AI Governance Framework Comparison: ISO 42001 vs NIST AI RMF vs EU AI Act vs OECD

ISO 42001, NIST AI RMF, EU AI Act, and OECD AI Principles do different jobs. Here is which one does what, and how they layer in a working programme.

Share
Four-column comparison diagram showing ISO 42001, NIST AI RMF, EU AI Act, and OECD AI Principles as layers of the AI governance stack.
The four dominant AI governance instruments do different jobs, a management system standard, a risk framework, a law, and a set of intergovernmental principles and layer rather than compete.

The four dominant AI governance instruments — ISO/IEC 42001, the NIST AI Risk Management Framework, the EU AI Act, and the OECD AI Principles — do different jobs and are not interchangeable. ISO/IEC 42001 is a certifiable management system standard, NIST AI RMF is a voluntary US risk framework, the EU AI Act is binding law with defined obligations and penalties, and the OECD Principles are non-binding intergovernmental values that shape national policy. For most organisations building auditable AI governance, ISO/IEC 42001 is the operational spine — with NIST AI RMF layered as a risk-analysis method, the EU AI Act as the compliance obligation where in scope, and the OECD Principles as background context that already sits inside the other three.

Key Takeaways

Different Jobs

A standard, a framework, a law, and a set of principles are not four options for the same problem. They sit at different layers of the governance stack.

Only One Is Certifiable

ISO/IEC 42001 is the only one of the four that carries a third-party audited certification path. NIST, EU AI Act, and OECD do not.

Only One Is Binding Law

The EU AI Act is enforceable law with penalties. The other three are voluntary — however widely adopted, adherence is not compulsion.

Certification ≠ Compliance

ISO/IEC 42001 certification is strong evidence of due diligence, but it does not by itself satisfy EU AI Act obligations or any national regulation.

They Layer, Not Compete

Mature programmes run ISO 42001 as the management system, NIST AI RMF inside it as the risk method, EU AI Act obligations where scoped, and the OECD Principles as the values baseline.

Digital Omnibus Shift

The May 2026 Digital Omnibus on AI moved high-risk deadlines to 2 December 2027 (Annex III) and 2 August 2028 (Annex I). Prohibitions and GPAI obligations already apply.

On This Page

What Each Framework Actually Is

The confusion in AI governance conversations usually comes from treating a management system, a risk framework, a piece of law, and a set of intergovernmental principles as if they were four competing products on the same shelf. They are not. Reading them at the right layer of abstraction is the first step to putting them to work.

ISO/IEC 42001:2023 is a management system standard published by the International Organization for Standardization. It defines the structure of an Artificial Intelligence Management System — the AIMS — that an organisation can build, run, and have audited by an accredited certification body. Like ISO/IEC 27001 for information security, it uses Annex SL's Plan-Do-Check-Act structure and specifies controls in an Annex A. Because it is certifiable, it is the only one of the four instruments that produces a piece of paper an external assessor has signed off on.

NIST AI Risk Management Framework 1.0 — published as NIST AI 100-1 in January 2023 — is a voluntary framework from the US National Institute of Standards and Technology. It is not a standard and there is no certification. It provides four core functions (Govern, Map, Measure, Manage), seven characteristics of trustworthy AI, and 19 categories with 72 subcategories that organisations use to structure their risk analysis. A companion Generative AI Profile, NIST AI 600-1, was released in July 2024 with 12 GenAI-specific risk categories.

The EU AI Act — Regulation (EU) 2024/1689 — is binding law across all 27 EU member states, in force since 1 August 2024 with obligations rolling out in phases. It is not a framework anyone adopts by choice: if you place an AI system on the EU market or your system's output is used in the EU, you are in scope. It categorises AI by risk (unacceptable, high, limited, minimal), prohibits specific practices under Article 5, and imposes documentation, transparency, and human-oversight requirements on high-risk systems with penalties up to 7% of global turnover.

