NIST AI RMF and ISO/IEC 42001 in Practice: A One-Page Map to Microsoft Controls
NIST's AI Risk Management Framework is voluntary and ISO/IEC 42001 is certifiable, but they describe the same management cycle. This guide lines the two up, maps each theme to the Microsoft controls that produce evidence for it (Purview, Entra Agent ID, Agent 365, Defender for Cloud and Foundry), and is clear about what no tool can do for you. Checked against NIST, ISO and Microsoft documentation in September 2026.
Published 24 September 2026. Every product claim, price and availability status below was checked against Microsoft's, NIST's or ISO's own documentation on 19 September 2026. Where sources disagree, I say so rather than pick one. AI governance tooling changes quarterly, so check the linked source before you rely on anything here in an audit.
This article continues the AI Security and Governance series. In Building Secure and Governed Enterprise AI Services I described the controls an AI service needs. This one answers the question that comes after it, usually from an auditor or a board: which framework are we following, and how do we show it?
Two frameworks come up most often. The NIST AI Risk Management Framework is voluntary and widely referenced in the US. ISO/IEC 42001 is an international standard you can be certified against. Teams often treat them as a choice. They are closer to two views of the same work.
The one idea that organizes the mapping
Frameworks tell you what to manage. Microsoft tools produce evidence that you are managing it. Only an audit turns that evidence into certification.
Every row of the map below follows that chain, and the last link is the one no product can supply.
What the two frameworks are, as of September 2026
| NIST AI RMF 1.0 | ISO/IEC 42001:2023 | |
|---|---|---|
| Published | 26 January 2023 (NIST AI 100-1) | 18 December 2023, first edition |
| Nature | "Intended for voluntary use" | Requirements for an AI management system |
| Structure | Four functions: Govern, Map, Measure, Manage | Management-system clauses 4 to 10, plus Annex A reference controls |
| Certification | None | By an accredited certification body |
| Generative AI | NIST AI 600-1 profile (July 2024), 12 risks | Companion standard ISO/IEC 23894 gives AI risk management guidance |
| Status | Being revised (see below) | Current |
The AI RMF is changing. NIST's page now says AI RMF 1.0 "is being revised as part of the White House AI Action Plan." The July 2025 Action Plan asked NIST to "eliminate references to misinformation, Diversity, Equity, and Inclusion, and climate change." No revised text had been published when I checked. In April 2026 NIST also released a concept note for a profile on trustworthy AI in critical infrastructure. Until a revision appears, 1.0 and the 600-1 profile are the documents to map to. Keep your mapping at the function level so a revision does not force you to redo it.
ISO/IEC 42001 is where certification lives. Its clauses follow ISO's standard management-system structure: context, leadership, planning, support, operation, performance evaluation and improvement. Annex A holds reference controls in nine areas, from policies related to AI through to third-party and customer relationships. Published implementation guides count 38 of them. I could not check that count against the standard itself, which is paid for and copyrighted. The controls you adopt go into a statement of applicability. Since July 2025, ISO/IEC 42006 has set the requirements for the bodies that audit and certify against 42001.
How the functions line up with the clauses
NIST publishes a crosswalk from the AI RMF to the final draft of ISO/IEC 42001. It maps, for example, Govern 1.1 (legal and regulatory requirements are understood) to clause 4.1 (understanding the organization and its context), and Map 1.1 (intended purposes are documented) to 6.1.4 (AI system impact assessment).
The practical consequence is that you do not need two programmes. Build the ISO/IEC 42001 management system, and use the AI RMF and the 600-1 profile as the risk vocabulary inside it. The profile's 12 risks, such as confabulation, information security and value chain and component integration, make a useful checklist for the impact and risk assessment that clause 6 requires.
