Your Thursday briefing · AI series
The previous episodes laid the groundwork: the inventory of uses, who answers for AI, the risks specific to language models, your vendors' AI and the AI used against you. Since then, one question comes up in almost every conversation: "So, do we go with ISO 42001 or the NIST AI RMF?"
It is a good question, asked too early. The first question is not "which one". It is: what do you need to prove, and to whom?
Why "which one" comes too early
Picking a framework before you know what you must demonstrate is like picking a report template before you have the data. The two documents do different jobs. One helps you find AI risk and reason about it. The other helps you show a customer, an auditor or a prime contractor that this risk is managed by a system that holds up over time.
Mixing them up produces two familiar failures. A certification project launched without an inventory, documenting processes that do not exist yet. Or a careful risk analysis that never becomes evidence, because nobody planned how to keep it current.
The NIST AI RMF: understand and treat the risk
NIST released its AI Risk Management Framework, AI RMF 1.0, on January 26, 2023. It is voluntary: no certification, no auditor, no seal. It is a method.
Its core comes down to four functions:
- Govern: build a risk management culture in the organization that designs, deploys, evaluates or buys AI systems. It is the cross-cutting function, the one that makes the other three possible.
- Map: establish the context of each system. What it is for, who it affects, what can go wrong.
- Measure: analyze, assess and track those risks, with quantitative, qualitative or mixed methods.
- Manage: allocate resources to the mapped and measured risks, and plan response and recovery.
On July 26, 2024, NIST added a Generative AI Profile, NIST AI 600-1, which applies those functions to language models and generative tools, the very ones the episode on LLM-specific risks walked through. NIST also says the framework is being revised: one more reason to use it as a method, not as a frozen checklist.
What it changes: the AI RMF is useful from day one, even for an 80-person company, because all it asks for is an orderly way to ask the questions. Its limit is the mirror image: it proves nothing to anyone.
ISO/IEC 42001: prove the risk is managed
ISO and IEC published ISO/IEC 42001 on December 18, 2023. It is the first AI management system standard. It sets the requirements for establishing, implementing, maintaining and continually improving such a system, and applies to any organization that provides or uses AI-based products or services, whatever its size. Unlike the AI RMF, it can be certified by an independent body.
The point that changes everything if you already work on information security: ISO 42001 follows the same harmonized structure as the other management system standards, ISO/IEC 27001 included. Same clauses, same core terms, same cycle: context, leadership, planning, support, operation, performance evaluation, improvement. If you already run an ISO 27001 certified information security management system, your policy, risk assessment, internal audit and management review extend. They do not start over.
What it changes: a certificate is evidence, and evidence has a cost. It pays off when someone asks for it: a customer in a tender, a prime contractor in a contract clause, a regulator. Before that, it mostly documents good intentions.
The decision tree
| What you need | Start with | Why | | ------------------------------------------------------------------------- | -------------------------------------------- | ------------------------------------------------------------------ | | Understand where AI creates risk in your organization | NIST AI RMF | A free method you can apply right away, with no audit | | Prove to a customer, an auditor or a prime contractor that AI is governed | ISO/IEC 42001 | The only one of the two that produces a certificate | | Both | The AI RMF for substance, ISO 42001 for form | The mapping feeds the management system, which makes it verifiable |
For most organizations, the right sequence is the third: the AI RMF to do the work, then ISO 42001 the day that work has to be demonstrated. Certification then lands on prepared ground instead of serving as the excuse to prepare it.
The first 30 days
- Week 1: go back to the inventory. The register from the shadow AI episode is your entry point. Without it, any framework turns into paperwork. If it has aged since late August, update it before anything else.
- Week 2: confirm the owners. The roles from the governance episode map to the AI RMF Govern function and to the leadership clauses of ISO 42001. A use with no named owner does not move forward.
- Weeks 3 and 4: map three systems. Not all of them, three. The one that handles personal information, the one that influences a decision about a person (hiring, credit, access to a service), and the one a vendor added without asking you, as in the episode on your vendors. For each, run the Map function: what it is for, who it affects, what can go wrong, who approved it.
By the end of the month, you have what you need to decide whether certification is worth it, and a documented base an auditor will recognize the day it is.
This week's test
Take your register of AI uses and answer three questions for every system in production:
- Who owns it, by name?
- Who approved putting it into service, and when?
- What data goes in, and what comes out?
If a single row stays blank, you are not ready for either framework. That is not a failure: it is your plan for the next 30 days.
What you should have in a month
An up-to-date register, one owner per system, three dated mappings and a written decision: certify to ISO 42001 now, later or not at all, with the reason. If a customer or a prime contractor is already asking for evidence, that decision has been made for you; all that is left is the date.
To see where you stand, ISO 42001 can be assessed directly in Forta Compliance, and the NIST AI RMF is one of the 40+ frameworks mapped to the same control baseline: a control validated once counts for every framework that requires it.
Next Thursday: securing AI agents. Permissions, oversight, and a log of what they do on their own: what changes when AI stops answering and starts acting.
Sources: NIST, AI Risk Management Framework · NIST AIRC, the four functions of the AI RMF Core · IEC, ISO/IEC 42001:2023 · ISO, ISO/IEC 42001 explained