ISO27K

ISO 42001 vs the NIST AI RMF

One of these you can be audited against by an accredited certification body. The other you cannot, by design. That single difference decides which one answers the question your customer asked.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

The NIST AI Risk Management Framework is voluntary guidance that you apply to yourself, and no certificate exists for it. ISO/IEC 42001 is a requirements standard that an accredited certification body can audit you against and issue a three-year certificate for, at roughly $15,000 to $45,000 CAD in certification body fees for a first standalone certification in Canada. If somebody has asked you to prove your AI governance to a third party, that is the entire answer and the rest of this page is detail. If nobody has asked and you want a way to think about AI risk, the NIST framework is free, better written, and the right place to start.

4 NIST AI RMF functions

38 ISO 42001 Annex A controls

$0 Cost of the NIST framework, in CAD or any currency

What the NIST AI RMF actually is

NIST released version 1.0 of the AI Risk Management Framework in January 2023, under a mandate from the National Artificial Intelligence Initiative Act. It is a free publication, it is voluntary everywhere including in the United States, and it is written as guidance rather than as requirements. There is no shall in it, so there is nothing for an auditor to test conformity against. NIST added a Generative AI Profile, published as NIST AI 600-1 in July 2024, which applies the same four functions to the risks specific to generative systems.

GOVERN
The cross-cutting function. Policies, accountability, culture, workforce competence, and third-party risk. It is meant to run through the other three rather than sit before them.
MAP
Establish the context. What is the system for, who does it affect, what are its capabilities and limits, and what could go wrong given the setting it is deployed into.
MEASURE
Analyse, assess, benchmark and monitor. Choose metrics, test for the risks you mapped, and track whether the measures still hold once the system is live.
MANAGE
Allocate resources to the risks you measured, treat them, plan for incidents and recovery, and manage risk from third-party systems.

The framework is deliberately not a checklist. That is its strength as a thinking tool and its weakness as a procurement answer, because two companies can both say they align to the NIST AI RMF and mean completely different amounts of work.

How do the four functions map to ISO 42001?

They map cleanly enough that doing one is real progress towards the other. The mapping below is the practical one rather than a formal crosswalk, and the column that matters is the third.

NIST AI RMF functions against ISO/IEC 42001
NIST functionISO 42001 clauses and controlsWhat ISO adds that NIST does not
GOVERN Clause 5 leadership, clause 7 support, A.2 policies, A.3 internal organization, A.10 third parties A required approved policy, named accountability, documented competence, and an auditor who asks a random engineer whether they know the reporting route
MAP Clause 4 context, clause 6.1.2 AI risk assessment, clause 6.1.4 impact assessment, A.4 resources, A.5 impact, A.9 intended use A written intended use per system, and a societal impact assessment as a separate deliverable rather than a consideration
MEASURE Clause 9.1 monitoring and measurement, A.6 verification and validation, A.6 operation and monitoring, A.7 data quality Defined criteria set in advance, evidence retained, and an internal audit that tests whether the measurement actually happens
MANAGE Clause 6.1.3 risk treatment, clause 8 operation, clause 10 nonconformity and corrective action, A.8 incident communication A Statement of Applicability recording every decision, and corrective action with root cause rather than a fix

The pattern across the third column is the same one that separates any management system standard from a framework: ISO 42001 requires the record, the review and the independent check. That is what makes it certifiable and it is also why it costs money.

The differences that decide the purchase

ISO/IEC 42001 and the NIST AI RMF compared
 ISO/IEC 42001NIST AI RMF 1.0
Type of documentRequirements standardVoluntary guidance
PublishedDecember 2023January 2023, plus the Generative AI Profile in July 2024
Cost of the documentPurchased from ISO or the Standards Council of Canada, roughly $200 to $400 CADFree download
Third-party certificationYes, by an accredited body, on a three-year cycleNone. No accreditation scheme exists for it
What you can show a customerA certificate naming a scope, plus your Statement of ApplicabilityA self-assessment or a consultant's report saying you align to it
StructureClauses 4 to 10 plus 38 Annex A controlsFour functions with categories and subcategories
Geographic pullInternational, and the one European and UK buyers recogniseStrongest with United States federal and federal-adjacent buyers
Ongoing cost in CanadaSurveillance audits at roughly $5,000 to $15,000 CAD a year, plus internal effortYour own time only

Which one should you actually do?

Work through this in order and stop at the first one that fits.

