Learn / AI governance, risk and compliance: NIST AI RMF, ISO/IEC 42001, EU AI Act, CSA AICM
AI governance, risk and compliance: NIST AI RMF, ISO/IEC 42001, EU AI Act, CSA AICM
Applying formal risk management, management-system, and regulatory frameworks to how an organisation builds, buys, and operates AI.
Researched on 2026-09-26 with AI assistance. Links and summaries can change; verify details with the original source. Not yet reviewed by a person.
What it is
This skill is about running AI risk through formal structures: a voluntary risk framework (NIST AI RMF 1.0), a certifiable management system (ISO/IEC 42001), a binding regulation (EU AI Act), and a control set you can audit against (CSA AI Controls Matrix). NIST frames AI risk as socio-technical, arguing that AI risks differ from traditional software risks because training data shifts over time and failures are hard to detect in deployment.1
The regulatory anchor in Europe is Regulation (EU) 2024/1689, published in the Official Journal on 12 July 2024, which sets risk-based rules for AI providers and deployers rather than rules about AI techniques.106
Frameworks are complementary, not competing, and the practical work is crosswalking them: CSA's AI Controls Matrix v1.1 ships mappings to ISO 42001:2023, ISO 27001, BSI AIC4, the EU AI Act, and NIST AI RMF plus AI 600-1, so one control can satisfy several obligations.8
Day to day it looks like inventories, risk registers, classification decisions, control design, evidence collection and third-party assessment questionnaires, applied to models and AI features instead of only to servers and applications.87
Why postings ask for it
14 of 48 postings ask for it (29%), and it is the defining skill of the governance cluster at 86% of 7 postings, so it is the entry requirement for those roles rather than a nice-to-have.P
Demand spreads into design and delivery work: 57% of 7 AI Security Architect postings and 40% of 5 consulting postings ask for it, which matches work like classifying a use case against the Act's risk tiers and choosing controls before build starts.P6
It is near-absent in red team (0% of 9) and research (0% of 4) and low in engineering (12% of 16), so treat it as the language you use to translate technical findings into obligations, evidence and owners.P
Concepts you should be able to explain
If you can say each of these out loud in two minutes, with an example, you are ready for the technical part of an interview on this skill.
The AI RMF is voluntary, rights-preserving, non-sector-specific and use-case agnostic, written for any organisation designing, developing, deploying or using AI. Part 1 frames AI risk and names the audience as AI actors, using the OECD definition of those who play an active role in the AI lifecycle. Part 1 also sets out characteristics of trustworthy AI systems, including valid and reliable, safe, and secure and resilient. Note that NIST says AI RMF 1.0 is being updated.1
The GenAI Profile is a cross-sectoral companion to the AI RMF for generative systems, published as NIST AI 600-1. Third-party documentation summarises it as 12 risk categories, including confabulation (false or misleading output) and CBRN information risk. Use it when your risk register needs GenAI-specific entries rather than generic model risk.23
ISO/IEC 42001:2023, Information technology, Artificial intelligence, Management system, is a certifiable AI management system standard published in 2023. Like other ISO management systems it separates mandatory clauses (context, leadership, planning, support, operation, performance evaluation, improvement) from a reference control set in Annex A; secondary guides summarise Annex A as 38 controls under nine objectives, and counts differ between commentators, so read the standard itself. The point for an interview is that 42001 governs how the organisation manages AI, not whether one model is safe.45
The Act sets four levels of risk and bans nine practices outright, including social scoring, untargeted scraping to build facial recognition databases, emotion recognition in workplaces and schools, and real-time remote biometric identification for law enforcement in public spaces. High-risk use cases include credit scoring, CV sorting and worker management, education scoring, biometric identification, law enforcement, migration, and safety components of critical infrastructure and products. Classification is driven by use case and context, so the same model can be high-risk in one product and not in another.6
Obligations attach to roles. A provider develops an AI system or general-purpose AI model, or has one developed, and places it on the market or puts it into service under its own name, whether paid or free; deployers use systems supplied by others. The Act's definition of an AI system covers machine-based systems that operate with varying autonomy, may adapt after deployment, and infer outputs such as predictions, content, recommendations or decisions. Fine-tuning and rebranding a model can move you from deployer to provider, which changes the paperwork you owe.76
