Use the EU AI Act to determine legal obligations, ISO/IEC 42001 to structure organisation-wide AI management, ISO/IEC 27001 to strengthen information-security governance and controls, and NIST AI RMF to organise practical AI risk identification and treatment. A mature programme can use all four without pretending that one automatically proves conformity with another.
High-level comparison
Where the frameworks reinforce each other
A practical way to combine them
Layer 1 — legal applicability
Use the AI Act to classify your role, intended purpose, risk category and applicable obligations. This defines the legal floor and deadlines.
Layer 2 — AI management system
Use ISO/IEC 42001 concepts to organise AI policy, objectives, responsibilities, risk processes, impact considerations, lifecycle controls, performance evaluation and continual improvement.
Layer 3 — information security
Use ISO/IEC 27001 to integrate AI into existing information-security governance: asset context, access control, supplier management, logging, incident management, change control, business continuity and risk treatment.
Layer 4 — operational AI risk
Use NIST AI RMF’s GOVERN, MAP, MEASURE and MANAGE functions as a practical language for identifying and treating AI-specific risks. For generative AI, the NIST AI 600-1 profile adds targeted considerations for generative-system risks.
What evidence can be reused?
- AI system inventory and ownership register.
- AI risk and impact assessments.
- Supplier and model due-diligence records.
- Security architecture and access-control decisions.
- Testing, monitoring and incident evidence.
- Human-oversight design and escalation paths.
- Training and AI-literacy records.
- Management review, metrics and improvement actions.
The same evidence object can support multiple frameworks, but its interpretation may differ. For example, a supplier assessment may support ISO 27001 third-party risk, ISO 42001 AI lifecycle governance, NIST risk management and AI Act value-chain due diligence — without being sufficient by itself for any one of them.
Which should an SME start with?
Start with the legal baseline and a lightweight control model rather than launching four separate programmes. For many European SMEs, a practical sequence is: AI inventory → role/risk classification → minimum security and supplier controls → transparent use rules → AI risk register → evidence and review cycle. Then map that operating model to the frameworks that matter to customers, regulators and procurement.
Primary sources
- EU AI Act — consolidated EUR-Lex text
- ISO — ISO/IEC 42001:2023 AI management systems
- ISO — ISO/IEC 27001:2022 information security management systems
- NIST — AI Risk Management Framework
- NIST AI 600-1 — Generative AI Profile
SundAI does not claim that use of any standard automatically proves AI Act compliance. Standards and frameworks should be mapped to the organisation’s actual legal and operational context.
Build one AI control model instead of four silos
SundAI focuses on reusable evidence, proportionate controls and clear ownership across AI governance and security.
Explore AI governance support →