ISO/IEC 42001 vs NIST AI RMF: which one does your buyer actually want?

Somebody in a sales call has asked which AI framework you follow, and the two names that came back from the first search were ISO/IEC 42001 and the NIST AI Risk Management Framework. They are not competing answers to one question. They are answers to two different questions, and the one you need depends entirely on who is asking.

Published 22 September 2026. Written by the SecHB practice, Greater Vancouver, British Columbia.

The short version

The difference that decides it is what exists at the end: one path ends in a certificate issued by an accredited certification body, and the other ends in your own documented practice, because nobody issues anything against NIST AI RMF 1.0.

Everything else — effort, timeline, what the work looks like day to day — follows from that one structural fact. Choose on the artifact, not on the content, because the content overlaps far more than the marketing for either suggests.

ISO/IEC 42001: a management system standard with a certificate at the end

ISO/IEC 42001 is a management system standard for artificial intelligence, published by ISO and IEC. Structurally it belongs to the same family as the information security management standard most security teams have already met, which means the shape is familiar even where the subject matter is not: scope, policy, responsibilities, risk process, operation, measurement, review, improvement.

What matters commercially is the ending. An organization that runs the management system can be assessed by an independent third party, and if the assessment succeeds a certificate is issued. The certificate names its issuer, carries a validity period, and is kept alive by periodic surveillance visits. No. A consultant prepares an organization and never issues the certificate; the certificate is issued by an accredited certification body, and a firm that both prepared you and issued it would have assessed its own work.

This page deliberately says nothing about the standard’s clauses, its Annex or how many controls it contains. Those live in the standard itself, which is a paid document; anyone quoting them at you from a blog post has copied them from somewhere.

NIST AI RMF 1.0: a voluntary framework with no certificate and no issuer

The NIST AI Risk Management Framework (AI RMF 1.0) was released on 26 January 2023 and is described by NIST as intended for voluntary use. It is organized into four functions — Govern, Map, Measure and Manage — and it is free.

There is no scheme behind it. No body assesses you against it, no artifact is issued, and no expiry date starts running. The same NIST page also states that AI RMF 1.0 is being revised, which is why the version number belongs in every sentence that names it.

That absence is not a weakness; it is the design. A framework nobody grades you against can be adopted in part, adapted to context and started on a Monday. It simply cannot be shown to a stranger as proof.

What each one is good at

If the goal isThe better fitWhy
Proving something to a strangerISO/IEC 42001A certificate is a third-party artifact with an issuer and an expiry. A procurement team can file it without understanding AI.
Deciding what to actually doNIST AI RMF 1.0The four functions are written as questions about your context, not as requirements to conform to, which makes them better at producing a work plan.
Generative-specific riskNIST AI RMF 1.0The Generative AI Profile exists for exactly this and is free to read.
Surviving staff turnoverISO/IEC 42001A management system carries a surveillance cycle, so the practice has to still be running next year to keep the certificate.
Moving this quarterNIST AI RMF 1.0No scheduling, no external body, no readiness gate before you are allowed to start.
Answering a questionnaire line that demands a credentialISO/IEC 42001It is the only one of the two with a true yes available.

What the preparation work looks like, and how it overlaps

Here is the part that is rarely said plainly: for the first several months, the two paths are close to the same project.

  • An inventory of AI in use. Both need it. Both projects stall in the same place when nobody can produce one.
  • Named ownership. Who decides whether a use is allowed, who signs off on a new model, who can stop a deployment.
  • A risk method you actually apply. Written down, applied to the inventory, with results recorded per system rather than in aggregate.
  • Evidence per claim. For every control asserted, the artifact in your own systems that shows it operates. This is the piece that decides whether an assessment goes well, and the piece most often left to the last month.
  • Supplier and model provenance. Where each model came from, what the contract says about your data, and what happens when the provider changes the model underneath you.

Where they diverge is the last stretch. The standard path adds the formality a third party needs in order to assess: the documented scope, the internal review cycle, the management review, the corrective-action record. The framework path adds nothing formal at all — it ends when your own documentation is good enough for your own purposes, which is both its efficiency and its limitation.

Cost and effort, described without a figure

No number appears on this site, and none is needed to see the shape. Three things drive the difference.

First, the standard path carries a second party. There is an external assessment to schedule, prepare for and repeat on a cycle, and that cost recurs. The framework path has one party in it.

Second, the standard path has a floor. A management system is not partially implementable if you want the certificate at the end: the scope can be narrow, but everything inside the scope has to be real. The framework path scales down smoothly, and a partial adoption that is honestly described is still useful.

Third, the standard path has a schedule you do not control. The framework path can be paused for a quarter with no consequence beyond the work not being done.

Doing both: where the work is shared

The common sequence in practice is framework first, standard second, and it is the cheaper order. Run a gap review against AI RMF 1.0 and the Generative AI Profile, build the inventory and the evidence map, and let that tell you whether a certificate is worth the recurring cost at all. If it is, most of what the assessment will ask for already exists, and the remaining work is formality rather than discovery.

The expensive order is the reverse: committing to a scheme first, then discovering during preparation that nobody knows what AI the organization is running.

What your customer is probably actually asking for

Most questionnaire lines that name either of these are not asking what they appear to ask. They are asking three things underneath: is there a named owner for AI risk here, has anyone looked at the AI features from a security point of view, and will we be told if something changes.

An honest answer to those three, with artifacts behind it, closes more deals than a framework name with nothing behind it. And where the buyer genuinely needs a filed document — a regulated counterparty, a public-sector procurement, an enterprise vendor programme with a hard gate — the certificate is the only thing that satisfies them, and that is worth finding out early.

Neither is written into Canadian law, so recognition here is set by your customers rather than by a regulator. Buyers with an international supply chain tend to ask for the certificate because it is a document they can file; buyers judging your engineering tend to ask what you did, which is where the framework answers better. Neither is named in the Regulation. The full text of Regulation (EU) 2024/1689 contains no reference to ISO/IEC 42001 and none to NIST; it works instead through harmonised standards, which grant a presumption of conformity once they are published and assessed as suitable.

How the work is bounded

The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.

SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.

Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.

Questions we are asked

Can a consultant issue us an ISO/IEC 42001 certificate?

No. A consultant prepares an organization and never issues the certificate; the certificate is issued by an accredited certification body, and a firm that both prepared you and issued it would have assessed its own work.

Does the EU AI Act require either of them?

Neither is named in the Regulation. The full text of Regulation (EU) 2024/1689 contains no reference to ISO/IEC 42001 and none to NIST; it works instead through harmonised standards, which grant a presumption of conformity once they are published and assessed as suitable.

Which is more recognized in Canada?

Neither is written into Canadian law, so recognition here is set by your customers rather than by a regulator. Buyers with an international supply chain tend to ask for the certificate because it is a document they can file; buyers judging your engineering tend to ask what you did, which is where the framework answers better.

What is the real difference between the two?

The difference that decides it is what exists at the end: one path ends in a certificate issued by an accredited certification body, and the other ends in your own documented practice, because nobody issues anything against NIST AI RMF 1.0.

Where to go from here

If a customer has forced the question, AI governance readiness is the engagement that prepares either path, including readiness for the assessment that accredited certification bodies carry out. If you want the framework on its own terms first, NIST AI RMF 1.0 and the Generative AI Profile covers what each document is for. The same structural question comes up one layer down in SOC 2 versus ISO 27001, and the wider compliance and privacy practice sits behind both. Other pieces are indexed under Writing.

Say who is asking and what they will accept as an answer, and the reply will say which path closes it.

Discuss a scope