For high-risk systems, Article 9 requires a risk management system that is established, implemented, documented and maintained, and treated as a continuous iterative process across the whole lifecycle with regular systematic review and updating. It requires identification and analysis of known and reasonably foreseeable risks to health, safety and fundamental rights when the system is used for its intended purpose, then estimation and evaluation of those risks. This is where a familiar ISO 27005 style risk process transfers, with fundamental rights added to the impact axis.7
Obligations arrive in stages: prohibitions 1 to 8 became effective in February 2025, the ninth prohibition (AI-generated non-consensual intimate imagery and CSAM) applies from December 2026 and was introduced through the AI Omnibus, and high-risk obligations start from 2 December 2027. Article 9 itself is listed as coming into force on 2 December 2027 for Annex III high-risk systems and 2 August 2028 for Annex I systems under Article 113(c). Because the text is being amended, always check the date and version you are advising on.67
The AI Controls Matrix v1.1 is a free vendor-agnostic control set for cloud-based AI: 247 control objectives across 18 security domains, analysed by control type, applicability and ownership, architectural relevance, LLM lifecycle relevance and threat category. It splits implementation and audit guidance by role (model provider, orchestrated service provider, application provider, AI customer, cloud service provider) and ships the AI-CAIQ questionnaire for self-assessment or vendor review, plus a STAR for AI Level 1 submission guide and machine-readable JSON/YAML/OSCAL bundles. It is the most direct bridge from framework text to a control list you can test.8
Use fictional data and authorised sandboxes. Remove employer details and secrets from any portfolio write-up. Time estimates exclude setup. Check model and cloud costs before running tests, set spending limits, and delete lab resources afterwards.
Three exercises
In order of difficulty. Free tools. Keep what you build; it is evidence.
You can state, with article references, whether a use case is prohibited, high-risk or neither, and whether your organisation is provider or deployer.67
- Pick three real use cases, for example a CV-screening assistant, an internal RAG helpdesk bot, and an emotion analytics pilot for staff calls.
- Check each against the nine prohibited practices and the high-risk use case list on the Commission's AI Act page.
- Decide provider or deployer for each using the Article 3 provider definition, and note what changes if you fine-tune a vendor model.
- Write one page per use case: tier, reasoning, role, the date obligations begin, and what you would need to confirm with legal.
Tools: web browser, text editor or spreadsheet
A risk register a reviewer accepts: named risks traced to a published taxonomy, impact on health, safety and fundamental rights, and review triggers.7921
- Choose one GenAI feature and write its intended purpose and conditions of use in plain language.
- Pull candidate risks from the MIT AI Risk Repository domain taxonomy (7 domains, 24 subdomains) and from the GenAI Profile risk categories such as confabulation.
- For each risk record the Article 9 steps: identification and analysis, then estimation and evaluation under intended use.
- Add the socio-technical angle NIST stresses: who operates it, who is affected, and how a failure would be detected.
- Define the review trigger and cadence that makes the register a continuous iterative process rather than a one-off document.
Tools: MIT AI Risk Repository database copy, spreadsheet
A gap report that shows control coverage for one AI service, evidence per control, and which ISO 42001 and EU AI Act obligations each gap touches.8
- Download AICM v1.1 and pick the role view that matches your position (for example AI Customer or Application Provider).
- Scope to one AI service and select the relevant domains from the 18, filtering by LLM lifecycle relevance and threat category.
- Complete the AI-CAIQ for that scope, recording owner and evidence for each answer rather than yes or no.
- Use the bundled mappings to ISO 42001:2023, the EU AI Act and NIST AI RMF and 600-1 to show which obligations each gap affects.
- Write a two-page report: top five gaps, owners, proposed control text, and what evidence would close each gap.
Tools: CSA AICM v1.1 spreadsheet and AI-CAIQ, spreadsheet
Practice questions
Written from the concepts above, not collected from a named employer. Open one, answer it out loud, then tick the points you covered; the score stays in this browser.
