You're setting up governance for generative AI and face a key decision: should you build on your existing enterprise risk management framework, adopt a new AI-specific standard, or combine both? The answer isn't one-size-fits-all.
Your decision depends on three factors: your regulatory environment, your organization's AI maturity, and the specific risks your generative AI use cases introduce.
The Decision You're Facing
Your compliance and risk teams need a structured approach to govern generative AI systems. You have three main paths:
Path A: Extend your current Enterprise Risk Management Framework (ERMF) with AI-specific controls
Path B: Implement a dedicated AI Management System under ISO/IEC 42001
Path C: Adopt the NIST AI RMF as your primary governance layer
Each path addresses core risks, non-deterministic outputs, deepfake threats, layered opacity, but through different mechanisms. Your choice shapes everything from audit scope to board reporting.
Key Factors That Affect Your Choice
Regulatory scrutiny: If you're a financial institution subject to SR 11-7, your model risk management framework already covers validation, approval, and ongoing monitoring. Generative AI fits into this structure, but you'll need new controls for probabilistic outputs and third-party foundation models.
Existing governance maturity: Organizations with mature Plan-Do-Check-Act (PDCA) cycles and established risk tiers can often extend current frameworks. Those building governance from scratch may benefit from a purpose-built AI Management System.
Deployment speed vs. control: If you're racing to production, adding AI controls to your ERMF gets you moving faster. If you're planning enterprise-wide AI transformation, a dedicated AI Management System provides better long-term structure.
Supply chain complexity: When you're using Foundation Model Providers and multi-layered AI systems, you need clear accountability across the AI supply chain. ISO/IEC 42001's Annex A Controls explicitly address vendor model risk and outsourced models.
Path A: Extend Your Enterprise Risk Management Framework
Choose this path if you're in a regulated industry with established risk functions and your generative AI use cases fit within existing business processes.
When this works:
- You already operate under SR 11-7 or equivalent model risk management guidance
- Your GRC leaders, CROs, and CIAs have authority across three lines of defense
- You're deploying generative AI to augment existing workflows (customer service, document analysis, fraud detection)
- Your organization values consistency with current risk taxonomy and reporting
What you'll need to add:
- Controls for non-deterministic outputs (your traditional preventive-detective-corrective model still applies, but you need verification mechanisms like Amazon Bedrock Guardrails Automated Reasoning checks)
- Deepfake detection capabilities in KYC and document verification processes
- Risk tiering that accounts for AI System Impact Assessment results
- Vendor Due Diligence procedures that cover Foundation Model Providers
The trade-off: You maintain governance continuity but risk treating generative AI as just another technology risk. The gap between recognition and implementation remains real, 84% of executives view responsible AI as a top management responsibility, yet only 25% have programs that fully address it. Extending your ERMF works only if you genuinely adapt it, not just relabel existing controls.
Path B: Implement ISO/IEC 42001 as a Dedicated AI Management System
Choose this path if you're building enterprise-wide AI capabilities and need board-level commitment to AI governance.
When this works:
- You're deploying multiple AI systems across business units
- You need third-party certification for customer assurance or regulatory positioning (AWS became the first major cloud provider to achieve accredited certification for ISO/IEC 42001)
- Your organization responds well to structured management systems (you've successfully implemented ISO 27001 or ISO 9001)
- You want governance that scales with AI innovation
What you'll implement:
- Annex A Controls covering the full AI lifecycle (ISO/IEC AI Lifecycle Processes (ISO/IEC 5338) from development through Post-Market Monitoring)
- Documented AI Actors and Stakeholder Engagement procedures
- Impact Assessment (ISO/IEC 42005) as a required step before high-risk deployments
- Continuous improvement through PDCA cycles specific to AI systems
The trade-off: You create a parallel governance structure that may duplicate existing risk functions. Your internal audit team now has two frameworks to validate. You'll need executive sponsorship to integrate the AI Management System with your ERMF rather than operating them in silos.
Path C: Adopt NIST AI RMF as Your Primary Governance Layer
Choose this path if you're a U.S.-based organization or government contractor prioritizing alignment with federal guidance.
When this works:
- You operate in sectors where NIST frameworks carry regulatory weight
- You need a risk-based approach that doesn't prescribe specific controls
- Your AI use cases vary widely in risk profile, requiring flexible Risk Tiering
- You want to use the AI RMF Playbook and generative AI Profile for implementation guidance
What you'll implement:
- Govern, Map, Measure, Manage functions applied to each AI system
- AI RMF Profiles tailored to your organization's risk appetite and use cases
- Contextual Risk Factors analysis for each deployment
- Root Cause Analysis procedures when AI systems produce harmful outputs
The trade-off: The AI RMF provides principles and functions but less prescriptive detail than ISO/IEC 42001's Annex A Controls. You'll need to define your own controls and validation evidence. For organizations accustomed to checkbox compliance, this flexibility can feel like ambiguity.
Summary Matrix
| Factor | Path A: Extend ERMF | Path B: ISO/IEC 42001 | Path C: NIST AI RMF |
|---|---|---|---|
| Best for | Regulated financial institutions | Enterprise AI transformation | U.S. federal contractors |
| Governance model | Integrate with existing risk functions | Dedicated AI Management System | Risk-based framework overlay |
| Certification | No external certification | Third-party certification available | No certification program |
| Implementation speed | Fastest (builds on current controls) | Moderate (requires new PDCA structure) | Fast (principles-based) |
| Control specificity | Varies by existing ERMF | High (Annex A prescribes controls) | Low (organization defines controls) |
| Vendor risk coverage | Requires custom additions | Built-in Outsourced Models controls | Addressed in Map function |
Your choice isn't permanent. Many organizations start with Path A to address immediate compliance needs, then evolve toward Path B as AI deployment scales. Others combine Path C's risk functions with Path B's control structure.
The wrong choice isn't picking the "lesser" framework, it's picking one that doesn't match your organization's governance maturity, regulatory environment, and AI ambitions. If you're unsure which path fits, start by auditing your current risk framework against the eight risk areas: fairness, explainability, privacy and security, safety, controllability, veracity and robustness, governance, and transparency. The gaps you find will point you toward the framework that closes them most efficiently.



