Stop Comparing AI Frameworks—Build One Governance Operating System
- Daniel Ruggles
- 16 hours ago
- 5 min read

Stop Comparing AI Frameworks—Build One Governance Operating System
Posts keep stacking the EU AI Act, NIST AI RMF, and ISO/IEC 42001 side by side as if they were competing products on a shelf. The result is decision paralysis: legal teams treat the Act as non-negotiable law, risk teams cling to NIST’s practical structure, and audit-minded leaders push for ISO 42001’s certifiable management system. Teams end up running three parallel programs, duplicating work, and still feeling non-compliant.
The more practical path is the opposite of choosing. Map the three frameworks once, extract the shared core, and operate a single governance operating system that views the same controls through three lenses: legal obligations (EU AI Act), risk functions (NIST AI RMF), and management-system evidence (ISO/IEC 42001 PDCA).
Organizations that do this report 60–80% operational overlap, fewer redundant audits, clearer board reporting, and compliance that feels achievable rather than aspirational.
Why a Converged Framework Beats Framework Shopping
The three instruments were never designed as mutually exclusive alternatives.
EU AI Act (Regulation 2024/1689, with 2026 Omnibus adjustments) is binding law with extraterritorial reach. It is risk-tiered. High-risk systems (Annex III use cases) face the densest obligations—risk management system (Art. 9), data governance (Art. 10), technical documentation (Art. 11 + Annex IV), record-keeping (Art. 12), transparency (Art. 13), human oversight (Art. 14), accuracy/robustness/cybersecurity (Art. 15), and a quality management system (Art. 17). High-risk rules for most Annex III systems now apply from 2 December 2027; product-embedded systems later. Penalties reach €35 million or 7% of global turnover.
NIST AI RMF 1.0 is voluntary guidance organized around four functions—GOVERN, MAP, MEASURE, MANAGE—plus categories and subcategories. It supplies the day-to-day methodology for identifying context, quantifying risk, and treating it across the AI lifecycle. No certification, no fines, but widely adopted as the practical operating playbook, especially in the United States and by global enterprises.
ISO/IEC 42001:2023 is the first international AI management system (AIMS) standard. It follows the familiar Plan-Do-Check-Act structure (Clauses 4–10: context, leadership, planning, support, operation, performance evaluation, improvement) plus Annex A controls. It is certifiable by accredited bodies and integrates cleanly with other ISO management systems.
Because the instruments target different layers—legal floor, risk methodology, and auditable management system—they reinforce rather than compete. A single, well-designed control (for example, documented human oversight with override capability and logs) can simultaneously satisfy Art. 14 of the Act, NIST MANAGE and GOVERN subcategories, and ISO 42001 Clause 8 / Annex A requirements. Mapping once eliminates the “three programs” tax and produces reusable evidence.
The Practical Crosswalk: Legal Obligations → NIST Functions → ISO 42001 PDCA Evidence
Here is a high-level crosswalk focused on the core high-risk obligations. Treat it as the backbone of your governance operating system. One control set, three evidence views.
EU AI Act Obligation | Primary NIST AI RMF Function(s) | ISO/IEC 42001 PDCA Evidence |
Art. 9 – Risk management system (lifecycle identification, analysis, mitigation, residual risk communication) | MAP (context, categorization, impacts) + MEASURE (evaluation) + MANAGE (treatment & monitoring); GOVERN for policy embedding | Clause 6.1 (actions to address risks & opportunities) + Clause 8 (operation, including recurring risk/impact assessments) + Annex A.5; risk treatment plans, Statement of Applicability |
Art. 10 – Data & data governance (relevant, representative, bias examination, quality for training/validation/test data) | MAP (data context & third-party components) + MEASURE (data quality, bias metrics, TEVV) | Clause 8 + Annex A.7 (data for AI systems); data quality records, bias audit reports, dataset documentation |
Art. 11 + Annex IV – Technical documentation | MAP (system characterization) + MEASURE (validation results) | Clause 7.5 (documented information) + Clause 8.4; design methodology, validation results, architecture descriptions |
Art. 12 – Record-keeping / automatic logging | MEASURE (monitoring) + MANAGE (ongoing tracking) | Clause 8 + Annex A controls on logging/traceability; audit logs retained for required periods |
Art. 14 – Human oversight | GOVERN (accountability & roles) + MANAGE (human-in-the-loop controls) | Clause 5.3 (roles) + Clause 8 + Annex A; defined override mechanisms, training records, decision logs |
Art. 15 – Accuracy, robustness, cybersecurity | MEASURE (testing, metrics) + MANAGE (risk response) | Clause 8 + Annex A (lifecycle & security controls); test reports, robustness evaluations |
Art. 17 – Quality management system | GOVERN (policies, accountability, culture) across all functions | Entire AIMS (Clauses 4–10); AI policy, internal audits (Clause 9.2), management review (Clause 9.3), continual improvement (Clause 10) |
Gaps remain—most notably EU-specific conformity assessment, CE marking, EU database registration, and certain highly prescriptive data-bias statistical requirements—but the shared core covers most of the operational work. Build the ISO 42001 management system as the evidence backbone, use NIST functions as the risk engine inside Clauses 6 and 8, and overlay the Act’s legal requirements as the compliance floor.
