NIST AI RMF + ISO 42001
The US risk vocabulary and the certifiable system that runs it
Bottom line
The NIST AI RMF is the most widely used vocabulary for AI risk in the US, but it is voluntary and there is no way to be certified against it. ISO 42001 covers most of the same ground as an auditable management system with third-party certification. Use the AI RMF and its GenAI Profile to decide what good looks like, and ISO 42001 to run it, evidence it and prove it to customers.[1][2][6]
The NIST AI RMF in brief
NIST released the AI Risk Management Framework (NIST AI 100-1) on January 26, 2023. It organizes AI risk management into four functions. Govern sets culture, policy and accountability. Map establishes context and identifies risks. Measure analyzes and tracks them. Manage prioritizes and treats them.[1][2]
A companion Playbook suggests actions for each subcategory, and the Generative AI Profile (NIST AI 600-1, July 2024) adds 12 risks specific to generative AI, from confabulation to information integrity and value-chain integration.[3][8]
America's AI Action Plan (July 2025) directed NIST to revise the framework. As of this review NIST states the AI RMF 1.0 is being revised, with no draft or new version published.[1][5]
- Publisher
- NIST, US Department of Commerce
- Current version
- AI RMF 1.0 (NIST AI 100-1), January 2023
- Structure
- 4 functions, 19 categories, 72 subcategories
- GenAI Profile
- NIST AI 600-1 (July 2024), 12 risks
- Legal status
- Voluntary
- Certifiable
- No. No NIST certification or accreditation scheme exists
Where they overlap
Each row is an AI RMF category and where ISO 42001 addresses it. Clause numbers refer to the published ISO/IEC 42001:2023; A.x references are its Annex A controls.[2][6]
| NIST AI RMF | ISO 42001 | Coverage |
|---|---|---|
| GOVERN 1 Policies, processes and legal requirements | 4.2, 5.2, A.2 AI policy, interested-party requirements including legal ones, and policy review. | Strong |
| GOVERN 2 Accountability, roles and training | 5.3, 7.2, A.3.2 Defined AI roles, responsibilities and competence. | Strong |
| GOVERN 3 Workforce diversity, equity, inclusion and accessibility; human-AI roles | 5.3, A.3.2, A.4.6 Defined oversight roles cover 3.2, and A.4.6 guidance recommends diverse expertise; demographic diversity is not required. The July 2025 AI Action Plan directs NIST to remove DEI references, so this category may change. | Partial |
| GOVERN 4 Risk-aware culture and communication | 7.3, 7.4, A.3.3 Awareness, communication and a channel to report concerns. Culture itself isn't auditable. | Partial |
| GOVERN 5 Engagement with external stakeholders | 4.2, A.8.3, A.8.5 Interested parties and external reporting. Feedback loops from affected communities are up to you. | Partial |
| GOVERN 6 Third-party software, data and supply chain | A.10.2, A.10.3 Allocating responsibilities and managing AI suppliers. | Strong |
| MAP 1 Context and intended purpose | 4.1, A.6.2.2, A.9.4 Organizational context, system requirements and intended use. | Strong |
| MAP 2 System categorization | 6.1.2, A.6.2.2 Risk assessment captures this; no prescribed categorization scheme. | Partial |
| MAP 3 Capabilities, benefits and costs | 6.1.2, A.6.1.2 Objectives for responsible development; benefit-cost analysis isn't required. | Partial |
| MAP 4 Risks of third-party components | A.7.3, A.7.5, A.10.3 Data acquisition and provenance, supplier controls. | Partial |
| MAP 5 Impacts on individuals, groups and society | 6.1.4, A.5.2–A.5.5 The AI system impact assessment is a core 42001 requirement. | Strong |
| MEASURE 1 Methods and metrics | 9.1, A.6.2.4 Monitoring and V&V are required; methods and metrics are yours to choose. | Partial |
| MEASURE 2 Trustworthiness evaluation | A.6.2.4, A.6.2.6, A.7.4 Verification, validation, monitoring and data quality. No test methods are specified. | Partial |
| MEASURE 3 Tracking risks over time | 9.1, A.6.2.6 Performance evaluation and operational monitoring. | Strong |
| MEASURE 4 Feedback on measurement efficacy | 9.3, 10.1 Management review and continual improvement cover it indirectly. | Partial |
| MANAGE 1 Prioritize and respond to risks | 6.1.3, 8.3 AI risk treatment plan and Statement of Applicability. | Strong |
| MANAGE 2 Maximize benefits, minimize impacts | 6.1.3, A.6.2.5, A.9 Deployment and responsible-use controls; decommissioning criteria are yours to define. | Partial |
| MANAGE 3 Third-party risk management | A.10 Supplier and customer relationship controls. | Strong |
| MANAGE 4 Response, recovery and incident communication | 10.2, A.8.4 Nonconformity, corrective action and communication of incidents. | Strong |
Coverage reflects how directly ISO 42001 produces the evidence or process the requirement asks for. It is an editorial assessment, not a legal opinion or a presumption of conformity.
