← Latest papers
💻 computer science

Bridging AI Risk Frameworks: Reconciling ISO/IEC 42001, the NIST AI Risk Management Framework, and the EU AI Act into a Uni ed Governance Taxonomy

This paper proposes a Unified AI Governance Taxonomy (UAGT) that reconciles the structurally distinct ISO/IEC 42001, NIST AI RMF, and EU AI Act into a single, five-layer framework with eight stable domains, enabling organizations to achieve certification, voluntary adoption, and legal compliance through a unified control library while explicitly acknowledging the inherent limitations of such unification.

Original authors: Vinod Dhiman

Published 2026-08-11
📖 7 min read🧠 Deep dive

Original authors: Vinod Dhiman

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

The Great AI Rulebook Tangle

Imagine you are trying to build a robot that can help doctors diagnose illnesses or decide who gets a loan. You want to make sure this robot is safe, fair, and doesn't accidentally hurt anyone. But here is the problem: the world doesn't have just one rulebook for building robots. Instead, it has three different, very loud librarians shouting instructions from three different corners of the room. One librarian is a strict judge from Europe who says, "If your robot does this specific job, you must follow these 100 pages of rules, or you get in trouble." Another is a helpful coach from the United States who says, "Here is a flexible playbook to help you think about risks, but you don't have to use it unless you want to look good." The third is a global certification agency that says, "If you want a shiny gold star to prove your company is organized, you need to follow this specific checklist."

This paper lives in the world of Artificial Intelligence (AI) Governance. In simple terms, this is the study of how to make sure AI systems are built and used responsibly. The three key concepts the paper jumbles together are: ISO/IEC 42001 (a standard for getting a certificate to prove your company is well-organized), the NIST AI Risk Management Framework (a voluntary guide to help teams manage risks), and the EU AI Act (a real law that bans dangerous AI and sets strict rules for high-risk AI). Everyone cares about this because AI is everywhere now. If companies try to follow all three rulebooks at once, they end up writing the same rules three times, getting confused, and wasting a lot of money. The big question is: Can we make these three different rulebooks work together without losing the strictness of the law or the flexibility of the guide?

The Paper's Big Idea: One Map, Three Destinations

This paper, written by Vinod Dhiman, argues that trying to mash these three rulebooks into one giant, flat list is a bad idea. It's like trying to merge a map of a city, a list of traffic laws, and a driver's manual into a single sheet of paper. If you do that, you might miss the fact that one rule is a law you must obey, while another is just a suggestion. The author suggests that instead of flattening them, we should build a Unified AI Governance Taxonomy (UAGT). Think of this as a "super-organizer" or a Lego instruction manual that has five different layers.

Here is how the paper breaks it down:

1. The Five Layers of the "Super-Organizer"
The paper says we need to look at AI governance through five different lenses, stacked on top of each other:

  • The "Why" Layer (Normative Purpose): What is the goal? (e.g., "Don't be racist," "Be safe").
  • The "Who" Layer (Governance Subject): Who is responsible? (e.g., The whole company, the specific robot, or the person using the robot).
  • The "Risk" Layer (Risk Logic): How do we measure danger? (e.g., Is it dangerous because it's on a "bad list," or because it actually caused harm in a specific situation?).
  • The "How" Layer (Control Architecture): What specific rules do we follow?
  • The "Proof" Layer (Evidence): What paperwork do we show to prove we did it?

The paper finds that these three rulebooks (ISO, NIST, and EU) all agree on the "Why" and the "How" mostly, but they disagree on the "Who" and the "Risk" layer. For example, the EU law says a robot is "High Risk" just because it's used for hiring people (a list-based rule). But the US guide might say, "Well, let's measure how much harm this specific robot actually caused." The paper argues we shouldn't force these to be the same. Instead, the UAGT keeps both answers side-by-side. It's like having a backpack with two pockets: one for the "Legal High Risk" label and one for the "Measured Low Risk" label. You carry both, so you don't get in trouble with the law, but you also know the real situation.

2. The Eight "Stable" Buckets
To make this work in the real world, the paper organizes all the rules into eight stable buckets (called governance domains). These are like eight different drawers in a filing cabinet that won't change even if the laws get updated. The buckets are:

  1. Accountability: Who is in charge?
  2. Risk Assessment: Checking for dangers.
  3. Data Governance: Making sure the data is clean and fair.
  4. Transparency: Being open about how the AI works.
  5. Human Oversight: Making sure a human is watching the AI.
  6. Robustness & Security: Making sure the AI doesn't crash or get hacked.
  7. Monitoring: Watching the AI after it's launched.
  8. Third-Party & AI Models: Managing outside tools and big AI models.

The paper suggests that companies can put their rules into these eight drawers. Inside each drawer, they can have a "control library" that satisfies all three rulebooks at once. For example, in the "Human Oversight" drawer, a company writes one rule that says, "A human must check the decision." This single rule can be shown to the ISO auditor (to get the certificate), the NIST team (to show they are managing risk), and the EU regulator (to prove they are following the law).

3. Real-World Examples
The paper tests this idea with two examples: a medical AI that helps doctors read X-rays and a credit-scoring AI that decides who gets a loan.

  • In the medical case, the AI is "High Risk" by EU law because it's a medical device. The paper shows how the company can use the UAGT to create one set of documents that proves the AI is safe for the doctor (NIST), safe for the hospital's management system (ISO), and legal for the EU.
  • In the credit case, the AI is "High Risk" because it's on the EU's "bad list" for financial decisions. The paper shows that even if the company's internal tests say the AI is very safe, they still have to follow the strict EU rules. The UAGT helps them keep the "Strict Law" version and the "Internal Test" version separate but organized in the same folder.

4. What the Paper Says is NOT Possible
The paper is very careful to say what this system cannot do. It explicitly rules out the idea that getting an ISO certificate automatically means you are following the EU law. It's like having a driver's license (ISO) doesn't mean you can drive a truck (EU Law) without a special permit. The paper says you cannot "map away" the differences. If the EU says a system is High Risk, it stays High Risk, even if your internal tests say it's low risk. The paper also notes that this system is a "blueprint" or a "map," not a finished, proven product. It hasn't been tested in a giant real-world experiment yet; it's a proposed structure based on analyzing the documents.

5. The "Brussels Effect" and Future Changes
The paper mentions that because the EU law is so strict, companies all over the world often just follow the EU rules to be safe (this is called the "Brussels Effect"). The UAGT helps companies do this efficiently. However, the paper warns that the rules are still changing. The EU just passed a "Digital Omnibus" update in 2026 that moved some deadlines around, and the US is updating its guides. The paper suggests that while the eight buckets will stay the same, the specific rules inside them might need to be updated as the laws change.

In Summary
The paper concludes that we shouldn't try to force the three rulebooks to be identical. Instead, we should use this "Unified Taxonomy" to build a smart filing system. This system lets companies use one set of rules and one set of evidence to satisfy the strict EU law, the flexible US guide, and the global certification standard all at the same time. It saves time and money, but it keeps the strict legal rules safe and separate from the internal company rules. It's a way to stop the chaos of having three different rulebooks without pretending they are all the same thing.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →