Exec × AI
EMEA Edition

ISO 42001 · NIST AI RMF · ISO 27001

Four AI standards, side by side, in plain English

The standards reader you can hand to your audit committee without further translation.

How the reader reads

You can compare ISO 42001, NIST AI RMF, ISO 27001 and the EU AI Act on the same page across the same controls. The mapping is open-source and updated quarterly.

Where two standards say the same thing in different language, the ledger says so and lists the control once. Audit clients save approximately 40 per cent of their first-year ISO 42001 implementation cost when an existing ISO 27001 baseline is mapped first.

We will not sell you a certification. We will sell you the controls a certification body will accept.

Cross-standard mapping

ControlNIST AI RMFISO/IEC 27001
Risk managementClause 6MAP / MEASUREA.6.1Article 9
DocumentationClause 7.5GOVERNA.5Annex IV
Human oversightClause 9.3MANAGEA.5.36Article 14
Data governanceClause 8.2MAP-2.3A.5.34Article 10
Post-market monitoringClause 10MEASUREA.8.16Article 17
“Most of the work is already done in your existing 27001 file.”
From the editor's letter