Live 16 practitioner certifications live · First lesson free on every course Back to main site →

ISO 42001 vs NIST AI RMF vs the EU AI Act — which one is your customer actually asking for?

Boards and buyers use "AI governance" as a single word, but they mean three different things. This lesson walks the differences between ISO 42001, NIST AI RMF and the EU AI Act, so you can identify which one your customer, your regulator or your board actually wants — and design your programme so it satisfies all three.

Free preview 13 min read Under review
Legal basis
ISO/IEC 42001 primary-source stack current to 19 September 2026. Core: ISO/IEC 42001:2023 first edition December 2023 (ten clauses 0-10 plus Annex A with 38 controls across groups A.2 Policies related to AI, A.3 Internal organisation, A.4 Resources for AI systems, A.5 Assessing impacts of AI systems on individuals or groups and societies, A.6 AI system lifecycle, A.7 Data for AI systems, A.8 Information for interested parties of AI systems, A.9 Use of AI systems, A.10 Third-party and customer relationships, plus Annex B implementation guidance, Annex C AI-related organisational objectives, Annex D use of AIMS across domains). Companion standards: ISO/IEC 23894:2023 (guidance on AI risk management), ISO/IEC 23053:2022 (framework for AI systems using machine learning), ISO/IEC 42005:2025 (AI system impact assessment), ISO/IEC 22989:2022 (AI concepts and terminology), ISO/IEC TR 24028:2020 (trustworthiness in AI). Integration standards: ISO/IEC 27001:2022 for the AIMS-on-top-of-ISMS pattern, ISO/IEC 27701:2025 for the PIMS integration. India-specific stack: India AI Governance Guidelines released by MeitY in November 2025 (seven sutras Trust / People-first / Innovation over restraint / Fairness and equity / Accountability / Understandability by design / Safety resilience sustainability, across six pillars Infrastructure / Capacity building / Policy and regulation / Risk mitigation / Accountability / Institutions, with Annexure 6 recommending ISO/IEC 42001), Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules 2026 notified 10 February 2026 effective 20 February 2026 introducing Synthetically Generated Information as a due-diligence category with visual labelling audio disclosure metadata embedding and 2 to 3 hour takedown for deepfake harm, MeitY AI Advisory dated March 2024 on labelling AI-generated content operative until superseded on labelling by the 2026 Rules, SEBI Circular No. HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026 dated 5 May 2026 (Advisory on emerging advanced AI tools for vulnerability detection, Cyber-suraksha.ai task force, applies to every regulated entity in the Indian securities market), Report of the RBI Committee on FREE-AI (Framework for Responsible and Ethical Enablement of Artificial Intelligence) chaired by Professor Pushpak Bhattacharyya of IIT Bombay released 13 August 2025 (seven sutras 26 recommendations six pillars Infrastructure Policy Capacity Governance Protection Assurance), DPDP Act 2023 and DPDP Rules 2025 notified November 2025 with phased commencement (no equivalent to GDPR Article 22, no right to explanation), BIS adoption as IS/ISO/IEC 42001:2023 identical to ISO text, IndiaAI Mission approved March 2024 with ₹10,371 crore outlay over five years across seven pillars including Safe & Trusted AI (13 projects funded as of July 2026 on deepfake and bias), IndiaAI Safety Institute announced January 2025. Global adjacent regulation for extraterritorial reach and crosswalk: EU AI Act Regulation (EU) 2024/1689 phased application 2 February 2025 prohibited practices and AI literacy live, 2 August 2025 GPAI transparency for new models, 2 August 2026 general application and Article 50 transparency, 2 December 2026 new prohibited practices on synthetic intimate content and CSAM, 2 December 2027 Annex III high-risk (pushed back from August 2026 by Digital Omnibus), 2 August 2028 Annex I product-embedded high-risk. NIST AI Risk Management Framework 1.0 (January 2023) four functions Govern Map Measure Manage with official crosswalk to ISO/IEC 42001 published by NIST AIRC. OECD AI Principles (2019 updated 2024). UNESCO Recommendation on the Ethics of AI (2021). Council of Europe AI Framework Convention (opened for signature September 2024). Certification body landscape referenced: A-LIGN, BSI India, Bureau Veritas India, DNV Business Assurance India, Schellman, SGS India, TÜV SÜD South Asia, TÜV Nord India, Intertek India (accredited under ANAB, UKAS, RvA pending NABCB scheme extension). Personal certification schemes referenced (not primary): PECB Lead Implementer and Lead Auditor for ISO 42001, BSI ISO 42001 Lead Implementer, operating under ISO/IEC 17024. India first-mover organisational certifications referenced: Mphasis (first Indian IT services company to certify, 2025) and KPMG India (certified by SGS December 2025). Items requiring ongoing verification and flagged inside the relevant lessons: NABCB scheme extension timeline for ISO 42001; any ISO/IEC 42001 amendment beyond first edition; Digital India Act draft status and eventual enactment; RBI conversion of FREE-AI Report recommendations into binding master directions; DPDP Board of India Chairperson appointment status; new India AI-specific legislation.

