AI Governance Frameworks & Standards
Voluntary and certifiable structures for managing AI risk — what regulators point to when they're asking whether your risk management was actually reasonable.
Frameworks and standards don't carry the force of law on their own, but they matter for a very practical reason: when a regulator, a plaintiff's attorney, or an enterprise customer's security team asks how you manage AI risk, "we follow the NIST AI RMF" or "we're certified to ISO/IEC 42001" is a concrete, checkable answer in a way that "we're careful" is not.
We use "framework" for voluntary guidance without a formal certification path (NIST AI RMF, the OECD AI Principles) and "standard" for the certifiable, auditable specifications (ISO/IEC 42001, ISO/IEC 23894) — different governance instruments, same underlying job: giving you a structure to point to when someone asks how AI risk gets managed here.
Recently updated
frameworks
OECD AI Principles
frameworks
ISO/IEC 23894
frameworks
ISO/IEC 42001
Frequently asked questions
- Are AI frameworks legally required?
- No — frameworks and standards are voluntary. But several regulations reference them as evidence of reasonable practice (Colorado's AI Act explicitly creates an affirmative defense tied to NIST AI RMF compliance, for instance), so "voluntary" doesn't mean "irrelevant to your legal exposure."
- What's the practical difference between a framework and a standard?
- A framework like the NIST AI RMF gives you a structure and vocabulary for managing risk, but there's no third party auditing you against it. A standard like ISO/IEC 42001 is certifiable — an accredited body can audit your AI management system against the standard's specific requirements and issue a certificate, similar to how ISO 27001 works for information security.
- Which framework should a company adopt first?
- For most US-based organizations, the NIST AI RMF is the natural starting point — it's the framework US regulators and courts most commonly reference, it's free, and it maps cleanly onto existing risk management vocabulary. Organizations with EU exposure or enterprise customers demanding third-party certification often move toward ISO/IEC 42001 as a second step.