The OECD AI Principles — adopted in 2019 and updated in May 2024 — are the first intergovernmental standard on AI. They are non-binding by design. Forty-seven jurisdictions have endorsed them, including all OECD members and the EU. Their influence is upstream: the five values-based principles and five recommendations are the source material that later became national strategies, the EU AI Act's own value language, and much of the NIST framework's characterisation of trustworthy AI.

Put plainly: the OECD wrote the values, the EU turned some of them into law, NIST built a risk method around related concepts, and ISO/IEC 42001 gave organisations a way to run and prove all of it as a management system.

Side-by-Side Comparison Matrix

The table below reduces the four instruments to the eight questions organisations actually ask when choosing where to start.

Attribute ISO/IEC 42001 NIST AI RMF EU AI Act OECD AI Principles
Type Management system standard Risk management framework Regulation (binding law) Intergovernmental principles
Publisher ISO / IEC US NIST European Union OECD
Legal force Voluntary Voluntary Binding, penalties up to 7% of global turnover Non-binding
Certification available Yes — accredited third-party audit No Conformity assessment for high-risk systems (regulatory, not certification) No
Core structure PDCA cycle, Annex A controls Govern, Map, Measure, Manage — 72 subcategories Risk tiers (unacceptable / high / limited / minimal) + GPAI track 5 values-based principles + 5 policy recommendations
Geographic reach Global (any organisation, any sector) US-origin, referenced worldwide EU market + extraterritorial reach 47 adherent jurisdictions
Update status (July 2026) 2023 edition current Version 1.0 (2023) + GenAI Profile (2024) Digital Omnibus (May 2026) shifted HRAIS deadlines Updated May 2024
Best used as The auditable management system spine The internal risk-analysis method The compliance obligation where in scope The values baseline underneath the others

The rest of this article walks each framework in turn, then puts them back together into a stack that actually works in practice.

ISO/IEC 42001: The Auditable Spine

ISO/IEC 42001:2023 is the world's first management system standard for artificial intelligence. Its job is not to define what "trustworthy AI" is in the abstract — several other documents already do that. Its job is to give an organisation a repeatable structure for building, running, and improving an AI Management System that a third-party auditor can assess against defined criteria.

That is what "management system standard" means in the ISO family: a body of requirements structured so that an accredited certification body can audit conformity, issue a certificate, and re-audit periodically. ISO/IEC 27001 does this for information security, ISO/IEC 22301 does it for business continuity, and ISO/IEC 42001 now does it for AI.

Scope: what an AIMS actually covers

The AIMS covers the AI systems the organisation develops, provides, or uses — not just its own models, but bought-in models, third-party APIs, and embedded AI features in enterprise software. The scope statement is one of the first artefacts an auditor asks for, because it defines what is in and out.

Because the scope is set by the organisation itself, ISO/IEC 42001 works for a start-up building one model as readily as for a bank running dozens of them. What matters is that the scope is documented, defensible, and consistent with the risk assessments and controls that follow from it.

The PDCA cycle inside the standard

ISO/IEC 42001 follows the same Plan-Do-Check-Act structure common to all ISO management system standards under Annex SL. Clauses 4–6 establish context, leadership, and planning (Plan). Clauses 7–8 cover support and operation (Do). Clause 9 handles performance evaluation and internal audit (Check). Clause 10 handles improvement and corrective action (Act).

This is deliberately identical in shape to ISO/IEC 27001, ISO/IEC 22301, and ISO 9001. An organisation already running one of those standards can integrate ISO/IEC 42001 into the same management review, internal audit programme, and improvement cycle rather than duplicating them.

Annex A controls

Annex A of ISO/IEC 42001 provides a reference set of controls that organisations select from during risk treatment. The controls are organised into groups covering policies for AI, internal organisation, resources for AI systems, impact assessment, AI system life cycle, data for AI systems, information for interested parties, use of AI systems, and third-party relationships.

Not every control applies to every organisation. The Statement of Applicability — like its ISO/IEC 27001 counterpart — records which controls are in scope, which are excluded, and why. This is the document an external auditor spends the most time on.

