Introduction
Three AI governance frameworks dominate the 2026 conversation: ISO/IEC 42001 (the international standard), the NIST AI Risk Management Framework (US, voluntary but increasingly de facto), and the EU AI Act (regulation with teeth). Indian enterprises building or operating AI systems are increasingly being asked to map to one or more.
This is the engineer’s read — what each actually requires, where they overlap, and how to implement once and satisfy many.
What Happened
The three frameworks emerged from different starting points and have converged on overlapping outcomes:
- ISO/IEC 42001:2023 — AI management system standard. Certifiable. Process-focused.
- NIST AI RMF 1.0 (2023, with updates) — voluntary framework. Function-focused: Govern, Map, Measure, Manage.
- EU AI Act (2024–2027 phased) — risk-based regulation. Prohibits some uses; heavy obligations on “high-risk” systems.
Each framework produces some unique requirements, but the overlap is substantial. The savvy implementation maps once to a shared control catalogue, then traces requirements back to each framework.
Technical Breakdown
ISO/IEC 42001. Modelled on ISO 27001:2022’s management-system pattern. Requires: AI policy, leadership commitment, AI risk assessment, lifecycle controls (data, model, deployment, monitoring), human oversight design, documentation, internal audit, management review. Certifiable through accredited bodies. Practitioner cost: process maturity, less technical.
NIST AI RMF. Four core functions:
- Govern — establish culture and structure.
- Map — context, stakeholders, risk identification.
- Measure — assess and track AI system performance and risk.
- Manage — prioritise and respond.
Voluntary. Highly cross-mapped. Strong on trustworthy-AI characteristics: validity, reliability, safety, security, accountability, explainability, fairness, privacy.
EU AI Act. Risk-tiered:
- Prohibited uses (social scoring, exploitative manipulation, etc.).
- High-risk systems (employment, education, critical infrastructure, biometrics) face heavy obligations: risk management, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy/robustness, post-market monitoring.
- Limited-risk systems need transparency obligations (e.g., disclosure when interacting with AI).
- Minimal-risk mostly unregulated.
Extra-territorial: applies to systems producing output used in the EU, regardless of where the provider is. Indian SaaS serving EU customers is in scope.
Why This Matters
For developers. Most of the technical controls are the same across frameworks: model documentation, training-data lineage, evals, monitoring, incident response. Build them once.
For enterprises. The differentiating bits are: certification (ISO 42001), mandatory CE-marking for high-risk (EU AI Act), and conformity assessment (EU AI Act). Plan certification timing if you sell into the EU.
For India specifically. No DPDP-equivalent for AI exists yet (DPDP covers personal data, not AI risk broadly), but signals from MeitY suggest ISO 42001 will be the reference framework. Early adopters will have less retrofit work when Indian AI rules formalise.
RingSafe Analysis
The mapping that works in practice — a single control catalogue, traced to each framework:
- AI inventory. Every AI system, with purpose, training data sources, model, deployment surface, owner, risk classification.
- ISO 42001: required (Clause 6.1).
- NIST AI RMF: Map function.
- EU AI Act: required for high-risk (Article 11).
- Risk assessment per system. Per-deployment, not org-wide.
- ISO 42001: clause 6.1.
- NIST: Map + Measure.
- EU AI Act: required for high-risk (Article 9).
- Model documentation. Datasheets, model cards, training-data lineage, intended use.
- All three require it; format and depth vary.
- Evals + monitoring. Pre-deployment validation, ongoing monitoring, drift detection.
- All three require it.
- Human oversight. Documented design for when humans review AI decisions, the mechanism for override.
- EU AI Act is most specific (Article 14); the others require it in principle.
- Incident response. Process for AI-specific incidents (jailbreak in production, model bias incident, breach).
- All three require it; EU AI Act has reporting obligations for serious incidents.
For Indian enterprises, the recommended sequence in 2026:
- DPDP first. Hard regulatory obligation. Personal-data focus.
- ISO 42001 next. Sets up the management-system muscle that other frameworks reuse.
- NIST AI RMF mapping. Light additional cost; useful for US enterprise sales.
- EU AI Act only if relevant. Required if you serve EU customers or process EU data; expensive otherwise.
Key Takeaways
- Three major AI governance frameworks: ISO/IEC 42001, NIST AI RMF, EU AI Act. Significant overlap.
- Build a single control catalogue; trace to each framework’s requirements.
- ISO 42001 is certifiable and process-focused; EU AI Act is risk-tiered and mandatory for high-risk; NIST AI RMF is voluntary but widely adopted.
- For Indian enterprises: DPDP first, ISO 42001 next, EU AI Act only if EU-serving.
- Engineers carry most of the technical controls. The governance frameworks add documentation, audit, and process layers on top.
Conclusion
AI governance is the slow-moving but inevitable companion to AI engineering. The teams that build governance in early — by treating it as an extension of existing security and quality engineering — pay a small ongoing cost. The teams that defer until forced pay a much larger one, often in the middle of a regulator’s investigation. The frameworks are converging; the work is now mostly implementation.
For Indian-context AI compliance, see RingSafe’s AI Compliance India module and the DPDP Compliance Hub.
Get a free attack-surface review
We check what an attacker would see about your business — leaked credentials, exposed services, dark-web mentions. 30 minutes, no obligation.