Cohort: the five foundational AI risk-management instruments enterprises and governments anchor on: compared on type, legal status, structure, lifecycle coverage, auditability, risk-tiering, and how they interlock (the RMF process layer, ISO's certifiable management system, and the OECD/HLEG principles layer). Cell convention: concise treatment +
[key].—= source is silent / does not address this dimension.
Column keys: [NIST-RMF] NIST AI RMF 1.0 · [600-1] NIST AI 600-1 GenAI Profile · [ISO] ISO/IEC 42001:2023 AIMS · [OECD] OECD AI Principles · [HLEG] EU HLEG Ethics Guidelines for Trustworthy AI
| Dimension | NIST AI RMF 1.0 [NIST-RMF] | NIST AI 600-1 GenAI Profile [600-1] | ISO/IEC 42001:2023 [ISO] | OECD AI Principles [OECD] | EU HLEG Guidelines [HLEG] |
|---|---|---|---|---|---|
| Type | Voluntary process framework for managing AI risk [NIST-RMF] | Companion profile that extends the RMF to generative AI [600-1] | Certifiable management-system standard (AIMS), Annex SL family [ISO] | Intergovernmental values-based principles [OECD] | Expert-group ethics guidelines [HLEG] |
| Legal status | Voluntary; not enforcement-backed, but the de facto US technical reference [NIST-RMF] | Voluntary; most-cited US government GenAI-risk reference [600-1] | Voluntary to adopt but third-party certifiable by accredited auditors [ISO] | Soft-law; adopted by 40+ countries + G20: most broadly subscribed framework [OECD] | Soft-law guidance; fed directly into binding EU AI Act high-risk obligations [HLEG] |
| Core structure | Four functions: GOVERN (cross-cutting) · MAP · MEASURE · MANAGE, broken into categories/subcategories [NIST-RMF] | Same four RMF functions, each given GenAI-specific suggested actions tagged to risk categories [600-1] | Clauses 4–10 (PDCA management system) + Annex A (~38 controls / 9 objectives): secondary-sourced; normative text paywalled [ISO] | 5 values-based principles + 5 policy recommendations to governments [OECD] | 3 components (lawful/ethical/robust) · 4 ethical principles · 7 key requirements [HLEG] |
| Substantive content | 7 trustworthiness characteristics (valid/reliable, safe, secure, accountable/transparent, explainable, privacy-enhanced, fair): noted as interrelated and in tension [NIST-RMF] | 12 GenAI risk categories (CBRN, confabulation, data privacy, harmful bias, info integrity/security, IP, value-chain, etc.) [600-1] | Control domains: AI policy, impact assessment, AI system life cycle, data for AI, third-party relationships, responsible use (secondary summary) [ISO] | Inclusive growth · rule of law/human rights/fairness/privacy · transparency · robustness/security/safety · accountability [OECD] | Human agency/oversight · technical robustness · privacy/data governance · transparency · diversity/non-discrimination · societal/environmental well-being · accountability [HLEG] |
| Lifecycle coverage | Explicit lifecycle: Plan & Design → Data → Build → V&V → Deploy → Operate & Monitor, with TEVV running throughout [NIST-RMF] | Inherits RMF lifecycle; emphasizes value-chain inheritance + speed-of-harm at scale [600-1] | Clause 8 covers AI system life-cycle processes; PDCA = continual improvement loop [ISO] | 2024 update stresses safety throughout the lifecycle, not just deployment [OECD] | Requirements apply across design and operation; ALTAI operationalizes per-system [HLEG] |
| Risk-tiering | No fixed risk tiers: risk treated contextually via MAP/MEASURE [NIST-RMF] | No tiers; 12-category risk taxonomy instead [600-1] | Risk-based: Clause 6 AI risk + AI impact assessment, no prescribed tier bands [ISO] | Risk "continually assessed and managed"; no tiers [OECD] | Risk-based ethos that became the AI Act's tiers, but the Guidelines themselves set no tiers [HLEG] |
