13.1 RAGF and NIST AI RMF
13.2 RAGF and ISO/IEC 42001
13.3 RAGF and OECD AI Principles
13.4 RAGF and EU AI Act
13.5 RAGF and FAR 52.203-13
Part IV — RAGF Implementation and Ecosystem
Chapter 13: Relationship With Existing AI Governance Standards
The Righteous AI Governance Framework (RAGF) does not seek to replace existing AI governance frameworks and standards. Rather, it is designed to complement and extend them by adding a righteousness dimension—a higher ethical standard that goes beyond risk management, compliance, and trustworthiness (Floridi et al., 2018; Jobin et al., 2019).
This chapter examines how RAGF relates to five key frameworks and standards: the NIST AI Risk Management Framework (AI RMF), ISO/IEC 42001, the OECD AI Principles, the EU AI Act, and FAR 52.203-13.

Figure 1 — RAGF and Existing AI Governance Standards: Relationship Overview
This figure illustrates the relationship between RAGF and five existing AI governance frameworks and standards — NIST AI RMF, ISO/IEC 42001, OECD AI Principles, EU AI Act, and FAR 52.203-13 — showing how RAGF extends and complements each.
13.1 RAGF and NIST AI RMF
The NIST AI Risk Management Framework (AI RMF) is a voluntary framework developed by the U.S. National Institute of Standards and Technology to help organizations manage risks associated with AI systems (National Institute of Standards and Technology, 2023). Released in January 2023, it is built on four core functions: Govern, Map, Measure, and Manage. The framework is designed to improve the ability to incorporate trustworthiness considerations into the design, development, use, and evaluation of AI products, services, and systems (NIST, 2023).
This table outlines the core aspects of the NIST AI Risk Management Framework, including its nature, core functions, primary goal, certification status, and scope.
Table 1 — NIST AI RMF: Core Focus
| Aspect | Description |
|---|---|
| Nature | Voluntary risk management guidance |
| Core Functions | Govern, Map, Measure, Manage |
| Primary Goal | Manage AI-related risks and promote trustworthy AI |
| Certification | Not certifiable; self-attestation based |
| Scope | AI systems across the lifecycle |
RAGF and NIST AI RMF — Comparison
This table compares RAGF with the NIST AI RMF across five key dimensions — core question, focus, measurement, values, and scope.
Table 2 — RAGF and NIST AI RMF: Comparison
| Dimension | NIST AI RMF | RAGF |
|---|---|---|
| Core Question | “How do we manage AI risks?” | “How do we make AI righteous?” |
| Focus | Risk mitigation and trustworthiness | Moral excellence and righteousness growth |
| Measurement | Qualitative risk assessment | Quantitative RI, RGS, RDM, RPS metrics |
| Values | Trustworthy AI (transparency, fairness, accountability) | Righteous AI (Integrity, Justice, Stewardship, Wisdom, Beneficence) |
| Scope | AI systems | Full AI lifecycle + developers + organizations + users + agents + robots |
Relationship
NIST AI RMF provides a flexible playbook for managing AI risks (NIST, 2023). RAGF builds on this foundation by adding a righteousness layer—answering not only “How do we manage risk?” but also “How do we ensure AI actively pursues what is right, true, and good?” (Floridi & Cowls, 2019).
Organizations can use NIST AI RMF to establish their risk management posture and RAGF to elevate their governance to a higher ethical standard. Where NIST asks “Is this AI trustworthy?”, RAGF asks “Is this AI righteous?” (Smuha, 2021).
13.2 RAGF and ISO/IEC 42001
ISO/IEC 42001 is the first international standard for AI management systems, providing a structured framework for organizations to govern AI responsibly (ISO/IEC, 2023). Published in December 2023, it specifies requirements for establishing, implementing, maintaining, and continually improving an AI management system within the context of an organization (ISO/IEC, 2023).
ISO/IEC 42001 — Core Focus
This table outlines the core aspects of ISO/IEC 42001, including its nature, key requirements, primary goal, certification status, and scope.
Table 3 — ISO/IEC 42001: Core Focus
| Aspect | Description |
|---|---|
| Nature | Certifiable management system standard |
| Key Requirements | AI governance policies, risk assessments, ethical compliance, monitoring, roles and responsibilities |
| Primary Goal | Establish a structured AI management system |
| Certification | Yes—formal certification available |
| Scope | Organizations that provide or use AI-enabled technologies |
RAGF and ISO/IEC 42001 — Comparison
Table Description: This table compares RAGF with ISO/IEC 42001 across five key dimensions — core question, focus, measurement, certification, and coverage.
Table 4 — RAGF and ISO/IEC 42001: Comparison
| Dimension | ISO/IEC 42001 | RAGF |
|---|---|---|
| Core Question | “How do we manage AI systems?” | “How do we make AI righteous?” |
| Focus | Management system structure | Moral governance and growth |
| Measurement | Compliance with requirements | Continuous RI, RGS, RDM, RPS metrics |
| Certification | ISO 42001 certification | RAGF Certification (righteousness validation) |
| Coverage | AI management systems | Full AI lifecycle + culture + agents + robots |
Relationship
ISO/IEC 42001 provides a structured blueprint for establishing an AI management system (ISO/IEC, 2023). RAGF complements this by providing the ethical and moral foundation that guides the management system’s purpose and direction (Dignum, 2019).