Why does NIST argue AI risk needs its own framework rather than reuse of existing software risk practice?NIST AI RMF 1.0 framing
Say your answer out loud or write it down, then tick what you covered:
0 of 4 covered
A product team wants to fine-tune a vendor model and ship it under our brand. What changes from a compliance point of view?Provider and deployer roles
Say your answer out loud or write it down, then tick what you covered:
0 of 4 covered
Walk me through what Article 9 actually requires for a high-risk system.Article 9 risk management system
Say your answer out loud or write it down, then tick what you covered:
0 of 4 covered
What is the difference between certifying against ISO/IEC 42001 and conforming to the EU AI Act?ISO/IEC 42001 as a management system
Say your answer out loud or write it down, then tick what you covered:
0 of 4 covered
How would you choose controls for a customer-facing GenAI assistant without inventing a framework?CSA AICM and the AI-CAIQ
Say your answer out loud or write it down, then tick what you covered:
0 of 4 covered
Which AI use cases are simply off the table in the EU, and which are heavily regulated?EU AI Act risk tiers and prohibitions
Say your answer out loud or write it down, then tick what you covered:
0 of 4 covered
Where do you get your risk list from, and how do you avoid a register that is just a list of buzzwords?MIT AI Risk Repository and Generative AI Profile
Say your answer out loud or write it down, then tick what you covered:
0 of 4 covered
How do you keep advice current when the frameworks themselves are moving?Phased application and amendment
Say your answer out loud or write it down, then tick what you covered:
0 of 4 covered
Sources
Every numbered claim above links here. P = the platform's own coding of 48 job postings.
- AI Risk Management Framework 1.0, Executive Summary (AIRC) NIST
- Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1) NIST
- NIST AI RMF Generative AI Profile (NIST AI 600-1), 12 risk categories and operationalization (secondary summary, not a NIST page) Modulos documentation
- ISO/IEC 42001:2023, Information technology, Artificial intelligence, Management system (catalogue entry; page returned HTTP 403 on fetch, details from the search listing; price and page count not stated) ISO/IEC
- ISO 42001 Requirements: Clauses and Controls (secondary guide; Annex A control counts differ between commentators) Compyl
- AI Act: regulatory framework for AI European Commission
- Article 9: Risk Management System, EU AI Act Explorer artificialintelligenceact.eu
- AI Controls Matrix (AICM) v1.1 Cloud Security Alliance
- AI Risk Repository, risk database and taxonomies MIT AI Risk Initiative
- The Act Texts (Official Journal publication date and text versions) artificialintelligenceact.eu
Resources
Free first. Levels: intro means no prior knowledge of this skill; working means you can apply it on a project; advanced means research depth or specialist tooling.
- introAI Risk Management Framework (programme hub) NIST, Standard freeGet the shape of AI RMF and its current status before you commit a programme to it, including the note that a revision is in progress.GovernanceArchitectConsultantEngineer
- introSummary of Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence EUR-Lex (Publications Office of the EU), Guide freeShort official summary of scope, risk tiers and obligations, so you can brief a project team before reading the full regulation.GovernanceConsultantArchitect
- introAI Standards Hub training modules (trustworthy AI, risk management frameworks, explainability) AI Standards Hub (Alan Turing Institute, BSI, NPL), Course freeShort structured modules that take you from no standards background to knowing which bodies publish what and how risk frameworks fit together.GovernanceArchitectConsultant
- introTuring Commons skills tracks (responsible research and innovation, AI ethics and governance) The Alan Turing Institute, Course freeOpen course material on governance concepts and stakeholder engagement, useful background for GRC leads writing AI policy for the first time.GovernanceConsultantResearcher
- introAI Act: regulatory framework for AI European Commission (Shaping Europe's digital future), Standard freeLearn the AI Act risk tiers and provider versus deployer duties so you can place your organisation's systems in the right obligation bucket.GovernanceArchitectConsultantEngineer
- introAI Security and CSA's AI Controls Matrix (AICM): Framework for Trustworthy and Compliant GenAI Cloud Security Alliance (recorded session, listed via Class Central), Course freeHear the AICM authors explain the control domains and shared responsibility model before you open the spreadsheet yourself.GovernanceArchitectConsultant
- introAI Management Essentials tool (accessible version) UK Department for Science, Innovation and Technology, Hands-on lab freeWork through a short government self-assessment on AI policy, risk and reporting to produce your first honest baseline of organisational maturity.GovernanceConsultantArchitect
- introArtificial intelligence guidance hub (UK GDPR) Information Commissioner's Office, Guide freeSee how data protection law already bites on AI systems, so your AI governance work reuses DPIA and lawful basis processes instead of duplicating them.GovernanceConsultantArchitect
