OpenAI Shelves GPT-6.1 Astra After Safety Tests: What Went Wrong?
OpenAI shelved GPT-6.1 Astra after safety tests flagged scope, authorization and action-reporting issues. See what is confirmed and what remains...
Learn how to choose AI risk management frameworks by comparing NIST AI RMF, ISO/IEC 42001, and ISO/IEC 23894, assessing organizational needs, regulatory requirements, governance maturity, and when integrated approaches make sense for organizations.
Organizations adopting artificial intelligence often face a deceptively difficult question: which AI risk management framework should we use? The challenge is not a lack of available guidance. It is that different frameworks and standards are designed for different purposes.
A framework that helps structure AI risk-management activities may not provide the organization-wide governance structure required for a formal management system. Similarly, a voluntary framework or international standard does not automatically replace legal or regulatory requirements.
The right choice depends on factors such as the organization's role in the AI lifecycle, risk profile, governance maturity, regulatory environment, existing management processes, and implementation capability. Some organizations may need one primary approach, while others may benefit from combining complementary frameworks and standards.
In this blog, you will learn how to compare AI risk management frameworks, assess which approach fits your organization, understand the differences between NIST AI RMF, ISO/IEC 42001, and ISO/IEC 23894, and determine when combining complementary approaches makes sense.
AI risk management frameworks serve different organizational purposes.
Framework selection should follow business, AI, risk, governance, and regulatory needs.
NIST AI RMF provides flexible, voluntary guidance for managing AI risks.
ISO/IEC 42001 provides requirements for establishing and continually improving an Artificial Intelligence Management System (AIMS).
ISO/IEC 23894 provides AI-specific guidance for integrating risk management into AI-related activities and functions.
Regulatory requirements must be considered alongside voluntary frameworks and standards.
Combining complementary approaches can be effective when responsibilities, requirements, and controls are deliberately mapped.
The right approach is the one that fits the organization's objectives, risk profile, governance maturity, and operating environment.
An AI risk management framework provides a structured way to identify, assess, prioritize, treat, and monitor risks associated with artificial intelligence. It can help organizations establish consistent practices for understanding AI risks and integrating risk considerations into decisions across the AI lifecycle.
However, not every framework, standard, or regulation performs the same function.
It is useful to distinguish three related concepts:
|
Approach |
What it does |
Typical purpose |
|
Risk management framework |
Structures risk-management activities and outcomes |
Helps organizations identify, assess, and manage AI risks |
|
Management system standard |
Establishes requirements for an organization-wide management system |
Creates policies, processes, responsibilities, evaluation, and continual improvement |
|
Regulation |
Creates legally binding obligations where applicable |
Defines the requirements an organization must comply with |
For example, NIST AI RMF is a voluntary framework designed to help organizations manage AI risks. ISO/IEC 42001, by contrast, specifies requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System (AIMS). ISO/IEC 23894 focuses specifically on guidance for managing AI-related risks and integrating risk management into AI-related activities.
This distinction matters because choosing an approach that does not match the organization's needs can create unnecessary bureaucracy, duplicated controls, unclear ownership, or gaps between policy and operational practice.
The key question is therefore not
Which AI risk management framework is the best?
It is:
Which framework, standard, or combination of approaches provides the right governance and risk-management architecture for our organization?
Framework selection should begin with the organization rather than with the framework itself. Before choosing an approach, assess the following factors:
Primary objective: Are you looking for practical risk-management guidance, formal AI governance, certification readiness, regulatory support, or a combination?
AI role: Does the organization develop, provide, deploy, integrate, or use AI systems?
AI risk profile: What types of risks could arise from the organization's AI systems and their intended uses?
Governance maturity: Does the organization already have established risk, security, privacy, quality, or compliance management processes?
Regulatory and contractual requirements: Which laws, regulations, industry requirements, customer commitments, or procurement conditions apply?
Implementation capability: Does the organization have the people, expertise, resources, and governance structure needed to operationalize the chosen approach?
Evidence and improvement: How will the organization document decisions, monitor performance, evaluate controls, and improve its AI risk-management practices?
The framework should support how the organization actually operates.
For example, an organization looking for a flexible way to structure AI risk-management activities may not need the same level of management-system formalization as an organization seeking an organization-wide AI governance system.
Similarly, an organization already operating established ISO management systems may benefit from integrating AI governance into its existing management-system architecture rather than creating an isolated AI risk process.
Framework selection is therefore a governance decision, not simply a compliance purchase.
