AI Governance Frameworks Compared: NIST AI RMF, ISO/IEC 42001, APRA and the Voluntary AI Safety Standard

These four instruments are not competitors — they sit at different layers of the same discipline. Map which layers attach to your organisation, then run one control set beneath all of them.

NIST AI RMF NIST AI Risk Management Framework Voluntary US risk framework built on Govern, Map, Measure and Manage.
ISO 42001 ISO/IEC 42001:2023 — AI Management System The certifiable management-system standard for governing AI.
CPS 230/234 APRA Prudential Standards The binding prudential baseline: operational risk and information security.

By Gregory McKenzie · Registered Trans-Tasman Patent Attorney & Systems Architect · NETEVO · 11 min read · Published 26 Jul 2026

Ask five Australian executives which AI governance framework their organisation follows and you will hear five different names — NIST, ISO 42001, "the APRA requirements", "the government guardrails" — often used interchangeably, as if they were four brands of the same product.

They are not. One is a voluntary risk framework from a US standards agency. One is a certifiable international management-system standard. One is a set of binding prudential obligations that already applies to Australia's banks, insurers and superannuation trustees. One is the Australian Government's voluntary statement of what good AI governance looks like.

If you sit on a board being asked "which framework are we on?", lead a risk function trying to reconcile three vendor decks, or run an APRA-regulated entity where the answer is partly chosen for you, this comparison is the map. It sets out what each instrument is, whether it binds, who it applies to, and how the four layer together.

The practical conclusion arrives early: you do not pick one and discard the rest. You map which layers attach to your organisation and operate a single control set underneath all of them. That is the argument the rest of this page substantiates.

Which AI governance framework applies in Australia? #

Four reference points dominate the Australian conversation, and they sit at four different layers. The NIST AI Risk Management Framework is a voluntary risk framework — a structured way of finding and managing AI risk, with no legal force anywhere. ISO/IEC 42001 (adopted in Australia as AS ISO/IEC 42001:2023) is a certifiable management-system standard — the only one of the four an accredited certification body can audit you against. APRA's prudential standards — CPS 230 on operational risk and CPS 234 on information security — are binding obligations for APRA-regulated entities, and APRA has confirmed that AI activity falls inside their existing perimeter. The Voluntary AI Safety Standard is the Commonwealth's national statement of good practice: ten voluntary guardrails that give Australian organisations a shared vocabulary. Not four competitors — one underlying discipline, viewed through four lenses.

That layering matters because Australia deliberately chose not to enact a standalone AI act. Instead, existing laws were strengthened and sector regulators — APRA, ASIC, the OAIC — were left to apply their existing regimes to AI. The result is that "which framework?" is rarely a single-answer question in Australia. The AI Governance in ANZ whitepaper maps that regulatory posture in depth; this page does the narrower job of putting the four most-conflated instruments side by side.

How do the four frameworks compare at a glance? #

FrameworkWhat it isVoluntary or mandatoryWho it applies to in AustraliaWhat it demandsHow NETEVO operationalises it
NIST AI RMFUS national framework for managing AI risk, published January 2023, organised around four functions: Govern, Map, Measure, ManageVoluntary — no legal force in any jurisdictionAny organisation that adopts it; the default reference for US-headquartered groups and AU subsidiaries of US parentsA repeatable, documented practice for identifying, measuring and managing AI risk across the system lifecycleCross-walks the four functions onto one engineered control set, so the same controls can be reported against NIST and ISO simultaneously
ISO/IEC 42001International management-system standard for AI (an "AIMS"), published December 2023; adopted in Australia as AS ISO/IEC 42001:2023Voluntary — unless a contract, tender or group policy makes it a condition; certifiable by accredited certification bodiesAny organisation, any size, that chooses (or is required by counterparties) to run a certifiable AI management systemAn operating management system: leadership accountability, planned risk treatment, lifecycle controls over AI systems, and continual improvement an auditor can verifyBuilds the management system as executable controls with an evidence trail, so conformity can be demonstrated from records rather than asserted in documents
APRA CPS 230 + CPS 234 (as applied to AI)Binding prudential standards on operational risk management and information security; not AI-specific, but AI use falls inside their existing perimeterMandatory for APRA-regulated entitiesADIs, insurers and superannuation trustees regulated by APRAOperational-risk capability and service-provider management (CPS 230); information-security capability commensurate with threats, plus incident notification (CPS 234) — each now read to include AI systemsEngineers controls that emit regulator-readable signals, so operational-risk and information-security notification obligations can be supported from one observability layer
Voluntary AI Safety StandardThe Australian Government's voluntary standard (DISR, September 2024): ten guardrails describing what good AI governance looks likeVoluntary — a national reference, not a legal obligationAny Australian organisation that adopts it; the Commonwealth's shared vocabulary for AI governancePractices spanning accountability, risk management, testing, transparency and human oversight, demonstrated in operation rather than declared in policyMaps the ten guardrails onto the same engineered control set, so alignment with the national standard falls out of controls already running