Sample Portfolio-Level Risk Register
A living portfolio risk register is the single most useful artifact of the converged system. It sits at the center of MAP/MEASURE/MANAGE, feeds ISO risk treatment and impact assessments, and supplies the risk-management evidence demanded by Art. 9. Keep it at portfolio level first (system or use-case granularity), then drill down for high-risk items.
Illustrative excerpt (scoring = Likelihood × Impact, 1–5 scale; customize thresholds to your risk appetite):
Risk ID | AI System / Use Case | Risk Description | Category | Likelihood | Impact | Score | EU AI Act Mapping | NIST Function | ISO 42001 Evidence | Mitigation / Control | Owner | Status | Next Review |
AIR-001 | Credit-scoring model (high-risk, Annex III) | Demographic bias producing systematically worse outcomes for protected groups | Bias & Fairness | 4 | 5 | 20 | Art. 9, Art. 10 | MAP + MEASURE | Clause 6.1, Annex A.5 / A.7; bias assessment reports | Diversified training data, continuous fairness testing, residual risk disclosure to deployers | Model Risk Lead | Open | Q4 2026 |
AIR-002 | Customer-service generative chatbot | Prompt injection enabling data exfiltration or harmful outputs | Security & Adversarial | 3 | 4 | 12 | Art. 9, Art. 15 | MEASURE + MANAGE | Clause 8, Annex A security controls; penetration-test results | Input filtering, adversarial testing, human escalation path | Security Officer | Under treatment | Monthly |
AIR-003 | HR recruitment screening tool (high-risk) | Insufficient human oversight on final hiring recommendations | Governance & Oversight | 3 | 5 | 15 | Art. 14, Art. 9 | GOVERN + MANAGE | Clause 5.3, Clause 8; role definitions, override logs | Mandatory human review gate + documented override authority | HR AI Owner | Open | Quarterly |
AIR-004 | Portfolio-wide third-party foundation models | Supply-chain model updates introducing unassessed drift or new risks | Third-party / Supply Chain | 4 | 4 | 16 | Art. 9, value-chain obligations | GOVERN 6 + MAP | Clause 6.1, Annex A; vendor risk assessments | Contractual change-notification clauses, periodic re-evaluation | Procurement / AI Governance | Monitoring | Semi-annual |
Maintain the register as living documentation: update on model changes, new use cases, incidents, or regulatory updates. The same rows generate board heat maps, internal audit samples for ISO certification, and the continuous risk-management evidence required by the Act.
How to Operationalize the Single System
Inventory every AI system and classify against the Act’s risk tiers.
Stand up (or extend) an AIMS aligned to ISO 42001 Clauses 4–10; this becomes the evidence repository.
Embed NIST’s four functions as the operational rhythm inside planning and operation.
Map every control and piece of evidence to the three lenses once; store the mapping alongside the control.
Run one internal audit cycle and one management review that speaks to all three frameworks.
Treat remaining Act-specific items (conformity assessment, registration, certain labeling) as targeted overlays rather than a separate program.
The payoff is immediate: reduced duplication, faster evidence production for customers and regulators, clearer accountability, and a governance posture that scales with the organization’s AI portfolio instead of multiplying with every new regulation or standard.
Stop comparing the frameworks. Map them, converge them, and run one governance operating system. The executives who do so stop choosing and start governing. For more discussion, contact DanRuggles@proton.me


Comments