Two sources, treated differently
NIST AI Risk Management Framework 1.0 (January 2023) is a voluntary US government framework, publicly available and organised into four functions, Govern, Map, Measure and Manage, with categories and subcategories beneath them. It can be referenced openly.
The NIST AI 600-1 Generative AI Profile (July 2024) is a companion to AI RMF 1.0, not a replacement. It adds GenAI-specific risk considerations and actions. IO uses it when a finding concerns models, prompts, agents, plugins, training or retrieval data, model outputs or human-AI interaction.
ISO/IEC 42001:2023 is a copyrighted international management-system standard sold under licence. Its clause numbering can be cited. Its text cannot be reproduced, closely paraphrased, or embedded in any IO output. Where this document refers to it, it refers to clause identifiers only.
That asymmetry is why the two are handled differently below, and it is not a formality, reproducing licensed standard text inside a product would be a straightforward breach.
Function-level correspondence, NIST AI RMF
| AI RMF function | What IO holds |
|---|---|
| Govern | Policy clauses carrying machine-readable thresholds, attestation currency, exception records with owner and expiry |
| Map | Observed AI tool usage, sanctioned and unsanctioned, and the data classifications reaching each |
| Measure | Intervention outcomes against AI-governance findings, with baseline and re-measurement |
| Manage | The queue of accepted, owned AI-governance work and its disposition |
The strongest of these is Map. IO observes what is actually in use at the moment of use, which is the part of AI governance most organisations cannot see the gap between the tool list in the policy and the tool list in the browser.
The weakest is Govern. IO can evidence that a policy exists, is current, is attested, and is cited by findings. It cannot evidence that the policy is right.
The supplied C-suite GenAI guide usefully distinguishes sanctioned, tolerated and unsanctioned applications and highlights plugins, connected applications, service accounts and embedded subprocessors. IO adopts that discovery taxonomy as an operational lens, but not as a standard: it is vendor guidance from Palo Alto Networks. Classification alone is also insufficient. IO asks whether the restriction, approval or monitoring attached to each class is operating and whether an intervention changed the observed behaviour.
Likewise, security-industry surveys about AI in the SOC are context, not normative evidence. Torq's 2026 survey reports demand for transparency, governance and adjustable human oversight. IO uses that as support for a risk-tiered autonomy model, while retaining the underlying survey methodology, sample and vendor sponsorship whenever a statistic is cited.
Clause-level correspondence, ISO/IEC 42001:2023
Referenced by identifier only. No clause text appears here or in any generated report.
- Clause 6, planning, risk and opportunity: IO's AI-governance risk records, their inherent scores and their measured residual
- Clause 8, operation: the executed work and its recorded disposition
- Clause 9, performance evaluation: verification outcomes, including regressions
- Clause 10, improvement: playbooks modified or retired following poor observed effectiveness
Clauses 4, 5 and 7, context, leadership and support, are not mapped. They concern organisational arrangements that produce no execution record. IO holds no evidence speaking to them and does not imply otherwise.
What this map is not
It is not a gap assessment. It is not a certification path. It does not produce a conformity statement, and no IO report will say an organisation conforms to either source.
The NIST AI RMF is voluntary guidance rather than a conformity standard. ISO/IEC 42001 conformity can be assessed only by a qualified party against the licensed standard; an IO evidence map is not that assessment.
If an auditor asks what IO contributes, the accurate answer is: dated, attributable execution evidence organised so it can be navigated against these two structures, plus a measured position on whether the interventions taken against AI-governance findings actually changed anything. The conformity judgement stays with the auditor.
A note on the temptation here
AI governance is the area where the pull toward overclaiming is strongest, because buyers are anxious and the standards are new enough that few people will check. The rule that holds this in place: IO reports what it observed and what it measured. Any sentence that would let a reader believe a standard has been satisfied is out of scope, whatever the commercial pressure to include it.
Primary and contextual sources
- NIST, AI Risk Management Framework 1.0 (opens in a new tab)
- NIST, Generative AI Profile, NIST AI 600-1 (opens in a new tab)
- ISO, ISO/IEC 42001:2023 (opens in a new tab)
- Palo Alto Networks, The C-Suite Guide to GenAI Risk Management (2024), supplied resource
- Torq, The 2026 AI SOC Leadership Report (2026), supplied vendor-sponsored survey of 450 security leaders