One of the most common mistakes I see teams make is to treat "AI governance" as a single word. It is not. Right now, in September 2026, there are three different things that people mean when they say those two words. Which one your customer is asking for, which one your regulator is enforcing, which one your board is worried about — these are three separate questions and they usually have three separate answers. Let me walk each one, and then show you how they connect.

The three things people mean by "AI governance"

Look at any AI governance conversation and you will find three different framings competing for attention:

ISO/IEC 42001:2023NIST AI RMF 1.0EU AI Act 2024/1689
What it isInternational management-system standardVoluntary US federal risk management frameworkBinding EU law (Regulation)
Certifiable?Yes, by accredited CBNo formal certificationConformity assessment for high-risk AI (external for some)
Published / in forcePublished 18 Dec 2023Published 26 Jan 2023Phased in force from 2 Feb 2025 through 2 Aug 2028
Who publishes / enforcesISO and IEC (JTC 1/SC 42)US National Institute of Standards and TechnologyEuropean Parliament and Council; enforced by national market surveillance authorities and EU AI Office
Structure10 clauses + 38 Annex A controls4 functions: Govern, Map, Measure, ManageArticle-and-Annex structure with risk tiers
Penalty for non-complianceCertificate withheld or suspended by CBNone (voluntary)Up to EUR 35 million or 7% of global turnover

These are not competing standards. They are three different types of instrument. Let me walk each one so you understand which one applies when.

ISO/IEC 42001 — the management-system standard

ISO 42001 is a management-system standard [L3-C1]. That means it does not tell you what technology to use, what fairness metric to hit, or what risk score to allow. It tells you what processes to run — a policy, a risk methodology, an impact assessment, an internal audit programme, a management review. If you run those processes properly and pass an audit, you get a certificate that says so. The certificate is what your enterprise buyer wants to see because it is verifiable third-party evidence that you are managing AI risk in a documented, repeatable way. Certification bodies accredited by IAF-MLA signatories (ANAB in the US, UKAS in the UK, RvA in the Netherlands, NABCB pending in India) issue the certificates. The certificate is valid for three years with annual surveillance.

When your European buyer says "provide your ISO 42001 certificate," they mean this. When MeitY's India AI Governance Guidelines recommend a management-system standard in Annexure 6, they mean this. When your GCC parent's compliance team says "we need an AI Management System," they mean this. This is the operational answer.

NIST AI Risk Management Framework 1.0 — the voluntary framework

NIST published the AI Risk Management Framework Version 1.0 on 26 January 2023 [L3-C7]. It is voluntary. There is no certification, no penalty for non-compliance, no auditor. NIST publishes it as guidance and organisations adopt as much or as little as they want.

The AI RMF has four core functions:

  • GOVERN — cultivate a culture of AI risk management, establish policies, accountability structures, and oversight across the organisation. This function is cross-cutting: it applies at all stages of the other three.
  • MAP — establish the context for the risks related to each AI system.
  • MEASURE — analyse, assess, benchmark and monitor AI risk quantitatively and qualitatively.
  • MANAGE — allocate risk resources, implement risk treatments, incident response, continual improvement.

There is an official crosswalk document published by NIST at airc.nist.gov that maps 71 AI RMF categories to corresponding sections of ISO/IEC 42001. So if you have already invested in AI RMF, you can carry that investment forward into 42001. Module 8 of this course walks the crosswalk in detail.

