AI Governance Framework Comparison: ISO 42001 vs NIST AI RMF vs EU AI Act vs OECD
ISO 42001, NIST AI RMF, EU AI Act, and OECD AI Principles do different jobs. Here is which one does what, and how they layer in a working programme.
The four dominant AI governance instruments — ISO/IEC 42001, the NIST AI Risk Management Framework, the EU AI Act, and the OECD AI Principles — do different jobs and are not interchangeable. ISO/IEC 42001 is a certifiable management system standard, NIST AI RMF is a voluntary US risk framework, the EU AI Act is binding law with defined obligations and penalties, and the OECD Principles are non-binding intergovernmental values that shape national policy. For most organisations building auditable AI governance, ISO/IEC 42001 is the operational spine — with NIST AI RMF layered as a risk-analysis method, the EU AI Act as the compliance obligation where in scope, and the OECD Principles as background context that already sits inside the other three.
Key Takeaways
Different Jobs
A standard, a framework, a law, and a set of principles are not four options for the same problem. They sit at different layers of the governance stack.
Only One Is Certifiable
ISO/IEC 42001 is the only one of the four that carries a third-party audited certification path. NIST, EU AI Act, and OECD do not.
Only One Is Binding Law
The EU AI Act is enforceable law with penalties. The other three are voluntary — however widely adopted, adherence is not compulsion.
Certification ≠ Compliance
ISO/IEC 42001 certification is strong evidence of due diligence, but it does not by itself satisfy EU AI Act obligations or any national regulation.
They Layer, Not Compete
Mature programmes run ISO 42001 as the management system, NIST AI RMF inside it as the risk method, EU AI Act obligations where scoped, and the OECD Principles as the values baseline.
Digital Omnibus Shift
The May 2026 Digital Omnibus on AI moved high-risk deadlines to 2 December 2027 (Annex III) and 2 August 2028 (Annex I). Prohibitions and GPAI obligations already apply.
On This Page
What Each Framework Actually Is
The confusion in AI governance conversations usually comes from treating a management system, a risk framework, a piece of law, and a set of intergovernmental principles as if they were four competing products on the same shelf. They are not. Reading them at the right layer of abstraction is the first step to putting them to work.
ISO/IEC 42001:2023 is a management system standard published by the International Organization for Standardization. It defines the structure of an Artificial Intelligence Management System — the AIMS — that an organisation can build, run, and have audited by an accredited certification body. Like ISO/IEC 27001 for information security, it uses Annex SL's Plan-Do-Check-Act structure and specifies controls in an Annex A. Because it is certifiable, it is the only one of the four instruments that produces a piece of paper an external assessor has signed off on.
NIST AI Risk Management Framework 1.0 — published as NIST AI 100-1 in January 2023 — is a voluntary framework from the US National Institute of Standards and Technology. It is not a standard and there is no certification. It provides four core functions (Govern, Map, Measure, Manage), seven characteristics of trustworthy AI, and 19 categories with 72 subcategories that organisations use to structure their risk analysis. A companion Generative AI Profile, NIST AI 600-1, was released in July 2024 with 12 GenAI-specific risk categories.
The EU AI Act — Regulation (EU) 2024/1689 — is binding law across all 27 EU member states, in force since 1 August 2024 with obligations rolling out in phases. It is not a framework anyone adopts by choice: if you place an AI system on the EU market or your system's output is used in the EU, you are in scope. It categorises AI by risk (unacceptable, high, limited, minimal), prohibits specific practices under Article 5, and imposes documentation, transparency, and human-oversight requirements on high-risk systems with penalties up to 7% of global turnover.
The OECD AI Principles — adopted in 2019 and updated in May 2024 — are the first intergovernmental standard on AI. They are non-binding by design. Forty-seven jurisdictions have endorsed them, including all OECD members and the EU. Their influence is upstream: the five values-based principles and five recommendations are the source material that later became national strategies, the EU AI Act's own value language, and much of the NIST framework's characterisation of trustworthy AI.
Put plainly: the OECD wrote the values, the EU turned some of them into law, NIST built a risk method around related concepts, and ISO/IEC 42001 gave organisations a way to run and prove all of it as a management system.