What Microsoft actually provides
Six Microsoft capabilities produce most of the evidence. Their status matters, because an auditor will ask whether a control runs on a preview feature.
| Capability | What it gives you | Status, September 2026 |
|---|---|---|
| Purview Compliance Manager AI templates | Assessments for the EU AI Act, ISO/IEC 23894, ISO/IEC 42001 and NIST AI RMF 1.0; syncs Foundry evaluation results | Premium templates; free for six months with Copilot or agent licences |
| Purview DSPM | AI observability, agent inventory, reports on sensitive data in AI interactions | Unified DSPM GA; DSPM for AI now labelled "classic" |
| Entra Agent ID | An identity for each agent, with Conditional Access, Identity Protection and governance | GA |
| Agent 365 | Agent registry, agent map, lifecycle and access control | GA since 1 May 2026; $15 per user per month, or in Microsoft 365 E7 |
| Defender for Cloud | AI posture (AI bill of materials, attack paths) and threat protection for AI services | Posture and threat protection GA; agent discovery in preview |
| Foundry evaluations and guardrails | Quality, safety and agent evaluators, AI red teaming, runtime content controls | Evaluations GA; agent guardrails in preview |
Four details are easy to miss.
- Compliance Manager can pull test results from Foundry. Microsoft says the integration provides 75 actions, including 15 automated evaluation actions whose pass or fail status syncs into the assessment. That is the closest any tool gets to continuous evidence for Measure. The page still calls the product "Azure AI Foundry."
- Agent posture moved licences. Since 1 July 2026, discovery and posture for Foundry agents and third-party cloud agents need an Agent 365 licence. Defender CSPM still discovers Foundry accounts and projects, but not the agents inside them. Older design documents that rely on Defender CSPM alone are now wrong.
- The Responsible AI dashboard is not for generative AI. Microsoft's documentation limits it to tabular regression and classification models. For language models and agents, the evidence comes from Foundry.
- Guardrails can now inspect tool calls, not only prompts and outputs, but the tool call and tool response intervention points are in preview. If your control relies on them, record that.
The one page
This is my own construct, not Microsoft or ISO guidance. It is the table I would put at the front of an AI management system's evidence file. The Annex A references are my assignment of each theme to an objective area.
The amber band deserves the most attention. Compliance Manager can tell you which improvement actions are complete. It cannot decide whether a residual risk is acceptable, and it cannot hold your management review. Those are decisions made by named people, and the records of those decisions are what a certification auditor samples.
Microsoft's certificate is not yours
Microsoft has certified a number of its AI services to ISO/IEC 42001. Azure AI Foundry Models and Security Copilot were certified in July 2025, by a body accredited by the International Accreditation Service. Microsoft's compliance page, updated on 11 September 2026, lists nine services in scope, including Microsoft Foundry, Copilot Studio, GitHub Copilot and Security Copilot.
There is a naming inconsistency to check. That page lists "Microsoft Copilot" and "Microsoft Copilot Chat" but does not use the name "Microsoft 365 Copilot," while a May 2026 Microsoft post says Microsoft 365 Copilot and Copilot Chat were recertified for a second year. Read the scope statement on the Service Trust Portal before you cite it in a supplier assessment.
Microsoft's own FAQ is clear about the limit. You can use its certification in your assessment, but "you're responsible, however, for engaging an assessor to evaluate the controls and processes within your own organization and your implementation." Supplier certification helps with Annex A's third-party theme. It does nothing for your own clauses 4 to 10.
What I would actually do
Pick ISO/IEC 42001 as the management system, even if you never certify. It gives you the structure an auditor will recognise, and the AI RMF fits inside it.
Start with inventory, because every other row depends on it. Give each agent an Entra Agent ID and register it in Agent 365. Budget for Agent 365 early, since agent posture in Defender now depends on it.
Turn on one Compliance Manager AI template, not all four. Choose the one your regulator or customers actually ask about. Connect Foundry evaluations to it so Measure produces evidence without a spreadsheet.
Then write down what the tools will never produce: who accepts AI risk, how impact assessments are approved, and when management review happens. Put those decisions into the same forums that already govern your technology programme, as described in architecture governance in large technology programs, rather than creating a separate AI committee that nobody attends.
