Chapter 13: Relationship With Existing AI Governance Standards

13.1 RAGF and NIST AI RMF
13.2 RAGF and ISO/IEC 42001
13.3 RAGF and OECD AI Principles
13.4 RAGF and EU AI Act
13.5 RAGF and FAR 52.203-13

Part IV — RAGF Implementation and Ecosystem
Chapter 13: Relationship With Existing AI Governance Standards

The Righteous AI Governance Framework (RAGF) does not seek to replace existing AI governance frameworks and standards. Rather, it is designed to complement and extend them by adding a righteousness dimension—a higher ethical standard that goes beyond risk management, compliance, and trustworthiness (Floridi et al., 2018; Jobin et al., 2019).

This chapter examines how RAGF relates to five key frameworks and standards: the NIST AI Risk Management Framework (AI RMF), ISO/IEC 42001, the OECD AI Principles, the EU AI Act, and FAR 52.203-13.

Figure 1 — RAGF and Existing AI Governance Standards: Relationship Overview

This figure illustrates the relationship between RAGF and five existing AI governance frameworks and standards — NIST AI RMF, ISO/IEC 42001, OECD AI Principles, EU AI Act, and FAR 52.203-13 — showing how RAGF extends and complements each.


13.1 RAGF and NIST AI RMF

The NIST AI Risk Management Framework (AI RMF) is a voluntary framework developed by the U.S. National Institute of Standards and Technology to help organizations manage risks associated with AI systems (National Institute of Standards and Technology, 2023). Released in January 2023, it is built on four core functions: Govern, Map, Measure, and Manage. The framework is designed to improve the ability to incorporate trustworthiness considerations into the design, development, use, and evaluation of AI products, services, and systems (NIST, 2023).

This table outlines the core aspects of the NIST AI Risk Management Framework, including its nature, core functions, primary goal, certification status, and scope.

Table 1 — NIST AI RMF: Core Focus

AspectDescription
NatureVoluntary risk management guidance
Core FunctionsGovern, Map, Measure, Manage
Primary GoalManage AI-related risks and promote trustworthy AI
CertificationNot certifiable; self-attestation based
ScopeAI systems across the lifecycle

RAGF and NIST AI RMF — Comparison

This table compares RAGF with the NIST AI RMF across five key dimensions — core question, focus, measurement, values, and scope.

Table 2 — RAGF and NIST AI RMF: Comparison

DimensionNIST AI RMFRAGF
Core Question“How do we manage AI risks?”“How do we make AI righteous?”
FocusRisk mitigation and trustworthinessMoral excellence and righteousness growth
MeasurementQualitative risk assessmentQuantitative RI, RGS, RDM, RPS metrics
ValuesTrustworthy AI (transparency, fairness, accountability)Righteous AI (Integrity, Justice, Stewardship, Wisdom, Beneficence)
ScopeAI systemsFull AI lifecycle + developers + organizations + users + agents + robots

Relationship

NIST AI RMF provides a flexible playbook for managing AI risks (NIST, 2023). RAGF builds on this foundation by adding a righteousness layer—answering not only “How do we manage risk?” but also “How do we ensure AI actively pursues what is right, true, and good?” (Floridi & Cowls, 2019).

Organizations can use NIST AI RMF to establish their risk management posture and RAGF to elevate their governance to a higher ethical standard. Where NIST asks “Is this AI trustworthy?”, RAGF asks “Is this AI righteous?” (Smuha, 2021).


13.2 RAGF and ISO/IEC 42001

ISO/IEC 42001 is the first international standard for AI management systems, providing a structured framework for organizations to govern AI responsibly (ISO/IEC, 2023). Published in December 2023, it specifies requirements for establishing, implementing, maintaining, and continually improving an AI management system within the context of an organization (ISO/IEC, 2023).


ISO/IEC 42001 — Core Focus

This table outlines the core aspects of ISO/IEC 42001, including its nature, key requirements, primary goal, certification status, and scope.

Table 3 — ISO/IEC 42001: Core Focus

AspectDescription
NatureCertifiable management system standard
Key RequirementsAI governance policies, risk assessments, ethical compliance, monitoring, roles and responsibilities
Primary GoalEstablish a structured AI management system
CertificationYes—formal certification available
ScopeOrganizations that provide or use AI-enabled technologies

RAGF and ISO/IEC 42001 — Comparison

Table Description: This table compares RAGF with ISO/IEC 42001 across five key dimensions — core question, focus, measurement, certification, and coverage.

Table 4 — RAGF and ISO/IEC 42001: Comparison

DimensionISO/IEC 42001RAGF
Core Question“How do we manage AI systems?”“How do we make AI righteous?”
FocusManagement system structureMoral governance and growth
MeasurementCompliance with requirementsContinuous RI, RGS, RDM, RPS metrics
CertificationISO 42001 certificationRAGF Certification (righteousness validation)
CoverageAI management systemsFull AI lifecycle + culture + agents + robots

Relationship

ISO/IEC 42001 provides a structured blueprint for establishing an AI management system (ISO/IEC, 2023). RAGF complements this by providing the ethical and moral foundation that guides the management system’s purpose and direction (Dignum, 2019).

