
Two documents come up in every AI governance meeting. They are different kinds of thing. ISO/IEC 42001 is a standard you can be certified against. An auditor checks that you run an AI management system the way it says. The NIST AI Risk Management Framework is a framework you use. It gives you vocabulary and practices, and no certificate. Both apply to companies that use AI, not only to those that build it.
In one sentence: 42001 is the exam, the RMF is the textbook, and neither tells you where the hold goes.
Where they come from
NIST released the AI RMF 1.0 on 26 January 2023. It came out of a request for information, public drafts and workshops4. Its own text says it "is intended to be voluntary, rights-preserving, non-sector-specific, and use-case agnostic"3. A Playbook followed. On 26 July 2024 NIST added a Generative AI Profile, NIST AI 600-145. In April 2026 it released a concept note for a critical infrastructure profile. NIST now says the RMF 1.0 "is being revised as part of the White House AI Action Plan"4. Expect a 2.0.
ISO and IEC published 42001 as a first edition in December 20231. It copies the shape of ISO 27001. Clauses 4 to 10 set the requirements. Annex A lists "reference control objectives and controls". Annex B gives guidance for each. Annex C lists AI objectives and risk sources. Annex D covers use across sectors1.
The scope is wide on purpose. It "is intended for use by an organization providing or using products or services that utilize AI systems"1. Using counts.
What each actually asks for
ISO/IEC 42001. You build a management system. A written AI policy. Roles with authorities (clause 5.3). A risk assessment (6.1.2). An AI system impact assessment (6.1.4) that looks at individuals and society, not only the company1. You choose the Annex A controls that apply and justify the rest. You measure, audit internally and review at management level (clause 9). Then a certification body audits you. Pass, and you hold a certificate for a scope you defined.
NIST AI RMF. The RMF names seven traits of trustworthy AI: "valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy enhanced, and fair with their harmful biases managed"3. Its Core has four functions: Govern, Map, Measure and Manage. Govern is "a cross-cutting function" that runs through the other three3. Each function breaks into categories and subcategories. You pick the ones that fit. You write down what you did.
Here is how each answers a team running an agent that acts:
| Your question | 42001 answer | AI RMF answer |
|---|---|---|
| Who is accountable for this agent? | Clause 5.3: roles, responsibilities and authorities | Govern: accountability structures and roles |
| What could go wrong, for whom? | Clause 6.1.2 risk assessment, 6.1.4 impact assessment | Map: context, intended use, impacts |
| Which controls do we run? | Annex A, chosen and justified | Manage: prioritise and respond to mapped risks |
| Are the controls working? | Clause 9: monitoring, internal audit, management review | Measure: metrics and evaluation over time |
| Can we prove it to an outsider? | Yes, a certificate for a defined scope | No certificate. You show your documents |
Neither contains a threshold, a named approver or a hold rule. Both require you to have decided those things, written them down, and reviewed them. The content is yours.
What each is good for, and what it is not
42001 is good for proof. It shows a customer, a regulator or a board that your governance exists and was audited. It forces the paperwork most AI programmes skip. A scope statement. A risk register. An impact assessment. A review date. Sell agents to enterprises, and our view is buyers will ask for it the way they ask for 27001.
42001 is not proof that an agent behaves. The certificate covers the system for managing AI, inside a scope the company chose. A certified vendor can still ship an agent whose rules live in a prompt. Read the scope statement. Then check the agent's controls separately.
The RMF is good for starting. Govern, Map, Measure, Manage is a sensible agenda for a first governance meeting. The Generative AI Profile is a public list of what goes wrong with language-model systems. It is free. You do not need a consultant to read it.
The RMF is not something you comply with. "We follow the NIST AI RMF" states an intent. Nobody can verify it. If a vendor says it, ask which subcategories. Ask to see the documents.
Both are silent on runtime. They describe what an organisation does around a system. Policy, risk, roles, review. Neither describes the moment between the model's decision and the write to your ERP. That gap is where a control plane sits. It is where most incidents fall through.
What to check
For your own programme:
- /01
Is there a written scope? Which agents, which processes, which systems of record. Both documents start here. Most teams have not written it.
- /02
Does each agent have one named person with authority to stop it? That is 42001 clause 5.3 and RMF Govern. If the AI Act applies, it is also Article 26(2)6.
- /03
Has anyone written down the impact on the people the agent decides about?
- /04
Is there a review date? Did the last review change anything?
For a vendor who shows you a certificate:
- /05
What is the certified scope? Does it include the product you are buying?
- /06
Which Annex A controls did they exclude, and why?
- /07
Apart from the certificate: where do the agent's rules live? Can you read the record of one run?
Where it is going
Our view: 42001 becomes the backbone other AI rules assume, the way 27001 sits under security regulation. The RMF's revision is the chance to add agent-specific content to Map and Manage. Demand for certificates will come from procurement before it comes from regulators. Buyers copy each other's questionnaires faster than regulators write rules.
Gatehouse fit
Gatehouse supplies the runtime layer both documents leave to you. The rules are signed and versioned, which gives one agent its clause 5.3 and Govern artefact. One named approver can decline. The record is chained by SHA-256, so an internal audit can read it without trusting us. Surehand holds no ISO/IEC 42001 certificate and no SOC 2 today. The Trust page lists what is in place and what is not.
At a glance
| Category | Regulation (standards) |
|---|---|
| ISO/IEC 42001:2023 | Management system standard, December 2023, certifiable, clauses 4-10 plus Annexes A-D |
| NIST AI RMF 1.0 | Voluntary framework, January 2023, four functions, GenAI Profile July 2024, revision under way |
| Applies to | Both: organisations that provide or use AI systems |
| What neither contains | Thresholds, approvers, hold rules, runtime checks |
| Typical owner | Compliance or risk runs the programme. The process owner supplies the content |
| The one test | Can you show the scope, the named person and the last review? |
Sources
- [1]ISO/IEC 42001:2023, Artificial intelligence, Management system (first edition, December 2023), previewcdn.standards.iteh.ai In text
- [2]ISO/IEC 42001:2023, ISO catalogue pageiso.org
- [3]NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0), January 2023nvlpubs.nist.gov In text
- [4]AI Risk Management Framework, NIST programme pagenist.gov In text
- [5]NIST AI 600-1, AI RMF: Generative Artificial Intelligence Profile, July 2024doi.org In text
- [6]Regulation (EU) 2024/1689 (AI Act), Article 26: Obligations of deployersartificialintelligenceact.eu In text
Read next

EU AI Act obligations for deployers of AI agents, after the 2026 Omnibus
If you use an AI agent rather than build one, you are a deployer. What Article 26 asks of you, which agents count as high-risk, and the dates the 2026 Omnibus moved.
What is AI governance?
Six controls. What an AI system may do, on whose authority, at what cost, with what proof. A working guide, not a policy template.
What should you ask an AI vendor before signing?
Twelve questions that separate a system you can run from a demo you can't control. Ask us first.