This appendix provides a detailed mapping between the Righteous AI Governance Framework (RAGF) and three major existing AI governance frameworks and standards:
NIST AI Risk Management Framework (AI RMF 1.0) — U.S. voluntary risk management guidance
ISO/IEC 42001:2023 — International standard for AI management systems
EU AI Act — EU legally binding regulation with risk-based compliance requirements
K.1 Mapping Overview
RAGF is designed to complement and extend these existing frameworks. While NIST AI RMF, ISO/IEC 42001, and the EU AI Act focus on risk management, compliance, and trustworthiness, RAGF adds a righteousness dimension—the active pursuit of integrity, justice, stewardship, wisdom, and beneficence in AI governance.
Framework
Nature
Primary Focus
RAGF Relationship
NIST AI RMF
Voluntary risk guidance
Manage AI risks and promote trustworthy AI
RAGF adds a righteousness layer on top of risk management
ISO/IEC 42001
Certifiable management system
Establish AI management system
RAGF provides the ethical foundation for the management system
EU AI Act
Legally binding regulation
Ensure AI safety, fundamental rights, and compliance
RAGF goes beyond compliance to moral excellence
K.2 RAGF and NIST AI RMF Mapping
The NIST AI RMF is built on four core functions: Govern, Map, Measure, and Manage. These functions provide a structured approach to managing AI risks throughout the AI lifecycle.
K.2.1 Mapping Table
NIST AI RMF Function
NIST AI RMF Category
RAGF Layer
RAGF Pillar
Alignment Description
GOVERN
Organizational culture, policies, roles
Layer 1: Righteousness Foundation
Stewardship
Both establish organizational commitment and accountability structures
GOVERN
Risk management strategy
Layer 2: Policy and Process
Stewardship
Both define governance policies and processes
MAP
Context identification
Layer 3: Map and Analyze
Wisdom
Both identify system context, stakeholders, and risks
MAP
System classification
Layer 3: Map and Analyze
Justice
Both classify systems by risk and impact
MEASURE
Risk assessment
Layer 4: Measure and Monitor
All Pillars
Both assess and quantify AI risks and performance
MEASURE
Monitoring and evaluation
Layer 4: Measure and Monitor
All Pillars
Both enable continuous monitoring and evaluation
MANAGE
Risk treatment
Layer 5: Manage and Control
Stewardship
Both implement controls and safeguards
MANAGE
Incident response
Layer 5: Manage and Control
Stewardship
Both establish incident response procedures
K.2.2 RAGF Extension of NIST AI RMF
Dimension
NIST AI RMF
RAGF Extension
Core Question
“How do we manage AI risks?”
“How do we make AI righteous?”
Focus
Risk mitigation and trustworthiness
Moral excellence and righteousness growth
Measurement
Qualitative risk assessment
Quantitative RI, RGS, RDM, RPS metrics
Values
Trustworthy AI (transparency, fairness, accountability)
Righteous AI (Integrity, Justice, Stewardship, Wisdom, Beneficence)
Scope
AI systems
Full AI lifecycle + developers + organizations + agents + robots
K.3 RAGF and ISO/IEC 42001 Mapping
ISO/IEC 42001 specifies requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System (AIMS) within an organization. It provides a certifiable framework to map regulatory requirements to engineering practices.
K.3.1 Mapping Table
ISO/IEC 42001 Clause
ISO/IEC 42001 Requirement
RAGF Layer
RAGF Pillar
Alignment Description
Clause 4
Context of the organization
Layer 3: Map and Analyze
Wisdom
Both require understanding organizational context and stakeholder needs
Clause 5
Leadership and commitment
Layer 1: Righteousness Foundation
Stewardship
Both require leadership commitment to AI governance
Clause 6
Planning (risks and opportunities)
Layer 3: Map and Analyze
Wisdom
Both require risk identification and planning
Clause 7
Support (resources, competence, awareness)
Layer 2: Policy and Process
Stewardship
Both require resource allocation and capability building
Clause 8
Operation (planning and control)
Layer 5: Manage and Control
Stewardship
Both require operational controls and safeguards
Clause 9
Performance evaluation (monitoring, audit)
Layer 4: Measure and Monitor
All Pillars
Both require monitoring, measurement, and audit
Clause 10
Improvement (nonconformity, corrective action)
Layer 7: Sustain and Improve
All Pillars
Both require continuous improvement and corrective action
K.3.2 RAGF Extension of ISO/IEC 42001
Dimension
ISO/IEC 42001
RAGF Extension
Core Question
“How do we manage AI systems?”
“How do we make AI righteous?”
Focus
Management system structure
Moral governance and growth
Measurement
Compliance with requirements
Continuous RI, RGS, RDM, RPS metrics
Certification
ISO 42001 certification
RAGF Certification (righteousness validation)
Coverage
AI management systems
Full AI lifecycle + culture + agents + robots
K.4 RAGF and EU AI Act Mapping
The EU AI Act establishes a risk-based regulatory framework for AI systems, categorizing them into four risk tiers: unacceptable risk, high risk, limited risk, and minimal risk. High-risk AI systems are subject to mandatory conformity assessment and ongoing compliance obligations.