The major approaches considered in this article answer different questions:
|
Approach |
Primary purpose |
Best fit |
Main question it answers |
Key consideration |
|
NIST AI RMF |
Flexible AI risk management |
Organizations seeking adaptable risk guidance |
How should we manage AI risk? |
Voluntary and outcome-oriented |
|
ISO/IEC 42001 |
AI management system |
Organizations seeking structured AI governance and continual improvement |
How should we establish and operate an AI management system? |
Requires an organization-wide management-system approach |
|
ISO/IEC 23894 |
AI risk-management guidance |
Organizations integrating AI risk management into activities and functions |
How can AI risk management be integrated into organizational activities? |
Focused specifically on AI-related risk |
|
Combined approaches |
Complementary governance and risk management |
Organizations with broader governance and assurance needs |
How should different governance and risk requirements work together? |
Requires deliberate mapping to avoid duplication |
This comparison highlights why there is no universal winner. Each approach addresses a different organizational need.
The NIST Artificial Intelligence Risk Management Framework (AI RMF) was developed to help organizations designing, developing, deploying, or using AI systems manage AI risks and promote trustworthy and responsible AI. NIST describes the framework as voluntary, rights-preserving, non-sector-specific, and use-case agnostic.
The AI RMF Core is organised around four functions:
Govern: Establish and maintain organisational structures, policies, and practices for AI risk management.
Map: Establish context and identify risks associated with AI systems and their intended uses.
Measure: Assess, analyze, and monitor identified AI risks.
Manage: Prioritise and respond to identified risks.
These functions are not intended to operate as a rigid checklist or a mandatory sequence. NIST describes governance as a cross-cutting function that informs the other three functions, while AI risk management should remain continuous throughout the AI system lifecycle.
NIST also provides an AI RMF Playbook containing suggested actions and references for implementing the framework. The Playbook is voluntary and is not intended to be a checklist that organizations must follow in its entirety.
NIST AI RMF can be particularly useful when an organization:
wants a flexible AI risk-management structure;
needs practical guidance without adopting a formal management system;
wants to establish common AI risk terminology and practices;
is developing AI governance processes;
needs an adaptable approach across different AI use cases; or
Wants to complement existing governance, security, privacy, or compliance processes.
One important consideration is currency: NIST AI RMF 1.0 is currently being revised. Organizations using the framework should therefore monitor NIST updates and assess how future revisions affect their implementation approach.
ISO/IEC 42001: 2023 is an international standard that specifies requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System (AIMS). It applies to organisations of different sizes and across industries that develop, provide, or use AI-based products or services.
The distinction between ISO/IEC 42001 and a standalone AI risk framework is important.
An AIMS is not simply an AI risk register or a collection of risk assessments. It provides an organisation-wide structure for establishing AI-related policies and objectives and implementing processes to achieve them.
ISO/IEC 42001 addresses areas including:
organisational context and leadership;
AI policy and objectives;
planning and risk management;
operational processes;
performance evaluation;
monitoring and review; and
continual improvement.
The standard follows a management-system approach based on continual improvement, helping organizations move from ad hoc AI practices toward a structured and accountable governance model.
ISO/IEC 42001 may make more sense when an organization:
wants a formal AI management system;
needs organization-wide AI governance;
wants structured responsibilities and processes;
already uses management-system standards;
needs stronger evidence of governance and continual improvement;
wants to integrate AI risk management into broader organizational processes; or
is considering conformity assessment or certification.
ISO/IEC 42001 is not automatically a better choice than NIST AI RMF. It provides a different type of structure and therefore requires a greater organizational commitment to management-system implementation.
ISO/IEC 23894:2023 Information technology: Artificial intelligence Guidance on risk management provides guidance for organizations that develop, produce, deploy, or use AI products, systems, and services. It focuses specifically on managing AI-related risks and integrating risk management into AI-related activities and functions.
This makes its role different from ISO/IEC 42001:
ISO/IEC 23894 → AI-specific risk-management guidance.
ISO/IEC 42001 → requirements for an organization-wide AI management system.
The two approaches can therefore be complementary rather than interchangeable.
