Sentrix

Breakdown · AI

AI governance: ISO 42001 and the NIST AI RMF explained

ISO/IEC 42001 and the NIST AI RMF 1.0 frame how organizations use AI. What each one requires, how they complement each other, and which actions to start with.

By Sentrix · Published 2026-09-20

For two years, AI tools have entered organizations through the teams, not through management: an assistant in the office suite, a model in a product, an agent calling APIs with its own access. Auditors, customers and regulators are starting to ask who governs these uses. Two frameworks give a structured answer: ISO/IEC 42001 and the NIST AI RMF. They do not say the same thing, and that is exactly why they complement each other.

What the frameworks say

ISO/IEC 42001:2023, which the IEC catalogue entry lists as published in December 2023, specifies the requirements and provides guidance for establishing, implementing, maintaining and continually improving an AI management system within the context of an organization. It applies to any organization, whatever its size or sector, that provides or uses products or services relying on AI systems. It is a management system standard, in the same way as ISO 27001: it is certifiable and it follows the common structure of ISO standards (context, leadership, planning, support, operation, performance evaluation, improvement). What it adds comes down to three elements: an AI-specific risk assessment, an assessment of the impact of AI systems on people and society, and an annex of controls covering the life cycle of systems, data, transparency toward interested parties and responsible use.

The NIST AI Risk Management Framework 1.0, released on January 26, 2023 according to NIST, is a framework for voluntary use. It is not certifiable. It organizes the management of AI-related risk around four functions: Govern, Map, Measure and Manage. It describes the characteristics of trustworthy AI: valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, fair with harmful bias managed. NIST pairs it with an implementation guide (the Playbook) and, since July 26, 2024, with a profile dedicated to generative AI (NIST AI 600-1) that names the risks specific to these models and proposes actions. NIST also publishes crosswalks between its framework and other references, including ISO/IEC 42001, while stating that their inclusion does not imply endorsement.

In short: the NIST framework says what to watch and why; the ISO standard says how to organize it in an auditable way.

Why it matters

Customers already ask. The security questionnaires of large buyers increasingly include a section on AI use: which models, which data, which controls. Answering "we have no policy" closes doors.

Uses come before rules. Without an inventory, the organization does not know which data goes to which models. That is first a confidentiality risk, and ISO 27001:2022 already covers part of it: classification of information (5.12), supplier relationships (5.19 to 5.23), data leakage prevention (8.12). AI governance starts by applying these controls to AI tools.

Obligations are converging. In Quebec, Law 25 already requires informing a person when a decision about them rests exclusively on automated processing. Elsewhere, sector frameworks and contracts carry the same expectations: knowing which system decides, on which data, with what human oversight. A management system answers all these questions with the same evidence.

What we think at Sentrix

Do not start with certification. Start by knowing what you use, then attach AI governance to the management system you already have.

  1. Inventory AI uses: SaaS tools with AI features enabled, models embedded in your products, internal agents, each with an owner, the data processed and the purpose. This is the NIST Map function and the starting point of the context ISO 42001 requires.
  2. Write a short policy: permitted uses, prohibited uses, data that never leaves, approval process for a new tool. Attach it to your information security policy rather than creating a silo.
  3. Assess the impact of the high-stakes cases: any system that influences a decision about a person (hiring, credit, access to a service) goes through an impact assessment, as ISO 42001 requires, and through a privacy impact assessment when personal information is involved.
  4. Treat AI vendors as critical third parties: clauses on the use of data for training, location, logging, audit rights. Your ISO 27001 supplier controls apply as they are, and the third-party risk module of the Sentrix platform tracks them with the others.
  5. Measure what counts: a register of AI-related incidents (wrong outputs, data leakage, model drift), reviewed by the same committee as security incidents. This is the Measure function, and it is what an auditor will want to see.
  6. Decide on certification afterwards: if you sell AI to regulated customers, ISO 42001 becomes a commercial argument; otherwise the NIST AI RMF is often enough as an internal framework, and it prepares for the standard.

For an organization already certified to ISO 27001, the first four actions reuse the existing system: same management reviews, same internal audit, same risk register. Our pages on ISO/IEC 42001 and on the NIST AI RMF detail the requirements of each.

The next step

Do the inventory this week, without a tool: a list of uses, one name per line, the data involved. If the list is longer than you imagined, that is normal, and it is the first useful result. If you want to build it with someone who has done it before, talk to us.

Sources

Frequently asked questions

Do we have to choose between ISO/IEC 42001 and the NIST AI RMF?
No. The NIST framework is voluntary, free and not certifiable: it structures the thinking about risk (govern, map, measure, manage). ISO/IEC 42001 is a management system standard, certifiable, that turns the same concerns into auditable requirements. Many organizations start with the NIST framework and move to the standard when a customer or a regulator asks for independent proof.
We are ISO 27001 certified. What does 42001 add?
The same management system structure, with three AI-specific additions: a risk assessment that accounts for how models behave, an assessment of the impact of AI systems on people and society, and an annex of controls on the life cycle, the data and transparency. Existing management reviews, internal audits and the risk register are reused as they are.
Where do we start if we have nothing?
With an inventory of uses: SaaS tools with AI features enabled, models embedded in your products, internal agents, each with an owner, the data processed and the purpose. Then add a one-page policy (permitted uses, prohibited uses, data that never leaves) and an impact assessment for the cases that touch decisions about people. The rest follows.

Let's talk about your compliance program.

Last updated: 2026-09-20