If you are preparing for ISO/IEC 42001, aligning an AI programme to the NIST AI RMF, or trying to work out which Microsoft controls will produce evidence an auditor accepts, that is work Avalon does: framework gap assessments, AI evidence maps like the one above, agent inventory and identity design, and readiness work before an accredited audit. It sits at the centre of my enterprise AI and security practice, and the contact page is the best way to start a conversation.
Sources
All checked on 19 September 2026. Where two sources disagree, the text names the disagreement.
NIST — AI Risk Management Framework page (opens in a new tab) · NIST AI 100-1, AI RMF 1.0 (opens in a new tab) · NIST AI 600-1, Generative AI Profile (opens in a new tab) · NIST AI RMF to ISO/IEC FDIS 42001 crosswalk (opens in a new tab) · America's AI Action Plan, July 2025 (opens in a new tab)
ISO — ISO/IEC 42001:2023 (opens in a new tab) · ISO/IEC 42006:2025 (opens in a new tab) · Annex A controls list (implementation guide, secondary source) (opens in a new tab) · Statement of applicability guidance (Schellman) (opens in a new tab)
Microsoft certification — ISO/IEC 42001 offering page (opens in a new tab) · Foundry Models and Security Copilot certification, July 2025 (opens in a new tab) · Microsoft 365 Copilot recertification, May 2026 (opens in a new tab)
Purview — Compliance Manager assessments (opens in a new tab) · Compliance Manager regulations list (opens in a new tab) · Data Security Posture Management (opens in a new tab) · Purview for AI (opens in a new tab)
Identity and agents — Microsoft Entra Agent ID (opens in a new tab) · Agent 365 overview (opens in a new tab) · Agent 365 licensing FAQ (opens in a new tab)
Defender and Foundry — AI security posture management (opens in a new tab) · AI threat protection (opens in a new tab) · Foundry evaluations and observability (opens in a new tab) · Foundry guardrails (opens in a new tab) · Responsible AI dashboard (opens in a new tab)
Published 24 September 2026; sources checked on 19 September 2026. NIST has said AI RMF 1.0 is being revised, and Microsoft's AI governance tooling changes quarterly, so check the linked sources before relying on this in an audit. The alignment in Figure 1 and the one-page map in Figure 2 are guidance I propose, not NIST, ISO or Microsoft documentation. No ISO text is reproduced beyond short clause and control-area titles. No client, employer or engagement is named in this article, and any scenario described is an illustrative composite rather than a description of specific customer work.
- #NIST AI RMF
- #ISO/IEC 42001
- #AI Governance
- #AI Management System
- #NIST AI 600-1
- #Microsoft Purview
- #Compliance Manager
- #Microsoft Entra Agent ID
- #Agent 365
- #Defender for Cloud
- #Microsoft Foundry
- #AI Security
Related articles
The Microsoft AI Stack Explained: Copilot, Copilot Studio, Foundry, Agent 365 and Security Copilot
Microsoft's AI portfolio is not five versions of the same product — it is a layered enterprise architecture with an experience layer, two build platforms, a control plane, and the identity, data and threat controls underneath. A practical architecture guide to what each platform is for, which workloads belong where, how agent identity and authority actually flow, and what has to be true before an organization scales any of it.
47 min read
Agent Sprawl: An Inventory and Lifecycle Model for Enterprise AI Agents
Most organizations can now build AI agents faster than they can say who owns them. This article proposes a twelve-field inventory record and a seven-stage lifecycle from proposal to retirement, and maps each stage to what the Microsoft 365 Agent Registry, Microsoft Agent 365, Entra Agent ID and Power Platform inventory actually do as of September 2026, including where the tooling stops.
10 min read
Microsoft Copilot Studio vs Microsoft Foundry: Which AI Agent Platform Should Your Business Choose?
Copilot Studio and Microsoft Foundry are not competitors — they sit at different levels of abstraction, and three changes in 2026 have quietly retired most of the advice written about choosing between them. A decision framework built on who owns the runtime, where the data already lives, and who operates the agent on day ninety, with the cost shapes, governance asymmetries and interop paths verified against Microsoft's own documentation.
15 min read