K.4.1 Mapping Table
EU AI Act Requirement
EU AI Act Provision
RAGF Layer
RAGF Pillar
Alignment Description
Risk classification
Article 6, Annex III
Layer 3: Map and Analyze
Justice
Both require risk-based classification of AI systems
Data governance
Article 10
Layer 3: Map and Analyze
Justice
Both require data quality, representativeness, and bias mitigation
Technical documentation
Article 11
Layer 2: Policy and Process
Integrity
Both require documentation and transparency
Transparency and explainability
Article 13
Layer 2: Policy and Process
Integrity
Both require transparency and explainability
Human oversight
Article 14
Layer 5: Manage and Control
Stewardship
Both require meaningful human oversight
Accuracy, robustness, cybersecurity
Article 15
Layer 5: Manage and Control
Wisdom
Both require technical reliability and security
Post-market monitoring
Article 20
Layer 4: Measure and Monitor
All Pillars
Both require ongoing monitoring and reporting
Incident reporting
Article 22
Layer 5: Manage and Control
Stewardship
Both require incident detection and reporting
K.4.2 RAGF Extension of EU AI Act
Dimension
EU AI Act
RAGF Extension
Core Question
“Is this AI system compliant with the law?”
“Is this AI system righteous?”
Focus
Legal compliance and safety
Moral excellence and righteousness growth
Standard
Minimum legal requirements
Highest ethical standards
Measurement
Compliance/Non-compliance
Continuous RI, RGS, RDM, RPS metrics
Scope
AI products in EU market
Full AI lifecycle + developers + organizations + agents + robots
K.4.3 EU AI Act Risk Tiers and RAGF Response
EU AI Act Risk Tier
Definition
RAGF Response
Unacceptable Risk
Prohibited AI practices (e.g., social credit scoring, real-time biometric surveillance)
RAGF’s Justice and Beneficence pillars require proactively avoiding such practices; Integrity requires transparent disclosure
High Risk
AI systems in critical areas (hiring, credit, law enforcement, healthcare)
RAGF’s full framework applies: all Five Pillars, Seven Layers, and RI assessment are essential
Limited Risk
Chatbots and other systems with transparency obligations
RAGF’s Integrity pillar (transparency) and Layer 2 (Policy and Process) apply
Minimal Risk
Low-risk AI with no mandatory obligations
RAGF encourages voluntary adoption of righteousness principles even when not legally required
K.5 Summary Mapping
K.5.1 RAGF Layers to External Frameworks
RAGF Layer
NIST AI RMF
ISO/IEC 42001
EU AI Act
Layer 1: Foundation
GOVERN
Clause 5 (Leadership)
Preamble (Values)
Layer 2: Policy and Process
GOVERN
Clauses 6–7 (Planning, Support)
Articles 11, 13 (Documentation, Transparency)
Layer 3: Map and Analyze
MAP
Clause 4 (Context)
Articles 6, 10 (Risk Classification, Data)
Layer 4: Measure and Monitor
MEASURE
Clause 9 (Performance)
Articles 20, 22 (Monitoring, Reporting)
Layer 5: Manage and Control
MANAGE
Clause 8 (Operation)
Articles 14, 15 (Oversight, Robustness)
Layer 6: Assess Impact
MEASURE
Clause 9 (Evaluation)
Articles 20, 22 (Post-market Monitoring)
Layer 7: Sustain and Improve
MANAGE
Clause 10 (Improvement)
Article 23 (Corrective Action)
K.5.2 RAGF Pillars to External Frameworks
RAGF Pillar
NIST AI RMF
ISO/IEC 42001
EU AI Act
Integrity
Transparency, explainability
Documentation, communication
Articles 11, 13 (Documentation, Transparency)
Justice
Fairness, bias management
Risk assessment
Articles 10, 13 (Data, Non-discrimination)
Stewardship
Governance, accountability
Leadership, support
Articles 14, 22 (Oversight, Reporting)
Wisdom
Risk management, robustness
Planning, operation
Articles 15, 22 (Robustness, Incident Reporting)
Beneficence
Societal impact
Context of organization
Preamble (Human-centric AI)
K.6 Key Takeaways
Takeaway
Explanation
RAGF complements, not replaces
RAGF adds a righteousness dimension to existing frameworks rather than replacing them
NIST AI RMF provides the risk foundation
RAGF builds on NIST’s risk management by adding moral excellence
ISO/IEC 42001 provides the management structure
RAGF provides the ethical foundation for the AI management system
EU AI Act provides the legal floor
RAGF goes beyond legal compliance to moral excellence
RAGF fills the righteousness gap
None of the existing frameworks explicitly address righteousness as a measurable, auditable governance capability
K.7 References for Appendix K
European Parliament. (2024). Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Official Journal of the European Union.
ISO/IEC. (2023). ISO/IEC 42001:2023 — Information technology — Artificial intelligence — Management system. International Organization for Standardization.
National Institute of Standards and Technology. (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0). U.S. Department of Commerce.