AI Governance: Three Key Frameworks Explained
CyberKainos. Reading time: 5 mins
AI Governance: NIST AU RMF, ISO 42001, The EU Act Explained
NIST AI RMF. ISO 42001. The EU AI Act. They get used interchangeably as if they’re competing options to choose between. They aren’t. They’re three different AI governance frameworks, performing very different jobs. Knowing which is a legal requirement, which is crucial to your organisation, and which is simply good practice to adopt voluntarily is a key difference between an effective AI governance programme and a slide that says “AI Policy: Complete.”
Here’s what each of them actually is, without the jargon.
NIST AI RMF: the practical starting point
The NIST AI Risk Management Framework is published by the US National Institute of Standards and Technology. It is best understood as a well-designed thinking tool rather than a rulebook. It’s voluntary, nobody can fine you for not using it and it was built through an open, consensus-based process involving both industry and government, which is part of why it’s been adopted well beyond the US.
Structurally, it’s built around four functions: Govern (setting up oversight and accountability), Map (understanding what your AI risks actually are), Measure (assessing those risks properly), and Manage (doing something about them). There’s no certificate at the end of it, no badge for your website or to share with clients. Its value is as a sensible, well-tested starting structure for organisations that need to get their thinking organised before anything else, which is why it is a common recognised reference point for auditors, insurers, and regulators, even if it isn’t a legal requirement.
Who it’s for: Any organisation that wants a credible, low-friction way to start structuring its AI risk thinking, regardless of sector or geography. It’s a particularly strong fit if you have any US exposure, but its logic works anywhere.
ISO/IEC 42001: the certifiable standard
ISO/IEC 42001 is different in one crucial way: you can get certified against it in the same way organisations get certified against ISO 27001 for information security. Published in 2023, it’s the first international standard specifically for AI management systems, and if your organisation already holds ISO 27001 or ISO 9001, the structure will feel immediately familiar: leadership commitment, defined policies and objectives, risk management processes, lifecycle controls over your AI systems, and a cycle of monitoring and continuous improvement.
Because of the certification element, ISO 42001 has practical value. It’s a recognized, third-party-verified signal to clients, insurers, and procurement teams that your AI governance isn’t just a policy document, it’s been independently checked. For organisations bidding in regulated sectors or for public sector / enterprise contracts who are themselves under pressure to prove their supply chain is governed properly, ISO 42001 for AI governance is (for the moment) becoming a genuine commercial differentiator, not just a compliance exercise.
Who it’s for: Organisations that develop, sell, or heavily rely on AI systems and want (or need) to prove their governance to outside parties such as clients, insurers, regulators, or investors through independent certification rather than a self-declared policy.
The EU AI Act: the one that’s actually law
This is the one boards most need to get right, because unlike the other two, it isn’t optional where it applies. The EU AI Act is binding legislation, and critically, it applies based on where your AI system’s outputs are used, not where your company is headquartered. A UK organisation with EU customers, users, or even EU employees affected by an AI system can fall squarely within scope.
The Act takes a risk-tiered approach: some AI uses are banned outright (certain manipulative or biometric-surveillance systems), some carry heavy obligations (so-called “high-risk” uses like AI in recruitment, credit decisions, or safety-critical systems), and most carry lighter, transparency-focused duties.
The timelines are varied and have recently shifted:
- Prohibitions on banned AI practices and basic AI literacy obligations have been in force since February 2025, and obligations on general-purpose AI model providers have applied since August 2025.
- The headline change for 2026 follows the EU’s “Digital Omnibus” agreement reached in May which means the toughest obligations (the full compliance regime for standalone high-risk systems under Annex III) have been pushed back from August 2026 to December 2027, with high-risk AI embedded in already-regulated products (like machinery) extended further, to August 2028.
- Synthetic content transparency rules (labelling AI-generated audio, video, and images) now apply from December 2026 rather than August 2026.
The practical takeaway for boards is that while deadlines may have moved, the direction didn’t. Obligations that are already live: prohibitions, literacy, GPAI rules will stay live and the high-risk regime is delayed, not cancelled. Organisations that use this as an excuse to delay starting their own projects and waiting until late 2027 to start will be doing so under pressure rather than with room to get it right.
Which AI governance framework actually applies to you
You don’t need to actually ‘pick one’. It is clear which are legal and which are voluntary AI governance frameworks.
If your organisation’s AI systems touch EU users, customers, or employees in any capacity, the EU AI Act is not a choice, it’s an AI governance obligation with real penalties attached, and the first question for any vCISO conversation should be scoping exactly where that exposure sits.
Separately, and regardless of legal exposure, NIST AI RMF is worth adopting internally as the practical skeleton for how you think about AI risk day to day, because its highly credible, and globally recognised.
ISO 42001 sits on top of that as the commercial decision: pursue certification if you think it will give you a commercial edge or you need to prove your governance to a third-party; a client, an insurer, or a regulator.
How CyberKainos can help
The organisations getting this right are the ones who know precisely which framework is right for them and are reaching their goals quickly and efficiently. CyberKainos helps organisations without a full-time CISO do exactly this by building practical programmes around them. If you are still unsure which of these AI governance frameworks is best for you or how to start your AI governance compliance journey let’s talk.