Skip to main content
Arif Mughal

NIST AI RMF and ISO/IEC 42001 in Practice: A One-Page Map to Microsoft Controls

NIST's AI Risk Management Framework is voluntary and ISO/IEC 42001 is certifiable, but they describe the same management cycle. This guide lines the two up, maps each theme to the Microsoft controls that produce evidence for it (Purview, Entra Agent ID, Agent 365, Defender for Cloud and Foundry), and is clear about what no tool can do for you. Checked against NIST, ISO and Microsoft documentation in September 2026.

Arif Mughal10 min readAI Governance

Published 24 September 2026. Every product claim, price and availability status below was checked against Microsoft's, NIST's or ISO's own documentation on 19 September 2026. Where sources disagree, I say so rather than pick one. AI governance tooling changes quarterly, so check the linked source before you rely on anything here in an audit.

This article continues the AI Security and Governance series. In Building Secure and Governed Enterprise AI Services I described the controls an AI service needs. This one answers the question that comes after it, usually from an auditor or a board: which framework are we following, and how do we show it?

Two frameworks come up most often. The NIST AI Risk Management Framework is voluntary and widely referenced in the US. ISO/IEC 42001 is an international standard you can be certified against. Teams often treat them as a choice. They are closer to two views of the same work.

The one idea that organizes the mapping

Frameworks tell you what to manage. Microsoft tools produce evidence that you are managing it. Only an audit turns that evidence into certification.

Every row of the map below follows that chain, and the last link is the one no product can supply.

What the two frameworks are, as of September 2026

NIST AI RMF 1.0ISO/IEC 42001:2023
Published26 January 2023 (NIST AI 100-1)18 December 2023, first edition
Nature"Intended for voluntary use"Requirements for an AI management system
StructureFour functions: Govern, Map, Measure, ManageManagement-system clauses 4 to 10, plus Annex A reference controls
CertificationNoneBy an accredited certification body
Generative AINIST AI 600-1 profile (July 2024), 12 risksCompanion standard ISO/IEC 23894 gives AI risk management guidance
StatusBeing revised (see below)Current

The AI RMF is changing. NIST's page now says AI RMF 1.0 "is being revised as part of the White House AI Action Plan." The July 2025 Action Plan asked NIST to "eliminate references to misinformation, Diversity, Equity, and Inclusion, and climate change." No revised text had been published when I checked. In April 2026 NIST also released a concept note for a profile on trustworthy AI in critical infrastructure. Until a revision appears, 1.0 and the 600-1 profile are the documents to map to. Keep your mapping at the function level so a revision does not force you to redo it.

ISO/IEC 42001 is where certification lives. Its clauses follow ISO's standard management-system structure: context, leadership, planning, support, operation, performance evaluation and improvement. Annex A holds reference controls in nine areas, from policies related to AI through to third-party and customer relationships. Published implementation guides count 38 of them. I could not check that count against the standard itself, which is paid for and copyrighted. The controls you adopt go into a statement of applicability. Since July 2025, ISO/IEC 42006 has set the requirements for the bodies that audit and certify against 42001.

How the functions line up with the clauses

NIST publishes a crosswalk from the AI RMF to the final draft of ISO/IEC 42001. It maps, for example, Govern 1.1 (legal and regulatory requirements are understood) to clause 4.1 (understanding the organization and its context), and Map 1.1 (intended purposes are documented) to 6.1.4 (AI system impact assessment).

How the four NIST AI RMF functions line up with ISO/IEC 42001 clauses. Govern lines up with clauses 4, 5 and 7: context, leadership and support. Map lines up with clause 6: planning, including risk and impact assessment. Measure lines up with clauses 8 and 9: operation and performance evaluation. Manage lines up with clauses 8 and 10: risk treatment and improvement. Below, the AI RMF is shown as voluntary with no certificate, with NIST AI 600-1 adding 12 generative AI risks under the same four functions. ISO/IEC 42001 is shown as certifiable by an accredited body, with 38 Annex A reference controls chosen in a statement of applicability.
Figure 1: My simplification of NIST's crosswalk, showing the strongest fit for each function. The crosswalk itself spreads Govern across clauses 4 to 9.

The practical consequence is that you do not need two programmes. Build the ISO/IEC 42001 management system, and use the AI RMF and the 600-1 profile as the risk vocabulary inside it. The profile's 12 risks, such as confabulation, information security and value chain and component integration, make a useful checklist for the impact and risk assessment that clause 6 requires.

