Organisations preparing for AI governance often meet three names at once: the EU AI Act, ISO 42001 and the NIST AI Risk Management Framework. Treated separately they look like three projects. Mapped together they share most of their substance.

Where they meet

All three ask for the same core practices. A record of the AI systems in use. A risk assessment for each. Human oversight, monitoring after deployment, and documentation that a reviewer can follow. The Act makes several of these a legal duty for high-risk systems. ISO 42001 frames them as a management system that can be certified. The NIST framework sets them out as voluntary functions. The underlying evidence is largely one body of work.

The practical gain

Mapping the frameworks once, then gathering evidence against the combined set, avoids running three parallel exercises. A control that satisfies ISO 42001 usually answers an Act obligation and a NIST function at the same time. The saving comes from recognising that before the work starts.

Part of our guide: EU AI Act compliance for UK organisations.

Map once, evidence once

HEX 165 assesses your systems against these frameworks together rather than one at a time. Get in touch or read more about HEX 165.