When is AI RMF the right answer? Two situations. First, if your customer is a US federal agency or a federal contractor under NIST guidance, AI RMF is the framework of choice — because it is voluntary but named specifically in federal AI risk guidance documents. Second, if you want a framework to structure your internal risk thinking without committing to certification cost and audit cycle, AI RMF is a lightweight way in. But your enterprise buyer usually cannot accept "we follow NIST AI RMF" as a substitute for a certificate — because there is no third-party audit behind it.

EU AI Act — the binding law

Regulation (EU) 2024/1689 is a binding EU law with extraterritorial reach. It applies not only to EU-based providers of AI systems but to any provider whose AI systems are placed on the EU market or whose output is used in the EU. So an Indian SaaS whose AI feature is used by European customers is caught. An Indian outsourcing company running an AI-enabled analytics service for a European insurer is caught. This is why the Act matters to a lot of Indian teams even though we are not in the EU.

The Act has a risk-tier structure. It divides AI systems into four categories:

  1. Prohibited practices (Article 5) — social scoring, subliminal manipulation, real-time biometric identification in public spaces (with narrow exceptions), workplace emotion inference. Live from 2 February 2025 [L3-C8].
  2. High-risk AI systems — either specifically listed (Annex III: education, employment, credit, insurance, law enforcement, migration, judicial) or embedded in products already regulated (Annex I: medical devices, machinery, toys, aviation). Full conformity assessment obligations. Live for Annex III from 2 December 2027; for Annex I from 2 August 2028. Both were pushed back by the Digital Omnibus.
  3. Limited-risk AI systems with transparency obligations — chatbots, generative content. Users must be informed. Article 50. Live from 2 August 2026 [L3-C9].
  4. Minimal-risk AI systems — everything else. No obligations.

General-Purpose AI (GPAI) models — foundation models like GPT-family, Claude-family, Gemini-family — have their own transparency obligations that came into force on 2 August 2025 for newly-released models. Any Indian organisation training or providing a general-purpose model for EU deployment must meet Article 53 documentation requirements.

Penalties: up to EUR 35 million or 7 percent of global turnover for prohibited-practice violations, EUR 15 million or 3 percent for other violations, EUR 7.5 million or 1 percent for supplying incorrect information. These are annual-turnover-based penalties, so a global Indian IT services company that trips prohibited-practice enforcement is exposed to real money.

How the three connect

The clean way to think about this is: the EU AI Act tells you what you cannot do and what you must document. NIST AI RMF tells you how to think about AI risk. ISO 42001 tells you how to run the management system that operationalises both. Well-run organisations do not pick one and ignore the other two — they build the AIMS and then use it to demonstrate compliance with the AI Act (for EU exposure) and alignment with AI RMF (for US exposure).

Concretely, in a running organisation, ISO 42001 becomes your operating system for AI governance. Your Statement of Applicability shows how each of the 38 Annex A controls is implemented. When the EU AI Act asks about your risk management, human oversight, transparency and post-market monitoring, you point at the SoA and say — here is the process, here is the evidence, here is the audit report. Same when a NIST-aligned customer asks about your Govern-Map-Measure-Manage cadence.

This is the strategic insight. ISO 42001 is not an alternative to the EU AI Act or NIST AI RMF. It is the vehicle through which you demonstrate compliance with the EU AI Act and alignment with NIST AI RMF, using a single documented system.

India's own layer sits above all three

Then, above all three, sits India's own regulatory layer. The India AI Governance Guidelines released by MeitY in November 2025 name ISO 42001 in Annexure 6 [L3-C3]. The IT Amendment Rules 2026 on Synthetically Generated Information add operational duties for AI-generated content [L3-C4]. The SEBI 5 May 2026 AI Advisory imposes vulnerability-management duties on regulated entities [L3-C5]. The RBI FREE-AI Committee Report of August 2025 signals what is coming for BFSI [L3-C6]. Module 8 of this course walks the whole India layer in detail. For now, know that the ISO baseline plus the India overlay is the full picture. Neither one is sufficient on its own.

Next lesson, I want to walk what actually happens inside an ISO 42001 certification project — the twelve to eighteen month path, the artefacts you produce, the audit stages, and what happens after certification. That will give you the shape of what the rest of this course is teaching you to build.

Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview in progress 7 more modules waiting behind enrolment

Enjoying the preview? Here's what enrolment unlocks.

