
Artificial intelligence adoption is accelerating faster than many organisations can establish effective governance.
Bain reported in 2025 that 95% of surveyed US companies were using generative AI. The research also found that the average number of production use cases had doubled between October 2023 and December 2024.
This growth creates enormous opportunities, but it also introduces risks involving privacy, cybersecurity, discrimination, transparency, accountability, intellectual property and regulatory compliance.
Organisations therefore need more than an AI policy. They need structured ways to identify risks, assign accountability, evaluate impacts and monitor AI systems throughout their lifecycle.
For professionals preparing for the IAPP Artificial Intelligence Governance Professional certification, understanding the major AI governance instruments is essential. However, candidates must also recognise an important distinction:
A framework, regulation, standard, policy directive and code of conduct are not the same thing.This guide examines five important AI governance instruments and explains how each should be understood.
1. NIST Artificial Intelligence Risk Management Framework
The NIST Artificial Intelligence Risk Management Framework, commonly called the NIST AI RMF, was released in January 2023 by the US National Institute of Standards and Technology.
It is a voluntary and industry-agnostic framework designed to help organisations manage risks associated with the design, development, deployment and use of AI systems.
Rather than providing a rigid compliance checklist, the framework helps organisations establish repeatable processes for trustworthy AI.
The NIST AI RMF is structured around four functions:
Govern
Establish policies, accountability, organisational roles, risk tolerances and oversight mechanisms for AI.
Map
Understand the purpose, context, stakeholders, potential impacts and operating environment of an AI system.
Measure
Assess, analyse and track AI risks using appropriate qualitative and quantitative methods.
Manage
Prioritise identified risks, implement controls, monitor responses and determine whether risks should be accepted, mitigated, transferred or avoided.
AIGP Accuracy Note
The four official functions are:
Govern → Map → Measure → Manage
“Monitor” is not a separate NIST AI RMF function. Monitoring activities may support the framework, but the fourth function is officially called Manage.
Why it matters
The NIST AI RMF helps organisations translate broad responsible-AI principles into practical governance activities. It can be adapted across industries and used alongside privacy, cybersecurity, enterprise-risk and compliance programmes.
For AIGP candidates, the important point is to understand both the four functions and the iterative relationship between them.
2. European Union Artificial Intelligence Act
The EU AI Act is not a voluntary framework. It is a legally binding regulation governing the development, deployment and use of AI systems within its scope.
The Act entered into force on 1 August 2024 and follows a phased implementation timeline. Prohibited AI practices and AI-literacy requirements began applying in February 2025. Obligations concerning general-purpose AI models began applying in August 2025.
Most remaining provisions are scheduled to become applicable from 2 August 2026, while certain requirements for high-risk AI systems connected with regulated products follow a later timeline.
The Act applies a risk-based regulatory model.
Prohibited AI practices
Certain practices presenting unacceptable risks to fundamental rights are prohibited. These include specific forms of social scoring, manipulative AI, biometric categorisation and other practices defined by the regulation.
The prohibitions are specific. It would be inaccurate to assume that every use of surveillance, biometrics or automated monitoring is automatically banned.
High-risk AI systems
AI used in sensitive areas such as employment, education, essential services, law enforcement and certain regulated products may be classified as high risk.
Depending on the system and the organisation’s role, requirements may include:
- Risk-management processes
- Data-governance controls
- Technical documentation
- Record keeping
- Human oversight
- Accuracy, robustness and cybersecurity
- Conformity assessments
- Post-market monitoring
Transparency obligations
Certain AI systems must disclose that users are interacting with AI. Additional transparency requirements may apply to synthetic content, deepfakes and general-purpose AI models.
Minimal or no-risk systems
Many ordinary AI applications remain largely unaffected, although organisations may still voluntarily adopt codes of conduct and responsible-AI practices.
AIGP Accuracy Note
The EU AI Act was not adopted in late 2023 and is no longer merely “expected to take effect.”
It entered into force in August 2024, and several of its provisions are already applicable.
Why it matters
The EU AI Act moves AI governance from voluntary principles to enforceable responsibilities. Its influence is also likely to extend beyond Europe because organisations offering AI systems or services in the EU may fall within its scope.
AIGP candidates should understand the difference between prohibited practices, high-risk requirements, transparency obligations and general-purpose AI responsibilities.
3. ISO/IEC 42001 and ISO/IEC 23894
ISO and the International Electrotechnical Commission have developed complementary standards for AI governance and risk management.
Although they are frequently discussed together, ISO/IEC 42001 and ISO/IEC 23894 serve different purposes.
ISO/IEC 42001:2023
ISO/IEC 42001 establishes requirements for an Artificial Intelligence Management System.
It helps an organisation build an enterprise-wide system of policies, roles, objectives, processes and controls for the responsible development or use of AI.
The standard follows the Plan-Do-Check-Act model commonly used across ISO management-system standards.
It addresses areas such as:
- AI governance policies
- Roles and responsibilities
- AI risk and impact assessments
- Data management
- System lifecycle controls
- Third-party relationships
- Performance evaluation
- Continual improvement
Because ISO/IEC 42001 is a requirements-based management-system standard, an organisation may pursue certification through an independent certification body.
ISO/IEC 23894:2023
ISO/IEC 23894 provides guidance on managing risks specifically associated with AI.
