AI Governance Compliance: NIST, ISO 42001, and the EU AI Act
Compliance is where governance meets obligation. The good news: the major frameworks overlap heavily, so a well-structured program satisfies several at once. Here is how they fit together and how to sequence your effort.
Take the free AI Governance Readiness Assessment — results on the page, no email required.
NIST AI RMF
The NIST AI Risk Management Framework organizes work into Govern, Map, Measure, and Manage. It is voluntary, widely referenced, and a sensible default structure for a program, especially in the United States.
ISO/IEC 42001
ISO/IEC 42001 specifies requirements for an AI management system (AIMS). It is certifiable, which matters when customers or tenders ask for evidence. Aligning to NIST first makes ISO alignment easier.
EU AI Act
The EU AI Act imposes binding, risk-tiered obligations (unacceptable, high, limited, minimal). It applies to providers placing AI systems on the EU market (or putting them into service there), to deployers established in the EU, and to providers/deployers outside the EU whose AI output is used in the EU. Know your role and each system's tier, and the corresponding duties.
Sector rules
Healthcare (HIPAA), finance, and public sector bring additional duties. Our HIPAA and AI guide covers the healthcare case; the same data-governance discipline generalizes.
A pragmatic sequence
Inventory and classify first, adopt an acceptable-use policy and owner, map your program to NIST AI RMF functions, then align to ISO or the EU AI Act as your market requires. Document decisions and evidence as you go — compliance is a byproduct of good records.
Frequently asked questions
Do we have to comply with the EU AI Act?
Only if you place AI systems on the EU market or your AI affects people in the EU. In that case the obligations depend on your risk tier under the Act.
Is ISO/IEC 42001 mandatory?
It is not legally mandatory, but it is increasingly requested in procurement and tenders as evidence of a managed AI program.
Can one program satisfy several frameworks?
Yes. The frameworks overlap substantially; a structured program mapped to NIST AI RMF can be extended to ISO/IEC 42001 and the EU AI Act rather than built three times.