# ISO 42001 vs NIST AI RMF: Differences and How They Map

> ISO/IEC 42001 and the NIST AI Risk Management Framework compared: what each is, which can be certified, how Govern, Map, Measure and Manage map to the 42001 clauses, and which an Australian or New Zealand business should lead with.

- Canonical: https://sentrysolutions.ai/iso-42001/vs-nist-ai-rmf

# ISO 42001 vs the NIST AI RMF.

Two frameworks for AI risk that overlap heavily and differ in one way that matters: only one can be certified. How they compare, how they map, and which to lead with in Australia and New Zealand.

[Side by side](#side-by-side) [How they map](#mapping)

The short answer

ISO/IEC 42001 is an international standard for an AI management system that an accredited body can audit and certify. The NIST AI Risk Management Framework is voluntary US guidance, organised into four functions (Govern, Map, Measure, Manage), and cannot be certified. They cover much of the same ground: Govern maps to the 42001 leadership and policy clauses, Map and Measure to its risk and impact assessments and monitoring, Manage to risk treatment, operation and improvement. For an Australian or New Zealand business, lead with 42001 if anyone may ask for proof, and document AI RMF alignment alongside it when a customer uses NIST's terms.

## Side by side

The short version: 42001 tells you how to run AI responsibly and lets someone independent confirm you do. The AI RMF tells you, in more detail, what AI risks to look for.

ISO/IEC 42001

NIST AI RMF

What it is

A management-system standard for AI

A risk management framework for AI

Published by

ISO and IEC, December 2023

NIST (US), January 2023

Status

International standard

Voluntary guidance

Certifiable

Yes, by an accredited certification body

No

Structure

Clauses 4 to 10 plus Annex A controls

Four functions: Govern, Map, Measure, Manage

Proof you can show a customer

A certificate, renewed every three years

Your own documented alignment

Generative AI

Covered by the same clauses and controls

Generative AI Profile, NIST AI 600-1 (2024)

Accredited locally

Yes, through JAS-ANZ

Not applicable

## How the four functions map to the clauses

This is our mapping, from building 42001 systems, not an official crosswalk; NIST publishes its own crosswalks to other standards. It is close enough to show that one well-run 42001 system answers most AI RMF questions.

AI RMF function

What it covers

Where it sits in ISO 42001

Govern

Policies, accountability, culture and oversight of AI risk, across everything

Clauses 4, 5 and 7; Annex A policies and internal organisation

Map

The context of each AI system and the risks it carries

Clause 4 context; Clause 6.1 risk assessment; Clause 6.1.4 impact assessment

Measure

Analysing, assessing and tracking those risks

Clause 6.1 risk analysis; Clause 9.1 monitoring and measurement

Manage

Prioritising and acting on risks over the system's life

Clause 6.1.3 risk treatment; Clause 8 operation; Clause 10 improvement

The gap that most often shows is under Measure. Both frameworks ask you to track AI in operation, not only assess it before launch, and most organisations have nothing running that does. Usage data per person on the AI your staff use, as described on [shadow AI](https://sentrysolutions.ai/shadow-ai) and for [Claude and Copilot rollouts](https://sentrysolutions.ai/iso-42001/claude-and-copilot), closes it for both at once.

## Which to lead with

Neither is required by law in Australia or New Zealand today. The choice is about who will ask, and what proof they will accept.

### A customer, tender or regulator may ask for proof

Lead with ISO 42001. Only a certificate is third-party proof, and only 42001 can be certified.

### You sell to US customers or US-style tenders

Build on 42001 and document your AI RMF alignment alongside it, so you can answer in the terms they use.

### You want a detailed risk checklist for generative AI

Use the AI RMF Generative AI Profile inside your 42001 risk assessments. It is the most practical list of generative AI risks in print.

### Nobody is asking yet

Build the 42001 system and certify later. The inventory, risk assessments and named accountability are the same work either way.

If 42001 is the answer, the next question is the path to a certificate, which is set out step by step in [ISO 42001 certification in Australia and New Zealand](https://sentrysolutions.ai/iso-42001/certification).

