L5. AI Risk Frameworks: NIST AI RMF, EU AI Act & ISO 42001
Course outlineLesson 5 of 21
Three major frameworks now shape enterprise AI governance: the NIST AI Risk Management Framework, the EU AI Act, and ISO 42001. Security architects need to understand how they interlock and what each one demands.
Why Frameworks Matter for Security Architects
Security architects often own the intersection of technical controls and compliance requirements. For AI, three frameworks are now non-negotiable in enterprise contexts: NIST AI RMF defines how to manage AI risk operationally, the EU AI Act defines legal obligations tied to risk tiers, and ISO 42001 defines a management system standard for AI governance.
Understanding all three as a system prevents duplicating effort: many controls satisfy requirements across all three simultaneously.
NIST AI Risk Management Framework (AI RMF)
The NIST AI RMF (released January 2023) structures AI risk management into four functions:
| Function | Core Activity |
|---|---|
| GOVERN | Establish AI risk culture, policies, roles, and accountability structures |
| MAP | Identify and categorize AI risks in the context of the system's use case and deployment environment |
| MEASURE | Analyze, assess, and track identified risks using quantitative and qualitative methods |
| MANAGE | Prioritize and address risks with controls, monitoring, and response plans |
EU AI Act
The EU AI Act (effective August 2024, most provisions apply from August 2026) classifies AI systems into risk tiers:
| Risk Tier | Definition | Examples | Obligations |
|---|---|---|---|
| Unacceptable | Prohibited outright | Social scoring by governments, real-time biometric surveillance in public | Banned |
| High risk | Significant risk to health, safety, or fundamental rights | Hiring tools, credit scoring, medical devices, critical infrastructure | Conformity assessment, transparency, human oversight, incident reporting |
| Limited risk | Transparency obligations only | Chatbots, deepfakes | Must disclose AI nature to users |
| Minimal risk | No obligations | Spam filters, AI in video games | Voluntary codes of conduct |
ISO 42001
ISO 42001 (published December 2023) is the first international standard for AI management systems. It follows the same Annex SL structure as ISO 27001 and ISO 9001, making integration straightforward for organizations already certified.
Key additions over ISO 27001:
- AI-specific risk assessment criteria (impact on people, explainability, data quality)
- AI system lifecycle controls (from design through decommissioning)
- AI-specific incident management procedures
- Requirements for documenting intended use and reasonably foreseeable misuse
- ✓NIST AI RMF four functions: GOVERN (culture & policy), MAP (identify risks), MEASURE (analyze risks), MANAGE (address risks)
- ✓EU AI Act risk tiers: Unacceptable (banned), High risk (conformity assessment + human oversight), Limited risk (transparency only), Minimal risk (voluntary)
- ✓High-risk AI systems under EU AI Act require: technical documentation, risk management, data governance, accuracy testing, and human oversight mechanisms
- ✓ISO 42001 uses Annex SL structure: integrates with ISO 27001 by extending existing ISMS with AI-specific controls
- ✓GOVERN and MAP in NIST AI RMF must happen before system design is finalized to capture technical risks early
1. Under the EU AI Act, which risk tier applies to an AI-powered hiring tool that screens CVs?
2. What is the primary structural advantage of ISO 42001 for organizations already certified to ISO 27001?
Recommended: Pluralsight
Pluralsight's AI security courses cover threat modeling, governance, and practical red teaming for AI systems to complement what you learn here.