ISO 42001 / NIST

AI management standards

Voluntary, auditable frameworks for running AI responsibly: ISO/IEC 42001 as a certifiable management system, and the NIST AI Risk Management Framework as a risk method.

Who it applies to

Organisations that need to show customers, auditors, insurers or boards that their AI governance is systematic — and anyone building the evidence the EU AI Act and UK regulators will ask for.

Latest check 27 Sep 2026 6 rules · See changes in the Ledger


The rules

ISO/IEC 42001:2023

"Information technology — Artificial intelligence — Management system", published December 2023 (edition 1). ISO describes it as the world's first AI management system standard: requirements for establishing, implementing, maintaining and continually improving an AI management system, for organisations of any size that develop, provide or use AI.

Verified 27 Sep 2026 · Read the source

ISO/IEC 42006:2025

Published July 2025. It sets additional requirements for bodies that audit and certify AI management systems against ISO/IEC 42001, supplementing ISO/IEC 17021-1 — so certificates are issued by auditors with AI-specific competence.

Verified 27 Sep 2026 · Read the source

NIST AI Risk Management Framework 1.0

Released 26 January 2023 by the US National Institute of Standards and Technology. It is intended for voluntary use, to help organisations build trustworthiness into the design, development, use and evaluation of AI.

Verified 27 Sep 2026 · Read the source

The NIST Generative AI Profile

NIST AI 600-1, "Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile", released 26 July 2024. It applies the AI RMF to risks specific to or heightened by generative AI.

Verified 27 Sep 2026 · Read the source

The four functions of the NIST AI RMF

Govern, Map, Measure and Manage. Govern is the cross-cutting culture and accountability layer; Map establishes context and risks; Measure analyses and tracks them; Manage prioritises and acts on them.

Verified 27 Sep 2026 · Read the source

Status of the NIST AI RMF

NIST states that AI RMF 1.0 is being revised as part of the White House AI Action Plan. Check which version your assurance work references.

Verified 27 Sep 2026 · Read the source


What people get wrong

The three misreadings we see most often, and what follows from them.

Treating ISO/IEC 42001 certification as proof of EU AI Act compliance.

42001 certifies a management system, not that a particular AI system meets the Act's legal requirements. It is strong evidence of governance, but high-risk systems still need their own conformity assessment.

Adopting the NIST AI RMF as a document rather than a practice.

The framework is voluntary and outcome-focused. A mapped policy with no measurement or management activity behind it shows an auditor exactly where the gap is.

Picking one framework and ignoring the other.

They answer different questions: 42001 is how you run AI governance as a system; the NIST RMF is how you analyse risk in a given AI use. Most mature programmes use a management system for the first and a risk method for the second.


The other four

The EU AI ActThe UK's approach to AI regulationThe Information Commission and UK GDPRSector regulators and AI
Next step

Knowing the rule is not the same as having a process

Module 31, AI regulation: the EU AI Act and the UK approach, turns these into what you actually need: which rules apply to you, what they require and by when, and the steps to put in place.

This is education, not legal advice. Every rule links to its primary source so you can read the original for yourself.