top of page

Stop Comparing AI Frameworks—Build One Governance Operating System

  • Writer: Daniel Ruggles
    Daniel Ruggles
  • 16 hours ago
  • 5 min read

Map the three frameworks once, extract the shared core, and operate a single governance operating system that views the same controls through three lenses: legal obligations (EU AI Act), risk functions (NIST AI RMF), and management-system evidence (ISO/IEC 42001 PDCA). Organizations that do this report 60–80% operational overlap, fewer redundant audits, clearer board reporting, and compliance that feels achievable rather than aspirational

Stop Comparing AI Frameworks—Build One Governance Operating System

Posts keep stacking the EU AI Act, NIST AI RMF, and ISO/IEC 42001 side by side as if they were competing products on a shelf. The result is decision paralysis: legal teams treat the Act as non-negotiable law, risk teams cling to NIST’s practical structure, and audit-minded leaders push for ISO 42001’s certifiable management system. Teams end up running three parallel programs, duplicating work, and still feeling non-compliant.

The more practical path is the opposite of choosing. Map the three frameworks once, extract the shared core, and operate a single governance operating system that views the same controls through three lenses: legal obligations (EU AI Act), risk functions (NIST AI RMF), and management-system evidence (ISO/IEC 42001 PDCA).


Organizations that do this report 60–80% operational overlap, fewer redundant audits, clearer board reporting, and compliance that feels achievable rather than aspirational.

Why a Converged Framework Beats Framework Shopping

The three instruments were never designed as mutually exclusive alternatives.

  • EU AI Act (Regulation 2024/1689, with 2026 Omnibus adjustments) is binding law with extraterritorial reach. It is risk-tiered. High-risk systems (Annex III use cases) face the densest obligations—risk management system (Art. 9), data governance (Art. 10), technical documentation (Art. 11 + Annex IV), record-keeping (Art. 12), transparency (Art. 13), human oversight (Art. 14), accuracy/robustness/cybersecurity (Art. 15), and a quality management system (Art. 17). High-risk rules for most Annex III systems now apply from 2 December 2027; product-embedded systems later. Penalties reach €35 million or 7% of global turnover.

  • NIST AI RMF 1.0 is voluntary guidance organized around four functions—GOVERN, MAP, MEASURE, MANAGE—plus categories and subcategories. It supplies the day-to-day methodology for identifying context, quantifying risk, and treating it across the AI lifecycle. No certification, no fines, but widely adopted as the practical operating playbook, especially in the United States and by global enterprises.

  • ISO/IEC 42001:2023 is the first international AI management system (AIMS) standard. It follows the familiar Plan-Do-Check-Act structure (Clauses 4–10: context, leadership, planning, support, operation, performance evaluation, improvement) plus Annex A controls. It is certifiable by accredited bodies and integrates cleanly with other ISO management systems.


Because the instruments target different layers—legal floor, risk methodology, and auditable management system—they reinforce rather than compete. A single, well-designed control (for example, documented human oversight with override capability and logs) can simultaneously satisfy Art. 14 of the Act, NIST MANAGE and GOVERN subcategories, and ISO 42001 Clause 8 / Annex A requirements. Mapping once eliminates the “three programs” tax and produces reusable evidence.

The Practical Crosswalk: Legal Obligations → NIST Functions → ISO 42001 PDCA Evidence

Here is a high-level crosswalk focused on the core high-risk obligations. Treat it as the backbone of your governance operating system. One control set, three evidence views.

EU AI Act Obligation

Primary NIST AI RMF Function(s)

ISO/IEC 42001 PDCA Evidence

Art. 9 – Risk management system (lifecycle identification, analysis, mitigation, residual risk communication)

MAP (context, categorization, impacts) + MEASURE (evaluation) + MANAGE (treatment & monitoring); GOVERN for policy embedding

Clause 6.1 (actions to address risks & opportunities) + Clause 8 (operation, including recurring risk/impact assessments) + Annex A.5; risk treatment plans, Statement of Applicability

Art. 10 – Data & data governance (relevant, representative, bias examination, quality for training/validation/test data)

MAP (data context & third-party components) + MEASURE (data quality, bias metrics, TEVV)

Clause 8 + Annex A.7 (data for AI systems); data quality records, bias audit reports, dataset documentation

Art. 11 + Annex IV – Technical documentation

MAP (system characterization) + MEASURE (validation results)

Clause 7.5 (documented information) + Clause 8.4; design methodology, validation results, architecture descriptions

