AI Governance 13 min read

ISO 42001 vs NIST AI RMF vs EU AI Act: Which Do You Need?

J

September 13, 2026

Most US companies that bring us this question end up with one of the three to certify to, one to borrow vocabulary from, and one to watch. ISO/IEC 42001 is the one you can be certified to. The NIST AI Risk Management Framework is the one your customers, your state legislature and your federal contracts will quote back to you. The EU AI Act is the one that applies only if your AI reaches the EU market, and if it does, nothing else on this list substitutes for it. The confusion comes from treating them as three competing answers to the same question. They are three different kinds of thing, and once you see that, the choice mostly makes itself.

Three different kinds of thing

ISO/IEC 42001:2023 is a management-system standard, published in December 2023. It follows the same Annex SL structure as ISO 9001, ISO 27001 and ISO 13485, so clauses 4 through 10 (context, leadership, planning, support, operation, performance evaluation, improvement) read the way anyone who has run a certified system expects. What makes it AI-specific is Annex A, a set of controls grouped into nine areas: AI policy, internal organisation, resources, impact assessment, the AI system lifecycle, data, information for interested parties, use of AI systems, and third-party and customer relationships. An accredited certification body audits you against it and issues a certificate. That certificate is the point. It is the only one of the three that produces a document a customer can ask to see. (Background in what is ISO 42001 and the clause-by-clause breakdown.)

NIST AI RMF 1.0 is voluntary guidance from the US National Institute of Standards and Technology, released in January 2023. It organises AI risk work into four functions, Govern, Map, Measure and Manage, with a companion Playbook of suggested actions and a Generative AI Profile added in 2024. Nobody certifies you to it. There is no auditor, no certificate and no penalty for ignoring it. Its value is that it has become the shared language of AI risk in the United States, and that language shows up in state statutes, federal procurement and customer questionnaires.

The EU AI Act (Regulation (EU) 2024/1689) is law. It entered into force in August 2024 and applies in stages. It sorts AI systems into risk tiers, bans a short list of practices outright, places heavy obligations on "high-risk" systems, adds transparency duties for systems like chatbots, and leaves most everyday AI use alone. It applies to providers placing systems on the EU market and to deployers using them in the EU, regardless of where the company is headquartered. Ignoring it is not a governance choice; it is a legal exposure with fines attached.

So you certify to 42001, you align with NIST, and you comply with the AI Act.

Side by side

ISO/IEC 42001:2023 NIST AI RMF 1.0 EU AI Act
What it is Certifiable management-system standard Voluntary guidance Binding EU regulation
Who issues it ISO and IEC US NIST European Parliament and Council
Legal force None on its own; contractual and market-driven None Mandatory for in-scope providers, deployers, importers and distributors
Third-party certificate Yes, from accredited certification bodies No Conformity assessment for high-risk systems, which is a different thing from an ISO certificate
Structure Clauses 4 to 10 plus Annex A controls in nine areas Govern, Map, Measure, Manage Risk tiers: prohibited, high-risk, transparency, minimal
Who it is for Any organisation developing or using AI Any organisation, US-centred in practice Anyone touching the EU market with an AI system
What ignoring it costs Lost deals and failed vendor reviews A weaker position under some US state laws Fines up to EUR 35 million or 7% of global turnover for the worst breaches
Relationship to the others Absorbs NIST vocabulary easily; helps with but does not satisfy the AI Act Crosswalked to 42001 by NIST itself Presumption of conformity only through harmonised standards cited in the Official Journal; none cited yet

What each one actually asks of you

ISO 42001

In practice, 42001 asks you to name the AI systems in scope, decide who is accountable for them, assess the risks and the impacts on people, choose which Annex A controls apply and justify the ones you leave out, run those controls, check them through internal audit and management review, and fix what you find. If you already run a 9001 or 27001 system, most of that already exists. The new work is the AI-specific inventory, the impact assessments and the Annex A controls. Our page on what 42001 adds to an ISO 9001 system walks through the difference.

NIST AI RMF

NIST asks nothing of you. It offers a way of organising the work. Govern covers policy, accountability and culture. Map covers understanding each system's context and the people it touches. Measure covers testing, metrics and monitoring. Manage covers what you do about what you measured. You can adopt it quickly by writing a profile that says which subcategories you address and which you do not, and many companies do exactly that to answer a customer questionnaire. The catch is that a self-declared profile is only as convincing as the evidence behind it, and NIST provides no mechanism to check.