While ISO 42001 helps organizations build a system to manage AI responsibly, RAGF helps them ensure that system is oriented toward righteousness—not just compliance and risk management, but the active pursuit of integrity, justice, wisdom, stewardship, and beneficence (Floridi et al., 2018).

Organizations seeking ISO 42001 certification can use RAGF as the ethical framework that informs their management system design, ensuring that their AI governance is not only structured but also righteous (Jobin et al., 2019).


13.3 RAGF and OECD AI Principles

The OECD AI Principles are the first intergovernmental standard on AI, promoting innovative, trustworthy AI that respects human rights and democratic values (OECD, 2019). Adopted in 2019 and updated in 2024, they provide a blueprint for policy frameworks on how to address AI risks and shape AI policies (OECD, 2019).


OECD AI Principles — Core Focus

This table 5 outlines the core aspects of the OECD AI Principles, including their nature, key principles, primary goal, certification status, and scope.

Table 5 — OECD AI Principles: Core Focus

AspectDescription
NatureIntergovernmental principles and policy guidance
Key PrinciplesInclusive growth, sustainable development, human rights, democratic values, fairness, transparency, accountability
Primary GoalShape AI policies and promote trustworthy AI
CertificationNot applicable—policy guidance
ScopeNational and international AI policy frameworks

RAGF and OECD AI Principles — Comparison

This table compares RAGF with the OECD AI Principles across five key dimensions — core question, focus, measurement, scope, and values.

Table 6 — RAGF and OECD AI Principles: Comparison

DimensionOECD AI PrinciplesRAGF
Core Question“What principles should guide AI policy?”“How do we operationalize righteousness in AI governance?”
FocusPolicy framework and principlesPractical governance implementation
MeasurementPolicy alignmentQuantitative RI, RGS, RDM, RPS metrics
ScopeNational and international policyOrganizational and system-level implementation
ValuesTrustworthy, human-centric AIRighteous AI (Integrity, Justice, Stewardship, Wisdom, Beneficence)

Relationship

The OECD AI Principles provide the high-level policy direction for trustworthy AI (OECD, 2019). RAGF translates these principles into operational governance practices that organizations can implement (Floridi & Cowls, 2019).

Where the OECD says “AI should respect human rights and democratic values,” RAGF provides the methodology, measurement, and accountability structures to make that a reality (Smuha, 2021). RAGF operationalizes the OECD’s aspirational principles into concrete governance activities.

RAGF can be seen as an implementation framework for the OECD AI Principles, providing organizations with the tools to turn high-level policy guidance into everyday governance practice (Jobin et al., 2019).


13.4 RAGF and EU AI Act

The EU AI Act is the world’s first comprehensive legal framework for AI, providing legally binding requirements for AI systems based on their risk level (European Parliament, 2024). It categorizes AI systems into different risk tiers—unacceptable risk, high risk, limited risk, and minimal risk—with corresponding regulatory requirements (European Parliament, 2024).


EU AI Act — Core Focus

This table outlines the core aspects of the EU AI Act, including its nature, key requirements, primary goal, certification status, and scope.

Table 7 — EU AI Act: Core Focus

AspectDescription
NatureLegally binding regulation
Key RequirementsRisk-based classification, compliance obligations, transparency, human oversight, data governance
Primary GoalEnsure AI safety and fundamental rights protection
CertificationConformity assessment for high-risk AI systems
ScopeAI products and systems placed on the EU market

RAGF and EU AI Act — Comparison

This table compares RAGF with the EU AI Act across five key dimensions — core question, focus, standard, measurement, and scope.

Table 8 — RAGF and EU AI Act: Comparison

DimensionEU AI ActRAGF
Core Question“Is this AI system compliant with the law?”“Is this AI system righteous?”
FocusLegal compliance and safetyMoral excellence and righteousness growth
StandardMinimum legal requirementsHighest ethical standards
MeasurementCompliance/Non-complianceContinuous RI, RGS, RDM, RPS metrics
ScopeAI products in EU marketFull AI lifecycle + developers + organizations + agents + robots

Relationship

The EU AI Act establishes the legal floor for AI governance—what is minimally required by law (European Parliament, 2024). RAGF establishes the ethical ceiling—what is required for AI to be truly righteous (Floridi et al., 2018; Smuha, 2021).

Where the EU AI Act asks “Is this AI safe and compliant?”, RAGF asks “Is this AI righteous?” RAGF goes beyond legal compliance to address the higher standard of moral excellence (Dignum, 2019).

