One is a free framework that Texas has written into law as a legal defense. The other is a certifiable international standard that roughly 350 organizations on Earth hold. Both are excellent, both were written for organizations that build AI, and a 60-person firm that uses AI needs to know what each buys before spending a dollar on either.
Published by the US National Institute of Standards and Technology in January 2023, the AI RMF is a voluntary framework for identifying, assessing and managing AI risk. It is organized around four functions: Govern (policies, accountability, culture, inventory), Map (context and risk identification), Measure (assessment and monitoring) and Manage (response, incident handling, third-party risk). A companion Generative AI Profile (NIST-AI-600-1, Jul 2024) translates it for generative tools, and a Cyber AI Profile was released in preliminary draft for comment in late 2025 and early 2026. NIST has said the framework is being revised under the White House AI Action Plan, without a date. It is free to read, nobody certifies against it, and NIST endorses no one. Its power is that it is a common vocabulary that regulators, insurers and now state legislatures reference.
Published in December 2023, ISO/IEC 42001 is the international standard for an AI management system: the same structure as ISO 27001 for security or ISO 9001 for quality, with clauses 4 through 10 covering context, leadership, planning, support, operation, performance evaluation and improvement, plus an Annex A of controls covering policies, internal organization, resources, impact assessment, the AI system lifecycle, data, information for interested parties, use of AI systems and third-party relationships. It is certifiable: an accredited certification body (Schellman was the first ANAB-accredited body in September 2024; A-LIGN followed in October 2024) conducts a staged audit, issues a certificate valid for three years, and returns annually for surveillance. Approximately 350 organizations worldwide held the certificate by spring 2026, compiled from public announcements because no official register exists (Atoro, Jul 2026); BCG announced in January 2026 that it was among the first 100.
| NIST AI RMF 1.0 | ISO/IEC 42001:2023 | |
|---|---|---|
| What it is | Voluntary risk-management framework; four functions, subcategories and a playbook | Certifiable management-system standard; clauses 4–10 plus Annex A controls |
| Who publishes it | US NIST (government); free | ISO/IEC (international); standard purchased; certification by accredited bodies |
| Certification | None. You align; no one certifies | Yes: staged audit, 3-year certificate, annual surveillance |
| Cost | $0 for the framework; implementation is internal time, plus consultants if you want them | ~$73,000 all-in year one for 30 people; ~$185,000 for 120; $353,000+ for 500+; certification-body fees $20,000–$40,000 initial plus $13,000–$20,000/yr surveillance (certbetter, Jun 2026) |
| Effort | Weeks to a few months to build a proportionate program for a firm that uses AI | 6–12 months; a consultant in most cases; a documented management system with internal audits |
| Written for | Any organization designing, developing, deploying or using AI | Organizations providing or using AI systems; in practice adopted by developers and large enterprises |
| Legal weight (US) | Texas TRAIGA affirmative defense for substantial compliance (Jan 1, 2026); referenced by insurers and regulators as the default vocabulary | Recognized as a "recognized standard" in the same Texas defense language; strongest weight is with enterprise procurement |
| Legal weight (EU) | Referenced in guidance; not an EU instrument | Informs harmonized-standards work; a certificate is not by itself EU AI Act compliance |
| Adoption | Widespread as a reference; no count exists because there is nothing to register | ~350 certified organizations worldwide (Atoro, Jul 2026; estimate) |
| Best for | Firms that need a defensible, proportionate governance program and legal alignment | AI developers and vendors whose customers demand a certificate |
Texas. The Texas Responsible Artificial Intelligence Governance Act (TRAIGA), effective January 1, 2026, applies to anyone who promotes, advertises or conducts business in Texas, developers and deployers alike. It creates an affirmative defense where the entity "substantially complies with the NIST AI Risk Management Framework or other recognized standards," with attorney-general enforcement, a 60-day cure period, and penalties of $10,000 to $12,000 per curable violation and $80,000 to $200,000 per uncurable one (Baker Botts, Jul 2025). This is the single strongest legal reason for a US firm to build its governance on the NIST vocabulary and to be able to prove it.
Colorado. The original Colorado AI Act (SB 24-205) offered a rebuttable presumption for NIST AI RMF alignment. It never took effect: a federal court paused enforcement on April 27, 2026, and the state replaced it with SB 26-189, effective January 1, 2027, a notice-and-explanation law that eliminated impact assessments and the NIST presumption (Seyfarth, May 2026). Any pitch built on a Colorado NIST safe harbor, or on a Colorado audit mandate, is out of date.
Connecticut. SB 5, signed May 29, 2026, takes general effect October 1, 2026 and lets AI users apply to the Department of Consumer Protection for a voluntary presumption of compliance (Holland & Knight, Jun 2026). It does not name a framework, but evidence of a documented program is what such an application needs.
