ISO/IEC 42001:2023NIST AI Risk Management Framework (AI RMF 1.0)

ISO/IEC 42001:2023 covers 47.2% of NIST AI Risk Management Framework (AI RMF 1.0)

34 of the 72 controls in NIST AI Risk Management Framework (AI RMF 1.0) are already satisfied by evidence you collected for ISO/IEC 42001:2023. 38 are genuine gaps. Every claim below was judged against both control sets and then argued against; the ones that did not survive are published further down with the reason each failed.

47.2%
of the target already covered
34
controls evidenced
38
genuine gaps
0
claims rejected in review

This number is directional. It says how much of NIST AI Risk Management Framework (AI RMF 1.0) your ISO/IEC 42001:2023 evidence satisfies. The reverse pair is a different number, often very different, because a security standard has enormous depth for access control and almost none for lawful basis or data subject rights.

52 candidate mappings were examined and 0 were removed. Signed off 2026-08-20, review level machine verified. Mappings were judged by Claude Code rather than read line by line by a practitioner. Every claim shows its reasoning so you can check it. Ask and a practitioner will review this pair.

Where the gaps are

Coverage is never evenly spread. A source standard usually satisfies one part of a target almost completely and barely touches another, and which part is which is the thing worth knowing before you plan the work.

MAP - NIST AI RMF 1.014 of 18 evidenced, 4 to do
GOVERN - NIST AI RMF 1.09 of 19 evidenced, 10 to do
MANAGE - NIST AI RMF 1.05 of 13 evidenced, 8 to do
MEASURE - NIST AI RMF 1.06 of 22 evidenced, 16 to do

Theme level, not control level, deliberately. The per-control list of what is evidenced and what is a gap is the report itself, so publishing it here would be publishing the thing being sold.

Claims that held

A sample. Each one names the control whose evidence does the work, the control it satisfies, and why.

A.2.2AIRMF-GV-1.2argued against and upheld
The characteristics of trustworthy AI are integrated into organizational policies, processes, and procedures

A documented AI policy aligned to strategic direction is the integration into organisational policy.

A.2.2AIRMF-GV-1.4argued against and upheld
The risk management process and its outcomes are established through transparent policies, procedures, and other controls based on organizational risk priorities

The documented AI policy establishes the process and its outcomes transparently.

A.2.4AIRMF-GV-1.5argued against and upheld
Ongoing monitoring and periodic review of the risk management process and its outcomes are planned, organizational roles and responsibilities are clearly defined, including determining the frequency of periodic review

Review at planned intervals for continuing suitability, adequacy and effectiveness is this periodic review.

A.3.2AIRMF-GV-2.1argued against and upheld
Roles and responsibilities and lines of communication related to mapping, measuring, and managing AI risks are documented and are clear to individuals and teams throughout the organization

Roles and responsibilities for AI defined and allocated according to organisational needs.

A.3.3AIRMF-GV-4.1argued against and upheld
Organizational policies and practices are in place to foster a critical thinking and safety-first mindset in the design, development, deployment, and uses of AI systems to minimize negative impacts

A process enabling reporting of concerns about AI development, deployment or use is this practice.

A.5.3AIRMF-GV-4.2argued against and upheld
Organizational teams document the risks and potential impacts of the AI technology they design, develop, deploy, evaluate and use, and communicate about the impacts more broadly

Impact assessment documentation maintained and made available to interested parties.

A.6.2.8AIRMF-GV-4.3argued against and upheld
Organizational practices are in place to enable AI testing, identification of incidents, and information sharing

Event logs recorded to enable monitoring, accountability and incident investigation.

A.8.3AIRMF-GV-5.1argued against and upheld
Organizational policies and practices are in place to collect, consider, prioritize, and integrate feedback from those external to the team that developed or deployed the AI system regarding the potential individual and societal impacts related to AI risks

Mechanisms for external interested parties to report concerns or impacts.

Claims that did not hold

Nothing proposed for this pair was rejected in review. That is unusual and worth knowing rather than hiding: it means the candidate set was small and every candidate held.

The full report

Everything above is a sample. The report is every evidenced control and every gap, with the reasoning and the source document behind each one, in a form you can hand to an assessor. $299, emailed immediately.

Buy this crosswalk