Read the rows as layers, not options. The two voluntary frameworks give you structure; the certifiable standard gives you an auditable operating spine; the prudential standards — where they apply — give you the binding floor everything else sits on. The same engineered control can appear in all four rows at once, which is the entire economic argument for treating this as one discipline.

When is the NIST AI RMF the right lens? #

Reach for the NIST AI RMF when your organisation needs a structured way to reason about AI risk and a vocabulary that travels across borders. Published by the US National Institute of Standards and Technology in January 2023, the framework organises AI risk work into four functions — Govern, Map, Measure and Manage — applied across the AI lifecycle. It is the most operationally detailed AI risk framework outside the ISO/IEC stack, and its 2024 companion, the NIST AI 600-1 Generative AI Profile, extends it with generative-AI-specific risks and recommended actions.

Two things follow for an Australian reader. First, the RMF is voluntary everywhere — including in the United States — so it is never the instrument that makes AI governance "mandatory" for you. Second, it is the default frame for US-headquartered groups, which makes it the lens Australian subsidiaries most often inherit. In that situation the practical work is the cross-walk: the four NIST functions map cleanly onto the clause structure ISO management-system standards share, so one control set can be reported against both. The NIST AI RMF entry in the Citation Catalogue summarises the framework and its official source at nist.gov.

When is ISO/IEC 42001 the right lens? #

Choose ISO/IEC 42001 when you need something no framework can give you: independent, certifiable proof. Published in December 2023 and adopted in Australia as AS ISO/IEC 42001:2023, it is the first management-system standard for AI — the same architecture as ISO/IEC 27001 for information security, applied to how an organisation governs AI systems across their lifecycle. Because it is a management-system standard, an accredited certification body can audit against it and issue a certificate; NETEVO builds and operationalises management systems but does not certify anyone — only accredited certification bodies do that.

ISO/IEC 42001 is the layer to anchor on when customers, boards or tenders start asking for demonstrable AI governance rather than described AI governance. It is also the natural operating spine for the other three layers, because its management-system shape is designed to absorb external obligations — prudential, contractual, or national-standard — into one planned, reviewed system. The full treatment is in ISO 42001 explained: the certifiable path, with the standard's official record at iso.org and the Australian adoption at standards.org.au. The international-edition digest covers what the standard contains without reproducing it.

What do APRA's prudential standards require for AI? #

For APRA-regulated entities — the banks, insurers and superannuation trustees within APRA's remit — the prudential layer is not a choice. It is the binding baseline the voluntary layers sit on top of. APRA has not issued an AI-specific prudential standard; instead, its April 2026 Letter to Industry on AI confirmed that AI risk is governed through the standards already in force, and reported that across its supervisory review, AI adoption was outpacing the governance and assurance practices meant to contain it. The letter asked regulated entities to lift their practice materially under the existing framework rather than wait for new rules.