Side-by-Side Comparison Matrix
The table below reduces the four instruments to the eight questions organisations actually ask when choosing where to start.
| Attribute | ISO/IEC 42001 | NIST AI RMF | EU AI Act | OECD AI Principles |
|---|---|---|---|---|
| Type | Management system standard | Risk management framework | Regulation (binding law) | Intergovernmental principles |
| Publisher | ISO / IEC | US NIST | European Union | OECD |
| Legal force | Voluntary | Voluntary | Binding, penalties up to 7% of global turnover | Non-binding |
| Certification available | Yes — accredited third-party audit | No | Conformity assessment for high-risk systems (regulatory, not certification) | No |
| Core structure | PDCA cycle, Annex A controls | Govern, Map, Measure, Manage — 72 subcategories | Risk tiers (unacceptable / high / limited / minimal) + GPAI track | 5 values-based principles + 5 policy recommendations |
| Geographic reach | Global (any organisation, any sector) | US-origin, referenced worldwide | EU market + extraterritorial reach | 47 adherent jurisdictions |
| Update status (July 2026) | 2023 edition current | Version 1.0 (2023) + GenAI Profile (2024) | Digital Omnibus (May 2026) shifted HRAIS deadlines | Updated May 2024 |
| Best used as | The auditable management system spine | The internal risk-analysis method | The compliance obligation where in scope | The values baseline underneath the others |
The rest of this article walks each framework in turn, then puts them back together into a stack that actually works in practice.
ISO/IEC 42001: The Auditable Spine
ISO/IEC 42001:2023 is the world's first management system standard for artificial intelligence. Its job is not to define what "trustworthy AI" is in the abstract — several other documents already do that. Its job is to give an organisation a repeatable structure for building, running, and improving an AI Management System that a third-party auditor can assess against defined criteria.
That is what "management system standard" means in the ISO family: a body of requirements structured so that an accredited certification body can audit conformity, issue a certificate, and re-audit periodically. ISO/IEC 27001 does this for information security, ISO/IEC 22301 does it for business continuity, and ISO/IEC 42001 now does it for AI.
The AIMS covers the AI systems the organisation develops, provides, or uses — not just its own models, but bought-in models, third-party APIs, and embedded AI features in enterprise software. The scope statement is one of the first artefacts an auditor asks for, because it defines what is in and out.
Because the scope is set by the organisation itself, ISO/IEC 42001 works for a start-up building one model as readily as for a bank running dozens of them. What matters is that the scope is documented, defensible, and consistent with the risk assessments and controls that follow from it.
ISO/IEC 42001 follows the same Plan-Do-Check-Act structure common to all ISO management system standards under Annex SL. Clauses 4–6 establish context, leadership, and planning (Plan). Clauses 7–8 cover support and operation (Do). Clause 9 handles performance evaluation and internal audit (Check). Clause 10 handles improvement and corrective action (Act).
This is deliberately identical in shape to ISO/IEC 27001, ISO/IEC 22301, and ISO 9001. An organisation already running one of those standards can integrate ISO/IEC 42001 into the same management review, internal audit programme, and improvement cycle rather than duplicating them.
Annex A of ISO/IEC 42001 provides a reference set of controls that organisations select from during risk treatment. The controls are organised into groups covering policies for AI, internal organisation, resources for AI systems, impact assessment, AI system life cycle, data for AI systems, information for interested parties, use of AI systems, and third-party relationships.
Not every control applies to every organisation. The Statement of Applicability — like its ISO/IEC 27001 counterpart — records which controls are in scope, which are excluded, and why. This is the document an external auditor spends the most time on.
The certification path follows the standard ISO route: a gap assessment against the standard, implementation of the AIMS, an internal audit and management review to demonstrate the system is running, then a two-stage external audit by an accredited certification body — Stage 1 (documentation review) and Stage 2 (implementation audit). If the Stage 2 audit passes, the certification body issues a three-year certificate with annual surveillance audits.
Because ISO/IEC 42001 is new, the population of accredited certification bodies with AI-specific auditor qualifications is still growing. That gap is the practical bottleneck most organisations hit — not the standard's requirements themselves.
Ready to make ISO/IEC 42001 your AI governance anchor?
The PECB ISO/IEC 42001 Lead Implementer certification is the practitioner qualification for building an auditable AI Management System — the same AIMS that anchors every other framework in this article.
NIST AI RMF: The Risk-Analysis Method
The NIST AI Risk Management Framework 1.0 is a different kind of document to ISO/IEC 42001. It is not a standard. It cannot be certified against. There is no auditor, no Statement of Applicability, no accreditation body. What it provides — deliberately and usefully — is a shared vocabulary and a repeatable analytical structure for thinking about AI risk across the lifecycle.
