The Raido AI Briefing

The Raido AI® Briefing  ·  Issue 02

NIST AI RMF vs. ISO 42001

Which framework to choose, and what the choice actually turns on.

One question will settle this matter. Do you need to prove your AI governance to someone outside your organization, or do you need to practice it well within your organization?

If you want to provide proof to a certification body, an enterprise customer’s procurement team, a regulator, or a board as evidence that the proof wasn’t prepared by them, then ISO/IEC 42001 is the way to go since it is certifiable; NIST AI RMF is not and no level of internal rigor will result in a certificate that doesn’t actually exist.

If you need to establish governance quickly, adapt it to your own context, and begin without committing to an audit cycle, NIST AI RMF gives you a working operating model at materially lower cost and in a materially shorter time.

The two are not competitors. NIST supplies the risk-management vocabulary. ISO 42001 supplies the management-system structure. This is rarely a question about frameworks, but rather a question about which audience an organization is answering to. And organizations that have not settled that question first tend to implement whichever framework their advisor happens to know best.

The Regulation Watch

What changed, and whether it reaches you

In Washington. The federal situation has changed considerably and much of the published guidance has failed to keep up. Executive Order 14110, which had directed federal agencies to use the NIST framework as a baseline for risk management, was cancelled on January 20, 2025, and was replaced by Executive Order 14179 on January 23, 2025. The OMB Memorandum M-24-10 was also cancelled in April 2025 and was substituted by M-25-21, which deals with the use of AI by federal agencies, and M-25-22, which covers the acquisition of AI by the federal government.

M-25-21 keeps most of the previous governance structure in place, such as the position of Chief AI Officer, public listings of the agency’s AI use cases, and more stringent requirements for what it calls high-impact AI, although it reduces the number of categories believed to constitute that tier and takes a more lenient overall approach.

For a mid-market company there are two points to note. The first is that these regulations apply to federal agencies and not to private companies, and their actual impact on your organization comes about through the procurement process. If you are supplying goods or services to the federal government, you can expect governance, inventory, and documentation requirements to appear in the contract terms. The second point is that the NIST AI RMF remains voluntary in both cases: it was voluntary during the previous administration, and it is voluntary now.

In Brussels. The Digital Omnibus on AI, which the European Commission put forward on November 19, 2025, came into effect on July 27, 2026. The deadline for the high-risk obligations applicable to standalone systems covered in Annex III, such as those relating to hiring, credit scoring, biometric identification and similar areas, was postponed from August 2, 2026 to December 2, 2027. Likewise, the deadline for the high-risk obligations concerning AI incorporated in regulated products under Annex I was moved to August 2, 2028.

What did not change matters more than what did. Article 50 transparency obligations, which include disclosing to people that they are interacting with an AI system and labeling synthetic content, apply from August 2, 2026, and are now live. Article 50(2) reaches systems already on the market from December 2, 2026, alongside newly added prohibitions. The Article 4 AI literacy duty was unchanged. The deferral moved a date; it did not reduce an obligation.

Neither framework satisfies the Act’s legal requirements. Conformity assessment, CE marking, the EU declaration of conformity, registration in the EU database, and prohibited-practice screening are legal obligations, not governance practices. No voluntary framework substitutes for them. The workable arrangement for a US company with EU exposure is to use ISO 42001 as the governance backbone and layer the Act’s specific legal controls on top of it.

The Cautionary Tale

An untested system affected an eleven-year-old

Between 2012 and 2020, Rite Aid operated facial recognition surveillance in hundreds of its stores to identify people it had flagged as likely shoplifters. On December 19, 2023, the Federal Trade Commission (FTC) filed a complaint against the company in the Eastern District of Pennsylvania. The matter settled, and the final order sits on the Commission’s docket as File No. C-4308. It was the Commission’s first enforcement action addressing algorithmic discrimination. Rite Aid fundamentally disagreed with the facial recognition allegations, describing the deployment as a pilot in a limited number of stores that it had discontinued more than three years earlier. That history matters because it shows how a system can expand before governance does.

What the Commission alleged is worth reading as a governance case study rather than as a technology story. Rite Aid did not test the system’s accuracy before deploying it, nor did it track false-positive matches afterward or the actions employees took in response. It did not train the employees required to act on the alerts. It did not inform customers that the technology was in use, and it instructed employees not to disclose it. The vendor had stated that it could not vouch for the system’s reliability. The system was deployed regardless, which is exactly what a governance framework is meant to prevent.

The consequences were not statistical. According to the complaint, employees acting on false matches followed customers through stores, searched them, ordered them out without allowing them to collect prescriptions, publicly accused them of crimes in front of their families and their children, detained them, and called the police. During one five-day period, the system generated more than 900 alerts across more than 130 stores between New York and Seattle, all claiming to match a single person in the database. In one store, employees stopped and searched an eleven-year-old girl on the strength of a false match. Her mother reported missing work because the child was too distressed to be left alone after the ordeal.

The harm was not evenly distributed. Approximately 80 percent of Rite Aid stores were located in plurality-White areas, while approximately 60 percent of the stores using facial recognition were located in plurality non-White areas. The Commission found that Black, Asian, Latino, and women customers carried the greatest risk of being wrongly matched.

Now consider what the Commission ordered, because that is the part that bears on the choice of framework. A five-year prohibition on the technology, certainly. But also: delete the images and the models derived from them; implement a monitoring program; give written notice to people enrolled in the system; establish a complaint procedure; adopt a written retention schedule; properly oversee vendors; and place a security program under the direct oversight of senior executives. Commissioner Alvaro Bedoya described the order as a baseline for what a comprehensive algorithmic fairness program should look like. And that baseline is the point: these are the controls a management system is meant to create before deployment.

