Which AI Governance Framework Fits Your Organization?

The use of artificial intelligence has grown from being purely experimental to now becoming a popular topic in boardrooms all over the world. Despite this fact, organizations still grapple with the crucial question of how to manage AI without inhibiting innovation. This is where frameworks like ISO 42001 and NIST AI RMF come to the rescue.

On the surface, both seem to solve the same problem, but they are actually quite different from each other.

Different Frameworks for Different Goals

ISO 42001 is a standard that is applicable globally as an international management system standard. In essence, it can be regarded as a pre-defined operating model used in the development of AI solutions and other projects. ISO 42001 generally aims at putting various policies in place, assigning different responsibilities, managing the risks that are associated with various operations, and pursuing continuous improvement in the area of interest. If your organization uses any other standards such as ISO 27001 and ISO 9001, you will find ISO 42001 very similar to them.

The NIST AI RMF, on the other hand, represents a voluntary framework designed to let organizations know how to identify, assess, and manage the risks associated with AI. Instead of establishing a management system per se, it serves as a framework in which better intelligence can be achieved through the implementation of functions such as Govern, Map, Measure, and Manage.

You might also be interested in: AI Capacity is Strategy – Special Article

Which of the Two Should Be Selected?

The answer to this question lies in what the organization seeks to achieve.

Organizations that seek to obtain certification at a global level or establish some sort of governance structure will find ISO 42001 more useful than the NIST AI RMF. Those who want to strengthen their risk management associated with AI may benefit from the latter framework without being certified.

Interestingly, in most cases companies do not see the two frameworks as direct competition. They use ISO 42001 as their main framework, and apply NIST AI RMF to support their AI risk management and decision-making.

Governance: The Only True Differentiator

The adoption of AI itself no longer acts as a differentiating factor between companies, since practically everybody is utilizing it in his or her operations nowadays. The only differentiating factor lies in the capability of companies to demonstrate that their AI systems are trustworthy and accountable.

Thus, the choice of ISO 42001 and the NIST AI RMF is less about making a decision in favor of either of the frameworks, and more about understanding what the organization needs today and how to prepare for future expectations in terms of regulations and governance.

Leave a Reply

Your email address will not be published. Required fields are marked *

This field is required.

This field is required.