Certification path in practice

The certification path follows the standard ISO route: a gap assessment against the standard, implementation of the AIMS, an internal audit and management review to demonstrate the system is running, then a two-stage external audit by an accredited certification body — Stage 1 (documentation review) and Stage 2 (implementation audit). If the Stage 2 audit passes, the certification body issues a three-year certificate with annual surveillance audits.

Because ISO/IEC 42001 is new, the population of accredited certification bodies with AI-specific auditor qualifications is still growing. That gap is the practical bottleneck most organisations hit — not the standard's requirements themselves.

CERTIFICATION PATHWAY

Ready to make ISO/IEC 42001 your AI governance anchor?


The PECB ISO/IEC 42001 Lead Implementer certification is the practitioner qualification for building an auditable AI Management System — the same AIMS that anchors every other framework in this article.

reconn.io  |  Dubai  |  Remote delivery worldwide

NIST AI RMF: The Risk-Analysis Method

The NIST AI Risk Management Framework 1.0 is a different kind of document to ISO/IEC 42001. It is not a standard. It cannot be certified against. There is no auditor, no Statement of Applicability, no accreditation body. What it provides — deliberately and usefully — is a shared vocabulary and a repeatable analytical structure for thinking about AI risk across the lifecycle.

NIST published AI RMF 1.0 as NIST AI 100-1 in January 2023 and a Generative AI Profile as NIST AI 600-1 in July 2024. Version 1.0 is still the current edition; there is no 2.0 as of July 2026. Its status has quietly shifted from "voluntary guidance" to "the reasonable-care benchmark referenced in a growing list of US federal procurement rules and state AI statutes" — while remaining, formally, voluntary.

The four functions in plain terms

Govern is the only cross-cutting function. It covers organisation-wide culture, policy, accountability, legal and regulatory compliance, and the human oversight structures that hold the rest of the framework together. Govern is where the framework overlaps most directly with ISO/IEC 42001's leadership and planning clauses.

Map establishes the context of a specific AI system — its purpose, stakeholders, potential impacts, data lineage, and third-party dependencies. This is where AI system inventory work happens.

Measure analyses, benchmarks, and monitors identified risks using qualitative and quantitative metrics — evaluations, red-teaming, and ongoing monitoring with defined thresholds.

Manage allocates resources to prioritise, respond to, and remediate risks, and handles incident response. It is the treatment and continuous-improvement loop.

Categories and subcategories at a glance

The four functions are broken down into 19 categories and 72 subcategories. Each subcategory is a discrete practice or outcome — for example, GOVERN 1.1 addresses legal and regulatory requirements involving AI, while MEASURE 2.7 addresses the security and resilience of AI systems.

A companion NIST AI RMF Playbook provides suggested actions, documentation examples, and references for each subcategory. Organisations do not treat the subcategories as a checklist — they select the ones that apply to their context and their AI systems, and use the Playbook to guide implementation.

The Generative AI Profile (NIST AI 600-1)

Released in July 2024, NIST AI 600-1 extends the framework to twelve risk categories specific to generative AI — confabulation, harmful content generation, prompt injection, data poisoning, information integrity, IP infringement, obscene or degrading content, human-AI configuration risks, and others. It layers on top of AI RMF 1.0 rather than replacing it, and maps each generative-AI risk back to the four core functions.

The Profile is where organisations deploying LLMs, foundation model APIs, or embedded generative features in enterprise SaaS pick up specific guidance the base framework does not cover.

Seven characteristics of trustworthy AI

Alongside the four functions, NIST AI RMF defines seven characteristics of trustworthy AI: valid and reliable; safe; secure and resilient; accountable and transparent; explainable and interpretable; privacy-enhanced; and fair with harmful bias managed.

These characteristics are the framework's answer to "what are we optimising for?" — and they map closely to the OECD Principles' values, which is not a coincidence. NIST was one of the parties that helped shape both.

EU AI Act: The Binding Law

The EU AI Act is the only one of the four instruments that binds an organisation whether it wants to be bound or not. Regulation (EU) 2024/1689 entered into force on 1 August 2024, and its obligations roll out in phases through 2028. If you place an AI system on the EU market, if your AI system's output is used in the EU, or if you deploy AI to serve EU-based users, you are in scope regardless of where your organisation is headquartered.

