Unlock Exclusive Cybersecurity Learning Resources — Free & Limited-Time Offer!

ENROLL NOW

Enroll for CEH & Sec+ Hands-on Training Combo - get up to 30% Discount

Artificial intelligence adoption is accelerating faster than many organisations can establish effective governance.

Bain reported in 2025 that 95% of surveyed US companies were using generative AI. The research also found that the average number of production use cases had doubled between October 2023 and December 2024.

This growth creates enormous opportunities, but it also introduces risks involving privacy, cybersecurity, discrimination, transparency, accountability, intellectual property and regulatory compliance.

Organisations therefore need more than an AI policy. They need structured ways to identify risks, assign accountability, evaluate impacts and monitor AI systems throughout their lifecycle.

For professionals preparing for the IAPP Artificial Intelligence Governance Professional certification, understanding the major AI governance instruments is essential. However, candidates must also recognise an important distinction:

A framework, regulation, standard, policy directive and code of conduct are not the same thing.This guide examines five important AI governance instruments and explains how each should be understood.

1. NIST Artificial Intelligence Risk Management Framework

The NIST Artificial Intelligence Risk Management Framework, commonly called the NIST AI RMF, was released in January 2023 by the US National Institute of Standards and Technology.

It is a voluntary and industry-agnostic framework designed to help organisations manage risks associated with the design, development, deployment and use of AI systems.

Rather than providing a rigid compliance checklist, the framework helps organisations establish repeatable processes for trustworthy AI.

The NIST AI RMF is structured around four functions:

Govern

Establish policies, accountability, organisational roles, risk tolerances and oversight mechanisms for AI.

Map

Understand the purpose, context, stakeholders, potential impacts and operating environment of an AI system.

Measure

Assess, analyse and track AI risks using appropriate qualitative and quantitative methods.

Manage

Prioritise identified risks, implement controls, monitor responses and determine whether risks should be accepted, mitigated, transferred or avoided.

AIGP Accuracy Note  

The four official functions are:

Govern → Map → Measure → Manage

“Monitor” is not a separate NIST AI RMF function. Monitoring activities may support the framework, but the fourth function is officially called Manage.

Why it matters  

The NIST AI RMF helps organisations translate broad responsible-AI principles into practical governance activities. It can be adapted across industries and used alongside privacy, cybersecurity, enterprise-risk and compliance programmes.

For AIGP candidates, the important point is to understand both the four functions and the iterative relationship between them.


2. European Union Artificial Intelligence Act

The EU AI Act is not a voluntary framework. It is a legally binding regulation governing the development, deployment and use of AI systems within its scope.

The Act entered into force on 1 August 2024 and follows a phased implementation timeline. Prohibited AI practices and AI-literacy requirements began applying in February 2025. Obligations concerning general-purpose AI models began applying in August 2025.

Most remaining provisions are scheduled to become applicable from 2 August 2026, while certain requirements for high-risk AI systems connected with regulated products follow a later timeline.

The Act applies a risk-based regulatory model.

Prohibited AI practices  

Certain practices presenting unacceptable risks to fundamental rights are prohibited. These include specific forms of social scoring, manipulative AI, biometric categorisation and other practices defined by the regulation.

The prohibitions are specific. It would be inaccurate to assume that every use of surveillance, biometrics or automated monitoring is automatically banned.

High-risk AI systems  

AI used in sensitive areas such as employment, education, essential services, law enforcement and certain regulated products may be classified as high risk.

Depending on the system and the organisation’s role, requirements may include:


Transparency obligations  

Certain AI systems must disclose that users are interacting with AI. Additional transparency requirements may apply to synthetic content, deepfakes and general-purpose AI models.

Minimal or no-risk systems  

Many ordinary AI applications remain largely unaffected, although organisations may still voluntarily adopt codes of conduct and responsible-AI practices.

AIGP Accuracy Note  

The EU AI Act was not adopted in late 2023 and is no longer merely “expected to take effect.”

It entered into force in August 2024, and several of its provisions are already applicable.

Why it matters  

The EU AI Act moves AI governance from voluntary principles to enforceable responsibilities. Its influence is also likely to extend beyond Europe because organisations offering AI systems or services in the EU may fall within its scope.

AIGP candidates should understand the difference between prohibited practices, high-risk requirements, transparency obligations and general-purpose AI responsibilities.

3. ISO/IEC 42001 and ISO/IEC 23894

ISO and the International Electrotechnical Commission have developed complementary standards for AI governance and risk management.

Although they are frequently discussed together, ISO/IEC 42001 and ISO/IEC 23894 serve different purposes.

ISO/IEC 42001:2023  

ISO/IEC 42001 establishes requirements for an Artificial Intelligence Management System.

