Skip to main content

AI Governance Frameworks: A Practical Comparison

NIST AI RMF, ISO 42001, TRAIGA — there are now multiple AI governance frameworks to choose from. This guide explains what each covers, who should use them, and how to implement one in your organization.

What Is an AI Governance Framework?

An AI governance framework is a structured set of principles, practices, roles, and controls that organizations use to govern their AI systems. Frameworks provide the 'how' of AI governance — turning high-level principles into concrete operational steps.

Frameworks range from voluntary guidance (NIST AI RMF) to legally binding requirements (TRAIGA) to international standards (ISO 42001). Most organizations need to align to more than one.

The Major AI Governance Frameworks

Understanding the most widely adopted frameworks is the starting point for any AI governance program.

  • NIST AI RMF 1.0A voluntary US government framework organized around four functions: Govern, Map, Measure, Manage. Widely adopted by federal agencies and enterprise technology companies. Complementary to (not a substitute for) binding regulations.
  • ISO/IEC 42001:2023The international standard for AI management systems. Provides a certifiable governance framework aligned to ISO 9001 and ISO 27001 structures. Well-suited for organizations seeking third-party certification.
  • TRAIGA (HB 149, Texas)effective January 1, 2026, prohibits specific AI uses (manipulation, social scoring, biometric identification without consent, intentional discrimination, explicit deep fakes), requires government agencies (§ 552.051(b)) and health care providers using AI in care or treatment (§ 552.051(f)) to disclose AI use, and recognizes substantial compliance with the NIST AI RMF Generative AI Profile (or another recognized framework) as a safe harbor. Enforced exclusively by the Texas Attorney General with a 60-day notice-and-cure period. TRAIGA imposes no inventory, assessment, or reporting mandates on private deployers — documented governance is safe-harbor evidence, not a statutory requirement.
  • SB 1964 / 1 TAC Chapter 219Texas law governing artificial intelligence use by governmental entities (state agencies, hospital districts, counties, municipalities, school districts). Requires adoption of the DIR AI code of ethics, designation of an AI risk officer, binary Heightened Scrutiny AI (HSAI) classification, § 219.22 risk assessments and § 219.23(b) impact assessments for HSAI systems, standardized public notices, and vendor contract clauses.
  • SB 1188 (Texas, H&S Code ch. 183)health care practitioners using AI for diagnostic purposes must disclose that use to patients and review AI-created records under Texas Medical Board standards; EHR US-data-residency requirements; AG civil penalties up to $250,000.
  • HB 3512 (Texas, Gov't Code §§ 2054.5191–.5193)state agencies and local governments must annually require DIR-certified artificial intelligence training for employees and officials who use a computer for at least 25% of their duties, and verify/report completion to DIR.

How to Choose the Right Framework

Framework selection depends on three factors: your regulatory exposure (which binding laws apply to you), your industry (healthcare, finance, and government face additional sector-specific requirements), and your maturity goals (certification vs. compliance vs. best practice).

Most organizations adopt NIST AI RMF as their operational foundation (it is framework-agnostic and maps well to both ISO 42001 and the regulatory frameworks), then layer binding regulatory obligations on top.

Frequently asked questions

Which AI governance framework should I implement?

Start with NIST AI RMF as your operational foundation — it is vendor-neutral, well-documented, and maps well to other frameworks. Then layer the binding regulations that apply to your organization (TRAIGA, Colorado AI Act) and consider ISO 42001 if you need third-party certification.

Is NIST AI RMF mandatory?

NIST AI RMF is a voluntary framework for most organizations. However, US federal agencies and government contractors are increasingly required to align to it, and it is referenced in several binding regulations as a compliance safe harbor.

Can TRAIGA help me implement an AI governance framework?

Yes. TRAIGA is pre-mapped to NIST AI RMF, ISO 42001, and TRAIGA (Texas). Every control, risk assessment, and governance report in the platform aligns to the relevant framework requirements.

Start your AI governance program today

Risk Meridian is the fastest path to an audit-ready AI governance program — inventory, risk reviews, controls, disclosures, and board-ready reports in one place.

✓ No credit card ✓ Full platform access ✓ Cancel anytime

This platform provides tools to assist organizations in implementing AI governance programs aligned with the Texas Responsible AI Governance Act (TRAIGA). Use of the platform does not constitute legal advice or guarantee regulatory compliance. © 2026 Risk Meridian.