The Act does two things ISO/IEC 42001 and NIST AI RMF cannot do: it prohibits specific practices outright, and it attaches penalties — up to 7% of global annual turnover for prohibited-practice violations, and up to 3% for most other breaches.

The risk pyramid

The Act categorises AI systems into four risk tiers. Unacceptable risk systems are prohibited outright under Article 5 — this includes social scoring by public authorities, real-time remote biometric identification in public spaces (with narrow exceptions), and, following the May 2026 Digital Omnibus, AI-generated non-consensual intimate imagery and child sexual abuse material.

High-risk AI systems (HRAIS) — the main compliance category — cover use cases listed in Annex III (employment, education, credit scoring, biometrics, critical infrastructure, migration, law enforcement, and others) and AI safety components in products regulated under Annex I (medical devices, machinery, radio equipment, lifts, and others).

Limited-risk systems face transparency obligations — chatbots must disclose they are AI, and synthetic content must be labelled.

Minimal-risk systems have no specific obligations beyond voluntary codes of conduct.

High-risk AI systems: what the obligations actually require

Providers of high-risk AI systems must implement a risk management system, use governed training and test data, maintain technical documentation and automated logs, ensure human oversight, and pass a conformity assessment before placing the system on the market. Deployers have their own duties, including monitoring, incident reporting, and — for deployers of certain systems — a fundamental rights impact assessment.

The overlap with ISO/IEC 42001 is substantial but not total. An AIMS covers the organisation's management system for AI; the AI Act imposes system-level obligations on specific classes of AI. The two are complementary, not equivalent.

General-purpose AI (GPAI) obligations

Providers of general-purpose AI models — foundation models and large language models — face a separate set of obligations under Articles 51–55, in force since 2 August 2025. These include technical documentation, information disclosure to downstream deployers, EU copyright policy compliance, and, for models classified as posing systemic risk, additional model evaluation, adversarial testing, incident reporting, and cybersecurity requirements.

GPAI obligations were not affected by the May 2026 Digital Omnibus. Foundation model providers should continue working through the GPAI Code of Practice and the systemic-risk threshold criteria on the original timeline.

Digital Omnibus (May 2026): what changed

On 7 May 2026, the Council of the EU and the European Parliament reached provisional political agreement on the Digital Omnibus on AI — the first substantial amendment package to the AI Act since its adoption. The headline change is a staged delay to high-risk obligations: Annex III standalone HRAIS obligations move from 2 August 2026 to 2 December 2027, and Annex I embedded HRAIS obligations move from 2 August 2027 to 2 August 2028.

The Omnibus also adds a new Article 5 prohibition covering AI-generated non-consensual intimate imagery and child sexual abuse material, extends SME and small mid-cap accommodations, and simplifies specific registration information for systems self-assessed as non-high-risk. Formal adoption was expected before 2 August 2026.

Two things did not change: the Article 5 prohibitions in force since February 2025, and the GPAI obligations in force since August 2025. Both continue on their original timelines. Organisations treating the 16-month delay as licence to defer inventory and classification work will find themselves with weeks rather than months when the new deadline arrives.

Penalties

The Act uses a tiered penalty regime. Article 5 prohibited-practice violations carry the highest cap: up to €35 million or 7% of worldwide annual turnover for the preceding financial year, whichever is higher. Most other breaches — high-risk system non-compliance, GPAI obligation failures, supplying incorrect information to authorities — carry lower caps, typically up to €15 million or 3% of turnover.

SMEs benefit from proportionality: the lower of the two amounts applies rather than the higher. Enforcement is by national supervisory authorities coordinated through the AI Office.

PRACTITIONER TRAINING

Certify implementers and auditors on the same standard.


