Guide · Updated September 2026

NIST AI RMF vs ISO/IEC 42001: which one should a firm follow?

One is a free framework that Texas has written into law as a legal defense. The other is a certifiable international standard that roughly 350 organizations on Earth hold. Both are excellent, both were written for organizations that build AI, and a 60-person firm that uses AI needs to know what each buys before spending a dollar on either.

What each one is

NIST AI Risk Management Framework 1.0

Published by the US National Institute of Standards and Technology in January 2023, the AI RMF is a voluntary framework for identifying, assessing and managing AI risk. It is organized around four functions: Govern (policies, accountability, culture, inventory), Map (context and risk identification), Measure (assessment and monitoring) and Manage (response, incident handling, third-party risk). A companion Generative AI Profile (NIST-AI-600-1, Jul 2024) translates it for generative tools, and a Cyber AI Profile was released in preliminary draft for comment in late 2025 and early 2026. NIST has said the framework is being revised under the White House AI Action Plan, without a date. It is free to read, nobody certifies against it, and NIST endorses no one. Its power is that it is a common vocabulary that regulators, insurers and now state legislatures reference.

ISO/IEC 42001:2023

Published in December 2023, ISO/IEC 42001 is the international standard for an AI management system: the same structure as ISO 27001 for security or ISO 9001 for quality, with clauses 4 through 10 covering context, leadership, planning, support, operation, performance evaluation and improvement, plus an Annex A of controls covering policies, internal organization, resources, impact assessment, the AI system lifecycle, data, information for interested parties, use of AI systems and third-party relationships. It is certifiable: an accredited certification body (Schellman was the first ANAB-accredited body in September 2024; A-LIGN followed in October 2024) conducts a staged audit, issues a certificate valid for three years, and returns annually for surveillance. Approximately 350 organizations worldwide held the certificate by spring 2026, compiled from public announcements because no official register exists (Atoro, Jul 2026); BCG announced in January 2026 that it was among the first 100.

Side by side

NIST AI RMF 1.0ISO/IEC 42001:2023
What it isVoluntary risk-management framework; four functions, subcategories and a playbookCertifiable management-system standard; clauses 4–10 plus Annex A controls
Who publishes itUS NIST (government); freeISO/IEC (international); standard purchased; certification by accredited bodies
CertificationNone. You align; no one certifiesYes: staged audit, 3-year certificate, annual surveillance
Cost$0 for the framework; implementation is internal time, plus consultants if you want them~$73,000 all-in year one for 30 people; ~$185,000 for 120; $353,000+ for 500+; certification-body fees $20,000–$40,000 initial plus $13,000–$20,000/yr surveillance (certbetter, Jun 2026)
EffortWeeks to a few months to build a proportionate program for a firm that uses AI6–12 months; a consultant in most cases; a documented management system with internal audits
Written forAny organization designing, developing, deploying or using AIOrganizations providing or using AI systems; in practice adopted by developers and large enterprises
Legal weight (US)Texas TRAIGA affirmative defense for substantial compliance (Jan 1, 2026); referenced by insurers and regulators as the default vocabularyRecognized as a "recognized standard" in the same Texas defense language; strongest weight is with enterprise procurement
Legal weight (EU)Referenced in guidance; not an EU instrumentInforms harmonized-standards work; a certificate is not by itself EU AI Act compliance
AdoptionWidespread as a reference; no count exists because there is nothing to register~350 certified organizations worldwide (Atoro, Jul 2026; estimate)
Best forFirms that need a defensible, proportionate governance program and legal alignmentAI developers and vendors whose customers demand a certificate

Texas. The Texas Responsible Artificial Intelligence Governance Act (TRAIGA), effective January 1, 2026, applies to anyone who promotes, advertises or conducts business in Texas, developers and deployers alike. It creates an affirmative defense where the entity "substantially complies with the NIST AI Risk Management Framework or other recognized standards," with attorney-general enforcement, a 60-day cure period, and penalties of $10,000 to $12,000 per curable violation and $80,000 to $200,000 per uncurable one (Baker Botts, Jul 2025). This is the single strongest legal reason for a US firm to build its governance on the NIST vocabulary and to be able to prove it.

Colorado. The original Colorado AI Act (SB 24-205) offered a rebuttable presumption for NIST AI RMF alignment. It never took effect: a federal court paused enforcement on April 27, 2026, and the state replaced it with SB 26-189, effective January 1, 2027, a notice-and-explanation law that eliminated impact assessments and the NIST presumption (Seyfarth, May 2026). Any pitch built on a Colorado NIST safe harbor, or on a Colorado audit mandate, is out of date.

Connecticut. SB 5, signed May 29, 2026, takes general effect October 1, 2026 and lets AI users apply to the Department of Consumer Protection for a voluntary presumption of compliance (Holland & Knight, Jun 2026). It does not name a framework, but evidence of a documented program is what such an application needs.

The EU AI Act. The Act, as amended by the Digital Omnibus in force since July 27, 2026, pushed Annex III high-risk obligations to December 2, 2027, but the Article 4 AI-literacy duty for deployers has been enforceable since August 2, 2026 and Article 50 transparency applies from the same date (White & Case, Aug 2026). The Act grants a presumption of conformity to high-risk systems that meet harmonized European standards, which are still being developed; ISO/IEC 42001 informs that work and is widely used by AI providers as the management-system backbone, but holding a 42001 certificate is not by itself EU AI Act compliance. A US firm with EU clients is a deployer with a training-and-records obligation, whichever framework it follows.

