ISO 42001 vs the NIST AI RMF.
Two frameworks for AI risk that overlap heavily and differ in one way that matters: only one can be certified. How they compare, how they map, and which to lead with in Australia and New Zealand.
The short answer
ISO/IEC 42001 is an international standard for an AI management system that an accredited body can audit and certify. The NIST AI Risk Management Framework is voluntary US guidance, organised into four functions (Govern, Map, Measure, Manage), and cannot be certified. They cover much of the same ground: Govern maps to the 42001 leadership and policy clauses, Map and Measure to its risk and impact assessments and monitoring, Manage to risk treatment, operation and improvement. For an Australian or New Zealand business, lead with 42001 if anyone may ask for proof, and document AI RMF alignment alongside it when a customer uses NIST's terms.
Side by side
The short version: 42001 tells you how to run AI responsibly and lets someone independent confirm you do. The AI RMF tells you, in more detail, what AI risks to look for.
| ISO/IEC 42001 | NIST AI RMF | |
|---|---|---|
| What it is | A management-system standard for AI | A risk management framework for AI |
| Published by | ISO and IEC, December 2023 | NIST (US), January 2023 |
| Status | International standard | Voluntary guidance |
| Certifiable | Yes, by an accredited certification body | No |
| Structure | Clauses 4 to 10 plus Annex A controls | Four functions: Govern, Map, Measure, Manage |
| Proof you can show a customer | A certificate, renewed every three years | Your own documented alignment |
| Generative AI | Covered by the same clauses and controls | Generative AI Profile, NIST AI 600-1 (2024) |
| Accredited locally | Yes, through JAS-ANZ | Not applicable |
How the four functions map to the clauses
This is our mapping, from building 42001 systems, not an official crosswalk; NIST publishes its own crosswalks to other standards. It is close enough to show that one well-run 42001 system answers most AI RMF questions.
| AI RMF function | What it covers | Where it sits in ISO 42001 |
|---|---|---|
| Govern | Policies, accountability, culture and oversight of AI risk, across everything | Clauses 4, 5 and 7; Annex A policies and internal organisation |
| Map | The context of each AI system and the risks it carries | Clause 4 context; Clause 6.1 risk assessment; Clause 6.1.4 impact assessment |
| Measure | Analysing, assessing and tracking those risks | Clause 6.1 risk analysis; Clause 9.1 monitoring and measurement |
| Manage | Prioritising and acting on risks over the system's life | Clause 6.1.3 risk treatment; Clause 8 operation; Clause 10 improvement |
The gap that most often shows is under Measure. Both frameworks ask you to track AI in operation, not only assess it before launch, and most organisations have nothing running that does. Usage data per person on the AI your staff use, as described on shadow AI and for Claude and Copilot rollouts, closes it for both at once.
Which to lead with
Neither is required by law in Australia or New Zealand today. The choice is about who will ask, and what proof they will accept.
A customer, tender or regulator may ask for proof
Lead with ISO 42001. Only a certificate is third-party proof, and only 42001 can be certified.
You sell to US customers or US-style tenders
Build on 42001 and document your AI RMF alignment alongside it, so you can answer in the terms they use.
You want a detailed risk checklist for generative AI
Use the AI RMF Generative AI Profile inside your 42001 risk assessments. It is the most practical list of generative AI risks in print.
Nobody is asking yet
Build the 42001 system and certify later. The inventory, risk assessments and named accountability are the same work either way.
If 42001 is the answer, the next question is the path to a certificate, which is set out step by step in ISO 42001 certification in Australia and New Zealand.
Frequently asked questions
What is the difference between ISO 42001 and the NIST AI RMF?
ISO/IEC 42001 is an international, certifiable standard for an AI management system: an accredited body can audit you against it and issue a certificate. The NIST AI Risk Management Framework is a voluntary US framework of good practice, organised into four functions (Govern, Map, Measure, Manage), and cannot be certified. They overlap heavily; 42001 gives you the auditable structure, the AI RMF gives you a detailed vocabulary for AI risk.
Can you be certified against the NIST AI RMF?
No. The AI RMF is voluntary guidance and NIST does not certify against it. Anyone selling an AI RMF certificate is selling their own attestation. If a customer needs third-party proof, ISO 42001 is the certifiable route, and an AI RMF alignment can be documented alongside it.
Should an Australian or New Zealand business use ISO 42001 or NIST AI RMF?
Lead with ISO 42001 if anyone may ask for a certificate: it is the international standard and is accredited locally through JAS-ANZ. Use the AI RMF alongside it when US customers or tenders name it, or when you want its more detailed risk categories inside your 42001 risk assessments. Neither is required by law in either country today.
What are the four functions of the NIST AI RMF?
Govern sets the culture, policies and accountability for AI risk and runs across everything else. Map establishes the context of each AI system and the risks it carries. Measure analyses, assesses and tracks those risks. Manage prioritises and acts on them, and keeps doing so over the system's life.
Does the NIST AI RMF cover generative AI?
Yes, through the Generative AI Profile (NIST AI 600-1), published in July 2024. It applies the framework to risks specific to generative AI, such as confabulation, information integrity and data privacy, which makes it a useful checklist for a Claude, ChatGPT or Copilot rollout even where ISO 42001 is the system you certify.
If we implement ISO 42001, have we covered the NIST AI RMF?
Most of it. A working 42001 system covers the governance, risk assessment, operation and monitoring the AI RMF describes. What is usually left is documenting the mapping, so a customer who asks in AI RMF terms gets an answer in those terms, and checking the AI RMF's more detailed risk categories against your 42001 risk register.
Want to know how far you are from Stage 2?
Take the free readiness checker first. If the gaps are real, a short call will show you what building the management system involves for a business your size.
Ask an AI about this page
Opens the assistant with this page loaded: read it, summarise it, cite it.