Art. 12 – Record-keeping / automatic logging

MEASURE (monitoring) + MANAGE (ongoing tracking)

Clause 8 + Annex A controls on logging/traceability; audit logs retained for required periods

Art. 14 – Human oversight

GOVERN (accountability & roles) + MANAGE (human-in-the-loop controls)

Clause 5.3 (roles) + Clause 8 + Annex A; defined override mechanisms, training records, decision logs

Art. 15 – Accuracy, robustness, cybersecurity

MEASURE (testing, metrics) + MANAGE (risk response)

Clause 8 + Annex A (lifecycle & security controls); test reports, robustness evaluations

Art. 17 – Quality management system

GOVERN (policies, accountability, culture) across all functions

Entire AIMS (Clauses 4–10); AI policy, internal audits (Clause 9.2), management review (Clause 9.3), continual improvement (Clause 10)

Gaps remain—most notably EU-specific conformity assessment, CE marking, EU database registration, and certain highly prescriptive data-bias statistical requirements—but the shared core covers most of the operational work. Build the ISO 42001 management system as the evidence backbone, use NIST functions as the risk engine inside Clauses 6 and 8, and overlay the Act’s legal requirements as the compliance floor.


Sample Portfolio-Level Risk Register

A living portfolio risk register is the single most useful artifact of the converged system. It sits at the center of MAP/MEASURE/MANAGE, feeds ISO risk treatment and impact assessments, and supplies the risk-management evidence demanded by Art. 9. Keep it at portfolio level first (system or use-case granularity), then drill down for high-risk items.

Illustrative excerpt (scoring = Likelihood × Impact, 1–5 scale; customize thresholds to your risk appetite):

Risk ID

AI System / Use Case

Risk Description

Category

Likelihood

Impact

Score

EU AI Act Mapping

NIST Function

ISO 42001 Evidence

Mitigation / Control

Owner

Status

Next Review

AIR-001

Credit-scoring model (high-risk, Annex III)

Demographic bias producing systematically worse outcomes for protected groups

Bias & Fairness

4

5

20

Art. 9, Art. 10

MAP + MEASURE

Clause 6.1, Annex A.5 / A.7; bias assessment reports

Diversified training data, continuous fairness testing, residual risk disclosure to deployers

Model Risk Lead

Open

Q4 2026

AIR-002

Customer-service generative chatbot

Prompt injection enabling data exfiltration or harmful outputs

Security & Adversarial

3

4

12

Art. 9, Art. 15

MEASURE + MANAGE

Clause 8, Annex A security controls; penetration-test results

Input filtering, adversarial testing, human escalation path

Security Officer

Under treatment

Monthly

AIR-003

HR recruitment screening tool (high-risk)

Insufficient human oversight on final hiring recommendations

Governance & Oversight

3

5

15

Art. 14, Art. 9

GOVERN + MANAGE

Clause 5.3, Clause 8; role definitions, override logs

Mandatory human review gate + documented override authority

HR AI Owner

Open

Quarterly

AIR-004

Portfolio-wide third-party foundation models

Supply-chain model updates introducing unassessed drift or new risks

Third-party / Supply Chain

4

4

16

Art. 9, value-chain obligations

GOVERN 6 + MAP

Clause 6.1, Annex A; vendor risk assessments

Contractual change-notification clauses, periodic re-evaluation

Procurement / AI Governance

Monitoring

Semi-annual

Maintain the register as living documentation: update on model changes, new use cases, incidents, or regulatory updates. The same rows generate board heat maps, internal audit samples for ISO certification, and the continuous risk-management evidence required by the Act.


How to Operationalize the Single System

  1. Inventory every AI system and classify against the Act’s risk tiers.

  2. Stand up (or extend) an AIMS aligned to ISO 42001 Clauses 4–10; this becomes the evidence repository.

  3. Embed NIST’s four functions as the operational rhythm inside planning and operation.

  4. Map every control and piece of evidence to the three lenses once; store the mapping alongside the control.

  5. Run one internal audit cycle and one management review that speaks to all three frameworks.

  6. Treat remaining Act-specific items (conformity assessment, registration, certain labeling) as targeted overlays rather than a separate program.


The payoff is immediate: reduced duplication, faster evidence production for customers and regulators, clearer accountability, and a governance posture that scales with the organization’s AI portfolio instead of multiplying with every new regulation or standard.

Stop comparing the frameworks. Map them, converge them, and run one governance operating system. The executives who do so stop choosing and start governing. For more discussion, contact DanRuggles@proton.me 

Comments


bottom of page