EU AI Act

The AI Act asks different things of different roles. Providers of high-risk systems carry the heavy obligations: a risk management system (Article 9), data governance, technical documentation, logging, human oversight, accuracy and robustness, a quality management system (Article 17), conformity assessment and registration. Deployers of high-risk systems have their own duties under Article 26, and some deployers must run a fundamental rights impact assessment before use. Systems that interact with people must disclose that they are AI. The prohibited practices and the general-purpose model rules are already in force. Under the 2026 revisions, the high-risk obligations were pushed back to December 2027 and August 2028, which gives providers more time and also means the standards meant to support compliance are still being written.

Why ISO 42001 does not satisfy the EU AI Act

This is where most articles on the subject, including the earlier version of this one, were too generous. The AI Act gives a "presumption of conformity" to systems built to harmonised standards, but only to standards the European Commission has cited in the Official Journal of the European Union under Article 40. As of September 2026, no harmonised standard for the AI Act has been cited there.

EN ISO/IEC 42001:2026 was adopted as a European standard by CEN and CENELEC on 18 March 2026. That is real progress, and it makes 42001 a European standard in the formal sense. It does not make it a harmonised standard for the AI Act, and no citation has followed. The standard actually being drafted for the AI Act's quality management requirement is prEN 18286, targeted for late 2026. When it lands, it will be the document notified bodies look for under Article 17, and it will overlap heavily with 42001 without being identical to it.

So what does 42001 do for a company in AI Act scope? Quite a lot, as long as you describe it honestly. It gives you the management-system discipline (documented processes, defined accountability, internal audit, management review, corrective action) that Article 17 will require in some form. It gives you a risk and impact assessment process that maps closely to Article 9. It gives you records. What it does not give you is a certificate that an EU market surveillance authority is obliged to accept as evidence of compliance. In our experience buyers often assume a 42001 certificate will "cover" the AI Act, and budgets get built on that assumption. It will not, and the plan should say so. If EU exposure is your main driver, read ISO 42001 vs the EU AI Act for US companies before you set a budget.

Who needs which

A US company that sells AI-enabled products or services to enterprise customers, with no EU sales. You need ISO 42001. Vendor risk teams are starting to ask for it the way they came to ask for ISO 27001, and a NIST profile without a certificate answers the questionnaire without closing the gap. The AI Act does not apply to you unless your output is used in the EU.

A US company that uses AI internally, particularly inside a regulated quality system. Here the pressure comes from an investigator. In April 2026 FDA issued a warning letter (Purolea) citing "inappropriate use of artificial intelligence" under 21 CFR 211.22(c): specifications, procedures and master records written by AI and released without qualified review. It was the first time AI-generated quality records drew an FDA citation, and it is unlikely to be the last. For a GMP manufacturer, 42001 is the management-system answer to that finding, and a narrower AI-in-the-quality-system review is the fast first step. Our page for GMP manufacturers covers pharma, supplements, cosmetics and devices.

A federal contractor, or a company with exposure to state AI laws. NIST AI RMF alignment is what the paperwork asks for. Texas's TRAIGA took effect on 1 January 2026 and, in our reading, gives weight to documented adherence to the NIST AI RMF when a company is defending its conduct. Colorado replaced its 2024 AI Act with a narrower law, SB 26-189, effective 1 January 2027. Other states are moving, and none of this is settled. The sensible position is to be able to produce a NIST-shaped profile on request, with the evidence behind it. No certificate is needed for that.

A company placing AI systems on the EU market, or whose AI output is used in the EU. The AI Act applies. Work out your role (provider, deployer, importer, distributor) and the risk tier of each system first, because that determines nearly everything else. Then build the management system, with 42001 as the sensible shape for it, while watching prEN 18286.

A company building or deploying AI agents. AIUC-1 is a newer assurance standard written specifically for AI agents, with published crosswalks to 42001. Treat it as a complement: 42001 governs the organisation and AIUC-1 attests to the agent. It does not replace either of the other two.