- workingIntroductory Guidance to the AI Controls Matrix Cloud Security Alliance, Standard freeUnderstand how AICM splits duties across the AI supply chain before you assign controls to model providers, platform teams and application owners.GovernanceArchitectEngineerConsultant
- workingArtificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 NIST, Standard freeThe framework document itself; read it to map each function and subcategory onto controls and owners in your organisation.GovernanceArchitectConsultantEngineer
- workingAI RMF: Generative Artificial Intelligence Profile (NIST AI 600-1) NIST, Standard freePull concrete suggested actions for generative AI risks such as data leakage, confabulation and CBRN misuse into your control set and risk register.GovernanceArchitectEngineerConsultant
- workingNIST AI RMF Playbook NIST, Hands-on lab freeWork a real system through the subcategories and produce the evidence artifacts; output is a filled gap assessment you can show an auditor.GovernanceArchitectEngineer
- workingRegulation (EU) 2024/1689 (AI Act), consolidated text EUR-Lex / Publications Office of the EU, Standard freeRead the in-force wording with amendments applied so obligations and dates you quote in a compliance plan are current.GovernanceConsultantArchitect
- workingMIT AI Risk Repository (database, causal and domain taxonomies) MIT FutureTech / MIT AI Risk Initiative, Hands-on lab freeFilter 1700+ catalogued risks drawn from 74 frameworks to build a risk register for your own use case instead of inventing one.GovernanceArchitectResearcherConsultant
- workingAI RMF Knowledge Base and Playbook NIST Trustworthy and Responsible AI Resource Center, Tool freeLift suggested actions, documentation prompts and references per subcategory straight into control descriptions and audit evidence lists.GovernanceArchitectEngineerConsultant
- workingAI Standards Hub standards database AI Standards Hub (Alan Turing Institute, BSI, NPL), Tool freeSearch published and in-development AI standards by topic and body, so you can answer which standard covers a given control question.GovernanceArchitectConsultant
- workingModel Cards for Model Reporting Mitchell et al. (arXiv), Paper freeAdopt the documentation pattern that transparency clauses in AI RMF, AICM and AI Act technical documentation all trace back to.GovernanceEngineerResearcherArchitect
- workingAI Risk Management Framework 1.0, full framework text NIST Trustworthy and Responsible AI Resource Center, Guide freeRead the Govern, Map, Measure and Manage functions in full so you can write outcomes and evidence requirements that trace to named subcategories.GovernanceArchitectConsultantEngineer
- advancedAI Controls Matrix (AICM) v1.1 Cloud Security Alliance, Tool freeMap an AI service against a control matrix built for cloud AI systems and turn gaps into an assessment plan or vendor questionnaire.GovernanceArchitectEngineerConsultant
- advancedCOMPL-AI: EU AI Act technical interpretation and LLM benchmarking suite (code) ETH Zurich / INSAIT / LatticeFlow AI, Hands-on lab freeRun benchmarks that are mapped to 18 technical requirements derived from the AI Act and see what evidence a model actually produces.GovernanceEngineerResearcherArchitect
- advancedRisk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems arXiv, Paper freeA catalogue of GPAI risk sources and mitigations you can lift into a foundation-model risk assessment or a supplier questionnaire.GovernanceResearcherArchitectConsultant
- advancedDigital Omnibus on AI: proposal amending Regulation (EU) 2024/1689, COM(2025) 836 European Commission / EUR-Lex, Standard freeRead the proposed simplification changes directly so your compliance timeline is based on the text rather than on press coverage.GovernanceConsultantArchitect
- advancedData Cards: Purposeful and Transparent Dataset Documentation for Responsible AI Pushkarna, Zaldivar, Kjartansson (arXiv), Paper freeSpecify dataset provenance and limitation records at the level of detail auditors and data governance reviews demand, not just a README.GovernanceEngineerResearcher
- advancedFrom Transparency to Accountability and Back: A Discussion of Access and Evidence in AI Auditing arXiv (October 2024), Paper freeThink clearly about what access an auditor needs and what counts as evidence, before you agree to an audit scope you cannot deliver.GovernanceResearcherConsultant
Gaps the research could not fill with a good free source: ISO/IEC 42001 itself: the ISO catalogue page did not appear in any search result today, so the existing entry was dropped rather than reproduced from memory. Also found no free full text (ISO standards are paid) and no free implementation course.; ISO/IEC 23894 (AI risk management guidance) and the 42001 to NIST AI RMF crosswalk: no confirmed source page.; An article-by-article EU AI Act explorer: the artificialintelligenceact.eu URL in the existing list did not reappear in a search result, so official Commission pages are used instead.; NIST AI 100-2 (adversarial machine learning taxonomy): no confirmed URL in today's results, although GRC readers need it for control mapping.; A free hands-on conformity assessment or high-risk classification lab for the EU AI Act (fill-in exercise with model answers).; A free ISO 42001 or AICM internal audit workbook with worked evidence examples; CSA and IAPP audit training in this space is paid.; Confirmed course durations and prices for CSA STAR AI Controls Auditor training: page not fetched, price not stated in search results.
