AI Governance Frameworks Compared: NIST vs ISO 42001

Photo: RDNE Stock project / Pexels
Key takeaways
- NIST AI RMF, ISO 42001, the EU AI Act and Singapore's Model AI Governance Framework all address AI governance but differ sharply in legal status.
- Only the EU AI Act is legally binding; the other three are voluntary.
- ISO 42001 is the only one you can get externally certified against.
- A written policy, a tool register and an attestation record satisfy the documentation core of all four.
Type "model AI governance framework" into a search bar and you land on two different things. There's the generic idea, a reference framework you model your own programme on, and there's a specific document: Singapore's Model AI Governance Framework, first published by the city-state's regulators in 2019 and updated with a generative AI addendum in 2024. Both readings point at the same problem. There is no single global standard for AI governance, only several overlapping ones: the NIST AI Risk Management Framework, ISO/IEC 42001, the EU AI Act, and Singapore's framework. Knowing how they differ, and where they overlap, stops you building four separate compliance programmes when one foundation would do.
What is Singapore's Model AI Governance Framework?
It's not law. Singapore's Infocomm Media Development Authority and Personal Data Protection Commission publish it as voluntary guidance, aimed mostly at boards and senior management rather than engineers. First launched in 2019, well before the EU AI Act existed in any form, it sets out internal governance structures, how to assess AI risk before deployment, and how to communicate AI use to customers and staff. The 2024 update added a companion annex for generative AI specifically, covering things like content provenance and third-party model risk. There's no certification scheme attached, unlike ISO 42001, so treat it as a well-regarded checklist rather than an audit-ready standard. If your customers or regulators sit in Singapore, or you simply want a clear-headed starting checklist for a board conversation, it's worth reading alongside NIST and ISO rather than instead of them.
NIST AI RMF: the risk-management lens
Published in January 2023, the NIST AI Risk Management Framework organises governance into four functions: GOVERN, MAP, MEASURE, MANAGE. It's deliberately flexible, meant to scale from a five-person startup to a federal agency, and it carries no legal weight of its own. What it does carry is adoption: it's become the framework US enterprise buyers and government customers mean by default when they ask how you manage AI risk. If your organisation is US-headquartered, or sells into the US, GOVERN (a named owner and a written policy) and MAP (an inventory of the AI tools you actually use) are the two functions worth tackling first. MEASURE and MANAGE, which cover ongoing monitoring and response, matter more once you're building or heavily customising AI systems rather than simply using off-the-shelf tools.
ISO 42001: the one you can get certified against
ISO/IEC 42001 is a management-system standard for AI, built the way ISO 27001 is built for information security: documented policies, risk assessments, internal audits, and, critically, third-party certification. That last part sets it apart from NIST and Singapore's framework. An accredited certification body can audit you against it and issue a certificate your customers can verify. It suits organisations that want AI governance to show up as a credential in a security questionnaire, not just a policy document on file. See the ISO/IEC 42001 standard page for the clause structure, and our deeper ISO 42001 guide for what deployers versus providers actually need to do.
The EU AI Act: the one with legal teeth
Unlike the other three, the EU AI Act isn't guidance you can choose to follow. It's law, and it applies to any organisation whose AI systems reach the EU, regardless of where the company is based. Most small businesses are "deployers" of general tools like ChatGPT rather than "providers" of high-risk AI systems, so the practical duties are narrower than the headlines suggest: avoid a short list of banned practices, be transparent about AI-generated content, and, since Article 4 came into force on 2 February 2025, ensure staff have a sufficient level of AI literacy. Penalties for serious breaches scale with company turnover, which is reason enough to treat this as the compliance floor, not an aspirational framework. None of the voluntary frameworks above change that; they can help you evidence compliance, but they can't substitute for it.
Do these frameworks contradict each other?
No, they're additive rather than competing, once you stop treating them as four separate projects. The EU AI Act sets the legal minimum if it applies to you. ISO 42001 gives you a structured management system to meet that minimum and prove it externally. NIST AI RMF supplies the risk-assessment vocabulary that sits underneath either one. Singapore's framework adds a board-level communication layer on top. In practice, most compliance teams run one set of activities, inventory your AI tools, assess and document the risk each carries, write the rules down, and that single set of evidence satisfies pieces of all four.
One policy, three frameworks: a worked example
A 40-person software vendor we spoke with sells into the EU, has a US federal contractor as a customer, and had just signed a deal with a Singapore-based bank. Three separate security questionnaires landed in the same quarter, each written in a different framework's language: one asked about "AI-literacy evidence," one about "GOVERN and MAP artefacts," one about "internal AI governance structures." The company didn't write three answers. It had one AI usage policy, one register of approved tools with their data-handling terms, and a log of staff attestation, and mapped those same three documents to each questionnaire's wording. The whole exercise took an afternoon of relabelling, not a fresh compliance project for each customer. Build the underlying artefacts once, then translate them into whichever framework's vocabulary the person on the other end is using.
Common mistakes when picking a framework
The most common mistake is treating ISO 42001 as something you're legally required to have. You aren't, and chasing certification before the basics are in place, no policy, no tool register, wastes months an audit-ready company would spend elsewhere. The second is assuming the EU AI Act doesn't apply because you're not EU-based, while quietly using EU-hosted subprocessors or serving EU customers through a UK or US entity; reach, not headquarters, is what triggers it. The third is picking a framework because it sounds impressive rather than because a customer or regulator is actually asking for it. Start from what's being asked of you, not from a league table of acronyms.
Where to start
If the EU AI Act applies to you, start there; it's the legal minimum, not a choice. If you want a credential customers can verify, layer in ISO 42001. If your buyers speak NIST's language, adopt its GOVERN/MAP vocabulary. Whichever order you tackle them in, the foundation is identical: a written AI usage policy, a register of the tools you actually use, and a record that staff have read the rules. ModelCharter's policy generator builds that foundation in one sitting, and the frameworks hub breaks down what each standard specifically expects, including deeper guides to NIST AI RMF and the EU AI Act.
| Framework | Status | Certifiable? | Best for |
|---|---|---|---|
| NIST AI RMF | Voluntary guidance (US) | No | A risk vocabulary and a GOVERN/MAP/MEASURE/MANAGE process |
| ISO/IEC 42001 | Voluntary, certifiable standard | Yes, third-party audit | Demonstrating governance to customers via a credential |
| EU AI Act | Binding law for EU-reaching organisations | No, it's law, not a certification | The compliance floor if you have EU users or staff |
| Singapore Model AI Governance Framework | Voluntary guidance | No | Board-level governance checklist, with a generative AI addendum |
“Governance is cross-cutting: it surfaces throughout the other three functions rather than sitting apart from them.”