NIST published AI RMF 1.0 as NIST AI 100-1 in January 2023 and a Generative AI Profile as NIST AI 600-1 in July 2024. Version 1.0 is still the current edition; there is no 2.0 as of July 2026. Its status has quietly shifted from "voluntary guidance" to "the reasonable-care benchmark referenced in a growing list of US federal procurement rules and state AI statutes" — while remaining, formally, voluntary.
Govern is the only cross-cutting function. It covers organisation-wide culture, policy, accountability, legal and regulatory compliance, and the human oversight structures that hold the rest of the framework together. Govern is where the framework overlaps most directly with ISO/IEC 42001's leadership and planning clauses.
Map establishes the context of a specific AI system — its purpose, stakeholders, potential impacts, data lineage, and third-party dependencies. This is where AI system inventory work happens.
Measure analyses, benchmarks, and monitors identified risks using qualitative and quantitative metrics — evaluations, red-teaming, and ongoing monitoring with defined thresholds.
Manage allocates resources to prioritise, respond to, and remediate risks, and handles incident response. It is the treatment and continuous-improvement loop.
The four functions are broken down into 19 categories and 72 subcategories. Each subcategory is a discrete practice or outcome — for example, GOVERN 1.1 addresses legal and regulatory requirements involving AI, while MEASURE 2.7 addresses the security and resilience of AI systems.
A companion NIST AI RMF Playbook provides suggested actions, documentation examples, and references for each subcategory. Organisations do not treat the subcategories as a checklist — they select the ones that apply to their context and their AI systems, and use the Playbook to guide implementation.
Released in July 2024, NIST AI 600-1 extends the framework to twelve risk categories specific to generative AI — confabulation, harmful content generation, prompt injection, data poisoning, information integrity, IP infringement, obscene or degrading content, human-AI configuration risks, and others. It layers on top of AI RMF 1.0 rather than replacing it, and maps each generative-AI risk back to the four core functions.
The Profile is where organisations deploying LLMs, foundation model APIs, or embedded generative features in enterprise SaaS pick up specific guidance the base framework does not cover.
Alongside the four functions, NIST AI RMF defines seven characteristics of trustworthy AI: valid and reliable; safe; secure and resilient; accountable and transparent; explainable and interpretable; privacy-enhanced; and fair with harmful bias managed.
These characteristics are the framework's answer to "what are we optimising for?" — and they map closely to the OECD Principles' values, which is not a coincidence. NIST was one of the parties that helped shape both.
EU AI Act: The Binding Law
The EU AI Act is the only one of the four instruments that binds an organisation whether it wants to be bound or not. Regulation (EU) 2024/1689 entered into force on 1 August 2024, and its obligations roll out in phases through 2028. If you place an AI system on the EU market, if your AI system's output is used in the EU, or if you deploy AI to serve EU-based users, you are in scope regardless of where your organisation is headquartered.
The Act does two things ISO/IEC 42001 and NIST AI RMF cannot do: it prohibits specific practices outright, and it attaches penalties — up to 7% of global annual turnover for prohibited-practice violations, and up to 3% for most other breaches.
The Act categorises AI systems into four risk tiers. Unacceptable risk systems are prohibited outright under Article 5 — this includes social scoring by public authorities, real-time remote biometric identification in public spaces (with narrow exceptions), and, following the May 2026 Digital Omnibus, AI-generated non-consensual intimate imagery and child sexual abuse material.
High-risk AI systems (HRAIS) — the main compliance category — cover use cases listed in Annex III (employment, education, credit scoring, biometrics, critical infrastructure, migration, law enforcement, and others) and AI safety components in products regulated under Annex I (medical devices, machinery, radio equipment, lifts, and others).
Limited-risk systems face transparency obligations — chatbots must disclose they are AI, and synthetic content must be labelled.
Minimal-risk systems have no specific obligations beyond voluntary codes of conduct.
Providers of high-risk AI systems must implement a risk management system, use governed training and test data, maintain technical documentation and automated logs, ensure human oversight, and pass a conformity assessment before placing the system on the market. Deployers have their own duties, including monitoring, incident reporting, and — for deployers of certain systems — a fundamental rights impact assessment.
The overlap with ISO/IEC 42001 is substantial but not total. An AIMS covers the organisation's management system for AI; the AI Act imposes system-level obligations on specific classes of AI. The two are complementary, not equivalent.
Providers of general-purpose AI models — foundation models and large language models — face a separate set of obligations under Articles 51–55, in force since 2 August 2025. These include technical documentation, information disclosure to downstream deployers, EU copyright policy compliance, and, for models classified as posing systemic risk, additional model evaluation, adversarial testing, incident reporting, and cybersecurity requirements.
