AI Compliance Frameworks
NIST AI RMF, EU AI Act, ISO 42001 — what they require, who they apply to, and what you must do.
The AI compliance landscape shifted from voluntary best practices to mandatory regulatory requirements faster than most organizations anticipated. Understanding which frameworks apply to your AI deployments — and what each requires — is now a core governance responsibility. This page explains the four most important frameworks in operational terms: what they are, who they cover, and what you actually have to do.
The EU AI Act's high-risk designation may apply to AI you don't think of as "AI decisions" — including AI that influences HR decisions, customer credit, and insurance pricing. Review your AI inventory against the high-risk categories before assuming minimal risk.
NIST AI Risk Management Framework (AI RMF)
NIST AI RMF at a Glance
- Type: Voluntary US framework (but increasingly referenced in contracts and procurement)
- Published: January 2023 by the National Institute of Standards and Technology
- Who It Covers: Any US organization using or developing AI; increasingly required for federal contractors and vendors
- Key Requirements: Four functions — GOVERN, MAP, MEASURE, MANAGE — with specific practices under each
- Consequence of Non-Compliance: No direct penalty (voluntary), but increasingly cited in procurement disqualification, contract requirements, and regulatory expectations
The NIST AI RMF is structured around four core functions that together form a lifecycle approach to AI risk management:
- GOVERN: Establish the organizational context for AI risk — policies, roles, responsibilities, culture. This is where you define who owns AI risk and how decisions get made.
- MAP: Identify and categorize AI risks in context. What is this AI system doing? What could go wrong? Who is affected? What are the impacts if it fails or is compromised?
- MEASURE: Analyze, assess, and track AI risks. This is where you actually test and evaluate your AI systems — including for security, fairness, and reliability.
- MANAGE: Prioritize and act on identified risks. Implement controls, monitor for new risks, and have response plans for when things go wrong.
The companion document — the AI RMF Playbook — provides specific suggested actions for each function. It's available free from NIST and is the most actionable starting point for organizations building an AI risk program aligned to this framework.
Even if NIST AI RMF isn't contractually required for your organization today, aligning your AI governance program to its structure positions you well for future requirements. The framework's four-function structure maps cleanly onto a mature governance program and is increasingly referenced by sector-specific regulators (OCC, FFIEC, FDA) in their AI guidance.
EU AI Act
EU AI Act at a Glance
- Type: Mandatory regulation — world's first comprehensive AI law
- Timeline: Regulation adopted 2024; prohibited practices banned August 2024; high-risk provisions enforceable August 2026
- Who It Covers: Any organization deploying AI that affects EU residents — regardless of where the organization is based (GDPR-style extraterritorial scope)
- Key Requirements: Risk-tiered obligations from minimal (few requirements) to high-risk (extensive documentation, testing, human oversight) to prohibited (banned entirely)
- Fines: Up to €35 million or 7% of global annual turnover (whichever is higher) for prohibited practices; up to €15 million or 3% for other violations
The EU AI Act uses a four-tier risk classification system. Where your AI systems fall determines your compliance obligations:
Tier 1: Unacceptable Risk (Prohibited)
These AI applications are banned entirely under the EU AI Act. They include: social scoring systems that evaluate people based on behavior or personal characteristics; real-time remote biometric surveillance in public spaces by law enforcement (with narrow exceptions); AI that exploits vulnerable groups; and AI that manipulates people through subliminal techniques. If your AI does any of these things, you must discontinue it regardless of business case.
Tier 2: High Risk (Strict Requirements)
This is where most enterprise AI compliance work happens. High-risk AI includes: AI used in hiring, promotion, and employee management; AI that influences credit, insurance, or financial access decisions; AI used in critical infrastructure (energy, water, transport); AI used in education and vocational training; AI used in essential services; and AI used in law enforcement and judicial administration.
For high-risk AI, you must implement:
- A risk management system documented and maintained throughout the AI system's lifecycle
- Data governance — training data must be appropriate, relevant, and free of harmful bias
- Technical documentation sufficient for regulators to assess compliance
- Logging and traceability — the system must keep logs that allow post-deployment review
- Transparency — users must know they're interacting with an AI system
- Human oversight — the system must be designed to allow humans to understand, monitor, and intervene
- Accuracy, robustness, and cybersecurity requirements
- Conformity assessment before deployment (self-assessment or third-party, depending on category)
Tier 3: Limited Risk (Transparency Requirements)
AI systems with limited risk — primarily chatbots and systems that generate synthetic content — must disclose that they are AI systems. Chatbots must identify themselves as AI. Deepfakes must be labeled. These requirements are already in effect.
Tier 4: Minimal Risk (Few Requirements)
Most AI falls here — spam filters, recommendation engines, AI features in standard software. Few specific obligations apply, though providers may voluntarily adopt codes of conduct.
The August 2026 full enforcement deadline for high-risk AI provisions is not far away. Organizations with HR AI, credit scoring AI, or AI in regulated industries should be conducting their EU AI Act assessment now, not in 2025. The documentation, testing, and conformity assessment requirements take significant time to satisfy.
