← All executive insights

FRAMEWORKS & STANDARDS

NIST AI RMF, ISO/IEC 42001 or the EU AI Act: what does your organisation need?

A plain-English comparison of a voluntary risk framework, an AI management-system standard and binding European legislation.

Do you need a way to manage risk, a certifiable management system, legal compliance—or a combination of all three?
Written and reviewed by Phil Steele, Founder of unouiPublished 14 August 2026 · Reviewed 14 August 2026

THE SITUATION

Why this decision is reaching leadership now

NIST AI RMF, ISO/IEC 42001 and the EU AI Act are often discussed as competing versions of the same thing. They are not. One is a voluntary risk-management framework, one specifies requirements for an AI management system, and one is legislation whose application depends on role, system and jurisdiction.

An organisation may use NIST to structure risk thinking, implement ISO/IEC 42001 to establish a repeatable management system, and still need separate legal analysis where the EU AI Act applies. None replaces understanding the organisation’s actual AI systems and evidence.

THE IMPLICATION

What could happen if the issue remains unresolved?

Treating guidance as legal compliance

Using a respected framework strengthens governance but does not automatically prove that every applicable legal duty has been met.

Pursuing certification before establishing the problem

A management system can become documentation-heavy if leadership has not agreed its scope and intended outcomes.

Waiting for one perfect framework

AI may already be entering through employees, suppliers and software while leadership debates which model to adopt.

THE DECISION

What a controlled approach requires

01

NIST AI RMF

A voluntary framework organised around Govern, Map, Measure and Manage. Useful for structuring AI risk and trustworthiness decisions throughout the lifecycle.

02

ISO/IEC 42001

An international standard specifying requirements for establishing, implementing, maintaining and continually improving an AI management system. Independent certification is possible.

03

EU AI Act

Binding EU legislation using a risk-based approach. Obligations depend on the organisation’s role, the system and territorial scope.

04

UK AI Management Essentials

A UK government self-assessment approach for establishing baseline management practices. It is not certification or legal advice.

QUESTIONS TO TAKE INTO THE ROOM

How confidently could your organisation answer these?

  1. Which AI systems and use cases are currently in scope?
  2. Is the immediate need risk structure, management-system discipline, certification, legal compliance or procurement assurance?
  3. Which customers, markets or contracts create external requirements?
  4. What evidence already exists and where are the material gaps?
  5. Who will own continual operation after the initial framework work is complete?

FROM QUESTION TO EVIDENCE

An informed question is useful. An organisation-specific assessment is more valuable.

ARI does not certify compliance. It helps leadership establish current readiness, identify priority governance gaps and decide which standards, controls or specialist advice should be pursued next.

Take the free 10-question checkSee the executive reportBuy ARI™ for £3,500

PRIMARY SOURCES

Check the official guidance

General strategic information only. This page is not legal advice, certification or confirmation of compliance.