Search this site
Public information siteInstitutional framework and operating programs continue to evolve

Governance structure · Published September 24, 2026

AI Governance Framework: How NIST, ISO/IEC 42001, and the EU AI Act Fit Together

An AI governance framework is the set of owners, rules, decisions, and records an organization uses to decide which AI it runs, on what conditions, and how it finds out when something goes wrong. Most organizations do not have to choose between the three best-known sources. The EU AI Act is law that applies by role and risk. ISO/IEC 42001 is a certifiable management system that keeps governance running. The NIST AI Risk Management Framework is a voluntary set of risk practices used one system at a time. Build one structure and let each source fill its own layer.

Law, management system, risk practice

Three sources, three different jobs.

Programs stall when these are treated as competing checklists. They answer different questions: what you must do, how you keep doing it, and how you judge one system. Each status line below was checked against the publisher’s own page on September 24, 2026.

Law

EU AI Act, Regulation (EU) 2024/1689

What must we do?

Binding
Yes, where it applies. It reaches organizations outside the EU when a system’s output is used in the EU (Article 2).
Certificate
None for the organization. High-risk systems go through conformity assessment before they reach the market.
Unit of work
One AI system, and your role for it: provider, deployer, importer, or distributor.
Status
In force since August 1, 2024. Amended by the AI Omnibus, Regulation (EU) 2026/1744, in force July 27, 2026. Most remaining rules applied from August 2, 2026. Stand-alone high-risk rules now start December 2, 2027.
Also on this layer
US state law. Colorado repealed and re-enacted its 2024 AI Act as SB26-189, signed May 14, 2026, with duties for automated decisions starting January 1, 2027.
Management system

ISO/IEC 42001:2023

How do we keep doing it?

Binding
No. Voluntary, unless a contract or a customer requires it.
Certificate
Yes. A certification body audits the organization’s AI management system. The certificate covers that system, not an individual AI product.
Unit of work
The organization, within the scope it defines for its AI management system.
Structure
Clauses 4 to 10: context, leadership, planning, support, operation, performance evaluation, improvement. Annex A adds 38 reference controls under nine objectives, A.2 to A.10, selected through a Statement of Applicability.
Status
Edition 1, published December 2023. 51 pages, CHF 225 from ISO as listed on September 24, 2026.
Risk practice

NIST AI Risk Management Framework 1.0

How do we judge this one system?

Binding
No. NIST describes it as intended for voluntary use.
Certificate
None.
Unit of work
One AI system across its lifecycle.
Structure
Four functions, Govern, Map, Measure, and Manage, broken into 19 categories and 72 subcategories. The Generative AI Profile, NIST AI 600-1, was added July 26, 2024.
Status
Released January 26, 2023. NIST’s page, updated August 13, 2026, says AI RMF 1.0 is being revised as part of the White House AI Action Plan.

The three meet in the same place: the nine decisions further down. A decision recorded once can answer a NIST self-review, an ISO/IEC 42001 audit question, and an EU AI Act duty.

Five questions, nothing collected

Find the duties that are actually yours.

Answer for the organization as it operates today. Your answers stay on this page while it is open. They are not stored or sent anywhere. The result names the layers that carry duties for you and the order to build the documents in.

01Does output from any AI system you build or use reach people in the European Union?

The EU AI Act reaches organizations outside the EU when a system’s output is used in the EU (Article 2).

02Do you build AI systems, or sell them under your own name?

Builders and sellers are providers. Organizations that only use systems others built are deployers. The duties differ.

03Does any AI output influence a decision about a person’s work, education, credit, housing, insurance, health care, or access to essential services?

These are the decisions high-risk rules and US automated-decision laws are written for.

04Do customers, partners, or procurement teams ask for third-party proof of how you govern AI?

That demand, not the law, is the usual reason to certify against ISO/IEC 42001.

05Do people outside the organization talk to an AI system of yours, or see AI-generated images, audio, video, or text you publish?

Chatbots and published synthetic content carry transparency duties of their own.

0 of 5 answered

Answer the questions to see which layers carry duties for you and the order to build the documents in. Nothing you select leaves this page.

What every source asks you to decide

Nine decisions, each recorded once.

Each decision appears, in some form, in all three sources. The references show where. EU AI Act references apply only where the Act reaches your organization and the system in question. The last line names the Institute document where the decision is written down.

  1. 01

    Who is accountable, and who can stop a use case?

    Every later decision needs an owner with the authority to say no. Without one, the other eight become advice.

    NIST AI RMF
    GOVERN 2.1 roles documented; GOVERN 2.3 executive leadership takes responsibility for AI risk decisions
    ISO/IEC 42001
    Clause 5, leadership; A.3 internal organization
    EU AI Act
    Article 26(2): deployers of high-risk systems assign human oversight to people with the competence, training, and authority to use it
  2. 02

    What AI is in use, and who owns each system?