Paid options
Most of what postings ask for on this skill is covered by the free material above. These are the paid courses and certifications that touch it, with what they add and what free already covers. Showing 6 of 11: ones postings name first, then the most focused on this skill. All paid options.
- Cost
- USD 550 per exam (CIPP/A, CIPP/C, CIPP/CN, CIPP/E, CIPP/US), list price on the IAPP store
- Duration
- not stated
- Format
- exam only
- Prerequisite
- none stated
- In the 48 postings
- Named in 1 of 48 postings: a plus.
Adds over free material: Gives the privacy law grounding that AI governance work keeps running into, in a jurisdiction-specific form (EU, US, Canada, Asia).
Free already covers: Regulator guidance and the statutes themselves (GDPR text, state privacy laws, EDPB opinions) are free to read.
- Cost
- not stated on the provider page
- Duration
- Six-month eligibility period from registration to sitting the exam
- Format
- exam only
- Prerequisite
- Pass the exam, pay the US$50 application processing fee, submit an application demonstrating experience requirements, and comply with the Information Systems Auditing Standards
- Renewal
- ISACA Continuing Professional Education policy applies; credit numbers not stated on the page we fetched
- In the 48 postings
- Named in 1 of 48 postings: Information Security Architect - AI (listed).
Adds over free material: Audit and control testing discipline, which is what AI model and pipeline assurance work actually looks like day to day.
Free already covers: Control catalogues (NIST SP 800-53, ISO summaries) and AI audit guidance published free by standards bodies cover much of the content.
- Cost
- USD 799 non-member, USD 649 member (exam only). Optional AIGP online training is USD 1,195 non-member / USD 995 member, 13 CPEs.
- Duration
- 100 questions, 2.75 hours plus a 15-minute break; exam must be taken within one year of purchase
- Format
- exam only
- Prerequisite
- none stated
- Renewal
- 2-year term; 20 continuing education credits plus a maintenance fee (covered by IAPP membership, otherwise USD 250 at recertification)
- In the 48 postings
- Named in 1 of 48 postings: a plus.
Adds over free material: It forces one structured pass over AI law, risk and lifecycle governance vocabulary and gives a credential that governance hiring managers already recognise.
Free already covers: The NIST AI Risk Management Framework, the EU AI Act text, ISO/IEC 42001 summaries and OWASP LLM guidance are free and cover most of the same subject matter.
- Cost
- not stated on the provider page
- Duration
- 150-question exam covering four job practice domains
- Format
- exam only
- Prerequisite
- Pass the exam, pay the US$50 application processing fee, and submit an application demonstrating experience requirements; the years of experience are not stated on the page we fetched
- Renewal
- ISACA Continuing Professional Education policy applies; credit numbers not stated on the page we fetched
- In the 48 postings
- Named in 2 of 48 postings: Cyber - AI Security - Senior - Consulting (a plus); Information Security Architect - AI (listed).
Adds over free material: Management-level framing of security programme, risk and incident management, which is the language the GRC and consulting postings in this set use, and it is the prerequisite route into AAISM.
Free already covers: NIST Cybersecurity Framework, NIST AI RMF and ISO summaries cover the concepts free; what you buy is the exam and the credential.
- Cost
- not stated on the provider page
- Duration
- not stated
- Format
- exam only
- Prerequisite
- none stated
- In the 48 postings
- Named in 1 of 48 postings: a plus.
Adds over free material: Entry-level coverage of core security functions for people crossing in from IT or development rather than from a security role.
Free already covers: Free vendor and community training covers the same fundamentals; nothing in Security+ V7 is AI-specific.
- Cost
- USD 599 (US and all regions not otherwise listed, and Asia Pacific, Middle East, Africa); EUR 575.04 in EMEA; GBP 485.19 in the UK
- Duration
- not stated
- Format
- exam only
- Prerequisite
- not stated on the pages we read
- In the 48 postings
- Named in 2 of 48 postings: Cyber - AI Security - Senior - Consulting (a plus); Secure AI Engineer Manager (listed).
Adds over free material: Vendor-neutral cloud security coverage that satisfies the generic 'cloud security cert' wording in the field delivery posting without committing to one provider.
Free already covers: CSA Cloud Controls Matrix and the free guidance from AWS, Azure and Google cover the same control areas at no cost.