Inteligencia para Líderes de IA

EDICIÓN SEPTIEMBRE 2026EN
Volver al Inicio
AI Governance

DSIT, NIST, ISO 23894, ISO 42001: The Executive Matrix for Choosing an AI Risk Framework

—Founder & Chief Architect, ARCHAI WORLD™
September 20265 min
Compartir:
DSIT, NIST, ISO 23894, ISO 42001: The Executive Matrix for Choosing an AI Risk Framework

Four risk-management instruments now claim a seat at the same governance table. Here is what each one actually proves, where their coverage overlaps or runs out, and the evidence a risk committee should demand before accepting any of them as sufficient.

The UK's Department for Science, Innovation and Technology (DSIT) has published an AI Risk Management Toolkit that sits alongside NIST's AI Risk Management Framework and the ISO/IEC 23894 and 42001 standards. Four instruments now claim a seat at the same table. None of them replaces the other three — and that is precisely the governance problem enterprise leaders need to solve before their next AI risk committee meeting.

None of these frameworks was built to compete with the others. DSIT's toolkit is implementation guidance, not a certifiable standard. NIST's AI RMF is a voluntary framework designed for U.S. federal alignment and adopted informally worldwide. ISO/IEC 23894 defines AI risk management principles inside the broader ISO 31000 risk family. ISO/IEC 42001 is the only one of the four that is independently certifiable — an actual management-system standard an organization can be audited against.

The practical risk is not that these instruments conflict. It is that leadership teams treat them as interchangeable, pick whichever produces the cleanest-looking scorecard, and mistake a completed checklist for a defensible risk decision.

The Executive Matrix

The table below compares what each instrument actually contributes, where their coverage overlaps or runs out, and what evidence a governance committee should demand before accepting any of them as sufficient.

Instrument Distinctive Contribution Overlap & Limits Evidence to Demand
DSIT AI Risk Management Toolkit Practical, sector-agnostic implementation guidance built for teams that already know they need to manage AI risk but lack a working method to start. Not certifiable and not a standard. It is guidance, not an audit criterion — it cannot be cited as proof of compliance on its own. A worked risk register produced using the toolkit's own worksheets, not just a reference to having read it.
NIST AI Risk Management Framework A four-function structure — Govern, Map, Measure, Manage — with a Generative AI Profile that translates the framework into concrete practices for LLM-era risk. Voluntary and non-certifiable. Widely referenced internationally, but adoption is self-declared with no external attestation body. Evidence mapped explicitly to Govern / Map / Measure / Manage, and to the Generative AI Profile if the system involves generative models.
ISO/IEC 23894:2023 Extends ISO 31000's general risk-management principles specifically to AI, giving risk teams a vocabulary and structure consistent with existing enterprise risk practice. A principles document, not a management-system standard. It is not independently certifiable — there is no ISO 23894 certificate to earn. Documentation showing AI risk has been integrated into the organization's existing enterprise risk taxonomy, not managed in isolation.
ISO/IEC 42001:2023 The only certifiable AI management-system standard of the four. Defines requirements for an auditable AI Management System (AIMS), with ISO/IEC 42006:2025 governing how certification bodies themselves must be accredited to audit it. Certification proves a management system exists and operates — it does not, by itself, prove that any specific model or use case is low-risk. A current certificate issued by a body accredited under ISO/IEC 42006, plus the audit scope statement defining which systems it actually covers.

This is an independent editorial comparison of publicly available frameworks. It is not an official equivalence mapping endorsed by DSIT, NIST or ISO.

Three Findings for the Governance Committee

1. A framework is not evidence. A completed worksheet is.

Citing "we follow the NIST AI RMF" or "we reference the DSIT toolkit" in a board memo is not a risk control — it is a reading list. The distinctive value of these instruments only materializes when a team fills out the actual worksheets, risk registers, and control mappings each one prescribes. Executive action: require every AI risk submission to attach the completed artifact — the register, the mapped controls, the test results — not a citation to the framework's name.

