ModelCharter
ModelCharter Team

AI Governance Frameworks Compared: NIST vs ISO 42001

Business data charts comparing AI governance frameworks including NIST and ISO 42001

Photo: RDNE Stock project / Pexels

Key takeaways

  • NIST AI RMF, ISO 42001, the EU AI Act and Singapore's Model AI Governance Framework all address AI governance but differ sharply in legal status.
  • Only the EU AI Act is legally binding; the other three are voluntary.
  • ISO 42001 is the only one you can get externally certified against.
  • A written policy, a tool register and an attestation record satisfy the documentation core of all four.

Type "model AI governance framework" into a search bar and you land on two different things. There's the generic idea, a reference framework you model your own programme on, and there's a specific document: Singapore's Model AI Governance Framework, first published by the city-state's regulators in 2019 and updated with a generative AI addendum in 2024. Both readings point at the same problem. There is no single global standard for AI governance, only several overlapping ones: the NIST AI Risk Management Framework, ISO/IEC 42001, the EU AI Act, and Singapore's framework. Knowing how they differ, and where they overlap, stops you building four separate compliance programmes when one foundation would do.

What is Singapore's Model AI Governance Framework?

It's not law. Singapore's Infocomm Media Development Authority and Personal Data Protection Commission publish it as voluntary guidance, aimed mostly at boards and senior management rather than engineers. First launched in 2019, well before the EU AI Act existed in any form, it sets out internal governance structures, how to assess AI risk before deployment, and how to communicate AI use to customers and staff. The 2024 update added a companion annex for generative AI specifically, covering things like content provenance and third-party model risk. There's no certification scheme attached, unlike ISO 42001, so treat it as a well-regarded checklist rather than an audit-ready standard. If your customers or regulators sit in Singapore, or you simply want a clear-headed starting checklist for a board conversation, it's worth reading alongside NIST and ISO rather than instead of them.

NIST AI RMF: the risk-management lens

Published in January 2023, the NIST AI Risk Management Framework organises governance into four functions: GOVERN, MAP, MEASURE, MANAGE. It's deliberately flexible, meant to scale from a five-person startup to a federal agency, and it carries no legal weight of its own. What it does carry is adoption: it's become the framework US enterprise buyers and government customers mean by default when they ask how you manage AI risk. If your organisation is US-headquartered, or sells into the US, GOVERN (a named owner and a written policy) and MAP (an inventory of the AI tools you actually use) are the two functions worth tackling first. MEASURE and MANAGE, which cover ongoing monitoring and response, matter more once you're building or heavily customising AI systems rather than simply using off-the-shelf tools.

ISO 42001: the one you can get certified against

ISO/IEC 42001 is a management-system standard for AI, built the way ISO 27001 is built for information security: documented policies, risk assessments, internal audits, and, critically, third-party certification. That last part sets it apart from NIST and Singapore's framework. An accredited certification body can audit you against it and issue a certificate your customers can verify. It suits organisations that want AI governance to show up as a credential in a security questionnaire, not just a policy document on file. See the ISO/IEC 42001 standard page for the clause structure, and our deeper ISO 42001 guide for what deployers versus providers actually need to do.

The EU AI Act: the one with legal teeth

Unlike the other three, the EU AI Act isn't guidance you can choose to follow. It's law, and it applies to any organisation whose AI systems reach the EU, regardless of where the company is based. Most small businesses are "deployers" of general tools like ChatGPT rather than "providers" of high-risk AI systems, so the practical duties are narrower than the headlines suggest: avoid a short list of banned practices, be transparent about AI-generated content, and, since Article 4 came into force on 2 February 2025, ensure staff have a sufficient level of AI literacy. Penalties for serious breaches scale with company turnover, which is reason enough to treat this as the compliance floor, not an aspirational framework. None of the voluntary frameworks above change that; they can help you evidence compliance, but they can't substitute for it.

Do these frameworks contradict each other?