The PECB ISO/IEC 42001 Lead Implementer + Lead Auditor bundle covers both sides of the audit table — the qualification set most enterprise AI governance teams end up needing.

reconn.io  |  Dubai  |  Remote delivery worldwide

OECD AI Principles: The Values Baseline

The OECD AI Principles are the oldest of the four instruments and, in a strict sense, the least demanding. Adopted in May 2019 as the first intergovernmental standard on AI and updated in May 2024, they impose no obligations, define no controls, and cannot be audited. Forty-seven jurisdictions — every OECD member, the European Union, and adherents including Argentina, Brazil, Peru, Romania, Singapore, and Ukraine — have committed to promote them and reflect them in national policy.

Their significance is upstream. The EU AI Act's value language, NIST's seven characteristics of trustworthy AI, and much of the national AI-strategy vocabulary that has appeared in the UAE, the UK, Japan, and Canada trace directly back to OECD wording. If ISO/IEC 42001, NIST AI RMF, and the EU AI Act are the operational floor, the OECD Principles are the layer of shared vocabulary underneath them.

The five values-based principles

The five values-based principles cover: inclusive growth, sustainable development and well-being; respect for the rule of law, human rights and democratic values (including fairness and privacy); transparency and explainability; robustness, security and safety; and accountability.

A parallel set of five recommendations addresses governments directly — investing in AI research, fostering a digital ecosystem, shaping enabling policy environments, building human capacity and preparing for labour market transformation, and international cooperation for trustworthy AI.

What the May 2024 update changed

The 2024 update was the first substantive revision since 2019 and was driven by the emergence of general-purpose and generative AI. Privacy moved from implied to explicitly named in the human rights principle. New provisions on information integrity — misinformation and disinformation amplified by AI, and synthetic content generated at scale — were added under the same principle and under robustness, security and safety.

The update also sharpened language on intellectual property, safety mechanisms for foundation models, and environmental sustainability. None of the five principles was removed; the structure remains a common blueprint for policymakers rather than a checklist for organisations.

Why non-binding still matters

"Non-binding" does not mean "no influence." Adherence to the OECD Principles is a political commitment: adherent countries agree to promote the principles and reflect them in national policy. That is why the same five ideas reappear, reworded, in framework after framework — the EU AI Act's risk-based approach, NIST's trustworthy AI characteristics, national AI strategies across four continents.

For an organisation, the OECD Principles rarely appear on a control checklist. They appear in the way the other three instruments were written, and in the policy trajectory of jurisdictions that have not yet legislated AI.

How the Four Fit Together

Once the four instruments are read at the right layer, a working stack falls out naturally. The OECD Principles sit at the bottom as the shared vocabulary that every framework above them draws from. The EU AI Act sits at the top for anyone in scope, because it is the only layer that is not optional. In between, ISO/IEC 42001 provides the auditable management system, and NIST AI RMF provides the internal risk-analysis method that runs inside it.

In practice, a mature programme does not pick one and drop the others. It runs ISO/IEC 42001 as the management system — the AIMS, the risk assessments, the internal audits, the Statement of Applicability, the certificate on the wall. It uses NIST AI RMF as the internal risk method — the Govern/Map/Measure/Manage vocabulary for how a specific AI system is analysed, particularly where the Generative AI Profile adds coverage the AIMS controls do not name explicitly. It treats the EU AI Act as the compliance obligation where in scope — either the whole set of high-risk requirements, or the GPAI obligations, or the Article 5 prohibitions, or the transparency duties, depending on the system. And it treats the OECD Principles as the values baseline the other three are already aligned to.

The overlaps are real and useful. Much of what an ISO/IEC 42001 AIMS produces — the impact assessments, the documented AI system inventory, the human oversight arrangements, the data governance records — is directly reusable evidence for EU AI Act conformity assessment and NIST AI RMF subcategories. This is why teams that build the AIMS first typically find the AI Act obligations more tractable than teams that try to build to the AI Act's clauses without a management system underneath.

What none of the four can do is substitute for the others. ISO/IEC 42001 certification is strong evidence of due diligence but does not by itself satisfy the AI Act. NIST AI RMF adoption does not confer certification. The AI Act's conformity assessment is a regulatory process, not a management-system audit. And the OECD Principles are values, not controls.

