ISO 42001 vs EU AI Act vs NIST AI RMF: How They Fit Together (and Where to Start)
Published: July 2026
If you own AI governance at your organization, three names keep landing on your desk: the EU AI Act, ISO/IEC 42001 and the NIST AI RMF. They get compared as if they were competing options on a menu. They are not — one is a law, one is a certifiable management-system standard, and one is a voluntary framework, each built to do a different job.
The useful news: they share a common core. Build one solid AI inventory and risk assessment and you can map it to all three at once. Here is what each one is, what each demands, where they overlap, and the pragmatic order to tackle them in.
One is a law, one is a standard, one is a framework
The EU AI Act is binding law. It classifies AI systems into risk tiers and attaches enforceable obligations — with penalties — to providers and deployers. Prohibited practices are already banned, and obligations for general-purpose AI models have applied since August 2025. High-risk obligations were deferred by the simplification package the Council of the EU gave final approval to on 29 June 2026: they now apply from 2 December 2027 for standalone systems and 2 August 2028 for AI embedded in regulated products.
ISO/IEC 42001, published in December 2023, is a management-system standard — the AI counterpart to ISO 27001. It is voluntary, but you can be audited and certified against it, which makes it the natural answer when customers or procurement teams ask for proof of responsible AI practice.
NIST AI RMF 1.0, published in January 2023, is a voluntary framework from the US National Institute of Standards and Technology. There is no certification. It organizes AI risk work into four functions — Govern, Map, Measure, Manage — and is widely used as a shared vocabulary, especially in US-facing organizations.
What each one actually demands
The EU AI Act demands classification first: you must determine which risk tier each system falls into. High-risk systems then need a risk-management system, data governance, technical documentation, logging, human oversight and a conformity assessment. Classification is live work right now — the European Commission published draft guidelines on high-risk classification (Article 6) in May 2026.
ISO/IEC 42001 demands a functioning management system: an AI policy, defined roles and responsibilities, AI system impact assessments, lifecycle controls drawn from its Annex A, documented information, internal audits and management review. Auditors check that the system runs continuously — not that a binder exists.
The NIST AI RMF demands outcomes rather than clauses: Govern establishes accountability and culture, Map builds context and an inventory of AI systems, Measure assesses and tracks risks, and Manage prioritizes and responds to them.
Where they overlap: inventory, risk, documented oversight
Strip away the terminology and all three rest on the same three assumptions:
- You know what AI you have. You cannot classify systems under the Act, scope an ISO 42001 audit, or perform NIST's Map function without an inventory.
- You assess risk per system. The Act's risk-management requirements, ISO 42001's impact assessments and NIST's Measure function all start from a per-system risk view.
- You can show documented oversight. Every one of them expects named owners, review records and evidence — not verbal assurances.
That shared core is why a single well-maintained AI register does most of the work for all three. If you do not have one yet, start from our free AI risk register template.
A rough mapping between the three
Read the three side by side and the columns line up more than the acronyms suggest:
- Inventory and classification: EU AI Act risk classification (Article 6) sits alongside ISO 42001's scoping and impact-assessment requirements and NIST's Map function.
- Risk management: the Act's Article 9 risk-management system parallels ISO 42001's AI risk and impact assessments and NIST's Measure function.
- Oversight and accountability: the Act's human-oversight requirements (Article 14) map to ISO 42001's leadership and role clauses and NIST's Govern function.
- Documentation and evidence: Article 11 technical documentation and logging correspond to ISO 42001's documented information and internal audits, and to NIST's Manage function.
Treat this mapping as directional, not exact. A legal obligation, a certifiable clause and a voluntary outcome are different animals — but evidence produced for one is rarely wasted on the others.
Where to start: one inventory, three mappings
The common failure mode is running three parallel programs: an EU AI Act spreadsheet, an ISO 42001 workstream and a NIST self-assessment, each with its own owner and its own stale copy of the same system list. Six months later, none of them agree.
The pragmatic order is different. Build the inventory once, from where AI work already lives. Gartner projects that roughly 40% of enterprise applications will include embedded AI agents by the end of 2026, up from under 5% in 2025 — and Atlassian shipped Rovo agents into Jira in 2026, where they can be assigned work and embedded in workflows. Your work-tracking system is where new AI shows up first.
Then risk-score every system on the register, and map each entry to all three frameworks in a single pass. We keep dedicated guides for each mapping: EU AI Act from Jira, ISO 42001 from Jira and NIST AI RMF from Jira.
How AI Governance Hub maps one register to all three
AI Governance Hub automates exactly this sequence. Upload a Jira, Azure DevOps or CSV export — or install the Atlassian Forge app, which runs entirely inside your Jira Cloud tenant with no data egress. The platform discovers AI systems, builds a risk-scored register, maps every entry against the EU AI Act, ISO/IEC 42001 and the NIST AI RMF, computes a governance score, and generates board-ready reports in PDF, Word, PowerPoint and HTML. See a real report example, or test the flow with our sample CSV files first.
One clarification worth stating plainly: AI Governance Hub provides governance evidence and executive analysis — it is not legal advice, and no tool can certify legal compliance for you.
Frequently asked
Does ISO 42001 certification make us compliant with the EU AI Act? No. ISO 42001 is a voluntary management-system standard, while the EU AI Act is binding law with its own obligations and conformity routes. Certification is strong supporting evidence but does not by itself constitute legal compliance.
When do the EU AI Act's high-risk obligations apply? Following the 2026 simplification package, high-risk obligations apply from 2 December 2027 for standalone systems and 2 August 2028 for AI embedded in regulated products. Obligations for general-purpose AI models have applied since August 2025.
Do we need to adopt all three? The EU AI Act is mandatory wherever it applies; ISO 42001 and NIST AI RMF are voluntary. Because one inventory and risk assessment feeds all three, mapping to them together adds little extra work.
The fastest way to see how these three frameworks apply to your own AI portfolio is to try them on real data. Upload a Jira, Azure DevOps or CSV export and get a risk-scored register mapped to the EU AI Act, ISO 42001 and NIST AI RMF in minutes — the free preview runs on your own data, no credit card required, with founding pricing from ₹199.