Old Risk Frameworks Can't Handle AI. Here Are the New Ones That Try.

From ISO 42001 to NIST's AI RMF and ENISA's layered playbook, a clutch of frameworks is competing to define how organizations govern AI risk — each targeting a different gap.

ThreatVectr Newsdesk· 3 min read
Old Risk Frameworks Can't Handle AI. Here Are the New Ones That Try.
Share

Decades of enterprise risk management doctrine didn't anticipate large language models, adversarial inputs, or AI supply chain poisoning. The frameworks that replaced it are still young.

A new generation of AI-specific standards has arrived. None of them solve the same problem. Some tackle governance and organizational accountability; others address technical security controls, threat modeling, or regulatory alignment. Picking the right one — or the right combination — depends on where your gaps actually are.

ISO/IEC 42001

Published in December 2023 by ISO and the International Electrotechnical Commission, ISO/IEC 42001 is the first internationally recognized formal management system standard for AI. It mirrors the structure of ISO 27001. Organizations must document how they design, monitor, validate, and control AI systems, conduct AI impact assessments, and demonstrate governance over third-party suppliers and data pipelines.

It is voluntary, certifiable, and sector-agnostic. A growing number of organizations use it to show alignment with the EU AI Act.

Nicole Carignan, CISO at Darktrace, calls it the strongest foundation for building an AI risk program. "It forces organizations to think holistically about ownership, governance, oversight, data integrity, security risk mitigation, accountability, and continuous improvement," she says. The downside: it is resource-intensive, and the full standard is paywalled — a real barrier for organizations early in their AI governance journey.

NIST AI RMF

Released in January 2023, the NIST AI Risk Management Framework is public, free, and built around four interconnected functions: Govern, Map, Measure, and Manage. It does not hand out pass/fail grades. That matters.

Ram Varadarajan, CEO at Acalvio, recommends it as a first stop because "it forces the three conversations that have to happen first: who owns AI risk, what AI is actually running, and who gets hurt if something goes wrong." Forrester analysts welcomed the framework but flagged conflicts of interest among its drafters, a missing data governance layer, and its descriptive — rather than prescriptive — character. Chief data officers applying it need to interpret carefully.

ENISA FAICP

The European Union Agency for Cybersecurity published its Framework for AI Cybersecurity Practices in June 2023, designed explicitly to anticipate the EU AI Act. It runs across three layers: foundational IT security practices, AI-specific risks including adversarial attacks and model tampering, and sector-specific guidance for energy, healthcare, and telecoms.

FAICP is voluntary, but EU regulators treat it as a governance baseline for any organization operating inside the bloc. Varadarajan's prediction: "Europe's AI Act will likely become the global reference point, the same way Europe's data privacy law became the de facto standard for companies worldwide regardless of where they're headquartered."

The broader takeaway is that these frameworks are not rivals. Carignan puts it plainly: "There is overlap across these frameworks, but that overlap is helpful — it reinforces the core practices organizations need to get right." Governance, data integrity, accountability, continuous improvement. The fundamentals haven't changed. The attack surface has.

© 2026 Threat Vectr