Why a US company usually ends up with 42001 plus NIST vocabulary

In my experience the answer for a US client converges on the same place more often than not, and the reasons are practical. ISO 42001 becomes the certifiable spine of the program, and the NIST functions become the language the documents are written in.

First, customers want a certificate, and NIST cannot issue one. The moment a buyer's vendor risk questionnaire moves from "do you have an AI policy" to "are you certified", NIST alignment stops being a complete answer. Fewer than 100 organisations held a 42001 certificate in January 2026 and roughly 350 did by spring 2026 (there is no official register, so those numbers are assembled from announcements). That is small enough that certification still sets you apart and large enough that buyers have started to ask.

Second, the NIST vocabulary is what US law and US customers speak, and 42001 accommodates it without strain. NIST has published a crosswalk between the AI RMF and ISO 42001. In practice we write the AI policy and the risk assessment so that a reader looking for Govern, Map, Measure and Manage finds them, and a certification auditor looking for clauses 6 and 8 finds those too. One set of documents serves both audiences.

Third, if you already run a certified management system, 42001 adds to what you have. The clauses are the same clauses. Internal audit, management review, document control and corrective action already exist; you add the AI inventory, the impact assessments and the Annex A controls to them. This is also why organisations with a working 27001 or 9001 system tend to sit at the short end of the typical four-to-twelve-month timeline from gap assessment to certificate.

Fourth, the calendar argues for starting now. Certification bodies are reporting auditor backlogs, and some Stage 2 audits have waited six months or more. If a customer contract in 2027 will require the certificate, the timeline is already tight. Our realistic timeline article lays out the stages.

On cost, the 2026 market ranges we see are roughly $1,500 to $2,500 for a two-day gap assessment at a small organisation using one or two AI tools, $5,000 to $20,000 for a scoped readiness review at a larger one, and $85,000 to $150,000 in total first-year cost for a 50-to-200-person company once internal time, tooling and the certification body are included. Treat those as ranges. The full budget guide breaks them down.

What an auditor or an investigator will ask, whichever you pick

The three differ in legal weight, and the questions a competent auditor or FDA investigator asks barely differ at all. Which AI tools are in use, and where is the list? Who approved each one, and against what criteria? What data goes in, and who is allowed to send it? Who reviews the output before it becomes a record, a decision or a product feature, and how is that review documented? What happens when the tool is wrong? Whether the person asking holds a 42001 checklist, a NIST profile or an FDA Form 483, those are the questions. A management system exists so that the answers are written down before anyone asks.

Where to start

If you are still deciding, the cheapest way to find out where you stand is a gap assessment against 42001 that also notes the NIST functions and, where relevant, the AI Act articles each gap touches. Ours is a fixed fee of $9,750 and produces a prioritised list you can hand to whoever will own the system; details are on the gap assessment page. If your immediate worry is AI-written records inside an FDA- or ISO-regulated quality system, the $5,000 AI-in-the-quality-system review is narrower and faster. If you already know you need the full system, our ISO 42001 consulting page explains how we run an implementation, and the comparison of DIY, consultant and fractional approaches will tell you what each costs you in internal time.

Frequently Asked Questions

Does ISO 42001 certification satisfy the EU AI Act?

No. As of 2026 no harmonised standard for the AI Act has been cited in the Official Journal of the European Union, so a 42001 certificate gives no presumption of conformity. The standard being written for the AI Act's quality management requirement is prEN 18286, targeted for late 2026.

Is the NIST AI RMF certifiable?

No. NIST AI RMF 1.0 is voluntary guidance with no certification scheme behind it, so you can align to it and say so, but no third party will issue a certificate. ISO/IEC 42001 is the certifiable AI management-system standard.

Does the EU AI Act apply to a US company?

Only if the company places an AI system on the EU market or the system's output is used in the EU. If either is true, the obligations apply regardless of where the company is headquartered, and under the 2026 revisions the high-risk obligations phase in during December 2027 and August 2028.

Which should a US company start with?

For most US companies, ISO 42001 as the system you get certified to, written so that the NIST AI RMF functions (Govern, Map, Measure, Manage) are easy to find inside it. The EU AI Act only enters the plan if your AI reaches the EU market.

J

Jared Clark

Principal Consultant, Certify Consulting

Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.