Comparison

EU AI Act, ISO 42001, and NIST AI RMF: How the Three Fit Together

A mandatory law, a certifiable standard, and a voluntary playbook, what each one is and how to run them as a single AI governance program.

8 min read

The fastest way to feel overwhelmed by AI governance is to treat the EU AI Act, ISO/IEC 42001, and the NIST AI RMF as three separate projects. They are not. They sit at three different levels, a law, a standard, and a framework, and the same underlying controls satisfy all three. Understanding the levels is what turns three obligations into one program.

Three Different Things

  • The EU AI Act is a law. It is binding regulation with penalties, and it takes a risk-based approach: some AI uses are prohibited, some are high-risk and heavily regulated, and some carry only transparency obligations. If you offer AI systems in the EU, compliance is not optional.
  • ISO/IEC 42001 is a certifiable standard. Published in 2023, it defines an AI management system (AIMS), the way ISO 27001 defines an information security management system. You can be audited and certified against it, which gives you a credential to show buyers.
  • The NIST AI RMF is a voluntary framework. The US National Institute of Standards and Technology's AI Risk Management Framework is guidance, not a rule or a certification. It is widely referenced as a way to structure AI risk work, and NIST extends it with profiles for areas like generative AI rather than issuing a new version.

Why They Overlap

All three point at the same practices: govern who is accountable for AI, assess the risks of a given system, put controls around data and models, keep humans in the loop for consequential decisions, and document what you did. Build those once, and you are addressing the EU AI Act's requirements, ISO 42001's controls, and the NIST AI RMF's functions at the same time.

How to Run Them as One Program

  1. Inventory your AI uses and classify each by risk. The EU AI Act's risk tiers are a useful lens even outside the EU.
  2. Adopt a control set that covers governance, risk assessment, data and model management, and human oversight.
  3. Map that control set to whichever frameworks your buyers and regulators care about, so one program produces evidence for all of them.
  4. Keep it current. AI rules and your own AI systems both change quickly, so treat governance as a living program.

How Concord Fits

Concord Trust's control library includes an AI governance control family authored for ISO/IEC 42001 and the NIST AI RMF, and both are among its framework packs. You build and maintain the controls once and map them to each framework, so proving your AI posture in a security review draws on the same program that supports certification. Concord does not certify anyone against the EU AI Act; the Act is the regulatory context, and the controls and frameworks are what you actually operate.

Get Started

Turn Security Reviews into a Link You Send

Concord Trust turns your controls, frameworks, and scoped auditor access into a public trust center that answers security reviews and closes deals. Start free, then add a framework when you are ready.