← Library Reference · 2026

AI governance frameworks compared.

EU AI Act vs ISO 42001 vs NIST AI RMF vs Navigator Framework™. What each one does, where each operates, and why they are complementary layers rather than alternatives.

Orquestra AI 06 / 2026 Reference page

The most common question organisations ask when beginning an AI governance programme is "which framework should we use?" It is the wrong question. The EU AI Act, ISO 42001, NIST AI RMF, and the Navigator Framework™ are not competing answers to the same question. They operate at different levels and address different problems. The better question is: how do they fit together?

The answer is straightforward once the levels are clear. Three of the four frameworks operate above the delivery level — they define what AI governance requires, how to structure a management system, and how to categorise AI risk. None of them specify what human oversight looks like at the point where AI actually gets built. That is the gap. The Navigator Framework fills it.

Not alternatives. Layers.

  1. EU AI Act · what · regulatory
    Sets legal obligations. Classifies AI systems by risk and impact. Defines what organisations must demonstrate. Does not specify how to build the governance structures that meet those obligations.
  2. ISO 42001 + NIST AI RMF · what · management
    Structure the management system and risk framework. Define governance functions, categories, and oversight responsibilities. Do not specify the operational controls that make them work at the delivery level.
  3. Navigator Framework™ · how · operational
    Specifies exactly what human oversight looks like at every SDLC gate. Named approval. Quantitative controls. Attestation templates. The operational layer that makes the other three frameworks possible in practice.

The gap — and what fills it.

The comparison below shows where each framework operates, what question it answers, and critically — what it does and does not specify. The gap between the three "what" frameworks and the operational level is where most AI governance programmes stall.

Framework comparison infographic: Three frameworks tell you what — EU AI Act (Regulation), ISO 42001 (Standard), NIST AI RMF (Framework) — all fail to specify how to implement or deliver operational controls. Navigator Framework™ fills the gap at the Operational/Delivery Level, specifying gates, roles, checks, evidence, mechanisms and templates. Compliance starts at the top. Governance happens in the delivery.
Reference · EU AI Act · ISO 42001 · NIST AI RMF · Navigator Framework™
Compliance starts at the top. Governance happens in the delivery.

What each one actually does.

EU AI Act · regulation · mandatory in EU/EEA

What it is. EU regulation governing AI systems based on the risk they pose to individuals. Applies to organisations placing AI on the EU market or deploying it in the EU — including non-EU organisations serving EU users.

What it requires. Risk classification per AI system. Human oversight documentation. Post-market monitoring. Transparency obligations for limited-risk systems. Conformity assessment for high-risk systems.

What it does not specify. How to build the accountability structures, audit trails, or oversight checkpoints it requires. An organisation that is legally compliant still needs an operational framework to produce the evidence.

Defines the obligation. Does not specify the mechanism. Your organisation must build it.

ISO 42001 · management system standard · optional certification

What it is. International standard for AI management systems. Provides a certifiable framework for how organisations govern AI at the management system level — policies, responsibilities, objectives, and continual improvement.

What it requires. Management system documentation. AI policy. Risk assessment process. Objectives and performance indicators. Competency requirements. Internal audit. Management review. Continual improvement process.

What it does not specify. The operational controls that satisfy its clauses. ISO 42001 tells you what your management system must cover. It does not tell you what a human oversight checkpoint looks like in a live AI development workflow.

Structures the management system. Does not specify operational controls. Your organisation must design and run them.

NIST AI RMF · risk management framework · voluntary

What it is. Voluntary framework from the US National Institute of Standards and Technology. Provides a flexible, structured approach to managing AI risk across the AI lifecycle — particularly relevant for US federal and regulated sector contexts.

What it requires. AI risk governance structure. Risk identification, assessment, and response processes. Mapping of AI risk categories to organisational functions (Govern, Map, Measure, Manage). Documentation and review cadence.

What it does not specify. How to implement and evidence the controls it describes at the engineering and delivery level. Like ISO 42001, it operates above the point where AI is actually built.

Categorises risk and governance functions. Does not specify operational execution. Your organisation must implement and evidence it.

Navigator Framework™ · operational framework · open for adoption

What it is. An operational governance framework for AI-native development. Specifies named human accountability at five SDLC phase gates — Define, Design, Build, Verify, Run — with quantitative controls scaled by EU AI Act-aligned risk class.

What it specifies. Gates: Five mandatory checkpoints. Roles: Named human accountabilities at each gate. Controls: 25 quantitative controls with thresholds. Attestations: Signed evidence templates per gate. Risk classes: Four classes aligned to EU AI Act.

What it produces. Audit trails, approval records, and attestation evidence that satisfy EU AI Act documentation requirements and ISO 42001 control clauses — as a natural byproduct of how AI is built, not as a retrospective exercise.

Specifies gates, roles, checks, and evidence. Provides the mechanism, templates, and operational evidence that stands up to scrutiny.


How they work together.

Do I need all four? Not necessarily all at once — but each addresses a different need. EU AI Act applies if you have EU/EEA users, clients, or operations. ISO 42001 is relevant if you want certifiable management system assurance for clients, procurement, or board reporting. NIST AI RMF is most relevant for US federal and regulated sector contexts. Navigator Framework™ applies to any organisation building or operating AI regardless of jurisdiction — it is the operational foundation the others assume exists.

Where do I start? Start with the Navigator Framework. It is the operational foundation — the phase gates, human oversight checkpoints, and audit trails that the other three frameworks assume exist but do not specify. Building Navigator first means ISO 42001 controls fall naturally from your practice, EU AI Act documentation already exists as a product of your daily operations, and NIST AI RMF risk functions have an operational home. Compliance becomes a side effect of governance done properly — not a separate exercise.

How do they relate in practice? Think of them as four levels of the same building. EU AI Act sets the legal obligations — what you must demonstrate. ISO 42001 structures how you manage AI at the organisational level. NIST AI RMF provides a risk categorisation model. Navigator Framework™ is where it all becomes operational — the named approvals, the gate checkpoints, the attestation records that produce the evidence the other three require. An organisation implementing the Navigator Framework is already building toward the others. An organisation implementing the others without something like Navigator has documented obligations but no operational mechanism to meet them.

The Navigator Framework and ISO 42001. Every Navigator phase gate maps to specific ISO 42001 clauses. Gate 1 (Define) produces the documented AI use case requirements ISO 42001 Clause 6 requires. Gate 3 (Build) produces the independent review evidence Clause 8 requires. Gate 5 (Run) produces the operational control monitoring Clause 9 requires. Implementing the Navigator Framework accelerates ISO 42001 readiness because the evidence is built in, not produced retrospectively.

The right starting point for your situation.

  1. If you are building AI products — start with Navigator Framework™
    Build the operational governance foundation first. Phase gates, human oversight, attestation evidence. EU Act compliance and ISO 42001 readiness follow naturally from good practice at the delivery level.
  2. If you are facing regulatory or audit scrutiny — start with a Navigator Audit
    An independent assessment against the Navigator Framework identifies your specific gaps — gate by gate, failure mode by failure mode — and produces the remediation roadmap your compliance function needs.
  3. If you are seeking ISO 42001 certification — Navigator accelerates the path
    The Navigator Framework's controls map to ISO 42001 clauses. Implementing Navigator provides the operational evidence the certification requires. Ask us about the clause mapping and implementation approach.
Read next
What the EU AI Act actually requires.
Essay 06 →
Back to library
Library · essays & downloads.
All writing →