While ISO 42001 helps organizations build a system to manage AI responsibly, RAGF helps them ensure that system is oriented toward righteousness—not just compliance and risk management, but the active pursuit of integrity, justice, wisdom, stewardship, and beneficence (Floridi et al., 2018).
Organizations seeking ISO 42001 certification can use RAGF as the ethical framework that informs their management system design, ensuring that their AI governance is not only structured but also righteous (Jobin et al., 2019).
13.3 RAGF and OECD AI Principles
The OECD AI Principles are the first intergovernmental standard on AI, promoting innovative, trustworthy AI that respects human rights and democratic values (OECD, 2019). Adopted in 2019 and updated in 2024, they provide a blueprint for policy frameworks on how to address AI risks and shape AI policies (OECD, 2019).
OECD AI Principles — Core Focus
This table 5 outlines the core aspects of the OECD AI Principles, including their nature, key principles, primary goal, certification status, and scope.
Table 5 — OECD AI Principles: Core Focus
| Aspect | Description |
|---|---|
| Nature | Intergovernmental principles and policy guidance |
| Key Principles | Inclusive growth, sustainable development, human rights, democratic values, fairness, transparency, accountability |
| Primary Goal | Shape AI policies and promote trustworthy AI |
| Certification | Not applicable—policy guidance |
| Scope | National and international AI policy frameworks |
RAGF and OECD AI Principles — Comparison
This table compares RAGF with the OECD AI Principles across five key dimensions — core question, focus, measurement, scope, and values.
Table 6 — RAGF and OECD AI Principles: Comparison
| Dimension | OECD AI Principles | RAGF |
|---|---|---|
| Core Question | “What principles should guide AI policy?” | “How do we operationalize righteousness in AI governance?” |
| Focus | Policy framework and principles | Practical governance implementation |
| Measurement | Policy alignment | Quantitative RI, RGS, RDM, RPS metrics |
| Scope | National and international policy | Organizational and system-level implementation |
| Values | Trustworthy, human-centric AI | Righteous AI (Integrity, Justice, Stewardship, Wisdom, Beneficence) |
Relationship
The OECD AI Principles provide the high-level policy direction for trustworthy AI (OECD, 2019). RAGF translates these principles into operational governance practices that organizations can implement (Floridi & Cowls, 2019).
Where the OECD says “AI should respect human rights and democratic values,” RAGF provides the methodology, measurement, and accountability structures to make that a reality (Smuha, 2021). RAGF operationalizes the OECD’s aspirational principles into concrete governance activities.
RAGF can be seen as an implementation framework for the OECD AI Principles, providing organizations with the tools to turn high-level policy guidance into everyday governance practice (Jobin et al., 2019).
13.4 RAGF and EU AI Act
The EU AI Act is the world’s first comprehensive legal framework for AI, providing legally binding requirements for AI systems based on their risk level (European Parliament, 2024). It categorizes AI systems into different risk tiers—unacceptable risk, high risk, limited risk, and minimal risk—with corresponding regulatory requirements (European Parliament, 2024).
EU AI Act — Core Focus
This table outlines the core aspects of the EU AI Act, including its nature, key requirements, primary goal, certification status, and scope.
Table 7 — EU AI Act: Core Focus
| Aspect | Description |
|---|---|
| Nature | Legally binding regulation |
| Key Requirements | Risk-based classification, compliance obligations, transparency, human oversight, data governance |
| Primary Goal | Ensure AI safety and fundamental rights protection |
| Certification | Conformity assessment for high-risk AI systems |
| Scope | AI products and systems placed on the EU market |
RAGF and EU AI Act — Comparison
This table compares RAGF with the EU AI Act across five key dimensions — core question, focus, standard, measurement, and scope.
Table 8 — RAGF and EU AI Act: Comparison
| Dimension | EU AI Act | RAGF |
|---|---|---|
| Core Question | “Is this AI system compliant with the law?” | “Is this AI system righteous?” |
| Focus | Legal compliance and safety | Moral excellence and righteousness growth |
| Standard | Minimum legal requirements | Highest ethical standards |
| Measurement | Compliance/Non-compliance | Continuous RI, RGS, RDM, RPS metrics |
| Scope | AI products in EU market | Full AI lifecycle + developers + organizations + agents + robots |
Relationship
The EU AI Act establishes the legal floor for AI governance—what is minimally required by law (European Parliament, 2024). RAGF establishes the ethical ceiling—what is required for AI to be truly righteous (Floridi et al., 2018; Smuha, 2021).
Where the EU AI Act asks “Is this AI safe and compliant?”, RAGF asks “Is this AI righteous?” RAGF goes beyond legal compliance to address the higher standard of moral excellence (Dignum, 2019).