Which Framework Should You Start With?

The answer depends on where the organisation sits — geographically, sectorally, and in its own AI maturity. Four scenarios cover most cases.

EU-facing product or service

If any AI system in the portfolio touches the EU market — placed on it, deployed in it, or with output used in it — start with the EU AI Act inventory and classification. Identify which systems fall into Article 5, Annex III (standalone HRAIS), Annex I (embedded HRAIS), or the transparency-only tier.

Then build ISO/IEC 42001 underneath. The AIMS gives the organisation the documented risk assessments, the human oversight structures, the third-party arrangements, and the data governance records that a conformity assessment will ask for. The 16-month deadline shift from the May 2026 Digital Omnibus is planning time, not an excuse to defer.

US federal contractor or state-regulated sector

If the organisation supplies the US federal government or operates in a US sector with AI-specific regulation, NIST AI RMF is the near-mandatory reference. Federal procurement rules and several state statutes cite it as the reasonable-care baseline.

ISO/IEC 42001 is not a substitute, but it is a strong complement — the AIMS provides the governance structure NIST AI RMF assumes without specifying, and it opens the door to international markets that treat the ISO certificate as the standard signal of AI governance maturity.

Multinational with mixed exposure

Multinationals with mixed EU, US, Middle East, and APAC exposure typically get the most value from ISO/IEC 42001 first. The AIMS is the one management system that is genuinely portable across jurisdictions — it does not name any national regulator, and its clauses map cleanly against the AI Act, NIST AI RMF, national AI strategies in the UAE, Saudi Arabia, Singapore, and elsewhere, and the OECD Principles.

Building the AIMS once and then extending it with EU AI Act specifics for EU systems and NIST-specific evidence for US systems is more efficient than running two or three parallel governance regimes.

Early-stage organisation or single AI use case

Organisations with one or two AI systems and no immediate regulatory exposure usually do not need to commit to certification on day one. The right starting point is a lightweight NIST AI RMF walk-through — Govern, Map, Measure, Manage against the specific system — plus alignment to the OECD Principles as a values statement.

The moment the organisation grows to three or more AI systems, enters a regulated sector, or begins serving EU customers, the case for ISO/IEC 42001 becomes strong on its own merits — regardless of whether certification is pursued immediately.

EXPERT GUIDANCE

Ready to build an auditable AI Management System?


reconn's advisory practice helps organisations design, implement, and certify ISO/IEC 42001 AI Management Systems that also carry the evidence needed for EU AI Act conformity and NIST AI RMF alignment.

reconn.io  |  Dubai  |  Remote delivery worldwide

Common Misconceptions

Five misconceptions come up in almost every AI governance conversation. They are worth naming because acting on them creates real audit exposure.

"ISO/IEC 42001 certification satisfies the EU AI Act"

It does not. ISO/IEC 42001 is not a harmonised standard under the AI Act, and no ISO management system certification confers legal compliance with any regulation. What ISO/IEC 42001 does deliver is structured, documented evidence — impact assessments, oversight arrangements, control implementation records — that is directly reusable in an AI Act conformity assessment. The two are complementary; neither substitutes for the other.

"NIST AI RMF is a certification"

It is not. NIST does not certify organisations against AI RMF, and there is no accreditation scheme for external auditors to do so. Vendors that claim "NIST AI RMF certification" are describing internal assessments, self-attestations, or third-party consultancy reports — none of which are the equivalent of an ISO management system certificate.

"The OECD AI Principles are legally binding"

They are not. Adherence is a political commitment by governments to promote the principles and reflect them in national policy. Their significance is in how much of that national policy — including the EU AI Act — is drafted in their language. An organisation cannot be sued for OECD Principle non-compliance, but it can find itself out of step with the direction national law is heading.

"One framework can replace the others"

No single framework does the work of the others. A standard is not a law. A framework is not a certification. A set of principles is not a control set. Organisations that pick one and stop typically find that the piece they skipped — usually the management system or the legal obligation — is the piece that gets asked about first when an incident or an audit arrives.

