Two AI governance frameworks are getting the most attention in healthcare compliance right now. Neither is legally required. Both are increasingly referenced in vendor contracts, payer agreements, and OCR guidance. Understanding the difference — and which one applies to your situation — is the first step to building an AI governance posture that actually holds up.

What each framework actually is

ISO/IEC 42001 is an international standard published in 2023 for AI Management Systems (AIMS). It's structured like ISO 27001 — prescriptive, auditable, and certifiable by an accredited third party. Organizations that implement it can earn a certification that demonstrates external accountability for how they govern AI.

NIST AI RMF (AI Risk Management Framework) is a voluntary guide published by the US National Institute of Standards and Technology in 2023. It provides a structured approach to identifying, assessing, and managing AI risk — organized around four core functions.

Govern
Establish policies, accountability structures, and culture for responsible AI
Map
Identify the context, uses, and risks of specific AI systems
Measure
Analyze and assess AI risks using quantitative and qualitative methods
Manage
Prioritize and address identified risks with documented response plans

The key differences

Factor ISO 42001 NIST AI RMF
Type International standard (certifiable) US federal voluntary framework
Structure Prescriptive — specific clauses, annexes, required documentation Flexible — functions and practices to adopt as relevant
Third-party verification Yes — certification by accredited body available No — no formal certification path
Healthcare fit Strong — maps to HIPAA safeguard requirements for AI Strong — aligns with NIST CSF familiar to most healthcare IT
Implementation effort Higher — requires formal AIMS documentation set Lower — can be adopted incrementally
Current legal requirement Not required in US healthcare (2026) Not required in US healthcare (2026)

Why healthcare practices should care about both

Neither framework is legally required today. That will change. HHS has signaled AI governance as a priority area. State-level AI legislation is advancing in multiple US jurisdictions. The EU AI Act — which affects any organization with EU data subjects — already classifies certain healthcare AI as high-risk with mandatory governance requirements.

More immediately: payer contracts and vendor agreements are beginning to reference AI governance standards. A practice with a documented AIMS aligned to ISO 42001 or NIST AI RMF is in a stronger negotiating and liability position than one with no governance documentation at all.

The practical approach for small practices

Start with NIST AI RMF language — most healthcare IT professionals already know the NIST Cybersecurity Framework, so the vocabulary is familiar. Use it to inventory your AI tools, assess risk, and document your response. Then layer ISO 42001 structure on top if you need external certification or a more formal management system. The two frameworks are complementary — not competing.

What HIPAA adds to the picture

Neither ISO 42001 nor NIST AI RMF replaces HIPAA requirements. They sit above and around them. When an AI tool touches ePHI, HIPAA's Security Rule applies first — BAA requirements, SRA scope, breach notification. ISO 42001 and NIST AI RMF address the broader governance questions: How was this AI system selected? Who approved it? How is its performance monitored? What happens if it produces a harmful or biased output?

For a healthcare practice using AI scribes, automated prior auth, or clinical decision support, all three layers are relevant. HIPAA is the legal floor. NIST AI RMF is the operational guide. ISO 42001 is the certifiable system that demonstrates you've done both deliberately.

Where to start

If your practice is new to AI governance, the right sequence is:

That first step — the inventory — is where most practices discover their actual AI footprint is larger than they thought. Staff have been using AI tools that were never reviewed, never approved, and never covered by a BAA. The governance conversation almost always starts there.