NIST AI RMF and ISO/IEC 42001 are often compared because both support responsible AI governance and risk management. However, they should not be treated as equivalent frameworks.
|
Factor |
NIST AI RMF |
ISO/IEC 42001 |
|
Primary purpose |
AI risk-management framework |
AI management system |
|
Nature |
Voluntary framework |
International management-system standard |
|
Core structure |
Govern, Map, Measure, Manage |
AIMS requirements and management-system processes |
|
Primary focus |
Managing AI risks and supporting trustworthy AI |
Establishing and continually improving organisational AI governance |
|
Flexibility |
High |
More structured |
|
Organisation-wide system |
Not itself a management-system standard |
Yes |
|
Continual improvement |
Supported through ongoing risk management |
Core management-system principle |
|
Certification |
Not a certification standard |
Can provide a basis for conformity assessment or certification |
|
Best fit |
Flexible AI risk management |
Formal AI governance and management-system implementation |
The practical distinction is straightforward:
NIST AI RMF helps organisations structure how they manage AI risks. ISO/IEC 42001 provides a management-system structure for governing AI across the organisation.
An organisation may therefore use NIST AI RMF practices within a broader management-system environment rather than treating the two as mutually exclusive.
Organisations do not always need to choose a single framework.
In some cases, combining complementary approaches can provide a stronger governance architecture. The objective, however, should be complementarity rather than duplication.
For example, an organisation could use:
ISO/IEC 42001 to establish its organisation-wide AI management system;
NIST AI RMF to structure practical AI risk-management activities; and
ISO/IEC 23894 to provide additional AI-specific risk-management guidance.
This does not mean every organisation should implement all three.
The right combination depends on the organisation’s objectives, existing management systems, regulatory environment, AI use cases, resources, and assurance requirements.
A combined approach should clearly map:
Requirements: What does each framework or standard require or recommend?
Processes: Which organizational processes address those requirements?
Controls: Which controls or practices manage the relevant risks?
Ownership: Who is responsible for implementation and oversight?
Evidence: What records demonstrate that activities were performed?
Review: How will effectiveness and improvement be evaluated?
A simple mapping exercise can reveal overlapping requirements and help the organisation avoid creating separate processes for essentially the same risk.
The goal should be an integrated governance architecture rather than multiple disconnected compliance programmes.
Framework selection should never be separated from the legal environment in which an organisation operates.
A voluntary framework does not become legally binding simply because an organisation adopts it. Likewise, implementing an international standard does not automatically demonstrate compliance with every applicable AI regulation.
Organisations should therefore determine their legal and contractual obligations first and then use appropriate frameworks and standards to support implementation.
The EU AI Act illustrates this distinction.
For high-risk AI systems, Article 9 establishes requirements for a risk-management system. The regulation requires providers to establish, implement, document, and maintain a risk-management system that is intended to operate as an ongoing and iterative process throughout the lifecycle of the high-risk AI system.
An organisation subject to such requirements should therefore begin by determining whether and how the regulation applies to its AI systems.
It can then assess how NIST AI RMF, ISO/IEC 42001, ISO/IEC 23894, or other standards can support the organisation’s compliance and governance activities.
The sequence is important:
Legal obligations first → organizational requirements second → framework and standards selection third → implementation and evidence fourth.
This avoids the common mistake of assuming that adopting a recognized framework automatically equals regulatory compliance.
A practical selection process can be reduced to seven steps.
Start by identifying what the organization needs to achieve.
Is the objective to:
establish flexible AI risk-management practices;
create formal AI governance;
integrate AI risks into existing management systems;
prepare for assurance or certification;
address regulatory requirements; or
combine several of these objectives?
A clearly defined objective makes framework selection considerably easier.
Determine which AI systems, business functions, products, services, teams, and processes fall within scope.
Consider whether the organisation is acting as an AI developer, provider, deployer, user, or in multiple roles.
The scope should also consider the AI lifecycle and the relationships between internal teams and external suppliers.
Identify relevant:
laws and regulations;
industry requirements;
contractual obligations;
customer requirements;
internal policies; and
assurance expectations.
Do not assume that a voluntary framework or standard covers every legal obligation.
Ask whether the organisation needs:
Flexible guidance → NIST AI RMF may be appropriate.
AI-specific risk guidance → ISO/IEC 23894 may be useful.
A formal organisation-wide management system → ISO/IEC 42001 may be more appropriate.
Multiple governance and risk objectives → A combination may make sense.
Look at the organisation’s existing:
enterprise risk management;
information security;
privacy;
data governance;
quality management;
compliance;
internal audit; and
supplier-management processes.
The selected approach should integrate with these processes wherever possible rather than creating unnecessary parallel structures.
Document why the organisation selected the framework, standard, or combination of approaches.
A framework decision should identify:
scope;
objectives;
applicable requirements;
selected framework or standards;
supporting processes;
responsibilities;
controls;
evidence requirements; and
review mechanisms.