It helps organisations integrate AI-related risks into their existing risk-management activities and considers risks affecting organisations, individuals, groups and society.
The standard can support AI risk identification, analysis, evaluation, treatment, communication and monitoring.
AIGP Accuracy Note
ISO/IEC 42001 is an AI management-system requirements standard against which an organisation may be certified.
ISO/IEC 23894 is a risk-management guidance document. It is not a management-system certification standard.
Why they matter
Together, the two standards provide complementary value.
ISO/IEC 42001 helps establish the organisational management system, while ISO/IEC 23894 provides deeper guidance for managing AI-specific risks within that system.
For AIGP professionals, understanding this distinction is important when advising organisations about governance implementation and certification.
4. OECD Artificial Intelligence Principles
The OECD AI Principles were originally adopted in 2019 and updated in May 2024 to address developments involving general-purpose and generative AI.
They were the first intergovernmental standard for trustworthy AI and have influenced national policies, international initiatives and other governance instruments.
The principles promote:
- Inclusive growth, sustainable development and well-being
- Human rights, fairness and democratic values
- Transparency and explainability
- Robustness, security and safety
- Accountability
They are supported by recommendations for governments covering research investment, digital ecosystems, enabling policy environments, workforce development and international cooperation.
AIGP Accuracy Note
The OECD AI Principles are not a law or a certification standard.
They provide high-level, internationally recognised guidance for governments and AI actors. Their influence comes from policy adoption and global alignment rather than direct enforcement.
Why they matter
Many international AI governance initiatives build on concepts introduced or reinforced by the OECD Principles.
They also help AIGP candidates understand the values that sit behind more detailed regulations, risk frameworks and technical standards.
5. G7 Hiroshima Process International Code of Conduct
The G7 Hiroshima Process International Code of Conduct was introduced in 2023 to support safe, secure and trustworthy development of advanced AI systems.
It was developed by the G7 members with the participation of the European Union and is particularly relevant to organisations developing advanced AI systems, including powerful foundation and generative AI models.
The Code contains 11 principles covering areas such as:
- Risk identification throughout the AI lifecycle
- Testing and evaluation before deployment
- Incident reporting
- Transparency about system capabilities and limitations
- Security controls
- Protection of intellectual property
- Content-authentication mechanisms
- Responsible information sharing
- Research into AI safety and societal risks
AIGP Accuracy Note
The Hiroshima Process Code is a voluntary international code of conduct. It is not a binding global AI regulation.
Its principal focus is on organisations developing advanced AI systems, although many of its practices can also inform deployment and procurement decisions.
Why it matters
The Code addresses risks that became more visible with the growth of foundation models and generative AI, including disinformation, deepfakes, model misuse and systemic security concerns.
It also demonstrates how international cooperation can influence organisational behaviour even without creating a legally binding law.
Where Does the 2025 US Executive Order Fit?
Executive Order 14179, titled “Removing Barriers to American Leadership in Artificial Intelligence,” was signed on 23 January 2025.
It directed the development of a national AI Action Plan and required a review of existing federal AI policies that could conflict with the administration’s approach to innovation and US leadership.
The Executive Order is important policy context, especially for professionals monitoring the US regulatory environment.
However, it should not be classified as an organisational AI risk-management framework comparable to the NIST AI RMF.
It also should not be described as a comprehensive law establishing private-sector AI governance obligations.
AIGP Accuracy Note
Executive Order 14179 is a federal policy directive.
NIST AI RMF is a voluntary risk-management framework.
The EU AI Act is a binding regulation.
ISO/IEC 42001 is a management-system standard.
Recognising these classifications is essential for accurate AI governance analysis.
How These Instruments Work Together
Organisations do not necessarily have to choose only one instrument.
A multinational organisation could:
- Use the NIST AI RMF to structure AI risk-management activities.
- Implement ISO/IEC 42001 to establish an organisation-wide AI management system.
- Use ISO/IEC 23894 to strengthen its AI risk processes.
- Apply the OECD Principles as a foundation for trustworthy-AI values.
- Follow the G7 Code when developing advanced AI models.
- Comply with the EU AI Act wherever the regulation applies.
The right combination will depend on the organisation’s role, jurisdiction, industry, AI use cases and risk exposure.
Key Takeaways for AIGP Candidates
Before the examination, ensure that you can clearly explain the following:
- NIST AI RMF has four functions: Govern, Map, Measure and Manage.
- The EU AI Act is a regulation, not a voluntary framework.
- The EU AI Act entered into force on 1 August 2024.
- ISO/IEC 42001 establishes AI management-system requirements.
- ISO/IEC 23894 provides AI risk-management guidance.
- The OECD AI Principles provide internationally recognised principles for trustworthy AI.
- The G7 Hiroshima Code is voluntary and focuses on advanced AI systems.
- A US Executive Order is a policy instrument, not an enterprise risk framework.
- Governance requirements depend on an organisation’s role, jurisdiction and use of AI.
- Effective AI governance requires continuous oversight throughout the AI lifecycle.
Final Thought
AI governance is not about memorising the names of regulations and frameworks.
It is about understanding what each instrument does, who it applies to, whether it is mandatory and how it can be translated into practical organisational controls.
That distinction can make the difference between simply passing an examination and becoming a professional capable of leading trustworthy AI initiatives.
For AIGP training and practical AI governance learning support, connect with Wiseman CyberSec.
– Wiseman CyberSec