  1. A customer or tender has asked for evidence of AI governance and named a document they will accept. Do what they named. If they named neither, ask which one closes the requirement, because guessing costs $15,000 to $45,000 CAD.
  2. You sell into the European Union or the United Kingdom. ISO 42001. European procurement runs on ISO certificates and a NIST self-alignment statement lands as an American document nobody has a process for. Read what the EU AI Act asks of a Canadian supplier alongside it, because they are separate questions.
  3. Your buyers are United States federal agencies or their contractors. NIST first. The framework is the vocabulary those procurement processes already use, and mapping to it is often what the questionnaire asks for by name.
  4. Nobody has asked and you want to get ahead of it. NIST first, because it costs nothing and produces the AI system inventory and risk thinking that ISO 42001 will need anyway. Certify later if the demand arrives.
  5. You already hold ISO 27001 and AI is now material to the product. ISO 42001, and ask your existing certification body about an integrated audit. The clause 4 to 10 machinery is already running, which is the argument set out on ISO 42001 against ISO 27001.

Doing both is not double work

Organizations that use the NIST framework to structure their risk thinking and ISO 42001 as the auditable management system are not maintaining two systems. The NIST material informs how you run clause 6.1.2 and clause 9.1, and the ISO standard supplies the records and the audit. What is genuinely wasteful is paying a consultant separately to produce a NIST alignment report and an ISO gap assessment covering the same ground. Buy one engagement and ask for both outputs.

The case against certifying at all

Most companies asking this question do not need either document yet, and the vendor material will not tell you that. If your AI is a convenience feature, nobody outside has asked, and you are not selling into a regulated buyer, the useful work is an inventory of every AI system you run, a short written policy on what staff may put into commercial models, and vendor terms that say what your model provider does with your data. That is a week of work, it costs nothing beyond time, and it answers most questionnaires that arrive in the next year. The full argument, including the test for when that stops being enough, is on who needs ISO 42001.

The counter-argument is timing. Certification takes four to eight months from a working management system and nine to fifteen from nothing, so a company that waits for a customer to demand a certificate has already lost the deal that prompted it. If AI is your product and you sell to enterprises, the case for starting early is genuine rather than manufactured.

Work out which one your buyer meant

Send us the question your customer asked and a sentence about what your AI does, and we will tell you which document closes it.

Get matched

Common questions

Can you get certified against the NIST AI RMF?

No. There is no certification scheme and no accreditation body behind it, because NIST publishes it as voluntary guidance rather than as requirements. Firms will sell you a NIST AI RMF readiness assessment or an alignment report, and those are consulting deliverables with no third-party assurance behind them. The only AI management standard with accredited certification today is ISO/IEC 42001.

Is ISO 42001 better than the NIST AI RMF?

They do different jobs. NIST is better as a way to think about AI risk, it is free, and it is more readable. ISO 42001 is the one that produces something a customer can file. Companies that have done serious work usually use both, with NIST informing the risk method and ISO supplying the management system and the certificate.

Does NIST AI RMF alignment help us get ISO 42001 certified faster?

Yes, meaningfully. The MAP function produces the AI system inventory and context work that ISO clause 4 and clause 6.1.2 need, and MEASURE produces the evaluation evidence that Annex A verification and monitoring controls ask for. What NIST does not give you is the policy approvals, the Statement of Applicability, the internal audit and the management review, which is where the remaining work sits.

Our questionnaire asks about both. What do we answer?

Answer the NIST question by describing which functions your practices map to and where the evidence lives, and answer the ISO question with your certificate and scope statement if you hold one, or with your current position and timeline if you do not. Do not claim NIST alignment as certification, because a buyer who knows the difference will read it as either confusion or overreach.

Does the Generative AI Profile change any of this?

Not the certification answer. NIST AI 600-1 applies the same four functions to generative AI risks such as confabulation, harmful content and data leakage, and it is useful input to an ISO 42001 risk assessment for anyone shipping a generative feature. It is still guidance, and there is still nothing to certify against.

What does an ISO 42001 certificate cost in Canada compared with a NIST assessment?

The certification body portion runs roughly $15,000 to $45,000 CAD for a first standalone certification, or $10,000 to $25,000 CAD to add to an existing ISO 27001 audit, plus readiness support and surveillance audits of $5,000 to $15,000 CAD a year. A consultant-delivered NIST AI RMF alignment assessment is a one-off engagement with no audit or annual fee behind it. The itemised ISO numbers are on the certification page.