Two standards carry that weight. CPS 230 on operational risk management requires regulated entities to maintain operational-risk capability, continuity arrangements and disciplined management of service providers — all of which now have AI inside their scope, from models embedded in critical operations to AI vendors on the material-service-provider register. CPS 234 on information security requires information-security capability commensurate with the entity's threat profile, and notification of material incidents — and an AI system that processes, stores or routes sensitive information sits squarely inside that perimeter. Primary sources live at apra.gov.au. On the conduct side, ASIC's Report 798 documented the same governance gap among AFS and credit licensees — Australia's two financial regulators reaching the same finding from independent reviews.

Stated in operational terms: for a prudentially regulated entity, the question is not whether to govern AI but what evidence of governance the existing standards already require — and whether that evidence is produced by running controls or reconstructed for the regulator after the fact.

Where does the Voluntary AI Safety Standard fit? #

The Voluntary AI Safety Standard is Australia's national answer to "what does good look like?" — ten voluntary guardrails published by the Department of Industry, Science and Resources in September 2024, spanning accountability, risk management, testing, transparency, human oversight and engagement with the people AI systems affect. It binds no one. Its value is that it is the Commonwealth's own vocabulary: describe your governance posture in the guardrails' language and you have tied it to an official Australian reference point instead of a vendor's terminology. The Citation Catalogue digest summarises it; the official text is at industry.gov.au.

Three placement notes. First, the guardrails cross-walk cleanly onto ISO/IEC 42001, so adopting the national standard and operating a certifiable management system is one job, not two. Second, the policy layer above it keeps moving — the National AI Centre's Guidance for AI Adoption has since evolved the ten guardrails into the current national frame of six essential practices, the National AI Plan (December 2025) is now the Commonwealth's overarching statement of AI policy direction, and organisations supplying government should also know the National Framework for the Assurance of AI in Government, signed by every Australian jurisdiction in June 2024. Third, the contrast with Europe is deliberate: where the EU legislated a horizontal AI act, Australia chose voluntary national guardrails over binding cross-economy rules — which is precisely why the sector regulators' existing standards do the binding work here.

How do you choose? #

You mostly don't choose one — you sequence them. The decision logic falls out of three questions.

Does the prudential layer attach? If your organisation is APRA-regulated, CPS 230 and CPS 234 are the floor, in force today, with AI inside their perimeter. Voluntary frameworks then become the how — the structure you use to meet obligations that already bind — not the whether.

Do you need provable governance or described governance? If counterparties, tenders or the board need independent verification, ISO/IEC 42001 is the only certifiable path of the four. Start with ISO 42001 explained, and if you want a concrete first step, the ISO 42001 readiness checklist is a self-assessment a board or risk lead can run in an afternoon.

Do you need the full regulatory picture first? If the task is briefing a board on the whole Australian landscape — regulators, policy trajectory, readiness data — that is the job of the AI Governance in ANZ whitepaper, not this comparison.

When the reading is done and the question becomes delivery — one control set, engineered once, evidenced against every layer that attaches to you — that is the work described on the AI governance solution page, and the wider conceptual map lives in What is AI governance?.

One register note to close. This article explains the landscape in operational terms; it is not legal advice — consult your own advisers on how these instruments apply to your specific circumstances. NETEVO's discipline is the adjacent one: encoding obligations, once identified, into controls you can operate and evidence.

Choosing your lens: the three-phase read

Three passes to map which frameworks attach to your organisation, pick the operating spine, and turn the result into controls that produce evidence.

Phase 01

Map applicability

First pass

  • Establish whether the prudential layer attaches: APRA-regulated entity status and which standards are engaged
  • Inventory contractual and tender obligations that name ISO/IEC 42001 or equivalent assurance
  • Identify inherited frames: group-parent NIST AI RMF alignment, government supply-chain assurance expectations
Deliverable: An applicability map: which of the four layers bind, which are expected, which are elective
Phase 02

Select the operating spine

Second pass

  • Choose the management-system spine the other layers cross-walk onto — usually ISO/IEC 42001-shaped
  • Build the cross-walk matrix: prudential obligations, national guardrails, and NIST functions mapped to one control set
  • Locate the gaps where an obligation has no owning control
Deliverable: A single control spine with a four-framework cross-walk and a named gap list
Phase 03

Operationalise the controls

Third pass

  • Prioritise gaps by which attaching layer they expose — binding obligations first
  • Specify each control as something that runs and records, not a policy paragraph
  • Define the evidence each control must emit for auditors and, where relevant, regulators
Deliverable: A prioritised control build plan ready for board or risk-committee sign-off

Where the read identifies the gap, the solution page describes how the controls are built and evidenced.

