THE SITUATION
Why this decision is reaching leadership now
NIST AI RMF, ISO/IEC 42001 and the EU AI Act are often discussed as competing versions of the same thing. They are not. One is a voluntary risk-management framework, one specifies requirements for an AI management system, and one is legislation whose application depends on role, system and jurisdiction.
An organisation may use NIST to structure risk thinking, implement ISO/IEC 42001 to establish a repeatable management system, and still need separate legal analysis where the EU AI Act applies. None replaces understanding the organisation’s actual AI systems and evidence.
THE IMPLICATION
What could happen if the issue remains unresolved?
Treating guidance as legal compliance
Using a respected framework strengthens governance but does not automatically prove that every applicable legal duty has been met.
Pursuing certification before establishing the problem
A management system can become documentation-heavy if leadership has not agreed its scope and intended outcomes.
Waiting for one perfect framework
AI may already be entering through employees, suppliers and software while leadership debates which model to adopt.
THE DECISION
What a controlled approach requires
NIST AI RMF
A voluntary framework organised around Govern, Map, Measure and Manage. Useful for structuring AI risk and trustworthiness decisions throughout the lifecycle.
ISO/IEC 42001
An international standard specifying requirements for establishing, implementing, maintaining and continually improving an AI management system. Independent certification is possible.
EU AI Act
Binding EU legislation using a risk-based approach. Obligations depend on the organisation’s role, the system and territorial scope.
UK AI Management Essentials
A UK government self-assessment approach for establishing baseline management practices. It is not certification or legal advice.
QUESTIONS TO TAKE INTO THE ROOM
How confidently could your organisation answer these?
- Which AI systems and use cases are currently in scope?
- Is the immediate need risk structure, management-system discipline, certification, legal compliance or procurement assurance?
- Which customers, markets or contracts create external requirements?
- What evidence already exists and where are the material gaps?
- Who will own continual operation after the initial framework work is complete?
FROM QUESTION TO EVIDENCE
An informed question is useful. An organisation-specific assessment is more valuable.
ARI does not certify compliance. It helps leadership establish current readiness, identify priority governance gaps and decide which standards, controls or specialist advice should be pursued next.
PRIMARY SOURCES
Check the official guidance
- NIST AI Risk Management Framework ↗
- ISO/IEC 42001:2023 ↗
- European Commission: AI regulatory framework ↗
- UK Government: AI Management Essentials ↗
General strategic information only. This page is not legal advice, certification or confirmation of compliance.
