AI governanceUpdated 4 Sep 202613 min read

EU AI Act vs ISO/IEC 42001 vs ISO/IEC 27001 vs NIST AI RMF

These frameworks overlap, but they are not interchangeable. The AI Act is law; ISO/IEC 42001 is an AI management-system standard; ISO/IEC 27001 is an information-security management-system standard; and NIST AI RMF is a voluntary AI risk-management framework.

Answer first

Use the EU AI Act to determine legal obligations, ISO/IEC 42001 to structure organisation-wide AI management, ISO/IEC 27001 to strengthen information-security governance and controls, and NIST AI RMF to organise practical AI risk identification and treatment. A mature programme can use all four without pretending that one automatically proves conformity with another.

LawEU AI Act: mandatory where applicable.
Management systemsISO/IEC 42001 and 27001: structured, auditable organisational systems.
Risk frameworkNIST AI RMF: flexible, voluntary risk-management structure.

High-level comparison

DimensionEU AI ActISO/IEC 42001ISO/IEC 27001NIST AI RMF
TypeEU RegulationAI management-system standardInformation-security management-system standardVoluntary risk framework
Main questionWhat legal obligations apply to this role and AI system?How do we manage AI responsibly across the organisation?How do we manage information-security risk?How do we govern, map, measure and manage AI risk?
ScopeRisk- and role-based legal scopeOrganisation-wide AI managementOrganisation-wide information securityAI lifecycle and trustworthiness risk
CertificationNot an organisational certification schemeThird-party certification can be pursuedThird-party certification can be pursuedNo certification inherent in the framework
Best useLegal classification, duties and enforcement readinessPolicies, roles, objectives, risk processes, continual improvementSecurity risk, controls, assurance and ISMS governanceOperational AI risk language and risk treatment

Where the frameworks reinforce each other

Control areaEU AI ActISO 42001ISO 27001NIST AI RMF
AI inventory / system contextStrong relevanceStrong relevanceSupportingStrong relevance
Roles and accountabilityExplicit role modelCore management-system needCore governance needGovern function
AI risk assessmentRequired in relevant contextsCoreSecurity-focusedCore
Information securityImportant for high-risk and GPAI contextsIntegrated AI risk areaPrimary focusTrustworthiness dimension
Human oversightSpecific duties in relevant systemsGovernance relevanceIndirectRisk treatment relevance
Supplier / third-party riskValue-chain responsibilitiesManagement-system relevanceSupplier-security controlsLifecycle risk
Continual improvementCompliance lifecycleCore management-system principleCore management-system principleIterative risk management
Do not treat this as a clause-by-clause equivalence table. Similar control themes do not mean legal equivalence or automatic conformity. A control can support several frameworks while still needing framework-specific evidence and interpretation.

A practical way to combine them

Layer 1 — legal applicability

Use the AI Act to classify your role, intended purpose, risk category and applicable obligations. This defines the legal floor and deadlines.

Layer 2 — AI management system

Use ISO/IEC 42001 concepts to organise AI policy, objectives, responsibilities, risk processes, impact considerations, lifecycle controls, performance evaluation and continual improvement.

Layer 3 — information security

Use ISO/IEC 27001 to integrate AI into existing information-security governance: asset context, access control, supplier management, logging, incident management, change control, business continuity and risk treatment.

Layer 4 — operational AI risk

Use NIST AI RMF’s GOVERN, MAP, MEASURE and MANAGE functions as a practical language for identifying and treating AI-specific risks. For generative AI, the NIST AI 600-1 profile adds targeted considerations for generative-system risks.

What evidence can be reused?

The same evidence object can support multiple frameworks, but its interpretation may differ. For example, a supplier assessment may support ISO 27001 third-party risk, ISO 42001 AI lifecycle governance, NIST risk management and AI Act value-chain due diligence — without being sufficient by itself for any one of them.

Which should an SME start with?

Start with the legal baseline and a lightweight control model rather than launching four separate programmes. For many European SMEs, a practical sequence is: AI inventory → role/risk classification → minimum security and supplier controls → transparent use rules → AI risk register → evidence and review cycle. Then map that operating model to the frameworks that matter to customers, regulators and procurement.

Primary sources

SundAI does not claim that use of any standard automatically proves AI Act compliance. Standards and frameworks should be mapped to the organisation’s actual legal and operational context.

Build one AI control model instead of four silos

SundAI focuses on reusable evidence, proportionate controls and clear ownership across AI governance and security.

Explore AI governance support →
← All insightsNext: AI vendor security review →