The comparison places the four frameworks; the pages below take each route further — the certifiable path, the concept, the full regulatory evidence base, and the delivery.

Insight

ISO 42001 explained

The certifiable path: what the AI management-system standard asks of an Australian organisation, in operational terms.

Read the pillar
Insight

What is AI governance?

The front door: what AI governance means in Australia's no-standalone-AI-act posture, and where each instrument fits.

Read the explainer
Whitepaper

AI Governance in ANZ 2026

The deep evidence base: the full regulatory landscape, readiness data, and board expectations behind this comparison.

Read the evidence base
Solution

AI Governance & Readiness

The delivery: readiness assessment, policy-as-code, and the controls and evidence trail that serve every layer at once.

View solution

Questions

Frequently asked questions

Framework-comparison questions. Service-mechanics questions — how the controls are built, what an engagement looks like — are answered on AI Governance & Readiness.

What is the NIST AI Risk Management Framework?

The NIST AI Risk Management Framework is a voluntary framework for managing AI risk, published by the US National Institute of Standards and Technology in January 2023. It organises the work into four functions — Govern, Map, Measure and Manage — applied across the AI system lifecycle. A 2024 companion profile, NIST AI 600-1, extends it to generative-AI-specific risks.

Is the NIST AI RMF mandatory in Australia?

No. The NIST AI RMF is voluntary in every jurisdiction, including the United States, and it creates no obligation for Australian organisations. It matters in Australia mainly as an inherited frame — Australian subsidiaries of US-headquartered groups often adopt it as the group standard — and as a well-structured vocabulary that cross-walks onto ISO/IEC 42001 and Australian instruments.

NIST AI RMF vs ISO 42001 — what is the difference?

The NIST AI RMF is a voluntary risk framework — guidance for how to think about and manage AI risk, with nothing to certify against. ISO/IEC 42001 is a certifiable management-system standard: it specifies requirements an accredited certification body can audit, covering leadership, planning, lifecycle controls and continual improvement. The two map onto each other well, so one engineered control set can satisfy both — the practical choice is usually which one anchors your reporting, not either-or.

Does APRA have AI-specific rules?

No — and that is deliberate. APRA's April 2026 Letter to Industry confirmed that AI risk is governed through the existing prudential framework, principally CPS 230 (operational risk) and CPS 234 (information security), rather than through a new AI-specific standard. The letter reported that AI adoption across regulated entities was running ahead of governance and assurance practice, and asked entities to lift materially under the standards already in force.

What is the Voluntary AI Safety Standard?

The Voluntary AI Safety Standard is the Australian Government's voluntary statement of what good AI governance looks like, published by the Department of Industry, Science and Resources in September 2024. It sets out ten guardrails spanning accountability, risk management, testing, transparency and human oversight. It binds no one, but it supplies the Commonwealth's shared vocabulary for AI governance and cross-walks cleanly onto ISO/IEC 42001.

Can one AI governance program satisfy all four frameworks?

Yes — and that is the practical point of reading them as layers rather than competitors. A single management system with engineered controls and an evidence trail can be reported against NIST's four functions, audited against ISO/IEC 42001, and used to demonstrate the operational-risk and information-security practices APRA's standards require, while aligning with the national guardrails. What does not work is running four parallel paper programs, one per framework.

Author

Gregory McKenzie is the Principal of NETEVO, a registered Trans-Tasman patent attorney and systems architect, and the architect of NETEVO's Law-to-Code Methodology. He led RISKflo Associates Pty Ltd to ISO/IEC 27001:2022 certification in 2025. He writes from Sydney.