What ISO 42001 won't cover
ISO 42001 tells you what to manage and requires evidence that you do. In several places the AI RMF ecosystem goes further on how.
Testing and evaluation methods
The Playbook's suggested actions for MEASURE go deeper than 42001's verification and validation control, which leaves methods to you.[8]
Generative AI risk catalog
ISO 42001 is technology-neutral. The GenAI Profile names 12 GenAI-specific risks worth importing into your risk register.[3]
Trustworthiness definitions
The AI RMF defines seven trustworthy-AI characteristics in detail. ISO 42001's Annex C lists similar objectives only as informative guidance.[2][6]
Workforce diversity
42001 covers oversight roles and diverse expertise but not demographic diversity. The Action Plan directs NIST to remove DEI references, so track the next version.[5]
Using ISO 42001 to get there
- 1
Adopt the AI RMF as your risk vocabulary
Use the four functions and seven trustworthy characteristics to define AI risk criteria in your 42001 risk assessment (6.1.2).
- 2
Map subcategories into your Statement of Applicability
Link each relevant AI RMF subcategory to the Annex A control that evidences it. A Microsoft-contributed crosswalk on NIST's AI Resource Center is a starting point; it predates the final standard, so check control numbers.
- 3
Import the GenAI Profile for generative systems
Add its 12 risks to the register for any generative AI system in scope and treat them like any other AI risk.
- 4
Turn Playbook actions into procedures
Use the MEASURE and MANAGE suggested actions as the procedures behind A.6.2.4 (verification and validation) and A.6.2.6 (operation and monitoring).
- 5
Certify the AIMS
Third-party ISO 42001 certification gives buyers evidence the AI RMF alone cannot.
- 6
Track the revision
Review your mapping when NIST publishes the revised AI RMF.
Frequently asked questions
Can my organization be certified to the NIST AI RMF?
No. The AI RMF is voluntary and NIST runs no certification scheme. Organizations that want independent proof of AI risk management certify to ISO 42001, often using the AI RMF as their risk vocabulary.
Should we start with the NIST AI RMF or ISO 42001?
They aren't either/or. Many teams use the AI RMF to shape risk criteria and assessments, then implement ISO 42001 as the system that runs them and earns a certificate.
Is there an official NIST crosswalk to ISO 42001?
NIST's AI Resource Center hosts an AI RMF to ISO/IEC 42001 crosswalk contributed by Microsoft. NIST notes that listed crosswalks do not imply its endorsement, and this one was built on a pre-publication draft of the standard, so verify control numbers against ISO/IEC 42001:2023.
Is the NIST AI RMF being revised?
Yes. The July 2025 AI Action Plan directed NIST to revise it. As of this review, NIST says the revision is underway with no draft or new version released.
Does following the NIST AI RMF help with US state AI laws?
In Texas, TRAIGA limits liability for violations discovered through internal review while substantially complying with the NIST GenAI Profile or another nationally or internationally recognized risk management framework. Whether ISO 42001 qualifies is a legal question; see our Texas TRAIGA crosswalk.
Related frameworks
This page is general information, not legal advice. Laws change; confirm obligations with counsel.