It helps an organisation build an enterprise-wide system of policies, roles, objectives, processes and controls for the responsible development or use of AI.

The standard follows the Plan-Do-Check-Act model commonly used across ISO management-system standards.

It addresses areas such as:


Because ISO/IEC 42001 is a requirements-based management-system standard, an organisation may pursue certification through an independent certification body.

ISO/IEC 23894:2023  

ISO/IEC 23894 provides guidance on managing risks specifically associated with AI.

It helps organisations integrate AI-related risks into their existing risk-management activities and considers risks affecting organisations, individuals, groups and society.

The standard can support AI risk identification, analysis, evaluation, treatment, communication and monitoring.

AIGP Accuracy Note  

ISO/IEC 42001 is an AI management-system requirements standard against which an organisation may be certified.

ISO/IEC 23894 is a risk-management guidance document. It is not a management-system certification standard.

Why they matter  

Together, the two standards provide complementary value.

ISO/IEC 42001 helps establish the organisational management system, while ISO/IEC 23894 provides deeper guidance for managing AI-specific risks within that system.

For AIGP professionals, understanding this distinction is important when advising organisations about governance implementation and certification.


4. OECD Artificial Intelligence Principles

The OECD AI Principles were originally adopted in 2019 and updated in May 2024 to address developments involving general-purpose and generative AI.

They were the first intergovernmental standard for trustworthy AI and have influenced national policies, international initiatives and other governance instruments.

The principles promote:


They are supported by recommendations for governments covering research investment, digital ecosystems, enabling policy environments, workforce development and international cooperation.

AIGP Accuracy Note  

The OECD AI Principles are not a law or a certification standard.

They provide high-level, internationally recognised guidance for governments and AI actors. Their influence comes from policy adoption and global alignment rather than direct enforcement.

Why they matter  

Many international AI governance initiatives build on concepts introduced or reinforced by the OECD Principles.

They also help AIGP candidates understand the values that sit behind more detailed regulations, risk frameworks and technical standards.


5. G7 Hiroshima Process International Code of Conduct

The G7 Hiroshima Process International Code of Conduct was introduced in 2023 to support safe, secure and trustworthy development of advanced AI systems.

It was developed by the G7 members with the participation of the European Union and is particularly relevant to organisations developing advanced AI systems, including powerful foundation and generative AI models.

The Code contains 11 principles covering areas such as:


AIGP Accuracy Note  

The Hiroshima Process Code is a voluntary international code of conduct. It is not a binding global AI regulation.

Its principal focus is on organisations developing advanced AI systems, although many of its practices can also inform deployment and procurement decisions.

Why it matters  

The Code addresses risks that became more visible with the growth of foundation models and generative AI, including disinformation, deepfakes, model misuse and systemic security concerns.

It also demonstrates how international cooperation can influence organisational behaviour even without creating a legally binding law.

Where Does the 2025 US Executive Order Fit?  

Executive Order 14179, titled “Removing Barriers to American Leadership in Artificial Intelligence,” was signed on 23 January 2025.

It directed the development of a national AI Action Plan and required a review of existing federal AI policies that could conflict with the administration’s approach to innovation and US leadership.

The Executive Order is important policy context, especially for professionals monitoring the US regulatory environment.

However, it should not be classified as an organisational AI risk-management framework comparable to the NIST AI RMF.

It also should not be described as a comprehensive law establishing private-sector AI governance obligations.

AIGP Accuracy Note  

Executive Order 14179 is a federal policy directive.

NIST AI RMF is a voluntary risk-management framework.

The EU AI Act is a binding regulation.

ISO/IEC 42001 is a management-system standard.

Recognising these classifications is essential for accurate AI governance analysis.

How These Instruments Work Together  

Organisations do not necessarily have to choose only one instrument.

A multinational organisation could:

Key Takeaways for AIGP Candidates  

Before the examination, ensure that you can clearly explain the following:


Final Thought

AI governance is not about memorising the names of regulations and frameworks.

It is about understanding what each instrument does, who it applies to, whether it is mandatory and how it can be translated into practical organisational controls.

That distinction can make the difference between simply passing an examination and becoming a professional capable of leading trustworthy AI initiatives.

For AIGP training and practical AI governance learning support, connect with Wiseman CyberSec.


– Wiseman CyberSec

Ready to Advance Your Cybersecurity Career?

Stay ahead with expert-led cybersecurity training, practical learning, and insights into the latest technologies, standards, and industry best practices. Connect with Wiseman CyberSec to explore training programs designed for today’s security professionals.

Request For : Enrolling Our Course

By registering details, you agree with our Terms & Conditions, Privacy and Cookie Policy.

GET A FREE CONSULTATION

wisemancybersec.com
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.