ServicesLive DemosMCPEngineeringAboutProcessContactGet Started
Framework Mapping

NIST, ISO 42001, and the EU AI Act
aren't three separate homeworks

NIST AI RMF is a voluntary US risk-management framework organized around four functions. ISO 42001 is an international, certifiable AI management system standard built on the same functions, expressed as auditable controls. The EU AI Act is neither voluntary nor a framework — it's binding law for organizations with EU exposure, and its obligations for high-risk systems land on the same four functions from the other direction: as legal requirements rather than best practices.

This is a conceptual alignment, not a claim of ISO 42001 certification, a control-by-control audit mapping, or legal advice — Tioga AI is not yet ISO 42001 certified, and the EU AI Act obligations shown below apply only to systems that fall into the Act's high-risk tier. It shows where the architecture behind our governance ledger already reflects what these three demand, and where a formal engagement would close the remaining gap.

GOVERN

NIST AI RMF

Policy, accountability, and oversight structures established before any AI system runs.

ISO 42001

ISO 42001 requires a documented AI policy and clearly assigned roles and responsibilities as a foundational management-system requirement — the same starting point, expressed as a certifiable clause rather than a voluntary guideline.

EU AI Act

For high-risk systems, the Act requires a quality management system and named responsibility for conformity before deployment — governance stops being optional and becomes a legal precondition to placing the system on the market.

MAP

NIST AI RMF

Identify context, risks, and impacts of an AI system before and during deployment.

ISO 42001

ISO 42001 requires a formal AI system impact assessment process — evaluating effects on individuals, groups, and society — as a management-system control, not a one-time exercise.

EU AI Act

The Act requires classifying a system into a risk tier (prohibited, high-risk, limited-risk, or minimal) before deployment — the classification itself determines which legal obligations apply, not just an internal risk rating.

MEASURE

NIST AI RMF

Track performance, cost, and quality of AI systems on an ongoing basis.

ISO 42001

ISO 42001 requires organizations to define and monitor AI-system lifecycle controls across design, development, verification, deployment, and operation — including a specific documented control for AI system lifecycle management (Annex A.6.2.4, per public secondary sources on the standard).

EU AI Act

High-risk systems require technical documentation and conformity assessment evidence maintained across the system's lifecycle — measurement that has to be producible on demand for a regulator, not just for an internal audit.

MANAGE

NIST AI RMF

Prioritize and act on risks; allocate resources to the highest-impact controls.

ISO 42001

ISO 42001 requires ongoing risk treatment and third-party/supplier management as certifiable controls — extending governance beyond systems you built in-house to AI you procured or integrated.

EU AI Act

High-risk systems require a documented human oversight mechanism as a legal requirement, not a best practice — someone with the authority and information to intervene, not just a dashboard someone might check.