Phase 1: When AI Harms — Real-World Cases & the Responsible AI Landscape · 45 min · Python · pandas
The Responsible AI Stack — NIST, EU AI Act, ISO 42001
Implement once, evidence three times.
Hiring signal: Responsible AI Engineer postings at Cognizant, Citi, and Schwab all require 'working knowledge of AI regulatory frameworks such as EU AI Act, NIST AI RMF, ISO/IEC 42001.' Being able to produce a crosswalk that maps a single control across all three frameworks is the exact skill that separates candidates who've read about these frameworks from those who've worked with them.
What you will learn
- Explain the 4 functions of NIST AI RMF: Govern, Map, Measure, Manage
- Classify AI systems into EU AI Act's 4 risk tiers and identify applicable obligations
- Describe ISO/IEC 42001's role as the certifiable management system standard
- Build a framework crosswalk matrix mapping controls across all three frameworks
The Problem
A company deploying AI in both the U.S. and Europe faces a governance nightmare. The U.S. has the NIST AI Risk Management Framework (voluntary guidance). The EU has the AI Act (binding law with fines up to €35 million or 7% of global turnover). And the international market increasingly expects ISO/IEC 42001 certification (auditable management system). Three frameworks, three sets of documentation, three audit processes — or so it seems.
In practice, these three frameworks share approximately 70% of their substantive controls. A risk management policy written once can satisfy NIST AI RMF GOVERN 1.1 and EU AI Act Article 9 simultaneously. An accuracy and bias evaluation report satisfies NIST MEASURE 2, MEASURE 2.7, and EU AI Act Article 15 in a single artifact. The smart pattern — used by companies like Microsoft that have achieved ISO 42001 certification — is to build one evidence repository and tag each document against all three frameworks.
This lesson teaches you how to build that crosswalk.
NIST AI RMF: The Methodology
The NIST AI Risk Management Framework (AI RMF 1.0), published January 2023, is the U.S. government's voluntary framework for managing AI risk. It's organized around four core functions that operate concurrently — not sequentially:
| Function | Purpose | Key Categories |
|---|
| GOVERN | Policies, accountability, and culture | Governance policies, accountability structures, cross-functional review, third-party risk |
| MAP | Understand context and identify risks | Context establishment, risk identification, societal impacts, third-party impacts |
| MEASURE | Assess and track risks | Metrics, system evaluation, bias testing, risk tracking |
| MANAGE | Treat risks and monitor | Risk treatment, response, recovery, ongoing monitoring |
The Generative AI Profile (NIST AI 600-1, July 2024) extends the framework with 12 GenAI-specific risk categories including confabulation, data privacy, environmental impact, information integrity, and harmful bias — with over 400 suggested actions.
NIST is voluntary but not ignorable
NIST AI RMF has no enforcement mechanism — but the FTC, CFPB, FDA, SEC, EEOC, and Department of Defense all reference its principles. Federal procurement increasingly expects NIST alignment. Enterprise customers use it as the benchmark for evaluating vendor AI governance maturity. "Voluntary" in practice means "if you don't follow it, regulators and customers will ask why."
Unlock the full lesson
You've read the first 2 sections. The rest of this lesson covers EU AI Act: The Law, ISO/IEC 42001: The Certifiable System, The 70% Overlap: Building the Crosswalk, Building the Crosswalk Tool, What's Next — plus a hands-on lab, quiz, and project artifact.
Create a free account to unlock Phase 0 and Phase 1 of every course — no credit card.
Browse all courses · View pricing · DeVenture Academy