AI Governance Framework: ISO 42001, NIST AI RMF, EU AI Act Compared
An overview of the main AI governance frameworks in use globally as of 2026, how they differ, how they overlap, and how organisations typically combine them.
What "AI governance framework" means
AI governance is the set of policies, processes, controls, and accountability structures an organisation uses to ensure AI is developed and used responsibly, lawfully, and in line with organisational values. An AI governance framework is the scaffold that holds those elements together.
In 2026, organisations don't pick one framework, they typically assemble a stack, because different frameworks serve different purposes (regulation, standardisation, best practice, procurement).
The major frameworks
ISO/IEC 42001:2023 (AI Management System)
International, certifiable management-system standard. Published December 2023 by ISO and IEC. Defines an AIMS: policies, roles, risk assessment, impact assessment, lifecycle, audit, management review, continual improvement. 38 reference controls in Annex A. Certified by accredited bodies under ISO/IEC 42006.
Best for: organisations wanting externally-verifiable AI governance. See our complete guide.
NIST AI Risk Management Framework (AI RMF 1.0)
US voluntary risk-management framework. Published January 2023 by the US National Institute of Standards and Technology. Four functions: Govern, Map, Measure, Manage. Generative AI Profile published July 2024.
Best for: organisations building risk-practice muscle; US federal and state alignment. See our comparison.
EU AI Act (Regulation 2024/1689)
European Union regulation. Risk-based obligations by AI system category. In force from August 2024 in phases. Article 73 serious-incident reporting applies from 2 December 2027. Fines up to €35M or 7% global turnover.
Best for: any organisation placing AI on the EU market. See our EU AI Act page.
Colorado AI Act (SB 24-205)
US state law. Original SB 24-205 repealed and replaced by SB 189 (effective 1 January 2027), a transparency framework covering automated decisions affecting Colorado consumers in employment, housing, healthcare, finance, and similar areas. The original ISO 42001 / NIST AI RMF affirmative defense no longer exists.
Best for: compliance anchor for US organisations, see our Colorado AI Act page.
OECD AI Principles
Non-binding principles for trustworthy AI from the Organisation for Economic Co-operation and Development. Inclusive growth, human-centred values, transparency, robustness, accountability. Adopted by 40+ countries. The foundation many other frameworks build on.
GPAI Code of Practice (EU)
Voluntary code signed by major GPAI providers from July 2025. Operationalises EU AI Act Article 53 (transparency, training data summaries) and Article 55 (systemic risk, reporting, cybersecurity) for general-purpose AI.
Sector frameworks
- Microsoft SSPA DPR v12, supplier assurance; ISO 42001 accepted in lieu. See our SSPA page.
- SR 11-7 (US banking), model risk management; relevant for FinTech AI.
- FDA / MHRA / MDR (healthcare), medical-device AI governance.
- ISO/IEC 23894, AI risk management guidance (non-certifiable).
How frameworks stack together
A well-structured AI governance stack in 2026 typically looks like:
- ISO/IEC 42001:2023 as the operational AIMS, daily governance, procedures, evidence.
- NIST AI RMF as a complementary risk-practice framework, informs how risks are identified, measured, managed.
- EU AI Act as regulatory overlay for EU-facing AI, specific obligations on top of the AIMS.
- Colorado AI Act (and other US state laws) as a governance baseline for US-facing AI, recognised for procurement and regulatory readiness.
- Sector frameworks where applicable, SSPA for Microsoft suppliers, SR 11-7 for banking, FDA/MHRA for medical devices.
- OECD AI Principles as the underlying values statement.
Our Professional tier's Four-Way Crosswalk maps the relationships between four of these (ISO 42001 × ISO 27001 × NIST AI RMF × EU AI Act) across every clause and control, so evidence produced for one satisfies the others where overlap exists.
Common mistakes
- Picking one framework to the exclusion of others. Each framework serves a different purpose. You need a stack, not a silo.
- Building compliance silos that don't share evidence. One Risk Register should serve ISO 42001, NIST AI RMF, and the EU AI Act, with appropriate tagging and cross-referencing.
- Confusing certification with compliance. Certification is evidence of a well-functioning AIMS. It doesn't replace the obligation to comply with specific regulations.
- Waiting for frameworks to harmonise. They will, slowly. In the meantime, the overlap is large enough to build a practical stack today.