  • All 7 paid modules (35 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Lifetime access plus every future update
Inclusive of 18% GST. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Citations
ISO/IEC 42001:2023, ISO/IEC 42001:2023 (Dec 2023 first edition) (AI management systems Requirements) L3-C1
ISO/IEC 42001:2023, Information technology, Artificial intelligence, Management system. First edition published 18 December 2023 by ISO/IEC JTC 1/SC 42 (AI subcommittee). The worlds first international management-system standard specifically for artificial intelligence. Structure: ten main clauses (0 Introduction through 10 Improvement) following the Annex SL harmonised structure shared with ISO 27001 and ISO 9001, plus Annex A (38 controls across 9 control groups A.2 through A.10), Annex B (implementation guidance for Annex A controls), Annex C (potential AI-related organisational objectives and risk sources), and Annex D (using an AIMS in specific domains).
MeitY AI Governance Guidelines, India AI Governance Guidelines Nov 2025 (Seven sutras + six pillars) L3-C3
MeitY released the India AI Governance Guidelines in November 2025. Techno-legal principle-driven approach anchored by seven sutras: Trust, People-first governance, Innovation over restraint, Fairness and equity, Accountability, Understandability by design, Safety-resilience-sustainability. Six pillars: Infrastructure, Capacity building, Policy and regulation, Risk mitigation, Accountability, Institutions. Non-binding but reflects governmental direction. Annexure 6 recommends ISO/IEC 42001 as the operational management-system standard for organisations.
IT Amendment Rules 2026, IT Rules Amendment 2026 SGI (SGI due-diligence obligations) L3-C4
The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules 2026 were notified on 10 February 2026 and became effective 20 February 2026. Rule 3(1)(v) introduces Synthetically Generated Information (SGI) as a due-diligence category. Non-prohibited AI-generated content must be clearly and prominently labelled (visual for visual, audio for audio). Metadata must be embedded to trace the computer resource where feasible. Takedown timelines for harmful content reduced from 24-36 hours to 2-3 hours.
SEBI Circular 5-May-2026, SEBI Advisory 5-May-2026 Mythos (AI vulnerability detection advisory) L3-C5
SEBI Circular No. HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026 dated 5 May 2026 addressed to every regulated entity in the Indian securities market (exchanges, depositories, brokers, mutual funds, custodians, credit rating agencies, merchant bankers, portfolio managers, investment advisors). Response to advanced AI-driven vulnerability detection tools such as Mythos. Requires strengthened cybersecurity, immediate patch management, AI-assisted vulnerability assessments, enhanced API security, continuous SOC monitoring, system hardening and onboarding with the centralised Market SOC platform. Established the Cyber-suraksha.ai task force.
RBI FREE-AI Report, RBI FREE-AI Report 13-Aug-2025 (Bhattacharyya Committee framework) L3-C6
Report of the RBI Committee on FREE-AI (Framework for Responsible and Ethical Enablement of Artificial Intelligence) chaired by Professor Pushpak Bhattacharyya of IIT Bombay, released 13 August 2025. Seven guiding sutras and 26 recommendations across six pillars: Infrastructure, Policy, Capacity, Governance, Protection, Assurance. Non-binding today; sets RBI direction for future master directions applicable to banks, NBFCs, HFCs, AIFIs and payment system operators.
NIST AI RMF 1.0, NIST AI RMF 1.0 four functions (Govern Map Measure Manage) L3-C7
NIST AI Risk Management Framework Version 1.0 published 26 January 2023. Voluntary. Four core functions: GOVERN (cultivates a culture of AI risk management), MAP (establishes context for risks related to each AI system), MEASURE (quantitative and qualitative analysis), MANAGE (risk resources, treatments, incident response). GOVERN applies at all stages of MAP MEASURE MANAGE. Official crosswalk to ISO/IEC 42001 published by NIST AIRC maps 71 AI RMF requirements to corresponding ISO 42001 sections.
EU AI Act 2024/1689, EU AI Act Article 5 prohibited practices (Prohibited practices live Feb 2025) L3-C8
Regulation (EU) 2024/1689, the EU Artificial Intelligence Act, prohibited practices (Article 5) and AI literacy obligations (Article 4) became applicable on 2 February 2025. From that date organisations must have stopped social scoring, subliminal manipulation and workplace emotion inference in the EU. Indian exporters whose products place AI systems on the EU market or affect EU users are within extraterritorial reach.
