NIST / ISO / EU AI Act Mapping

Appendix K — NIST / ISO / EU AI Act Mapping

This appendix provides a detailed mapping between the Righteous AI Governance Framework (RAGF) and three major existing AI governance frameworks and standards:

  1. NIST AI Risk Management Framework (AI RMF 1.0) — U.S. voluntary risk management guidance
  2. ISO/IEC 42001:2023 — International standard for AI management systems
  3. EU AI Act — EU legally binding regulation with risk-based compliance requirements

K.1 Mapping Overview

RAGF is designed to complement and extend these existing frameworks. While NIST AI RMF, ISO/IEC 42001, and the EU AI Act focus on risk management, compliance, and trustworthiness, RAGF adds a righteousness dimension—the active pursuit of integrity, justice, stewardship, wisdom, and beneficence in AI governance.

FrameworkNaturePrimary FocusRAGF Relationship
NIST AI RMFVoluntary risk guidanceManage AI risks and promote trustworthy AIRAGF adds a righteousness layer on top of risk management
ISO/IEC 42001Certifiable management systemEstablish AI management systemRAGF provides the ethical foundation for the management system
EU AI ActLegally binding regulationEnsure AI safety, fundamental rights, and complianceRAGF goes beyond compliance to moral excellence

K.2 RAGF and NIST AI RMF Mapping

The NIST AI RMF is built on four core functions: Govern, Map, Measure, and Manage. These functions provide a structured approach to managing AI risks throughout the AI lifecycle.

K.2.1 Mapping Table

NIST AI RMF FunctionNIST AI RMF CategoryRAGF LayerRAGF PillarAlignment Description
GOVERNOrganizational culture, policies, rolesLayer 1: Righteousness FoundationStewardshipBoth establish organizational commitment and accountability structures
GOVERNRisk management strategyLayer 2: Policy and ProcessStewardshipBoth define governance policies and processes
MAPContext identificationLayer 3: Map and AnalyzeWisdomBoth identify system context, stakeholders, and risks
MAPSystem classificationLayer 3: Map and AnalyzeJusticeBoth classify systems by risk and impact
MEASURERisk assessmentLayer 4: Measure and MonitorAll PillarsBoth assess and quantify AI risks and performance
MEASUREMonitoring and evaluationLayer 4: Measure and MonitorAll PillarsBoth enable continuous monitoring and evaluation
MANAGERisk treatmentLayer 5: Manage and ControlStewardshipBoth implement controls and safeguards
MANAGEIncident responseLayer 5: Manage and ControlStewardshipBoth establish incident response procedures

K.2.2 RAGF Extension of NIST AI RMF

DimensionNIST AI RMFRAGF Extension
Core Question“How do we manage AI risks?”“How do we make AI righteous?”
FocusRisk mitigation and trustworthinessMoral excellence and righteousness growth
MeasurementQualitative risk assessmentQuantitative RI, RGS, RDM, RPS metrics
ValuesTrustworthy AI (transparency, fairness, accountability)Righteous AI (Integrity, Justice, Stewardship, Wisdom, Beneficence)
ScopeAI systemsFull AI lifecycle + developers + organizations + agents + robots

K.3 RAGF and ISO/IEC 42001 Mapping

ISO/IEC 42001 specifies requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System (AIMS) within an organization. It provides a certifiable framework to map regulatory requirements to engineering practices.

K.3.1 Mapping Table

ISO/IEC 42001 ClauseISO/IEC 42001 RequirementRAGF LayerRAGF PillarAlignment Description
Clause 4Context of the organizationLayer 3: Map and AnalyzeWisdomBoth require understanding organizational context and stakeholder needs
Clause 5Leadership and commitmentLayer 1: Righteousness FoundationStewardshipBoth require leadership commitment to AI governance
Clause 6Planning (risks and opportunities)Layer 3: Map and AnalyzeWisdomBoth require risk identification and planning
Clause 7Support (resources, competence, awareness)Layer 2: Policy and ProcessStewardshipBoth require resource allocation and capability building
Clause 8Operation (planning and control)Layer 5: Manage and ControlStewardshipBoth require operational controls and safeguards
Clause 9Performance evaluation (monitoring, audit)Layer 4: Measure and MonitorAll PillarsBoth require monitoring, measurement, and audit
Clause 10Improvement (nonconformity, corrective action)Layer 7: Sustain and ImproveAll PillarsBoth require continuous improvement and corrective action

K.3.2 RAGF Extension of ISO/IEC 42001

DimensionISO/IEC 42001RAGF Extension
Core Question“How do we manage AI systems?”“How do we make AI righteous?”
FocusManagement system structureMoral governance and growth
MeasurementCompliance with requirementsContinuous RI, RGS, RDM, RPS metrics
CertificationISO 42001 certificationRAGF Certification (righteousness validation)
CoverageAI management systemsFull AI lifecycle + culture + agents + robots

K.4 RAGF and EU AI Act Mapping

The EU AI Act establishes a risk-based regulatory framework for AI systems, categorizing them into four risk tiers: unacceptable risk, high risk, limited risk, and minimal risk. High-risk AI systems are subject to mandatory conformity assessment and ongoing compliance obligations.

