Glossary
AI Governance Framework
A structured set of principles, processes or controls intended to guide AI oversight inside an organization or across institutions.
Last reviewed 2026-08-22
In plain language
Frameworks may be voluntary (OECD AI Principles, NIST AI RMF), intergovernmental recommendations (UNESCO), or management-system standards (ISO/IEC 42001). They are not automatically law. Good use of a framework maps it onto legal duties, assigns owners, and reviews outcomes. Stacking frameworks without implementation produces paperwork. A direct comparison shows the distinction clearly: the EU AI Act is binding regulation—an organization operating in scope has legal duties whether or not it adopts any framework. The NIST AI Risk Management Framework, by contrast, is voluntary guidance with no independent legal force; an organization can be fully compliant with EU law while never having touched NIST's Govern-Map-Measure-Manage structure, and vice versa. A further distinction sits inside “framework” itself: ISO/IEC 42001 is not just a framework but a certifiable management-system standard, meaning a third party can formally audit and certify an organization against it, the way ISO 9001 works for quality management—OECD's AI Principles and NIST's AI RMF have no certification scheme attached. None of this makes voluntary frameworks unimportant: regulators, courts and procurement officers increasingly point to frameworks like NIST's as evidence of what “reasonable” AI governance looks like, even where no law requires adopting them by name. The practical question is always which framework, mapped onto which legal duties, with which named owner—not whether a framework exists on paper.
Why it matters for AI governance
Search demand for “AI governance framework” is high. This directory separates frameworks from statutes so readers can see what is binding.