system obligations and general-purpose AI model rules are capped at €15 million or 3%. If the infringement is less serious, such as giving false information to a regulator, it will be limited to €7.5 million or 1.5%. SMEs and startups receive the lesser of the fixed amount or percentage, not the greater.

Which framework should a US-only company start with?

In general, NIST AI RMF. It is open and does not require a certification budget and is the most cited framework language in the US Federal procurement process. Please be aware that Colorado's original statutory safe harbor for NIST or ISO 42001 alignment of AI models as an affirmative legal defense was omitted when SB 26-189 replaced Colorado's previous AI Act in May 2026, so don't assume that NIST alignment will afford you a legal defense in any given state.

Which framework should a company selling into the EU prioritize?

This EU AI Act is binding and applicable wherever the company is based, immediately. The first step is to classify each AI system into one of the four risk categories of the Act, as each obligation that follows depends on the classification.

What is the recommended order for adopting these frameworks?

This is an issue that professionals actually have varying opinions about. The first solution is based on ISO 42001 as a certified management framework, and adds NIST's risk methodology on top of that. The other begins with NIST AI RMF as a quick and audit-free on-ramp, with added ISO 42001 certification, as it may be required during procurement or customer requirements. Regardless, EU AI Act-specific requirements should be added incrementally to the framework that is implemented first, rather than added at the end.

How do NIST AI RMF, ISO 42001, and EU AI Act apply to agentic AI systems?

None of them are designed with the idea of autonomous agents that will use tools in mind, and all three require some level of human oversight prior to the downstream effects that are caused by an output, an assumption that agentic systems challenge. NIST is developing an AI Agent Standards Initiative to fill the gap on its own. The frameworks that were not created to address these three, such as IAPP's Three-Tiered Guardrail Framework and Singapore's Model AI Governance Framework for Agentic AI, which were introduced in January 2026, are filling the void.

What is the OECD AI Principles' relationship to these three frameworks?

All three are based on the OECD AI Principles adopted in 2019 and revised in 2024. The five values of the OECD are closely aligned with NIST's trustworthiness characteristics and the EU AI Act's own recitals. The Principles are not binding and do not apply to individual organizations; rather, they are the common language used by the other three frameworks.

How current is this comparison, given how fast AI regulation is changing?

Up to date as of September 2026, and some changes in the information here occurred in the past few months. The EU AI Act's high-risk deadlines were relocated from the Digital Omnibus, which came into effect on 27th July 2026, to December 2027 and August 2028. The original NIST/ISO related affirmative defense was removed and replaced in May 2026. Singapore's agentic AI framework was introduced in January 2026 and upgraded to v1.5 in June. As of this writing, specific dates listed here should be considered correct, and you should check with the primary sources before a compliance date.

How can platforms like Akto help map compliance efforts across these frameworks?

In order to fulfill the inventory requirements of ISO 42001's asset scoping, and the NIST Map function assumption that the AI and MCP inventory exists, Akto's agentic discovery delivers it, including infrastructure, cloud, and employee devices. It powers automated red teaming with over 4,000 probes that test for injection attacks, privilege escalation, data leakage, and more, providing NIST's Measure function and the EU AI Act's Article 15 accuracy and robustness with test evidence. It's a set of guardrails with human-in-the-loop overrides that brings the continuous oversight and monitoring record required by Article 14 and the Check phase of ISO 42001, and one that security teams can put in front of an auditor in a paper.

Follow us for more updates

The Largest Agentic AI Security Summit

The Secure, Governed AI Future.

October 27, 2026 | Virtual

Experience enterprise-grade Agentic Security solution