GPAI obligations were not affected by the May 2026 Digital Omnibus. Foundation model providers should continue working through the GPAI Code of Practice and the systemic-risk threshold criteria on the original timeline.
On 7 May 2026, the Council of the EU and the European Parliament reached provisional political agreement on the Digital Omnibus on AI — the first substantial amendment package to the AI Act since its adoption. The headline change is a staged delay to high-risk obligations: Annex III standalone HRAIS obligations move from 2 August 2026 to 2 December 2027, and Annex I embedded HRAIS obligations move from 2 August 2027 to 2 August 2028.
The Omnibus also adds a new Article 5 prohibition covering AI-generated non-consensual intimate imagery and child sexual abuse material, extends SME and small mid-cap accommodations, and simplifies specific registration information for systems self-assessed as non-high-risk. Formal adoption was expected before 2 August 2026.
Two things did not change: the Article 5 prohibitions in force since February 2025, and the GPAI obligations in force since August 2025. Both continue on their original timelines. Organisations treating the 16-month delay as licence to defer inventory and classification work will find themselves with weeks rather than months when the new deadline arrives.
The Act uses a tiered penalty regime. Article 5 prohibited-practice violations carry the highest cap: up to €35 million or 7% of worldwide annual turnover for the preceding financial year, whichever is higher. Most other breaches — high-risk system non-compliance, GPAI obligation failures, supplying incorrect information to authorities — carry lower caps, typically up to €15 million or 3% of turnover.
SMEs benefit from proportionality: the lower of the two amounts applies rather than the higher. Enforcement is by national supervisory authorities coordinated through the AI Office.
Certify implementers and auditors on the same standard.
The PECB ISO/IEC 42001 Lead Implementer + Lead Auditor bundle covers both sides of the audit table — the qualification set most enterprise AI governance teams end up needing.
OECD AI Principles: The Values Baseline
The OECD AI Principles are the oldest of the four instruments and, in a strict sense, the least demanding. Adopted in May 2019 as the first intergovernmental standard on AI and updated in May 2024, they impose no obligations, define no controls, and cannot be audited. Forty-seven jurisdictions — every OECD member, the European Union, and adherents including Argentina, Brazil, Peru, Romania, Singapore, and Ukraine — have committed to promote them and reflect them in national policy.
Their significance is upstream. The EU AI Act's value language, NIST's seven characteristics of trustworthy AI, and much of the national AI-strategy vocabulary that has appeared in the UAE, the UK, Japan, and Canada trace directly back to OECD wording. If ISO/IEC 42001, NIST AI RMF, and the EU AI Act are the operational floor, the OECD Principles are the layer of shared vocabulary underneath them.
The five values-based principles cover: inclusive growth, sustainable development and well-being; respect for the rule of law, human rights and democratic values (including fairness and privacy); transparency and explainability; robustness, security and safety; and accountability.
A parallel set of five recommendations addresses governments directly — investing in AI research, fostering a digital ecosystem, shaping enabling policy environments, building human capacity and preparing for labour market transformation, and international cooperation for trustworthy AI.
The 2024 update was the first substantive revision since 2019 and was driven by the emergence of general-purpose and generative AI. Privacy moved from implied to explicitly named in the human rights principle. New provisions on information integrity — misinformation and disinformation amplified by AI, and synthetic content generated at scale — were added under the same principle and under robustness, security and safety.
The update also sharpened language on intellectual property, safety mechanisms for foundation models, and environmental sustainability. None of the five principles was removed; the structure remains a common blueprint for policymakers rather than a checklist for organisations.
"Non-binding" does not mean "no influence." Adherence to the OECD Principles is a political commitment: adherent countries agree to promote the principles and reflect them in national policy. That is why the same five ideas reappear, reworded, in framework after framework — the EU AI Act's risk-based approach, NIST's trustworthy AI characteristics, national AI strategies across four continents.
For an organisation, the OECD Principles rarely appear on a control checklist. They appear in the way the other three instruments were written, and in the policy trajectory of jurisdictions that have not yet legislated AI.
How the Four Fit Together
Once the four instruments are read at the right layer, a working stack falls out naturally. The OECD Principles sit at the bottom as the shared vocabulary that every framework above them draws from. The EU AI Act sits at the top for anyone in scope, because it is the only layer that is not optional. In between, ISO/IEC 42001 provides the auditable management system, and NIST AI RMF provides the internal risk-analysis method that runs inside it.
