Pillar guide
AI governance for companies that ship AI features
ISO 42001, the EU AI Act and NIST AI RMF, explained in one place: what each one asks for, which applies to you, and how to build the inventory, risk register and controls without starting a second compliance program.
The short version. ISO 42001 is the certifiable management-system standard for AI. The EU AI Act is a regulation with obligations by risk tier, phasing in from 2025 to 2027. NIST AI RMF is a voluntary US framework of practices. If you build or deploy AI, ISO 42001 gives you a certificate customers recognise, and its structure covers most of what the EU AI Act and NIST AI RMF ask for. All three sit on top of a security management system such as ISO 27001.
Three frameworks, one register
| Framework | What it is | Applies when | Output |
|---|---|---|---|
| ISO/IEC 42001 | Certifiable AI management system standard (2023) | You develop, provide or use AI systems and want independent proof of governance | Certificate from an accredited body |
| EU AI Act | Regulation with obligations by risk tier: prohibited, high-risk, limited, minimal | You place AI on the EU market or its output is used in the EU | Legal compliance; conformity assessment for high-risk systems |
| NIST AI RMF | Voluntary framework: Govern, Map, Measure, Manage | US customers or public-sector buyers ask for it | Documented practices, no certificate |
What an AI management system contains
ISO 42001 follows the same structure as ISO 27001: context, leadership, planning, support, operation, evaluation and improvement. What changes is the subject. Instead of information assets you inventory AI systems; instead of security risks you assess AI-specific ones such as bias, robustness, transparency and misuse; instead of Annex A security controls you apply Annex A AI controls covering data, models, lifecycle and accountability.
Start here
AI system inventory
Every model, agent and third-party AI service you build or use, with purpose, data, owner and risk tier. The inventory is the foundation of every other requirement.
Clause 6 / Annex A
AI impact assessment
For each system: who is affected, what could go wrong, how likely, how severe, and what you do about it. High-risk EU AI Act systems need a formal one.
Annex A
Lifecycle controls
Data provenance, model documentation, testing before release, monitoring in production, human oversight and incident handling for AI failures.
Clauses 5 and 7
Accountability
Named owners, an AI policy leadership signs, training for people who build and use AI, and records that show decisions were made and reviewed.
Reusing your ISO 27001 work
Roughly two thirds of an ISO 42001 management system already exists if you hold ISO 27001: the governance clauses, risk methodology, document control, internal audit and management review. Certifyi keeps AI risk in the same register as security risk and maps the shared controls once, so the AI standard is an overlay rather than a second program. Customers who start from ISO 27001 typically add ISO 42001 in four to six weeks.
EU AI Act timing
Prohibited practices applied from February 2025, general-purpose AI obligations from August 2025, and most high-risk obligations from August 2026 with some product-safety categories following in 2027. If your product could be classed high-risk (employment, credit, education, critical infrastructure, biometrics, essential services), the inventory and impact assessment are the first two documents a regulator or enterprise buyer will ask to see.
Go deeper
Understand the frameworks
Build the program
Related frameworks
AI governance questions we hear most
Do we need ISO 42001 if we only use third-party models?
If AI features are part of your product or your operations, yes, the standard applies to users of AI as well as developers. Your controls focus on selection, data handling, monitoring and human oversight rather than model training.
Can ISO 42001 and ISO 27001 be audited together?
Yes. Many certification bodies run integrated audits, and Certifyi schedules them on one calendar so shared controls are examined once.
Is the EU AI Act relevant to a US or Asian company?
If your AI system is placed on the EU market or its output is used in the EU, the Act applies regardless of where you are based, in the same way GDPR does.
How long does ISO 42001 take?
From an existing ISO 27001 base, four to six weeks to audit-ready. From zero, 8 to 12 weeks alongside ISO 27001, since both share the management-system work.
Shipping AI features?
Bring your product and your customer list. A compliance lead will tell you which framework your buyers will ask for first and what the inventory needs to contain.