What Microsoft actually provides

Six Microsoft capabilities produce most of the evidence. Their status matters, because an auditor will ask whether a control runs on a preview feature.

CapabilityWhat it gives youStatus, September 2026
Purview Compliance Manager AI templatesAssessments for the EU AI Act, ISO/IEC 23894, ISO/IEC 42001 and NIST AI RMF 1.0; syncs Foundry evaluation resultsPremium templates; free for six months with Copilot or agent licences
Purview DSPMAI observability, agent inventory, reports on sensitive data in AI interactionsUnified DSPM GA; DSPM for AI now labelled "classic"
Entra Agent IDAn identity for each agent, with Conditional Access, Identity Protection and governanceGA
Agent 365Agent registry, agent map, lifecycle and access controlGA since 1 May 2026; $15 per user per month, or in Microsoft 365 E7
Defender for CloudAI posture (AI bill of materials, attack paths) and threat protection for AI servicesPosture and threat protection GA; agent discovery in preview
Foundry evaluations and guardrailsQuality, safety and agent evaluators, AI red teaming, runtime content controlsEvaluations GA; agent guardrails in preview

Four details are easy to miss.

  1. Compliance Manager can pull test results from Foundry. Microsoft says the integration provides 75 actions, including 15 automated evaluation actions whose pass or fail status syncs into the assessment. That is the closest any tool gets to continuous evidence for Measure. The page still calls the product "Azure AI Foundry."
  2. Agent posture moved licences. Since 1 July 2026, discovery and posture for Foundry agents and third-party cloud agents need an Agent 365 licence. Defender CSPM still discovers Foundry accounts and projects, but not the agents inside them. Older design documents that rely on Defender CSPM alone are now wrong.
  3. The Responsible AI dashboard is not for generative AI. Microsoft's documentation limits it to tabular regression and classification models. For language models and agents, the evidence comes from Foundry.
  4. Guardrails can now inspect tool calls, not only prompts and outputs, but the tool call and tool response intervention points are in preview. If your control relies on them, record that.

The one page

This is my own construct, not Microsoft or ISO guidance. It is the table I would put at the front of an AI management system's evidence file. The Annex A references are my assignment of each theme to an objective area.

A one-page map proposed by the author, with three columns: framework theme, Microsoft control and evidence produced. Inventory and ownership (Govern, Annex A areas A.3 and A.4): Agent 365 registry and Entra Agent ID, producing the agent registry, agent map and agent authentication logs. Data protection (Map and Manage, A.7): Purview DSPM with DLP and sensitivity labels, producing AI interaction reports and activity explorer AI events. Risk and impact assessment (Map, clause 6, A.5): Compliance Manager premium AI templates, producing assessment and control status and improvement actions with owners. Testing and evaluation (Measure, clause 9, A.6): Foundry evaluations and the AI red teaming agent, producing evaluation runs and metrics synced to Compliance Manager. Runtime safeguards (Manage, A.6 and A.9): Foundry guardrails and Defender for AI Services, producing blocked prompts and outputs and alerts in Defender XDR. Posture (Manage, A.6): Defender CSPM AI posture and Agent 365 for agents, producing an AI bill of materials, recommendations and attack paths. A final band says no tool produces the AI policy, risk acceptance, impact judgements, management review or internal audit, and that certification still needs an audit by an accredited certification body.
Figure 2: Every row ends in evidence. The amber band is the part auditors spend most time on, and no product fills it.

The amber band deserves the most attention. Compliance Manager can tell you which improvement actions are complete. It cannot decide whether a residual risk is acceptable, and it cannot hold your management review. Those are decisions made by named people, and the records of those decisions are what a certification auditor samples.

Microsoft's certificate is not yours

Microsoft has certified a number of its AI services to ISO/IEC 42001. Azure AI Foundry Models and Security Copilot were certified in July 2025, by a body accredited by the International Accreditation Service. Microsoft's compliance page, updated on 11 September 2026, lists nine services in scope, including Microsoft Foundry, Copilot Studio, GitHub Copilot and Security Copilot.

There is a naming inconsistency to check. That page lists "Microsoft Copilot" and "Microsoft Copilot Chat" but does not use the name "Microsoft 365 Copilot," while a May 2026 Microsoft post says Microsoft 365 Copilot and Copilot Chat were recertified for a second year. Read the scope statement on the Service Trust Portal before you cite it in a supplier assessment.