    Role and risk class are decided system by system, so a framework without an inventory has nothing to apply to. Vendor features count.

    NIST AI RMF
    GOVERN 1.6 mechanisms to inventory AI systems
    ISO/IEC 42001
    Clause 4, context and scope; A.4 resources for AI systems
    EU AI Act
    Articles 2 and 6: scope and high-risk classification are assessed per system
  3. 03

    What may staff do with AI tools?

    Most exposure starts with a person pasting data into a tool. This is the decision employees actually meet.

    NIST AI RMF
    GOVERN 1.2 trustworthy characteristics built into policy; GOVERN 2.2 training
    ISO/IEC 42001
    A.2 policies related to AI; A.9 use of AI systems
    EU AI Act
    Article 4 AI literacy (applies since February 2, 2025, reworded by the Omnibus); Article 5 prohibited practices
  4. 04

    How is each use case tiered and scored?

    A summarizing assistant and a benefits decision need different depth. The tier decides how much of everything else applies.

    NIST AI RMF
    MAP 1.5 risk tolerance; MAP 5.1 likelihood and magnitude of impacts; MEASURE 2 evaluation
    ISO/IEC 42001
    Clause 6.1 risk assessment, treatment, and impact assessment; A.5 assessing impacts of AI systems
    EU AI Act
    Article 6 and Annex III high-risk classification; Article 27 fundamental rights impact assessment for certain deployers
  5. 05

    What evidence must exist before a system reaches people?

    Launch is the last point where a no costs little. Decide in advance what proof a yes requires.

    NIST AI RMF
    MEASURE 2.3 and 2.5 performance shown in deployment-like conditions; MANAGE 1.1 go or no-go
    ISO/IEC 42001
    Clause 8, operation; A.6 AI system life cycle, including verification and validation
    EU AI Act
    Articles 16 and 17 provider obligations and quality management system; Article 43 conformity assessment for high-risk systems
  6. 06

    Where must a person check, override, or stop the system?

    Human review only works if the reviewer has the information, the time, and the authority to disagree.

    NIST AI RMF
    MAP 3.5 human oversight processes; GOVERN 3.2 human-AI roles; MANAGE 2.4 disengage or deactivate
    ISO/IEC 42001
    A.9 use of AI systems within defined boundaries
    EU AI Act
    Article 14 human oversight designed in by providers; Article 26(2) assigned by deployers
  7. 07

    What are affected people told, and how do they get a correction?

    People cannot question an outcome they do not know AI shaped.

    NIST AI RMF
    MEASURE 2.8 transparency and accountability; MEASURE 3.3 feedback and appeal
    ISO/IEC 42001
    A.8 information for interested parties
    EU AI Act
    Article 50 transparency, from August 2, 2026; Article 26(11) informing people subject to Annex III decisions
  8. 08

    Which vendors and models are trusted, and on what terms?

    Most organizations govern AI they did not build. The contract is where responsibilities are split.

    NIST AI RMF
    GOVERN 6.1 and 6.2 third-party risk; MANAGE 3.1 and 3.2 third-party resources and pre-trained models
    ISO/IEC 42001
    A.10 third-party and customer relationships
    EU AI Act
    Article 25: rebranding or substantially modifying a high-risk system makes you its provider
  9. 09

    How is the system watched, corrected, and retired?

    The approval expires when the model, the data, the population, or the law changes.

    NIST AI RMF
    MANAGE 4.1 post-deployment monitoring; MANAGE 4.3 incidents; GOVERN 1.7 decommissioning
    ISO/IEC 42001
    Clause 9, performance evaluation; Clause 10, improvement
    EU AI Act
    Article 26(5) and (6): deployers monitor, report serious incidents, and keep logs at least six months; Articles 72 and 73 for providers

Checked September 24, 2026

The framework dates that moved in 2026.

  1. EU law

    Prohibited AI practices and the AI literacy duty begin to apply.

    artificialintelligenceact.eu timeline
  2. EU law

    Obligations for general-purpose AI models and the governance rules apply.

    European Commission
  3. Guidance

    Singapore’s IMDA publishes the Model AI Governance Framework for Agentic AI, which it describes as the first of its kind.

    IMDA press release
  4. US state law

    Colorado signs SB26-189, repealing and re-enacting its 2024 AI Act as rules for automated decision-making technology in consequential decisions.

    Colorado General Assembly
  5. EU law

    The AI Omnibus enters into force. It moves the high-risk dates, rewords the AI literacy duty, and adds a prohibition on AI that generates non-consensual intimate imagery or child sexual abuse material.

    European Commission
  6. EU law

    The remainder of the AI Act applies, including the Article 50 transparency rules. The AI Office and national authorities are responsible for enforcement.

    European Commission
  7. EU law

    The new prohibition applies. Generative systems placed on the market before August 2, 2026 must meet the Article 50(2) marking duty.

    artificialintelligenceact.eu timeline
  8. US state law

    Colorado’s SB26-189 disclosure duties begin for developers and deployers of automated decision-making technology.