That is a management system. The Commission did not order Rite Aid to buy a more accurate algorithm. It ordered the company to build the documented, audited, executive-owned structure it should have had before the first camera was installed. Nearly every control in that order is one an AI management system already contains, which is the entire argument of this issue, stated by an enforcement agency rather than by a consultant.

Rite Aid paid no monetary penalty here because it was in Chapter 11 at the time. It received something more durable: a five-year prohibition on a capability it had already built, and a binding obligation to construct the governance it had skipped. The framework was never the expensive part. Not having one was.

Done Right

What good looks like when a board takes the reins

Organizations that handle this well follow the same sequence, and it begins before either framework is named.

Inventory before you choose. You cannot scope either framework without knowing what AI is in use across the organization, what data each system touches, and which uses influence decisions about people. Organizations that select a framework first almost always rescope later. And rescoping mid-implementation is where budgets are typically overrun and expanded.

Name the audience, in writing. Internal governance, customers, regulators, or some combination. This single answer determines whether certification is necessary more reliably than any other factor. It is the question most organizations skip.

Adopt in sequence, not in parallel. Most mid-market organizations that attempt both frameworks simultaneously ground neither. Start with the one that addresses your most immediate pressure, get it operating properly, then extend. Many organizations adopt NIST first and build toward ISO 42001 certification as external pressure justifies the investment. For organizations without an existing ISO management system, that sequence is usually the most efficient.

Document from the first day. Evidence gaps are a common cause of certification delay. Organizations that treat documentation as an end-of-project activity rather than a continuous practice find themselves struggling during the audit stage. This is frequently the difference between certifying on your intended timeline and certifying well after it.

Two cautions are worth stating at board level. ISO 42001 certification demonstrates that a management system exists and operates. It does not demonstrate that any specific AI system is safe, lawful, or fair, and directors sometimes read the certificate as the second thing. On cost: ask anyone who quotes you a figure: what is in scope, what is excluded, and what the recurring cost looks like in years two and three. A number without those three answers is not a quote. It is an anchor. The framework is not the expensive part. Choosing without clarity is.

The organizations that handle this well do not become experts in either standard. They become organizations whose leaders can state, in one sentence, which framework they adopted and why, and can produce evidence for it without first convening a working group. That is the close: choose the framework that fits the audience, then show the work.

The Comparison, Side by Side

NIST AI RMF and ISO/IEC 42001 at a glance

Factor NIST AI RMF ISO/IEC 42001
Type Voluntary risk management framework Certifiable management system standard
Published January 2023, as AI 100-1 December 2023
Structure Four Core functions: Govern, Map, Measure, Manage ISO clause structure, shared with 27001 and 9001
Third-party certification None available Available through accredited certification bodies
What it demonstrates That you manage AI risk That a management system exists and operates
Dominant cost Internal staff time Internal effort plus external audit fees
Recurring obligation Self-directed review at your own cadence Annual surveillance audits and recertification cycle
Time to a useful state Weeks to a few months Months, and longer without an existing ISO system
Existing ISO 27001 or 9001 Not applicable Shortens the path materially
EU AI Act Process-level alignment; does not satisfy legal obligations Strong governance alignment; does not satisfy legal obligations
US posture Native reference framework; reaches private firms through federal procurement Recognized; less commonly required in US-only environments
Best suited to First-time governance, speed, constrained budget, flexible adaptation External proof, regulated sectors, EU exposure, enterprise procurement

The Raido AI® Read

One takeaway, and one thing to do before your next meeting

The choice between NIST AI RMF and ISO 42001 is not a question of which framework is better. It is a question of which one best fits your organization’s needs and when. Neither replaces the legal obligations arising under the EU AI Act, GDPR, or US sector-specific rules. They are the operating backbone, not the whole compliance story.

Before your next board or leadership meeting, write one sentence that names the audience you are addressing, and circulate it. Not the framework, the audience. If that sentence cannot be written without a discussion, the discussion is the meeting you actually need, and it should happen before any budget is committed to a standard.

If you have not yet established which AI tools are in use across your organization, selecting a framework is premature. Inventory first, then choose.

The Board Question

Key question for management this month

Which of these three are we trying to accomplish, and who is the audience for the answer? To govern AI well. To prove that we govern AI well. To satisfy a specific legal obligation.

These are three different objectives. They cost different amounts, they take different lengths of time, and neither framework delivers all three on its own.

A strong response names one of the three as the priority, identifies the audience for it, and cites where that decision is recorded and when it was made. It is specific about what was decided rather than about what is being considered.

A weak response names all three, or names a framework instead of an audience, which is the most common form: we are doing ISO 42001. That is an answer about activity, not about purpose. A response that defers entirely to an advisor’s recommendation without stating the objective is even weaker, because it implies the organization has outsourced a decision only it can make.

Where Raido AI® Fits

Independent, and with no stake in the answer

Raido AI® is an independent AI governance advisory practice serving mid-market organizations. Independence is the point of it: the practice sells no software, accepts no vendor commissions, and holds no stake in which framework you choose.

Framework selection sits downstream of inventory, so the practice begins there. The Raido AI Health Check™ is a free self-serve diagnostic across seven governance domains, including Regulatory Exposure, and takes a few minutes. The Raido AI Review™ is a fixed-scope, independent engagement that produces a confidential findings report and a prioritized action plan. Both are designed to tell you what you are governing before you commit budget to a standard.

Start with the Health Check at raidoai.com.

Raido AI provides advisory services, not legal advice. Regulatory positions described here are current as of August 2026 and should be verified against primary sources before any compliance decision is taken. Nothing in this issue constitutes a determination of compliance with any law, regulation, or standard.

© 2026 Raido AI®. Please share. Attribution appreciated.