Compliance vs. Righteousness

Table 9 — Compliance Mindset vs. Righteousness Mindset

Compliance MindsetRighteousness Mindset
“What is the minimum we need to do?”“What is the best we can become?”
“How do we avoid punishment?”“How do we pursue excellence?”
“What does the law require?”“What does righteousness require?”
“We must meet the standard”“We must exceed the standard”

RAGF provides organizations with a framework to go beyond compliance, transforming AI governance from a legal obligation into a moral commitment (Smuha, 2021).


Compliance vs. Righteousness — Two Standards of AI Governance

Figure 2 — Compliance vs. Righteousness: Two Standards of AI Governance

This figure illustrates the relationship between legal compliance and righteousness as two distinct standards for AI governance. Legal compliance is depicted as the baseline with a “pass/fail” threshold, while righteousness is depicted as a higher, continuous standard that pursues moral excellence beyond legal requirements.


13.5 RAGF and FAR 52.203-13

FAR 52.203-13, the Contractor Code of Business Ethics and Conduct, is a federal acquisition regulation clause that requires government contractors to establish a written code of business ethics and conduct, implement an ethics and compliance training program, and maintain internal controls to prevent and detect violations (U.S. Federal Acquisition Regulation, 2021). The clause applies to contracts expected to exceed a certain threshold—typically $6 million to $7.5 million—with a performance period of 120 days or more (U.S. FAR, 2021).


FAR 52.203-13 — Core Focus

This table outlines the core aspects of FAR 52.203-13, including its nature, key requirements, primary goal, enforcement mechanisms, and scope.

Table 10 — FAR 52.203-13: Core Focus

AspectDescription
NatureMandatory contract clause for federal contractors
Key RequirementsWritten ethics code, employee training, internal controls, timely disclosure of violations
Primary GoalPrevent and detect fraud, conflict of interest, bribery, and False Claims Act violations
EnforcementSuspension, debarment, False Claims Act liability
ScopeFederal government contractors and subcontractors

RAGF and FAR 52.203-13 — Comparison

This table compares RAGF with FAR 52.203-13 across five key dimensions — core question, focus, standard, measurement, and scope.

Table 11 — RAGF and FAR 52.203-13: Comparison

DimensionFAR 52.203-13RAGF
Core Question“Are we complying with federal ethics requirements?”“Are we governing AI righteously?”
FocusLegal compliance and fraud preventionMoral excellence and righteousness growth
StandardMinimum federal requirementsHighest ethical standards
MeasurementCompliance/Non-complianceContinuous RI, RGS, RDM, RPS metrics
ScopeFederal contractorsFull AI lifecycle + developers + organizations + agents + robots

Relationship

FAR 52.203-13 establishes the minimum ethical requirements for federal contractors (U.S. FAR, 2021). RAGF provides a comprehensive governance framework that goes far beyond these minimum requirements (Floridi et al., 2018).

For federal contractors developing or deploying AI systems, RAGF offers a way to:

  1. Exceed the minimum requirements of FAR 52.203-13
  2. Build trust with government customers through demonstrable righteousness
  3. Reduce risk of violations by embedding righteousness into AI governance
  4. Demonstrate leadership in ethical AI governance (Smuha, 2021)

RAGF as a Compliance Enhancer

Organizations subject to FAR 52.203-13 can use RAGF to:

  • Strengthen their ethics and compliance programs
  • Provide evidence of a robust governance culture
  • Demonstrate proactive righteousness, not just reactive compliance
  • Build a competitive advantage through righteous AI governance

References

Dignum, V. (2019). Responsible artificial intelligence: How to develop and use AI in a responsible way. Springer.

European Parliament. (2024). Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Official Journal of the European Union.

Floridi, L., & Cowls, J. (2019). A unified framework of five principles for AI in society. Harvard Data Science Review, 1(1).

Floridi, L., Cowls, J., Beltrametti, M., Chatila, R., Chazerand, P., Dignum, V., … & Vayena, E. (2018). AI4People—An ethical framework for a good AI society: Opportunities, risks, principles, and recommendations. Minds and Machines, 28(4), 689–707.

ISO/IEC. (2023). ISO/IEC 42001:2023 — Information technology — Artificial intelligence — Management system. International Organization for Standardization.

Jobin, A., Ienca, M., & Vayena, E. (2019). The global landscape of AI ethics guidelines. Nature Machine Intelligence, 1(9), 389–399.

National Institute of Standards and Technology. (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0). U.S. Department of Commerce. https://doi.org/10.6028/NIST.AI.100-1

OECD. (2019). OECD Principles on Artificial Intelligence. OECD Publishing.

Smuha, N. A. (2021). From a ‘race to the bottom’ to a ‘race to the top’? The regulation of AI and the EU AI Act. European Journal of Legal Studies, 13(2), 45–72.

U.S. Federal Acquisition Regulation. (2021). 48 CFR 52.203-13 — Contractor Code of Business Ethics and Conduct.