    Colorado Legislative Council, final fiscal note
  9. EU law

    High-risk obligations apply to stand-alone systems in Annex III areas such as employment, education, credit, biometrics, and critical infrastructure.

    European Commission
  10. EU law

    High-risk obligations apply to AI built into regulated products listed in Annex I.

    European Commission

Dates after today are the ones set in law or published guidance as of September 24, 2026. The high-risk dates have already moved once. Recheck them before planning work around them.

ISO/IEC 42001

Certify the management system when someone will ask for proof.

Under the AI Act, a legal presumption of conformity comes from harmonised standards once they are cited in the Official Journal of the EU. The Commission’s standardisation page lists the first of them, prEN 18286 on quality management for AI Act purposes, as having entered public enquiry on October 30, 2025. ISO/IEC 42001 is a good operating backbone. It is not that presumption.

Certification is worth it when

  • Customers, partners, or procurement teams ask for third-party evidence of how you govern AI.
  • You already run a certified management system, such as ISO/IEC 27001, and can extend the same structure to AI.
  • You provide AI to other organizations and need a shared language with their auditors.

A certificate will not

  • Show that a specific AI system meets the EU AI Act.
  • Replace the conformity assessment a high-risk system needs before it reaches the EU market.
  • Cover AI outside the scope you define for the management system.
  • Lower the risk tier of any use case.

Source: European Commission, Standardisation of the AI Act, last updated August 3, 2026. LA Global Institute does not certify organizations, systems, or people.

AI governance framework FAQ

Answers to the questions people search for.

What is an AI governance framework?

It is the structure an organization uses to decide which AI it will use and on what conditions: owners with the authority to approve or stop a use case, rules for people using AI tools, a method to tier and assess each system, the evidence required before launch, and monitoring afterward. Public frameworks such as the NIST AI RMF and ISO/IEC 42001 supply the vocabulary and structure, and laws such as the EU AI Act set minimum duties. The organization’s own decisions are what turn those sources into a framework.

What are the three pillars of AI governance?

There is no official set of three pillars. Vendors and institutes publish different lists, from three pillars to five. The split this page uses is law (what you must do), a management system (how you keep doing it), and risk practice (how you judge one system). Whatever structure you choose, check that it covers all nine decisions above.

What are the five principles of AI governance?

The most widely adopted five are the values-based OECD AI Principles, adopted in 2019 and updated in May 2024, with 47 adherents: inclusive growth, sustainable development and well-being; human rights and democratic values, including fairness and privacy; transparency and explainability; robustness, security and safety; and accountability. They state values, not procedures. The nine decisions are how an organization turns them into owners and records.

What is the NIST framework for AI governance?

The NIST AI Risk Management Framework, AI RMF 1.0, released January 26, 2023. It is voluntary and organizes AI risk work into four functions: Govern, Map, Measure, and Manage, with 19 categories and 72 subcategories. Govern is cross-cutting and shapes the other three. NIST added a Generative AI Profile, NIST AI 600-1, on July 26, 2024, and states that AI RMF 1.0 is being revised under the White House AI Action Plan.

Does the EU AI Act apply to US companies?

It can. Article 2 applies the Act to providers that place AI systems on the EU market wherever they are based, and to providers and deployers outside the EU where the output of the system is used in the EU. A US employer screening applicants in the EU, or a US software company selling an AI feature to EU customers, should treat the Act as reaching that system until qualified counsel concludes otherwise.

Is ISO/IEC 42001 certification mandatory?

No. ISO/IEC 42001 is a voluntary international standard. Some customers and procurement teams ask for it, and a certificate shows an audited management system. It is not what the EU AI Act asks for: that law sets duties by role and risk class, and a certificate does not by itself show that any system meets them.

Is there an AI governance framework template I can copy?

Not one that would work. A framework is a set of decisions only your organization can make: who can stop a system, what data may enter which tool, which use cases count as high-risk for you, and what evidence a launch requires. A copied framework carries someone else’s answers. This page gives the structure and points to the Institute’s published document for each decision. The decisions themselves stay yours.

How does agentic AI change the framework?

Agents take actions, such as updating a record or making a payment, rather than only answering. Singapore’s IMDA published its Model AI Governance Framework for Agentic AI on January 22, 2026, with four dimensions: bound the risk up front by limiting an agent’s autonomy and its access to tools and data; make people accountable through checkpoints that require human approval; apply technical controls across the agent’s lifecycle; and prepare end users through transparency and training. Each maps to a decision above: bounding to decision 4, checkpoints to decision 6, lifecycle controls to decisions 5 and 9, and user preparation to decisions 3 and 7.

References show where the structure draws on public sources. They do not imply affiliation with, or endorsement by, NIST, ISO, the European Commission, the OECD, IMDA, the State of Colorado, or any other organization. OECD AI Principles.

Record each decision once

Put the framework into documents people can use.