In practice, a mature programme does not pick one and drop the others. It runs ISO/IEC 42001 as the management system — the AIMS, the risk assessments, the internal audits, the Statement of Applicability, the certificate on the wall. It uses NIST AI RMF as the internal risk method — the Govern/Map/Measure/Manage vocabulary for how a specific AI system is analysed, particularly where the Generative AI Profile adds coverage the AIMS controls do not name explicitly. It treats the EU AI Act as the compliance obligation where in scope — either the whole set of high-risk requirements, or the GPAI obligations, or the Article 5 prohibitions, or the transparency duties, depending on the system. And it treats the OECD Principles as the values baseline the other three are already aligned to.
The overlaps are real and useful. Much of what an ISO/IEC 42001 AIMS produces — the impact assessments, the documented AI system inventory, the human oversight arrangements, the data governance records — is directly reusable evidence for EU AI Act conformity assessment and NIST AI RMF subcategories. This is why teams that build the AIMS first typically find the AI Act obligations more tractable than teams that try to build to the AI Act's clauses without a management system underneath.
What none of the four can do is substitute for the others. ISO/IEC 42001 certification is strong evidence of due diligence but does not by itself satisfy the AI Act. NIST AI RMF adoption does not confer certification. The AI Act's conformity assessment is a regulatory process, not a management-system audit. And the OECD Principles are values, not controls.
Which Framework Should You Start With?
The answer depends on where the organisation sits — geographically, sectorally, and in its own AI maturity. Four scenarios cover most cases.
If any AI system in the portfolio touches the EU market — placed on it, deployed in it, or with output used in it — start with the EU AI Act inventory and classification. Identify which systems fall into Article 5, Annex III (standalone HRAIS), Annex I (embedded HRAIS), or the transparency-only tier.
Then build ISO/IEC 42001 underneath. The AIMS gives the organisation the documented risk assessments, the human oversight structures, the third-party arrangements, and the data governance records that a conformity assessment will ask for. The 16-month deadline shift from the May 2026 Digital Omnibus is planning time, not an excuse to defer.
If the organisation supplies the US federal government or operates in a US sector with AI-specific regulation, NIST AI RMF is the near-mandatory reference. Federal procurement rules and several state statutes cite it as the reasonable-care baseline.
ISO/IEC 42001 is not a substitute, but it is a strong complement — the AIMS provides the governance structure NIST AI RMF assumes without specifying, and it opens the door to international markets that treat the ISO certificate as the standard signal of AI governance maturity.
Multinationals with mixed EU, US, Middle East, and APAC exposure typically get the most value from ISO/IEC 42001 first. The AIMS is the one management system that is genuinely portable across jurisdictions — it does not name any national regulator, and its clauses map cleanly against the AI Act, NIST AI RMF, national AI strategies in the UAE, Saudi Arabia, Singapore, and elsewhere, and the OECD Principles.
Building the AIMS once and then extending it with EU AI Act specifics for EU systems and NIST-specific evidence for US systems is more efficient than running two or three parallel governance regimes.
Organisations with one or two AI systems and no immediate regulatory exposure usually do not need to commit to certification on day one. The right starting point is a lightweight NIST AI RMF walk-through — Govern, Map, Measure, Manage against the specific system — plus alignment to the OECD Principles as a values statement.
The moment the organisation grows to three or more AI systems, enters a regulated sector, or begins serving EU customers, the case for ISO/IEC 42001 becomes strong on its own merits — regardless of whether certification is pursued immediately.
Ready to build an auditable AI Management System?
reconn's advisory practice helps organisations design, implement, and certify ISO/IEC 42001 AI Management Systems that also carry the evidence needed for EU AI Act conformity and NIST AI RMF alignment.
Common Misconceptions
Five misconceptions come up in almost every AI governance conversation. They are worth naming because acting on them creates real audit exposure.
It does not. ISO/IEC 42001 is not a harmonised standard under the AI Act, and no ISO management system certification confers legal compliance with any regulation. What ISO/IEC 42001 does deliver is structured, documented evidence — impact assessments, oversight arrangements, control implementation records — that is directly reusable in an AI Act conformity assessment. The two are complementary; neither substitutes for the other.
It is not. NIST does not certify organisations against AI RMF, and there is no accreditation scheme for external auditors to do so. Vendors that claim "NIST AI RMF certification" are describing internal assessments, self-attestations, or third-party consultancy reports — none of which are the equivalent of an ISO management system certificate.