The EU AI Act. The Act, as amended by the Digital Omnibus in force since July 27, 2026, pushed Annex III high-risk obligations to December 2, 2027, but the Article 4 AI-literacy duty for deployers has been enforceable since August 2, 2026 and Article 50 transparency applies from the same date (White & Case, Aug 2026). The Act grants a presumption of conformity to high-risk systems that meet harmonized European standards, which are still being developed; ISO/IEC 42001 informs that work and is widely used by AI providers as the management-system backbone, but holding a 42001 certificate is not by itself EU AI Act compliance. A US firm with EU clients is a deployer with a training-and-records obligation, whichever framework it follows.
Everyone else. The SEC's FY2026 exam priorities, the NAIC AI Model Bulletin adopted in 24 states plus DC, ABA Formal Opinion 512 and the Joint Commission's responsible-AI guidance all describe governance in terms that map cleanly to the NIST functions: policy, accountability, inventory, data, human oversight, incident response, training, disclosure. None of them requires a certificate.
The AboveBoard Standard v1.0 is a private, voluntary standard of forty controls in five domains, written in plain English for firms that use AI. Every control is mapped to a NIST AI RMF 1.0 function and subcategory and cross-walked to an ISO/IEC 42001 clause or Annex A control, so work done for one transfers to the others. The domain-level mapping is below; the full 40-row crosswalk is delivered with every report and the rubric is published in full.
| AboveBoard domain | NIST AI RMF 1.0 | ISO/IEC 42001:2023 |
|---|---|---|
| 1. Governance & Accountability | GOVERN 1–6; MAP 1 | Clauses 4–6; Annex A.2, A.3, A.6 |
| 2. Data Security & Privacy | MAP 2, 4; MEASURE 2.6–2.10; MANAGE 3 | Annex A.7, A.4, A.10 |
| 3. Operational Controls | MEASURE 1–4; MANAGE 1–4 | Clauses 8, 10; Annex A.6.2, A.8, A.9, A.10 |
| 4. Workforce Capability & Training | GOVERN 2.2, 4.1; MAP 1.2 | Clauses 7.2–7.3; Annex A.4.6 |
| 5. Transparency & Client Trust | GOVERN 5, 6; MAP 5; MANAGE 4.2–4.3 | Clause 7.4; Annex A.8, A.9.3 |
Mappings are AboveBoard's own analysis. Neither NIST nor ISO endorses AboveBoardAI. AboveBoard is not an ISO certification, and we version the crosswalk so that when NIST publishes its revision, Texas-defense claims stay accurate.
Practically, this means a firm with a verified AboveBoard Score holds a dated, independently reviewed evidence file organized by NIST function, which is what "substantial compliance" has to be demonstrated with, and a gap list expressed in ISO 42001 terms, which is where a firm that later needs the certificate would start.
NIST AI RMF is a free, voluntary US framework for managing AI risk, organized around four functions: Govern, Map, Measure and Manage. Nobody certifies against it; you align with it. ISO/IEC 42001 is an international management-system standard with clauses and controls that an accredited certification body audits and certifies, on a three-year cycle with annual surveillance. NIST is a way of thinking that carries legal weight in Texas; ISO 42001 is a certificate that carries weight with enterprise procurement.
About $73,000 all-in in year one for a 30-employee company, roughly $185,000 for 120 employees and $353,000 or more above 500, including gap assessment, consultants, internal time and the certification audit. Certification-body fees alone run $20,000 to $40,000 initially plus $13,000 to $20,000 a year in surveillance, over six to twelve months (certbetter, Jun 2026).
For an organization that builds AI products and sells to enterprises, or that faces procurement teams demanding the certificate, usually yes. For a professional-services firm of 10 to 1,000 people that uses AI tools, usually not: the cost and effort are built for developers, only about 350 organizations worldwide held the certificate by spring 2026 (Atoro, Jul 2026), and the questions your regulators, carriers and clients ask are answered by a governance program mapped to NIST and cross-walked to ISO at a fraction of the price.
No. It is voluntary. But it has legal weight: Texas TRAIGA, in force since January 1, 2026, makes substantial compliance with the NIST AI RMF or another recognized standard an affirmative defense against enforcement (Baker Botts, Jul 2025), and the Connecticut law taking effect October 1, 2026 lets AI users apply for a presumption of compliance. Colorado's original AI law had a NIST presumption, but its 2026 replacement removed it.
Not by NIST. NIST publishes the framework and does not certify or endorse anyone. Third parties, including AboveBoard, publish mappings from their own standards to the NIST functions so that a verified score doubles as evidence of alignment. Any provider claiming NIST certification or NIST endorsement is misstating what NIST does.