"Certification proves an AI system is safe"

Certification proves that the organisation has designed and is running a management system that meets a defined set of requirements. It does not prove that any specific AI system inside that management system is safe, fair, or fit for its purpose. That is what the risk assessments, testing, monitoring, and incident response inside the system are for — and why the AIMS is a live programme, not a wall certificate.

Further Reading

FAQ

Which AI governance framework should we implement first?

For most organisations, ISO/IEC 42001 first. It is the only certifiable AI management system standard, its structure is portable across jurisdictions, and the evidence it produces is directly reusable for EU AI Act conformity and NIST AI RMF alignment. The exceptions are organisations with immediate EU AI Act obligations, which should start with AI Act scoping and classification, and US federal contractors, for whom NIST AI RMF is the near-mandatory reference.

Does ISO/IEC 42001 certification satisfy the EU AI Act?

No. ISO/IEC 42001 is not a harmonised standard under the EU AI Act, and no ISO management system certification confers legal compliance with any regulation. The certificate is strong evidence of due diligence and produces documentation directly reusable in an AI Act conformity assessment, but the two remain separate requirements.

Is NIST AI RMF mandatory in the United States?

NIST AI RMF is formally voluntary. No federal statute mandates it by name. That said, it is referenced across federal procurement rules, state AI statutes, and executive orders as the reasonable-care benchmark for AI risk management. Organisations supplying the US federal government or operating in regulated sectors typically treat it as effectively required, even though it is not law.

Can I use ISO/IEC 42001 and NIST AI RMF together?

Yes — and most mature programmes do. ISO/IEC 42001 provides the management system structure (leadership, planning, control implementation, internal audit, continuous improvement). NIST AI RMF provides the risk-analysis method (Govern, Map, Measure, Manage) that runs inside it. The Generative AI Profile in NIST AI 600-1 adds coverage for LLM and generative AI risks the base AIMS controls do not explicitly name.

Are the OECD AI Principles legally enforceable?

No. The OECD AI Principles are non-binding by design. Adherence is a political commitment by governments — 47 jurisdictions as of 2026 — to promote the principles and reflect them in national policy. Their influence is upstream: the EU AI Act, NIST AI RMF's trustworthy AI characteristics, and national AI strategies across four continents draw from OECD wording. Organisations cannot be sued for OECD non-compliance, but the direction national law is heading tracks closely to OECD language.

Which framework is best for a multinational organisation?

ISO/IEC 42001 as the base management system, with the other three layered on where relevant. The AIMS is the one management system that is portable across jurisdictions — it names no national regulator, and its clauses map cleanly against the EU AI Act, NIST AI RMF, national AI strategies in the UAE, Saudi Arabia, Singapore, and elsewhere, and the OECD Principles. Building it once and extending it with EU AI Act specifics for EU systems and NIST-specific evidence for US systems is more efficient than running parallel governance regimes.

Shenoy Sandeep

About the Author

Shenoy Sandeep

Shenoy Sandeep is the Founder of reconn, an AI-first cybersecurity firm based in Dubai, UAE. With 20+ years across cybersecurity focussing on offensive security and threat intelligence portfolio, and over 10 years in Enterprise AI, AI governance and data protection, he has assisted over 25+ startups in scaling their business in the Middle East and African region.

Training is Shenoy's passion project and reconn has associated themselves with PECB, the global leaders in personal certifications for AI, cybersecurity, data protection, privacy and business continuity professionals. He is a PECB-certified trainer and one of the world's early PECB-certified AI professionals, also specialising in ISO/IEC 27001, ISO/IEC 27701, ISO 42001, ISO 22301, and GDPR.

Via Reconn, Shenoy runs an advisory service assisting organisations in the EMEA with compliance and certification on ISO 42001, ISO 27001, ISO 27701, ISO 22301 and local data protection and privacy laws. His current interests include EU AI Act, NIS2, DORA, EU/UK GDPR, UAE PDPL and SDAIA PRPL.