How does your organization manage artificial intelligence risk?
As enterprises worldwide accelerate the deployment of AI models-from credit scoring and automated hiring tools to customer-support chatbots-executives face increasing scrutiny from boards, regulators, and customers. Technical enthusiasm alone is no longer an acceptable answer. Today, two globally recognized frameworks compete for executive attention: the American NIST AI Risk Management Framework (AI RMF 1.0) and the international certifiable standard ISO/IEC 42001.
Leaving leadership to choose between them creates unnecessary friction, duplicative documentation, and governance gaps. Trustworthy AI: Risk Governance under NIST AI RMF and ISO/IEC 42001 answers the compliance dilemma by refusing the premise: don't choose-integrate.
This authoritative guide demonstrates that both frameworks describe essentially the same risk-management program in two complementary languages. Rather than offering a high-level theoretical survey, the book provides a step-by-step working method for building a single, functioning organizational AI risk-management system.
Inside This Book:
Unified Dual-Framework Architecture: Learn how to seamlessly merge the NIST AI RMF Core with the certifiable requirements of an ISO/IEC 42001 Artificial Intelligence Management System (AIMS).Cross-Framework Mapping Methodology: Master a concrete mapping methodology that bridges NIST functions with ISO controls, illuminating mutual blind spots and eliminating redundant compliance efforts.End-to-End Practical Implementation: Follow a continuous running case study-CreditPlus, a fintech company deploying a credit-scoring model-across 8 detailed chapters. Watch how abstract standards turn into interlocked working documents: resource registers, data-provenance logs, Statements of Applicability (SoA), third-party responsibility matrices, and internal audit logs.The 7 Characteristics of Trustworthy AI: Practical breakdowns of validity, reliability, safety, security, accountability, transparency, explainability vs. interpretability, privacy, and fairness.Complete ISO/IEC 42001 Annex A Coverage: Practical, non-copyright-infringing guidance covering the AI system lifecycle, data governance, third-party supplier management, documentation, and continuous improvement.Who This Book Is For:
Chief AI Officers (CAIOs) & IT Executives: Designing and leading enterprise-wide AI governance strategies.Risk Managers & Compliance Officers: Navigating regulatory requirements, AI audits, and corporate risk alignment.Product Managers & Technical Leaders: Responsible for deploying AI-driven products safely, reliably, and ethically.Consultants & Auditors: Looking for an operational roadmap to audit or implement NIST AI RMF and ISO/IEC 42001.No advanced computer science background required. Written in clear, accessible language, this book equips public-sector officials, corporate boards, and technical teams alike with a common vocabulary and actionable tools.
AI risk management never concludes with a single signed policy-it thrives through continuous governance. Build your organization's trustworthy AI foundation today.