Compliance vs. Righteousness
Table 9 — Compliance Mindset vs. Righteousness Mindset
| Compliance Mindset | Righteousness Mindset |
|---|---|
| “What is the minimum we need to do?” | “What is the best we can become?” |
| “How do we avoid punishment?” | “How do we pursue excellence?” |
| “What does the law require?” | “What does righteousness require?” |
| “We must meet the standard” | “We must exceed the standard” |
RAGF provides organizations with a framework to go beyond compliance, transforming AI governance from a legal obligation into a moral commitment (Smuha, 2021).
Compliance vs. Righteousness — Two Standards of AI Governance

Figure 2 — Compliance vs. Righteousness: Two Standards of AI Governance
This figure illustrates the relationship between legal compliance and righteousness as two distinct standards for AI governance. Legal compliance is depicted as the baseline with a “pass/fail” threshold, while righteousness is depicted as a higher, continuous standard that pursues moral excellence beyond legal requirements.
13.5 RAGF and FAR 52.203-13
FAR 52.203-13, the Contractor Code of Business Ethics and Conduct, is a federal acquisition regulation clause that requires government contractors to establish a written code of business ethics and conduct, implement an ethics and compliance training program, and maintain internal controls to prevent and detect violations (U.S. Federal Acquisition Regulation, 2021). The clause applies to contracts expected to exceed a certain threshold—typically $6 million to $7.5 million—with a performance period of 120 days or more (U.S. FAR, 2021).
FAR 52.203-13 — Core Focus
This table outlines the core aspects of FAR 52.203-13, including its nature, key requirements, primary goal, enforcement mechanisms, and scope.
Table 10 — FAR 52.203-13: Core Focus
| Aspect | Description |
|---|---|
| Nature | Mandatory contract clause for federal contractors |
| Key Requirements | Written ethics code, employee training, internal controls, timely disclosure of violations |
| Primary Goal | Prevent and detect fraud, conflict of interest, bribery, and False Claims Act violations |
| Enforcement | Suspension, debarment, False Claims Act liability |
| Scope | Federal government contractors and subcontractors |
RAGF and FAR 52.203-13 — Comparison
This table compares RAGF with FAR 52.203-13 across five key dimensions — core question, focus, standard, measurement, and scope.
Table 11 — RAGF and FAR 52.203-13: Comparison
| Dimension | FAR 52.203-13 | RAGF |
|---|---|---|
| Core Question | “Are we complying with federal ethics requirements?” | “Are we governing AI righteously?” |
| Focus | Legal compliance and fraud prevention | Moral excellence and righteousness growth |
| Standard | Minimum federal requirements | Highest ethical standards |
| Measurement | Compliance/Non-compliance | Continuous RI, RGS, RDM, RPS metrics |
| Scope | Federal contractors | Full AI lifecycle + developers + organizations + agents + robots |
Relationship
FAR 52.203-13 establishes the minimum ethical requirements for federal contractors (U.S. FAR, 2021). RAGF provides a comprehensive governance framework that goes far beyond these minimum requirements (Floridi et al., 2018).
For federal contractors developing or deploying AI systems, RAGF offers a way to:
- Exceed the minimum requirements of FAR 52.203-13
- Build trust with government customers through demonstrable righteousness
- Reduce risk of violations by embedding righteousness into AI governance
- Demonstrate leadership in ethical AI governance (Smuha, 2021)
RAGF as a Compliance Enhancer
Organizations subject to FAR 52.203-13 can use RAGF to:
- Strengthen their ethics and compliance programs
- Provide evidence of a robust governance culture
- Demonstrate proactive righteousness, not just reactive compliance
- Build a competitive advantage through righteous AI governance
References
Dignum, V. (2019). Responsible artificial intelligence: How to develop and use AI in a responsible way. Springer.
European Parliament. (2024). Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Official Journal of the European Union.
Floridi, L., & Cowls, J. (2019). A unified framework of five principles for AI in society. Harvard Data Science Review, 1(1).
Floridi, L., Cowls, J., Beltrametti, M., Chatila, R., Chazerand, P., Dignum, V., … & Vayena, E. (2018). AI4People—An ethical framework for a good AI society: Opportunities, risks, principles, and recommendations. Minds and Machines, 28(4), 689–707.
ISO/IEC. (2023). ISO/IEC 42001:2023 — Information technology — Artificial intelligence — Management system. International Organization for Standardization.
Jobin, A., Ienca, M., & Vayena, E. (2019). The global landscape of AI ethics guidelines. Nature Machine Intelligence, 1(9), 389–399.
National Institute of Standards and Technology. (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0). U.S. Department of Commerce. https://doi.org/10.6028/NIST.AI.100-1
OECD. (2019). OECD Principles on Artificial Intelligence. OECD Publishing.
Smuha, N. A. (2021). From a ‘race to the bottom’ to a ‘race to the top’? The regulation of AI and the EU AI Act. European Journal of Legal Studies, 13(2), 45–72.
U.S. Federal Acquisition Regulation. (2021). 48 CFR 52.203-13 — Contractor Code of Business Ethics and Conduct.