This creates a defensible basis for future governance and assurance activities.
Framework selection is not a one-time exercise.
Assign clear ownership for implementation, monitoring, internal review, and continual improvement.
AI technologies, organizational priorities, regulatory requirements, and risk profiles can change. The governance approach should therefore be reviewed periodically and updated when necessary.
The decision can be simplified into the following model:
|
Organizational need |
Potentially suitable approach |
|
Flexible AI risk-management guidance |
NIST AI RMF |
|
Formal AI management system |
ISO/IEC 42001 |
|
AI-specific risk-management guidance |
ISO/IEC 23894 |
|
AI governance plus flexible risk-management practices |
ISO/IEC 42001 + NIST AI RMF |
|
Existing ISO management system environment |
Consider integrating ISO/IEC 42001. |
|
Specific legal obligation |
Applicable regulation first; framework or standard second |
This is not a prescriptive ranking. The appropriate choice depends on the organization's context.
A useful decision flow is:
Define objective → establish scope → identify legal requirements → assess governance maturity → select framework or combination → map requirements and controls → assign ownership → monitor and improve.
The framework provides the architecture. People, processes, controls, evidence, and decision-making make that architecture operational.
The best AI risk management framework is not necessarily the most comprehensive, popular, or widely recognized option. It is the approach that best fits the organization's objectives, AI risk profile, governance maturity, regulatory environment, and implementation capability.
NIST AI RMF is well suited to organizations seeking flexible, voluntary guidance for managing AI risks. ISO/IEC 42001 is designed for organizations that need a formal Artificial Intelligence Management System with structured governance and continual improvement. ISO/IEC 23894 provides focused guidance for integrating AI risk management into AI-related activities and functions.
These approaches do not necessarily compete. They can be combined when their roles are clearly defined and overlapping requirements are deliberately mapped.
The most effective approach is therefore to assess organizational needs first, choose the appropriate governance architecture second, and integrate the selected framework or standards into existing processes rather than treating them as standalone compliance exercises.
An AI risk management framework is a structured approach for identifying, assessing, prioritising, treating, and monitoring risks associated with artificial intelligence. It helps organisations establish consistent risk-management practices across AI-related activities and decisions.
An AI risk management framework primarily structures activities for managing AI risks. An AI management system, such as the one specified by ISO/IEC 42001, provides a broader organisational structure covering policies, objectives, responsibilities, processes, performance evaluation, and continual improvement.
NIST AI RMF is intended for voluntary use. Organisations can adopt it to structure AI risk-management practices, but its use does not by itself replace applicable legal or regulatory requirements.
ISO/IEC 42001 is an international standard rather than a universal legal requirement. Whether an organisation must implement it depends on applicable laws, contracts, customer requirements, sector expectations, or organisational decisions.
The answer depends on the organisation’s objective. NIST AI RMF is suited to flexible AI risk management, while ISO/IEC 42001 is designed around a formal AI management system. Some organisations may benefit from using them together.
Yes. Their purposes are complementary. ISO/IEC 23894 provides guidance on AI-related risk management, while ISO/IEC 42001 establishes requirements for an Artificial Intelligence Management System. Organisations can map the relevant risk-management guidance into their broader AIMS processes.
Start with the organisation’s objective, AI role, risk profile, governance maturity, legal obligations, existing processes, and implementation capability. Then determine whether flexible guidance, AI-specific risk guidance, a formal management system, or a combination is appropriate.
Not all AI risk management frameworks are mandatory. Some are voluntary frameworks or standards, while applicable laws and regulations can impose binding requirements. Organizations should determine which legal obligations apply before selecting supporting frameworks and standards.
No. Adopting a framework does not automatically demonstrate compliance with every applicable law or regulation. Compliance depends on the organization's specific legal obligations, AI systems, implementation practices, controls, documentation, and evidence.
NIST AI RMF is a voluntary AI risk-management framework organized around Govern, Map, Measure, and Manage. ISO/IEC 42001 is a management-system standard that specifies requirements for establishing, implementing, maintaining, and continually improving an artificial intelligence management system.
OpenAI shelved GPT-6.1 Astra after safety tests flagged scope, authorization and action-reporting issues. See what is confirmed and what remains...
AI Law
Learn AI compliance requirements, key risks, the EU AI Act, NIST AI RMF, ISO 42001, and practical steps to build...
AI Law
Understand AI regulation in the United States in 2026, including federal rules, state AI laws, privacy, discrimination and practical compliance...