AI governance frameworks explained

Short answer

NIST AI RMF is a voluntary US risk-management framework organized around four functions — Govern, Map, Measure, Manage — and is the most practical starting point. ISO/IEC 42001 is a certifiable management-system standard, useful when customers require third-party attestation. The EU AI Act is binding law with obligations tiered by risk level and real penalties. Most organizations should implement AI RMF practices first, since that work substantially satisfies the others.

4 min readUpdated 2026-09-28AI Security & Governance

Three frameworks dominate the conversation, they serve different purposes, and the overlap is large enough that sequencing matters more than choosing.

NIST AI RMF

A voluntary framework from the US National Institute of Standards and Technology, organized around four functions:

It is descriptive rather than prescriptive, which practitioners tend to like and auditors find frustrating. Its real value is as a structure for the conversation, and it is where we suggest most organizations begin because the artifacts it produces — a system inventory, risk assessments, measurement plans — feed directly into the other two.

ISO/IEC 42001

A management-system standard for AI, structured like ISO 27001, and certifiable by an accredited body. It requires a documented AI management system: scope, policy, risk assessment methodology, controls, internal audit, management review, and continual improvement.

Choose this when customers or regulators demand third-party attestation rather than self-assertion. If you already run ISO 27001, the structure will be familiar and much of the governance machinery is reusable.

The EU AI Act

Binding law, not a framework, with obligations scaled by risk category:

CategoryTreatment
ProhibitedCertain practices banned outright — including social scoring and some biometric categorization
High riskSubstantial obligations: risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness, conformity assessment
Limited riskTransparency duties — people must know they are interacting with AI
Minimal riskNo specific obligations

Two points organizations routinely miss. First, it applies extraterritorially — placing a system on the EU market or affecting people in the EU brings you in scope regardless of where you are based. Second, several common enterprise uses land in high risk, notably employment decisions, credit assessment, and education access. If you are doing automated hiring, read the high-risk obligations carefully.

Obligations phase in over time and guidance continues to develop, so verify current requirements and dates against official sources rather than relying on any summary.

Sector rules on top

Sector regulators add their own: financial services model risk management, healthcare device and clinical rules, insurance conduct requirements, and a growing body of state-level US law on automated employment decisions and insurance practices. These often bite sooner than the general frameworks.

A practical order

  1. Inventory your AI systems. You cannot govern what you have not listed, and most organizations discover they have more than they thought — including AI features inside approved SaaS.
  2. Classify by risk and jurisdiction. Who is affected, what happens when it is wrong, which regimes apply.
  3. Adopt AI RMF practices for the systems that matter. This produces most of the documentation the other regimes want.
  4. Close the technical controls — access control on retrieval, logging, human oversight, bias testing, evaluation.
  5. Pursue ISO 42001 certification only if customers require attestation.
  6. Track EU AI Act obligations if you have EU exposure, with legal advice on classification.
The documentation burden is real but mostly a byproduct of good engineering. If you have an eval set, a system inventory, access controls, and audit logs, you have the substance of compliance. Teams that treat governance as a separate paperwork exercise end up with documents that do not describe the system they built.

For a concrete deployment policy that sits alongside these frameworks, see Guardian's proposed Controlled Autonomy Standard and its thematic CSF and SOC 2 crosswalk.

Frequently asked questions

Is NIST AI RMF mandatory?

No, it is voluntary. However it is increasingly referenced in US federal procurement and contract language, and it is becoming a de facto expectation for vendors selling into government. If you sell to federal agencies, treat it as functionally required.

Does the EU AI Act apply to us if we are not in the EU?

Potentially yes. It has extraterritorial reach — if you place an AI system on the EU market, or the output is used in the EU, or it affects people in the EU, you can be in scope regardless of where your company sits. This mirrors GDPR's approach. Get legal advice on your specific situation.

What is the difference between ISO 42001 and NIST AI RMF?

AI RMF is a voluntary framework describing what good risk management looks like; you self-assess. ISO 42001 is a certifiable standard specifying a management system an accredited auditor can attest to. AI RMF tells you what to do; ISO 42001 gives you a certificate proving you do it.

Do we need a separate AI governance programme?

Usually not separate — extend what you have. Your existing security, privacy, and model-risk governance already covers much of it. What genuinely needs adding is an AI system inventory, evaluation and bias testing practices, and human-oversight requirements on consequential decisions.

Where do most organizations fail an AI governance review?

Three places consistently: no system inventory, so scope is unknown; no measurement, so claims about accuracy and fairness are unevidenced; and no documented human oversight on decisions that affect people. All three are fixable with engineering work rather than policy work.

Guardian Robotics is an AI consultancy.

We build the pipelines, agents, and automation this article describes — for commercial teams and federal agencies alike.