No, they're additive rather than competing, once you stop treating them as four separate projects. The EU AI Act sets the legal minimum if it applies to you. ISO 42001 gives you a structured management system to meet that minimum and prove it externally. NIST AI RMF supplies the risk-assessment vocabulary that sits underneath either one. Singapore's framework adds a board-level communication layer on top. In practice, most compliance teams run one set of activities, inventory your AI tools, assess and document the risk each carries, write the rules down, and that single set of evidence satisfies pieces of all four.

One policy, three frameworks: a worked example

A 40-person software vendor we spoke with sells into the EU, has a US federal contractor as a customer, and had just signed a deal with a Singapore-based bank. Three separate security questionnaires landed in the same quarter, each written in a different framework's language: one asked about "AI-literacy evidence," one about "GOVERN and MAP artefacts," one about "internal AI governance structures." The company didn't write three answers. It had one AI usage policy, one register of approved tools with their data-handling terms, and a log of staff attestation, and mapped those same three documents to each questionnaire's wording. The whole exercise took an afternoon of relabelling, not a fresh compliance project for each customer. Build the underlying artefacts once, then translate them into whichever framework's vocabulary the person on the other end is using.

Common mistakes when picking a framework

The most common mistake is treating ISO 42001 as something you're legally required to have. You aren't, and chasing certification before the basics are in place, no policy, no tool register, wastes months an audit-ready company would spend elsewhere. The second is assuming the EU AI Act doesn't apply because you're not EU-based, while quietly using EU-hosted subprocessors or serving EU customers through a UK or US entity; reach, not headquarters, is what triggers it. The third is picking a framework because it sounds impressive rather than because a customer or regulator is actually asking for it. Start from what's being asked of you, not from a league table of acronyms.

Where to start

If the EU AI Act applies to you, start there; it's the legal minimum, not a choice. If you want a credential customers can verify, layer in ISO 42001. If your buyers speak NIST's language, adopt its GOVERN/MAP vocabulary. Whichever order you tackle them in, the foundation is identical: a written AI usage policy, a register of the tools you actually use, and a record that staff have read the rules. ModelCharter's policy generator builds that foundation in one sitting, and the frameworks hub breaks down what each standard specifically expects, including deeper guides to NIST AI RMF and the EU AI Act.

FrameworkStatusCertifiable?Best for
NIST AI RMFVoluntary guidance (US)NoA risk vocabulary and a GOVERN/MAP/MEASURE/MANAGE process
ISO/IEC 42001Voluntary, certifiable standardYes, third-party auditDemonstrating governance to customers via a credential
EU AI ActBinding law for EU-reaching organisationsNo, it's law, not a certificationThe compliance floor if you have EU users or staff
Singapore Model AI Governance FrameworkVoluntary guidanceNoBoard-level governance checklist, with a generative AI addendum
How the major AI governance frameworks compare
Governance is cross-cutting: it surfaces throughout the other three functions rather than sitting apart from them.
NIST AI RMF 1.0

Frequently asked questions

Is ISO 42001 mandatory?
No. It's a voluntary standard, but enterprise customers and procurement teams increasingly ask for it as evidence of a structured AI governance programme, especially alongside ISO 27001.
Does the EU AI Act replace NIST AI RMF or ISO 42001?
No. The EU AI Act is law and sets binding minimums for organisations it covers. NIST AI RMF and ISO 42001 are voluntary frameworks you can use to organise the work needed to meet those minimums and to go further.
What's the real difference between NIST AI RMF and ISO 42001?
NIST AI RMF is a flexible risk-assessment framework with no certification attached. ISO 42001 is a certifiable management-system standard: it tells you what documented processes to run and lets an accredited auditor confirm you're running them.
Do I need to adopt all of these frameworks?
No. Start with the three foundational artefacts, a written policy, a tool register and attestation records, then pick which named framework to pursue in depth based on what your regulators and customers actually ask for.
Is Singapore's Model AI Governance Framework relevant outside Singapore?
It can be, especially as a plain-English checklist for board-level discussion, but it carries no legal weight outside Singapore and no certification scheme anywhere. Treat it as a useful reference rather than a compliance requirement unless you have Singapore-based operations or customers.

Put this into practice

Generate a free AI usage policy for your team, then see which of your tools are safe to use.

Open the generator