K.4.1 Mapping Table

EU AI Act RequirementEU AI Act ProvisionRAGF LayerRAGF PillarAlignment Description
Risk classificationArticle 6, Annex IIILayer 3: Map and AnalyzeJusticeBoth require risk-based classification of AI systems
Data governanceArticle 10Layer 3: Map and AnalyzeJusticeBoth require data quality, representativeness, and bias mitigation
Technical documentationArticle 11Layer 2: Policy and ProcessIntegrityBoth require documentation and transparency
Transparency and explainabilityArticle 13Layer 2: Policy and ProcessIntegrityBoth require transparency and explainability
Human oversightArticle 14Layer 5: Manage and ControlStewardshipBoth require meaningful human oversight
Accuracy, robustness, cybersecurityArticle 15Layer 5: Manage and ControlWisdomBoth require technical reliability and security
Post-market monitoringArticle 20Layer 4: Measure and MonitorAll PillarsBoth require ongoing monitoring and reporting
Incident reportingArticle 22Layer 5: Manage and ControlStewardshipBoth require incident detection and reporting

K.4.2 RAGF Extension of EU AI Act

DimensionEU AI ActRAGF Extension
Core Question“Is this AI system compliant with the law?”“Is this AI system righteous?”
FocusLegal compliance and safetyMoral excellence and righteousness growth
StandardMinimum legal requirementsHighest ethical standards
MeasurementCompliance/Non-complianceContinuous RI, RGS, RDM, RPS metrics
ScopeAI products in EU marketFull AI lifecycle + developers + organizations + agents + robots

K.4.3 EU AI Act Risk Tiers and RAGF Response

EU AI Act Risk TierDefinitionRAGF Response
Unacceptable RiskProhibited AI practices (e.g., social credit scoring, real-time biometric surveillance)RAGF’s Justice and Beneficence pillars require proactively avoiding such practices; Integrity requires transparent disclosure
High RiskAI systems in critical areas (hiring, credit, law enforcement, healthcare)RAGF’s full framework applies: all Five Pillars, Seven Layers, and RI assessment are essential
Limited RiskChatbots and other systems with transparency obligationsRAGF’s Integrity pillar (transparency) and Layer 2 (Policy and Process) apply
Minimal RiskLow-risk AI with no mandatory obligationsRAGF encourages voluntary adoption of righteousness principles even when not legally required

K.5 Summary Mapping

K.5.1 RAGF Layers to External Frameworks

RAGF LayerNIST AI RMFISO/IEC 42001EU AI Act
Layer 1: FoundationGOVERNClause 5 (Leadership)Preamble (Values)
Layer 2: Policy and ProcessGOVERNClauses 6–7 (Planning, Support)Articles 11, 13 (Documentation, Transparency)
Layer 3: Map and AnalyzeMAPClause 4 (Context)Articles 6, 10 (Risk Classification, Data)
Layer 4: Measure and MonitorMEASUREClause 9 (Performance)Articles 20, 22 (Monitoring, Reporting)
Layer 5: Manage and ControlMANAGEClause 8 (Operation)Articles 14, 15 (Oversight, Robustness)
Layer 6: Assess ImpactMEASUREClause 9 (Evaluation)Articles 20, 22 (Post-market Monitoring)
Layer 7: Sustain and ImproveMANAGEClause 10 (Improvement)Article 23 (Corrective Action)

K.5.2 RAGF Pillars to External Frameworks

RAGF PillarNIST AI RMFISO/IEC 42001EU AI Act
IntegrityTransparency, explainabilityDocumentation, communicationArticles 11, 13 (Documentation, Transparency)
JusticeFairness, bias managementRisk assessmentArticles 10, 13 (Data, Non-discrimination)
StewardshipGovernance, accountabilityLeadership, supportArticles 14, 22 (Oversight, Reporting)
WisdomRisk management, robustnessPlanning, operationArticles 15, 22 (Robustness, Incident Reporting)
BeneficenceSocietal impactContext of organizationPreamble (Human-centric AI)

K.6 Key Takeaways

TakeawayExplanation
RAGF complements, not replacesRAGF adds a righteousness dimension to existing frameworks rather than replacing them
NIST AI RMF provides the risk foundationRAGF builds on NIST’s risk management by adding moral excellence
ISO/IEC 42001 provides the management structureRAGF provides the ethical foundation for the AI management system
EU AI Act provides the legal floorRAGF goes beyond legal compliance to moral excellence
RAGF fills the righteousness gapNone of the existing frameworks explicitly address righteousness as a measurable, auditable governance capability

K.7 References for Appendix K

European Parliament. (2024). Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Official Journal of the European Union.

ISO/IEC. (2023). ISO/IEC 42001:2023 — Information technology — Artificial intelligence — Management system. International Organization for Standardization.

National Institute of Standards and Technology. (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0). U.S. Department of Commerce.