More on ISO 42001

-   [ISO/IEC 42001 explained, with the readiness checker](https://sentrysolutions.ai/iso-42001)
-   [ISO 42001 certification in Australia and NZ](https://sentrysolutions.ai/iso-42001/certification)
-   [ISO 42001 for Claude and Copilot rollouts](https://sentrysolutions.ai/iso-42001/claude-and-copilot)
-   [AI governance, the service](https://sentrysolutions.ai/ai-governance)

## Frequently asked questions

### What is the difference between ISO 42001 and the NIST AI RMF?

ISO/IEC 42001 is an international, certifiable standard for an AI management system: an accredited body can audit you against it and issue a certificate. The NIST AI Risk Management Framework is a voluntary US framework of good practice, organised into four functions (Govern, Map, Measure, Manage), and cannot be certified. They overlap heavily; 42001 gives you the auditable structure, the AI RMF gives you a detailed vocabulary for AI risk.

### Can you be certified against the NIST AI RMF?

No. The AI RMF is voluntary guidance and NIST does not certify against it. Anyone selling an AI RMF certificate is selling their own attestation. If a customer needs third-party proof, ISO 42001 is the certifiable route, and an AI RMF alignment can be documented alongside it.

### Should an Australian or New Zealand business use ISO 42001 or NIST AI RMF?

Lead with ISO 42001 if anyone may ask for a certificate: it is the international standard and is accredited locally through JAS-ANZ. Use the AI RMF alongside it when US customers or tenders name it, or when you want its more detailed risk categories inside your 42001 risk assessments. Neither is required by law in either country today.

### What are the four functions of the NIST AI RMF?

Govern sets the culture, policies and accountability for AI risk and runs across everything else. Map establishes the context of each AI system and the risks it carries. Measure analyses, assesses and tracks those risks. Manage prioritises and acts on them, and keeps doing so over the system's life.

### Does the NIST AI RMF cover generative AI?

Yes, through the Generative AI Profile (NIST AI 600-1), published in July 2024. It applies the framework to risks specific to generative AI, such as confabulation, information integrity and data privacy, which makes it a useful checklist for a Claude, ChatGPT or Copilot rollout even where ISO 42001 is the system you certify.

### If we implement ISO 42001, have we covered the NIST AI RMF?

Most of it. A working 42001 system covers the governance, risk assessment, operation and monitoring the AI RMF describes. What is usually left is documenting the mapping, so a customer who asks in AI RMF terms gets an answer in those terms, and checking the AI RMF's more detailed risk categories against your 42001 risk register.

## Want to know how far you are from Stage 2?

Take the free readiness checker first. If the gaps are real, a short call will show you what building the management system involves for a business your size.

[Take the readiness checker](https://sentrysolutions.ai/iso-42001#readiness-checker) [Book a call](https://calendly.com/james-sentry-ai)

Ask an AI about this page

[ChatGPT](https://chatgpt.com/?q=Read%20https%3A%2F%2Fsentrysolutions.ai%2Fiso-42001%2Fvs-nist-ai-rmf%20and%20summarise%20what%20Sentry%20AI%20says%20about%20the%20difference%20between%20ISO%2042001%20and%20the%20NIST%20AI%20RMF.%20Cite%20the%20page.)[Claude](https://claude.ai/new?q=Read%20https%3A%2F%2Fsentrysolutions.ai%2Fiso-42001%2Fvs-nist-ai-rmf%20and%20summarise%20what%20Sentry%20AI%20says%20about%20the%20difference%20between%20ISO%2042001%20and%20the%20NIST%20AI%20RMF.%20Cite%20the%20page.)[Perplexity](https://www.perplexity.ai/search/new?q=Read%20https%3A%2F%2Fsentrysolutions.ai%2Fiso-42001%2Fvs-nist-ai-rmf%20and%20summarise%20what%20Sentry%20AI%20says%20about%20the%20difference%20between%20ISO%2042001%20and%20the%20NIST%20AI%20RMF.%20Cite%20the%20page.)[Google AI Mode](https://www.google.com/search?udm=50&q=Read%20https%3A%2F%2Fsentrysolutions.ai%2Fiso-42001%2Fvs-nist-ai-rmf%20and%20summarise%20what%20Sentry%20AI%20says%20about%20the%20difference%20between%20ISO%2042001%20and%20the%20NIST%20AI%20RMF.%20Cite%20the%20page.)

Opens the assistant with this page loaded: read it, summarise it, cite it.