Everyone else. The SEC's FY2026 exam priorities, the NAIC AI Model Bulletin adopted in 24 states plus DC, ABA Formal Opinion 512 and the Joint Commission's responsible-AI guidance all describe governance in terms that map cleanly to the NIST functions: policy, accountability, inventory, data, human oversight, incident response, training, disclosure. None of them requires a certificate.

How AboveBoard maps to both

The AboveBoard Standard v1.0 is a private, voluntary standard of forty controls in five domains, written in plain English for firms that use AI. Every control is mapped to a NIST AI RMF 1.0 function and subcategory and cross-walked to an ISO/IEC 42001 clause or Annex A control, so work done for one transfers to the others. The domain-level mapping is below; the full 40-row crosswalk is delivered with every report and the rubric is published in full.

AboveBoard domainNIST AI RMF 1.0ISO/IEC 42001:2023
1. Governance & AccountabilityGOVERN 1–6; MAP 1Clauses 4–6; Annex A.2, A.3, A.6
2. Data Security & PrivacyMAP 2, 4; MEASURE 2.6–2.10; MANAGE 3Annex A.7, A.4, A.10
3. Operational ControlsMEASURE 1–4; MANAGE 1–4Clauses 8, 10; Annex A.6.2, A.8, A.9, A.10
4. Workforce Capability & TrainingGOVERN 2.2, 4.1; MAP 1.2Clauses 7.2–7.3; Annex A.4.6
5. Transparency & Client TrustGOVERN 5, 6; MAP 5; MANAGE 4.2–4.3Clause 7.4; Annex A.8, A.9.3

Mappings are AboveBoard's own analysis. Neither NIST nor ISO endorses AboveBoardAI. AboveBoard is not an ISO certification, and we version the crosswalk so that when NIST publishes its revision, Texas-defense claims stay accurate.

Practically, this means a firm with a verified AboveBoard Score holds a dated, independently reviewed evidence file organized by NIST function, which is what "substantial compliance" has to be demonstrated with, and a gap list expressed in ISO 42001 terms, which is where a firm that later needs the certificate would start.

Decision guide

  1. Do you build or train AI models that you sell, or that make consequential decisions about people? If yes, plan for ISO/IEC 42001 and, where a model is involved in hiring, credit, insurance or healthcare decisions, technical audits. Budget $73,000 and up and six to twelve months. Read what an AI audit costs.
  2. Does a client contract or an enterprise procurement team specifically require an ISO 42001 certificate? If yes, that decides it, whatever your size. If they "prefer" it or ask open questions about AI governance, a verified governance score usually satisfies them.
  3. Do you do business in Texas, or anywhere a NIST-based defense or presumption exists or is coming? Build on NIST. Document alignment in a way a third party can verify.
  4. Are the people asking your regulators, carriers, clients and board, and do you use AI rather than build it? Then you need a proportionate governance program mapped to NIST, cross-walked to ISO, verified independently, at a price a 40-person firm can approve in one meeting. That is what AboveBoard is for: $7,500 to $75,000 a year by headcount, everything included, listed in a public registry.
  5. Do you have EU clients? Whichever route you take, keep records of AI-literacy training for the people who use AI on that work; Article 4 has been enforceable since August 2, 2026.

Questions

What is the difference between NIST AI RMF and ISO 42001?

NIST AI RMF is a free, voluntary US framework for managing AI risk, organized around four functions: Govern, Map, Measure and Manage. Nobody certifies against it; you align with it. ISO/IEC 42001 is an international management-system standard with clauses and controls that an accredited certification body audits and certifies, on a three-year cycle with annual surveillance. NIST is a way of thinking that carries legal weight in Texas; ISO 42001 is a certificate that carries weight with enterprise procurement.

How much does ISO 42001 certification cost?

About $73,000 all-in in year one for a 30-employee company, roughly $185,000 for 120 employees and $353,000 or more above 500, including gap assessment, consultants, internal time and the certification audit. Certification-body fees alone run $20,000 to $40,000 initially plus $13,000 to $20,000 a year in surveillance, over six to twelve months (certbetter, Jun 2026).

Is ISO 42001 worth it?

For an organization that builds AI products and sells to enterprises, or that faces procurement teams demanding the certificate, usually yes. For a professional-services firm of 10 to 1,000 people that uses AI tools, usually not: the cost and effort are built for developers, only about 350 organizations worldwide held the certificate by spring 2026 (Atoro, Jul 2026), and the questions your regulators, carriers and clients ask are answered by a governance program mapped to NIST and cross-walked to ISO at a fraction of the price.

Is NIST AI RMF mandatory?

No. It is voluntary. But it has legal weight: Texas TRAIGA, in force since January 1, 2026, makes substantial compliance with the NIST AI RMF or another recognized standard an affirmative defense against enforcement (Baker Botts, Jul 2025), and the Connecticut law taking effect October 1, 2026 lets AI users apply for a presumption of compliance. Colorado's original AI law had a NIST presumption, but its 2026 replacement removed it.

Can you get certified in NIST AI RMF?

Not by NIST. NIST publishes the framework and does not certify or endorse anyone. Third parties, including AboveBoard, publish mappings from their own standards to the NIST functions so that a verified score doubles as evidence of alignment. Any provider claiming NIST certification or NIST endorsement is misstating what NIST does.