ISO/IEC 42001 (AI Management System)
ISO/IEC 42001 at a Glance
- Type: Certifiable international standard — like ISO 27001 for AI governance
- Published: December 2023 by ISO/IEC
- Who It Covers: Any organization developing or using AI that wants demonstrable governance for procurement, enterprise contracts, or regulatory relationships
- Key Requirements: Establish, implement, maintain, and continually improve an AI management system covering context, leadership, planning, support, operations, performance evaluation, and improvement
- Consequence of Non-Compliance: No regulatory penalty — but organizations without certification increasingly lose procurement bids and enterprise contracts requiring demonstrated AI governance
ISO/IEC 42001 provides the framework for a complete AI management system. Its structure mirrors ISO 27001 (information security management) and ISO 9001 (quality management), which means organizations already certified to those standards have a significant head start. The standard covers the full AI lifecycle from planning and design through deployment, operation, and decommissioning.
The strategic value of ISO/IEC 42001 certification: it provides a credible, audited, third-party-verified signal of AI governance maturity. For enterprise B2B sales, public sector procurement, and regulated industry relationships, certification is increasingly becoming a table-stakes requirement. Organizations that pursue it proactively gain a competitive advantage. Those that wait find themselves scrambling to satisfy procurement questionnaires with evidence that doesn't exist yet.
SOC 2 + AI
SOC 2 + AI at a Glance
- Type: Existing framework being extended to cover AI — not yet a formal standard, but actively evolving
- Who It Covers: Organizations already pursuing SOC 2 compliance whose systems include AI components
- Key Requirements: AI systems must satisfy existing trust service criteria (security, availability, confidentiality, processing integrity, privacy) — auditors are developing AI-specific tests
- Consequence: AI systems excluded from SOC 2 scope may create audit gaps; auditors are beginning to ask specifically about AI components
SOC 2 auditors are increasingly asking questions specifically about AI systems. They want to understand: Are AI systems included in the security boundary? How is AI model access controlled? How is AI output accuracy monitored? How are AI incidents detected and responded to?
Organizations pursuing SOC 2 should proactively include their AI systems in scope rather than waiting for auditors to raise questions. The five trust service criteria apply directly:
- Security: AI systems must have access controls, vulnerability management, and monitoring — same as any other system
- Availability: AI service dependencies (API providers, model hosting) must be part of uptime and resiliency planning
- Confidentiality: Data sent to AI systems must be handled with the same confidentiality controls as other sensitive data
- Processing Integrity: AI output quality and accuracy must be monitored — you must know if the AI is producing garbage
- Privacy: Personal data processed by AI systems must satisfy the same privacy controls as other personal data processing
Determining Which Frameworks Apply to Your AI Deployment
1 / 5🌍 Map the Geography of Your Users
EU AI Act applies to any AI that affects EU residents — not where your company is based. If you have customers, employees, or users in the EU, the EU AI Act applies to the AI systems they interact with. Start here because EU AI Act has the most expansive extraterritorial scope and the most significant penalties.
🔍 Identify the Type of AI Use Case
Walk through the EU AI Act's high-risk category list for each AI system. Check whether any NIST AI RMF sector-specific guidance applies (financial services, healthcare, critical infrastructure). Use case determines risk tier, which determines compliance requirements. A grammar checker and a credit scoring model have completely different compliance profiles.
🗄️ Assess Data Types Being Processed
AI systems that process personal data trigger GDPR (for EU data subjects) and CCPA (for California residents) requirements in addition to AI-specific regulations. Systems processing special category data (health, biometric, financial) face heightened requirements. Map data flows into and out of each AI system before concluding your compliance scope.
📄 Review Existing Certifications and Contracts
Check your existing compliance obligations: SOC 2 scope, ISO 27001 scope, sector-specific requirements (HIPAA, PCI-DSS, FedRAMP). These may have AI-relevant clauses or may need to be extended to cover AI systems. Check customer contracts for AI governance requirements — enterprise customers increasingly include these in procurement terms.
🏛️ Apply Industry Vertical Lens
Financial services, healthcare, insurance, and public sector face additional regulatory expectations from sector-specific regulators (OCC, FFIEC, FDA, FTC) who are issuing AI-specific guidance. These supplement — they don't replace — horizontal frameworks like EU AI Act and NIST AI RMF. Map all applicable vertical regulations before finalizing your compliance scope.
Compliance Readiness Checklist: 8 Items That Apply Across All Frameworks
Regardless of which specific frameworks apply to your organization, these eight items appear in some form across all major AI compliance frameworks. Satisfying them puts you in a position to demonstrate compliance to any framework.
- Maintain a current AI system inventory — documented, with named owners, risk tiers, and data classifications for each system
- Document the purpose and scope of each AI system — what it's designed to do, what decisions it influences, and what it is explicitly not authorized to do
- Establish data governance for AI — what data trains it, what data it processes, who can access outputs, and how long data is retained
- Implement human oversight mechanisms — defined points where human review occurs, documented escalation paths, and audit evidence that oversight is actually happening
- Create and maintain technical documentation — model cards, system architecture, testing results, and performance metrics for every production AI system
- Deploy logging and monitoring — AI system decisions and actions must be logged at a level that supports post-incident investigation and regulatory response
- Establish incident response procedures — AI-specific incident response playbook covering detection, containment, investigation, notification, and remediation
- Conduct regular audits and reviews — formal governance review at least annually for all AI systems; quarterly for high-risk systems; triggered review on model updates