One of the most common mistakes I see teams make is to treat "AI governance" as a single word. It is not. Right now, in September 2026, there are three different things that people mean when they say those two words. Which one your customer is asking for, which one your regulator is enforcing, which one your board is worried about — these are three separate questions and they usually have three separate answers. Let me walk each one, and then show you how they connect.
The three things people mean by "AI governance"
Look at any AI governance conversation and you will find three different framings competing for attention:
| ISO/IEC 42001:2023 | NIST AI RMF 1.0 | EU AI Act 2024/1689 | |
|---|---|---|---|
| What it is | International management-system standard | Voluntary US federal risk management framework | Binding EU law (Regulation) |
| Certifiable? | Yes, by accredited CB | No formal certification | Conformity assessment for high-risk AI (external for some) |
| Published / in force | Published 18 Dec 2023 | Published 26 Jan 2023 | Phased in force from 2 Feb 2025 through 2 Aug 2028 |
| Who publishes / enforces | ISO and IEC (JTC 1/SC 42) | US National Institute of Standards and Technology | European Parliament and Council; enforced by national market surveillance authorities and EU AI Office |
| Structure | 10 clauses + 38 Annex A controls | 4 functions: Govern, Map, Measure, Manage | Article-and-Annex structure with risk tiers |
| Penalty for non-compliance | Certificate withheld or suspended by CB | None (voluntary) | Up to EUR 35 million or 7% of global turnover |
These are not competing standards. They are three different types of instrument. Let me walk each one so you understand which one applies when.
ISO/IEC 42001 — the management-system standard
ISO 42001 is a management-system standard [L3-C1]. That means it does not tell you what technology to use, what fairness metric to hit, or what risk score to allow. It tells you what processes to run — a policy, a risk methodology, an impact assessment, an internal audit programme, a management review. If you run those processes properly and pass an audit, you get a certificate that says so. The certificate is what your enterprise buyer wants to see because it is verifiable third-party evidence that you are managing AI risk in a documented, repeatable way. Certification bodies accredited by IAF-MLA signatories (ANAB in the US, UKAS in the UK, RvA in the Netherlands, NABCB pending in India) issue the certificates. The certificate is valid for three years with annual surveillance.
When your European buyer says "provide your ISO 42001 certificate," they mean this. When MeitY's India AI Governance Guidelines recommend a management-system standard in Annexure 6, they mean this. When your GCC parent's compliance team says "we need an AI Management System," they mean this. This is the operational answer.
NIST AI Risk Management Framework 1.0 — the voluntary framework
NIST published the AI Risk Management Framework Version 1.0 on 26 January 2023 [L3-C7]. It is voluntary. There is no certification, no penalty for non-compliance, no auditor. NIST publishes it as guidance and organisations adopt as much or as little as they want.
The AI RMF has four core functions:
- GOVERN — cultivate a culture of AI risk management, establish policies, accountability structures, and oversight across the organisation. This function is cross-cutting: it applies at all stages of the other three.
- MAP — establish the context for the risks related to each AI system.
- MEASURE — analyse, assess, benchmark and monitor AI risk quantitatively and qualitatively.
- MANAGE — allocate risk resources, implement risk treatments, incident response, continual improvement.
There is an official crosswalk document published by NIST at airc.nist.gov that maps 71 AI RMF categories to corresponding sections of ISO/IEC 42001. So if you have already invested in AI RMF, you can carry that investment forward into 42001. Module 8 of this course walks the crosswalk in detail.
When is AI RMF the right answer? Two situations. First, if your customer is a US federal agency or a federal contractor under NIST guidance, AI RMF is the framework of choice — because it is voluntary but named specifically in federal AI risk guidance documents. Second, if you want a framework to structure your internal risk thinking without committing to certification cost and audit cycle, AI RMF is a lightweight way in. But your enterprise buyer usually cannot accept "we follow NIST AI RMF" as a substitute for a certificate — because there is no third-party audit behind it.
EU AI Act — the binding law
Regulation (EU) 2024/1689 is a binding EU law with extraterritorial reach. It applies not only to EU-based providers of AI systems but to any provider whose AI systems are placed on the EU market or whose output is used in the EU. So an Indian SaaS whose AI feature is used by European customers is caught. An Indian outsourcing company running an AI-enabled analytics service for a European insurer is caught. This is why the Act matters to a lot of Indian teams even though we are not in the EU.
The Act has a risk-tier structure. It divides AI systems into four categories:
- Prohibited practices (Article 5) — social scoring, subliminal manipulation, real-time biometric identification in public spaces (with narrow exceptions), workplace emotion inference. Live from 2 February 2025
[L3-C8]. - High-risk AI systems — either specifically listed (Annex III: education, employment, credit, insurance, law enforcement, migration, judicial) or embedded in products already regulated (Annex I: medical devices, machinery, toys, aviation). Full conformity assessment obligations. Live for Annex III from 2 December 2027; for Annex I from 2 August 2028. Both were pushed back by the Digital Omnibus.
- Limited-risk AI systems with transparency obligations — chatbots, generative content. Users must be informed. Article 50. Live from 2 August 2026
[L3-C9]. - Minimal-risk AI systems — everything else. No obligations.
General-Purpose AI (GPAI) models — foundation models like GPT-family, Claude-family, Gemini-family — have their own transparency obligations that came into force on 2 August 2025 for newly-released models. Any Indian organisation training or providing a general-purpose model for EU deployment must meet Article 53 documentation requirements.
Penalties: up to EUR 35 million or 7 percent of global turnover for prohibited-practice violations, EUR 15 million or 3 percent for other violations, EUR 7.5 million or 1 percent for supplying incorrect information. These are annual-turnover-based penalties, so a global Indian IT services company that trips prohibited-practice enforcement is exposed to real money.
How the three connect
The clean way to think about this is: the EU AI Act tells you what you cannot do and what you must document. NIST AI RMF tells you how to think about AI risk. ISO 42001 tells you how to run the management system that operationalises both. Well-run organisations do not pick one and ignore the other two — they build the AIMS and then use it to demonstrate compliance with the AI Act (for EU exposure) and alignment with AI RMF (for US exposure).
Concretely, in a running organisation, ISO 42001 becomes your operating system for AI governance. Your Statement of Applicability shows how each of the 38 Annex A controls is implemented. When the EU AI Act asks about your risk management, human oversight, transparency and post-market monitoring, you point at the SoA and say — here is the process, here is the evidence, here is the audit report. Same when a NIST-aligned customer asks about your Govern-Map-Measure-Manage cadence.
This is the strategic insight. ISO 42001 is not an alternative to the EU AI Act or NIST AI RMF. It is the vehicle through which you demonstrate compliance with the EU AI Act and alignment with NIST AI RMF, using a single documented system.
India's own layer sits above all three
Then, above all three, sits India's own regulatory layer. The India AI Governance Guidelines released by MeitY in November 2025 name ISO 42001 in Annexure 6 [L3-C3]. The IT Amendment Rules 2026 on Synthetically Generated Information add operational duties for AI-generated content [L3-C4]. The SEBI 5 May 2026 AI Advisory imposes vulnerability-management duties on regulated entities [L3-C5]. The RBI FREE-AI Committee Report of August 2025 signals what is coming for BFSI [L3-C6]. Module 8 of this course walks the whole India layer in detail. For now, know that the ISO baseline plus the India overlay is the full picture. Neither one is sufficient on its own.
Next lesson, I want to walk what actually happens inside an ISO 42001 certification project — the twelve to eighteen month path, the artefacts you produce, the audit stages, and what happens after certification. That will give you the shape of what the rest of this course is teaching you to build.