Should we use NIST AI RMF or ISO 42001, or both?

Organisations should consider using both NIST AI RMF and ISO 42001 to achieve comprehensive AI risk management and demonstrate due diligence. NIST AI RMF provides a flexible, risk-centric framework for identifying and mitigating AI-specific harms across diverse applications. ISO 42001 establishes a certifiable management system for AI, focusing on governance and continuous improvement. Leveraging their complementary strengths allows for a robust, auditable, and adaptable approach to responsible AI.

NIST AI RMF is a voluntary framework designed to help organisations manage risks associated with AI systems. It provides a flexible, adaptable structure for identifying, assessing, and mitigating AI-specific harms, such as bias, privacy violations, and security vulnerabilities. Its core functions (Govern, Map, Measure, Manage) guide practitioners through a risk management lifecycle, making it highly suitable for operationalising responsible AI principles across various use cases and organisational contexts. In contrast, ISO 42001 is a certifiable international standard for an Artificial Intelligence Management System (AIMS). It provides a structured approach to establishing, implementing, maintaining, and continually improving an AIMS, aligning with the familiar Plan-Do-Check-Act cycle of other ISO management system standards. This makes it particularly valuable for organisations seeking to demonstrate formal governance and assurance regarding their AI systems to stakeholders, regulators, and customers.

A common misconception is that these frameworks are mutually exclusive, forcing a choice between them. In practice, they are highly complementary. Organisations often err by focusing solely on technical AI risk mitigation without robust governance, or conversely, establishing governance without practical, granular risk assessment. NIST AI RMF can inform the risk assessment and treatment processes within an ISO 42001 AIMS, providing the 'how-to' for identifying specific AI risks that the ISO standard requires to be managed. Conversely, ISO 42001 provides the overarching management system structure, policies, and procedures necessary to embed NIST AI RMF's principles into an organisation's operational fabric, ensuring continuous monitoring, review, and improvement. Integrating both approaches allows for a comprehensive, auditable, and adaptable AI risk management strategy.

Sources

  • NIST AI Risk Management Framework (AI RMF) 1.0
  • ISO/IEC 42001:2023, Information technology — Artificial intelligence — Management system for artificial intelligence

Related