2. Certification and competence are not the same claim.

ISO/IEC 42001 is the only instrument in this matrix that produces a certificate, and certificates carry disproportionate weight in procurement and board conversations. But a 42001 certificate attests that a management system exists and is operating — it says nothing about whether a specific model, for a specific use case, performs safely. Executive action: treat a 42001 certificate as proof of process maturity, and require separate, model-specific evidence (testing, red-teaming, monitoring data) before approving any individual AI use case.

3. Every approval needs an expiration date.

None of the four instruments is static — NIST has already issued a Generative AI Profile as an amendment, and ISO's AI standards portfolio is still expanding. A risk approval granted under today's version of any of these frameworks will not automatically remain valid as the frameworks, the underlying models, and the regulatory environment evolve. Executive action: attach a mandatory review date — not just a renewal reminder — to every AI risk approval, tied to framework updates and model version changes, not only to the calendar.

When to Use Which Instrument

These four are complementary, not competing, and most mature governance programs will end up using more than one:

  • Starting from zero and need a working method today: the DSIT toolkit's worksheets are the fastest path to a first usable risk register.
  • Operating in or reporting to a U.S.-influenced regulatory or investor environment: map to the NIST AI RMF's four functions, and add the Generative AI Profile for any LLM-based system.
  • Already running a mature enterprise risk function built on ISO 31000: ISO/IEC 23894 lets you extend that existing taxonomy to AI without building a parallel structure.
  • Needing an externally auditable claim for customers, regulators, or the board: ISO/IEC 42001 is the only one of the four that produces a certificate — verify it was issued by a body accredited under ISO/IEC 42006.

The Decision That Matters

The question in front of most governance committees is not "which framework is best." It is whether the organization can produce, on demand, the specific artifact each instrument actually requires — the worksheet, the function-mapped evidence, the taxonomy integration, or the accredited certificate — rather than a slide citing the framework's name. That distinction, more than the choice of instrument, is what separates a governed AI program from one that merely looks governed.

Executive Reference

This comparison is also available as a one-page executive matrix, formatted for board and risk-committee distribution — in both English and Spanish.

Sources

  1. DSIT — AI Management Essentials / AI Risk Management Toolkit guidance, gov.uk
  2. NIST — AI Risk Management Framework (AI RMF 1.0)
  3. NIST AI Resource Center — AI RMF resources and crosswalks
  4. NIST — Generative Artificial Intelligence Profile (NIST-AI-600-1)
  5. ISO/IEC 23894:2023 — Information technology — Artificial intelligence — Guidance on risk management
  6. ISO/IEC 42001:2023 — Information technology — Artificial intelligence management system
  7. ISO/IEC 42006:2025 — Requirements for bodies providing audit and certification of AI management systems
Leonardo Ramírez

Sobre el Autor

Leonardo Ramírez

Editor en Jefe, AI Governance Today

Leonardo Ramírez es el Editor en Jefe de AI Governance Today y fundador de ARCHAI WORLD™. Con más de 30 años de experiencia en transformación de empresas Fortune 500, es especialista en Gobernanza de IA, Arquitectura Empresarial e ISO 42001.

La Nueva Guía de HBR sobre Gestión de Agentes de IA como Colegas: Implicaciones Prácticas para la Gobernanza de IA Empresarial en 2026
AI Leadership

La Nueva Guía de HBR sobre Gestión de Agentes de IA como Colegas: Implicaciones Prácticas para la Gobernanza de IA Empresarial en 2026

Harvard Business Review ha publicado un marco crítico para gestionar agentes de IA como talento organizacional en lugar de herramientas de software — con descripciones de trabajo estructuradas, supervisión humana, codificación contextual y gobernanza de desempeño. Este artículo analiza la guía de HBR, su alineación con ISO 42001, y qué deben hacer las empresas en los próximos 90 días para operacionalizarla.

Leonardo Ramírez·March 2026

INTELIGENCIA EJECUTIVA SEMANAL

Las decisiones que los líderes de IA no pueden descubrir demasiado tarde.

Reciba cada semana un briefing ejecutivo basado en evidencia sobre IA de frontera, gobernanza, arquitectura empresarial, regulación y modelos operativos inteligentes.

Sin spam. Puede cancelar la suscripción en cualquier momento.