They are not. Adherence is a political commitment by governments to promote the principles and reflect them in national policy. Their significance is in how much of that national policy — including the EU AI Act — is drafted in their language. An organisation cannot be sued for OECD Principle non-compliance, but it can find itself out of step with the direction national law is heading.
No single framework does the work of the others. A standard is not a law. A framework is not a certification. A set of principles is not a control set. Organisations that pick one and stop typically find that the piece they skipped — usually the management system or the legal obligation — is the piece that gets asked about first when an incident or an audit arrives.
Certification proves that the organisation has designed and is running a management system that meets a defined set of requirements. It does not prove that any specific AI system inside that management system is safe, fair, or fit for its purpose. That is what the risk assessments, testing, monitoring, and incident response inside the system are for — and why the AIMS is a live programme, not a wall certificate.
Further Reading
- ISO 42001: The Complete Global Guide to Artificial Intelligence Management Systems — the anchor guide to what ISO/IEC 42001 is and how the AIMS is structured.
- ISO 42001 Implementation Guide: Step-by-Step Methodology — the practitioner walkthrough of building an AIMS from scope statement to certification audit.
- ISO 42001 Lead Implementer — the qualification profile, curriculum, and career context for the implementer role.
- ISO 42001 Lead Auditor — the qualification profile for auditors assessing AIMS conformity.
FAQ
For most organisations, ISO/IEC 42001 first. It is the only certifiable AI management system standard, its structure is portable across jurisdictions, and the evidence it produces is directly reusable for EU AI Act conformity and NIST AI RMF alignment. The exceptions are organisations with immediate EU AI Act obligations, which should start with AI Act scoping and classification, and US federal contractors, for whom NIST AI RMF is the near-mandatory reference.
No. ISO/IEC 42001 is not a harmonised standard under the EU AI Act, and no ISO management system certification confers legal compliance with any regulation. The certificate is strong evidence of due diligence and produces documentation directly reusable in an AI Act conformity assessment, but the two remain separate requirements.
NIST AI RMF is formally voluntary. No federal statute mandates it by name. That said, it is referenced across federal procurement rules, state AI statutes, and executive orders as the reasonable-care benchmark for AI risk management. Organisations supplying the US federal government or operating in regulated sectors typically treat it as effectively required, even though it is not law.
Yes — and most mature programmes do. ISO/IEC 42001 provides the management system structure (leadership, planning, control implementation, internal audit, continuous improvement). NIST AI RMF provides the risk-analysis method (Govern, Map, Measure, Manage) that runs inside it. The Generative AI Profile in NIST AI 600-1 adds coverage for LLM and generative AI risks the base AIMS controls do not explicitly name.
No. The OECD AI Principles are non-binding by design. Adherence is a political commitment by governments — 47 jurisdictions as of 2026 — to promote the principles and reflect them in national policy. Their influence is upstream: the EU AI Act, NIST AI RMF's trustworthy AI characteristics, and national AI strategies across four continents draw from OECD wording. Organisations cannot be sued for OECD non-compliance, but the direction national law is heading tracks closely to OECD language.
ISO/IEC 42001 as the base management system, with the other three layered on where relevant. The AIMS is the one management system that is portable across jurisdictions — it names no national regulator, and its clauses map cleanly against the EU AI Act, NIST AI RMF, national AI strategies in the UAE, Saudi Arabia, Singapore, and elsewhere, and the OECD Principles. Building it once and extending it with EU AI Act specifics for EU systems and NIST-specific evidence for US systems is more efficient than running parallel governance regimes.
About the Author
Shenoy Sandeep
Shenoy Sandeep is the Founder of reconn, an AI-first cybersecurity firm based in Dubai, UAE. With 20+ years across cybersecurity focussing on offensive security and threat intelligence portfolio, and over 10 years in Enterprise AI, AI governance and data protection, he has assisted over 25+ startups in scaling their business in the Middle East and African region.
Training is Shenoy's passion project and reconn has associated themselves with PECB, the global leaders in personal certifications for AI, cybersecurity, data protection, privacy and business continuity professionals. He is a PECB-certified trainer and one of the world's early PECB-certified AI professionals, also specialising in ISO/IEC 27001, ISO/IEC 27701, ISO 42001, ISO 22301, and GDPR.
Via Reconn, Shenoy runs an advisory service assisting organisations in the EMEA with compliance and certification on ISO 42001, ISO 27001, ISO 27701, ISO 22301 and local data protection and privacy laws. His current interests include EU AI Act, NIS2, DORA, EU/UK GDPR, UAE PDPL and SDAIA PRPL.