AI Standards & Frameworks

NIST AI RMF 1.0 and ISO/IEC 42001:2023 are the two most widely adopted AI governance frameworks. These guides translate both from specification language into practical sprint-team actions and auditable artefacts.

Unlike the EU AI Act, NIST AI RMF and ISO 42001 are voluntary frameworks—but in practice they are increasingly referenced in procurement requirements, enterprise contracts, and regulatory guidance. The NIST AI RMF has been adopted as the de facto US standard and is referenced in US executive orders on AI. ISO/IEC 42001:2023 is the first certifiable AI management system standard and is being adopted by enterprise procurement as a baseline supplier requirement.

Both frameworks suffer from a documentation problem: they are written for senior governance audiences and organisational policy-setters, not for the engineers and product managers who have to implement them. These guides fix that.

Framework Quick Reference

NIST AI RMF 1.0

  • Published January 2023 by NIST
  • Four functions: GOVERN, MAP, MEASURE, MANAGE
  • Voluntary; no certification path
  • Referenced in US AI Executive Orders
  • Companion: AI RMF Playbook (subcategory-level guidance)
  • Sector profiles available (financial services, healthcare)

ISO/IEC 42001:2023

  • Published December 2023
  • Seven clauses (4–10) + Annex A AI controls
  • Certifiable by accredited certification bodies
  • Uses Annex SL (same structure as ISO 27001)
  • Requires internal audit and management review
  • Typical certification: 6–12 months