| Auditability / certifiability | Not certifiable; self-assessed against functions [NIST-RMF] | Not certifiable; map suggested actions to existing controls [600-1] | The only certifiable member: accredited audit against clauses + Annex A [ISO] | Not auditable; HAIP Reporting Framework offers voluntary transparency [OECD] | ALTAI self-assessment checklist (hundreds of questions); self-attested, not certified [HLEG] |
| Operationalization tooling | Categories/subcategories + companion Profiles [NIST-RMF] | Suggested actions mapped to RMF functions; working enterprise vocabulary [600-1] | Documented information, internal audit, management review (Clause 9) [ISO] | AI Policy Observatory + HAIP Reporting Framework for G7 Hiroshima CoC [OECD] | ALTAI self-assessment list (standalone tool, July 2020) [HLEG] |
| How it interlocks | Parent framework; maps cleanly onto ISO 42001's structure; US enterprises anchor here [NIST-RMF] | **A profile of the RMF**. Cannot stand alone; extends parent to GenAI [600-1] | The certifiable management system that maps onto RMF functions; NIST = process, ISO = auditable system [ISO] | The principles layer; echoed by EU AI Act preamble, G7 Hiroshima, most national strategies [OECD] | The principles→law bridge: Guidelines → White Paper → AI Act high-risk obligations (Arts 9–17) [HLEG] |
| Evidence limits | Framework description | Framework description | Secondary summaries; normative text paywalled | Framework description | Framework description |
How to read this
- Three layers, not five peers. These instruments operate at different altitudes: OECD and HLEG are the principles layer (what trustworthy AI should be), NIST RMF is the process layer (how to manage the risk), and ISO/IEC 42001 is the auditable management-system layer (how to prove you do). 600-1 is not a peer at all. It is a profile of the RMF, so it inherits the parent's structure and only adds GenAI-specific risk content.
- Only ISO is certifiable, and that's why procurement asks for it. NIST RMF, OECD, and HLEG are all self-assessed (HLEG via ALTAI, RMF via its functions); none yields a third-party certificate. ISO/IEC 42001 alone supports accredited audit, which is why enterprise buyers increasingly demand "ISO 42001 certified or roadmap." The trade-off: ISO's normative content is paywalled, so the structural description here relies on secondary sources, the opposite of the fully-open NIST/OECD/HLEG texts.
- None of these tiers risk; the EU AI Act did. Despite "risk management" in their names, no member here imposes the EU's high/limited/minimal risk bands. NIST treats risk contextually (MAP/MEASURE), ISO via impact assessment, and HLEG's risk-based ethos only became tiered after it was translated into the binding AI Act. The risk-tiering lives in the regulation, not the frameworks.
- GenAI is bolted on, not native. Only 600-1 (2024) and the OECD 2024 update were written for generative/general-purpose AI; confabulation, value-chain inheritance, and synthetic-media risks have no clean parallel in the 2019–2023 instruments. RMF 1.0, ISO 42001, and the 2019 HLEG Guidelines predate the GenAI risk surface and address it only through later profiles/updates.
- They converge on the same trustworthiness vocabulary. RMF's 7 characteristics, OECD's 5 principles, and HLEG's 7 requirements overlap heavily (transparency, robustness/safety, fairness/non-discrimination, accountability, privacy). The practical implication: an organization can satisfy all three principles-layer frameworks with one well-built RMF/ISO program, the divergence is in enforceability and proof, not in what counts as trustworthy.
Sources
NIST AI RMF 1.0 · NIST AI 600-1 GenAI Profile · ISO/IEC 42001 AI Management System · OECD AI Principles · EU HLEG Ethics Guidelines for Trustworthy AI
Refresh when any member ships a revision (watch for an ISO/IEC 42001 amendment or a new NIST RMF Profile). The ISO row is structural-only until a licensed copy is available for verbatim normative verification.