EU AI Act 2024/1689, EU AI Act general application 2-Aug-2026 (General application + Article 50) L3-C9
The EU AI Act becomes generally applicable on 2 August 2026, including Article 50 transparency obligations (every chatbot must disclose AI, every synthetic content must be labelled). New prohibited practices around synthetic intimate content and CSAM apply from 2 December 2026. Annex III high-risk conformity obligations pushed to 2 December 2027 by the Digital Omnibus; Annex I product-embedded high-risk to 2 August 2028.
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: What ISO/IEC 42001 actually is, and why it turned into a procurement gate in 2026
Module 2: Reading Clauses 4, 5 and 6: Context, Leadership and Planning
  • Clauses 4.1 and 4.2: understanding your context and identifying interested parties
  • Clause 4.3: writing an AIMS Scope Statement that a certification body will accept
  • Clause 5: Leadership, AI Policy and Roles — where an AIMS becomes real
  • Clause 6.1: the AI risk assessment methodology — the beating heart of the AIMS
  • Clauses 6.2 and 6.3: AI objectives and planning of changes
Module 3: Reading Clauses 7, 8, 9 and 10: Support, Operation, Performance evaluation, Improvement
  • Clauses 7.1 to 7.4: Resources, Competence, Awareness, Communication
  • Clause 7.5: Documented information — what must be in writing, and how it is controlled
  • Clause 8: Operation — executing the risk methodology and running the AIIA
  • Clause 9: Performance evaluation — monitoring, internal audit, management review
  • Clause 10: Continual improvement, nonconformity and the CAPA process
Module 4: Annex A controls Part 1: A.2 Policies, A.3 Internal organisation, A.4 Resources, A.5 Impact assessment
  • Annex A.2 — Policies related to AI: three controls that anchor the AIMS
  • Annex A.3 — Internal organisation: AI roles and the concerns-reporting channel
  • Annex A.4 Part 1 — Data and tooling resources (A.4.2 and A.4.3)
  • Annex A.4 Part 2 — Compute, human and financial resources (A.4.4 to A.4.6)
  • Annex A.5 — AI Impact Assessment: the four controls that decide whether an AIMS is real
Module 5: Annex A controls Part 2: A.6 AI lifecycle, A.7 Data, A.8 Information, A.9 Use, A.10 Third-party
  • Annex A.6 Part 1 — AI lifecycle: requirements, design and development
  • Annex A.6 Part 2 — Verification, deployment, operation, monitoring and event logs
  • Annex A.7 — Data for AI systems: five controls with the DPDP overlay
  • Annex A.8 — Information for interested parties: where the IT Rules 2026 SGI obligations land
  • Annex A.9 and A.10 — Responsible use of AI systems and third-party relationships
Module 6: Building the AIMS end-to-end: inventory, impact assessment, risk assessment, Statement of Applicability, tooling
  • Building the AI system inventory — the foundation everything else hangs on
  • Running an AI Impact Assessment per ISO/IEC 42005:2025 — the operational template
  • Running the AI risk assessment methodology per ISO/IEC 23894:2023
  • Building the Statement of Applicability — the single most-audited document
  • GRC tooling landscape — buy versus build for an AIMS
Module 7: Certification body selection, Stage 1 audit, Stage 2 audit, certificate issuance
  • The accreditation chain — why the certificate means anything, and where NABCB stands on ISO 42001
  • CB selection — the RFP process, scoring criteria and negotiation
  • Stage 1 — the documentation review: what the auditor tests and how to pass first time
  • Stage 2 — the operating-effectiveness audit: sampling, interviews, evidence
  • The three-year sustain cycle — surveillance, recertification and living with the certificate
Module 8: The India overlay + the next five years: AI Governance Guidelines, IT Rules 2026, SEBI, RBI FREE-AI, DPDP, EU AI Act, NIST AI RMF
  • The India AI Governance Guidelines in operational depth — the seven sutras and six pillars, clause by clause
  • IT Amendment Rules 2026 SGI obligations in operational depth — the first binding AI law in India
  • Sector-specific overlays — SEBI 5-May-2026, RBI FREE-AI, and the wider sectoral picture
  • DPDP intersection with AI, and EU AI Act extraterritorial reach on Indian exporters
  • NIST AI RMF crosswalk and the next five years — closing the course