Microsoft's own FAQ is clear about the limit. You can use its certification in your assessment, but "you're responsible, however, for engaging an assessor to evaluate the controls and processes within your own organization and your implementation." Supplier certification helps with Annex A's third-party theme. It does nothing for your own clauses 4 to 10.

What I would actually do

Pick ISO/IEC 42001 as the management system, even if you never certify. It gives you the structure an auditor will recognise, and the AI RMF fits inside it.

Start with inventory, because every other row depends on it. Give each agent an Entra Agent ID and register it in Agent 365. Budget for Agent 365 early, since agent posture in Defender now depends on it.

Turn on one Compliance Manager AI template, not all four. Choose the one your regulator or customers actually ask about. Connect Foundry evaluations to it so Measure produces evidence without a spreadsheet.

Then write down what the tools will never produce: who accepts AI risk, how impact assessments are approved, and when management review happens. Put those decisions into the same forums that already govern your technology programme, as described in architecture governance in large technology programs, rather than creating a separate AI committee that nobody attends.

If you are preparing for ISO/IEC 42001, aligning an AI programme to the NIST AI RMF, or trying to work out which Microsoft controls will produce evidence an auditor accepts, that is work Avalon does: framework gap assessments, AI evidence maps like the one above, agent inventory and identity design, and readiness work before an accredited audit. It sits at the centre of my enterprise AI and security practice, and the contact page is the best way to start a conversation.

Sources

All checked on 19 September 2026. Where two sources disagree, the text names the disagreement.

NIST — AI Risk Management Framework page (opens in a new tab) · NIST AI 100-1, AI RMF 1.0 (opens in a new tab) · NIST AI 600-1, Generative AI Profile (opens in a new tab) · NIST AI RMF to ISO/IEC FDIS 42001 crosswalk (opens in a new tab) · America's AI Action Plan, July 2025 (opens in a new tab)

ISO — ISO/IEC 42001:2023 (opens in a new tab) · ISO/IEC 42006:2025 (opens in a new tab) · Annex A controls list (implementation guide, secondary source) (opens in a new tab) · Statement of applicability guidance (Schellman) (opens in a new tab)

Microsoft certification — ISO/IEC 42001 offering page (opens in a new tab) · Foundry Models and Security Copilot certification, July 2025 (opens in a new tab) · Microsoft 365 Copilot recertification, May 2026 (opens in a new tab)

Purview — Compliance Manager assessments (opens in a new tab) · Compliance Manager regulations list (opens in a new tab) · Data Security Posture Management (opens in a new tab) · Purview for AI (opens in a new tab)

Identity and agents — Microsoft Entra Agent ID (opens in a new tab) · Agent 365 overview (opens in a new tab) · Agent 365 licensing FAQ (opens in a new tab)

Defender and Foundry — AI security posture management (opens in a new tab) · AI threat protection (opens in a new tab) · Foundry evaluations and observability (opens in a new tab) · Foundry guardrails (opens in a new tab) · Responsible AI dashboard (opens in a new tab)


Published 24 September 2026; sources checked on 19 September 2026. NIST has said AI RMF 1.0 is being revised, and Microsoft's AI governance tooling changes quarterly, so check the linked sources before relying on this in an audit. The alignment in Figure 1 and the one-page map in Figure 2 are guidance I propose, not NIST, ISO or Microsoft documentation. No ISO text is reproduced beyond short clause and control-area titles. No client, employer or engagement is named in this article, and any scenario described is an illustrative composite rather than a description of specific customer work.

AI Governance

The Microsoft AI Stack Explained: Copilot, Copilot Studio, Foundry, Agent 365 and Security Copilot

Microsoft's AI portfolio is not five versions of the same product — it is a layered enterprise architecture with an experience layer, two build platforms, a control plane, and the identity, data and threat controls underneath. A practical architecture guide to what each platform is for, which workloads belong where, how agent identity and authority actually flow, and what has to be true before an organization scales any of it.

47 min read

AI Governance

Agent Sprawl: An Inventory and Lifecycle Model for Enterprise AI Agents

Most organizations can now build AI agents faster than they can say who owns them. This article proposes a twelve-field inventory record and a seven-stage lifecycle from proposal to retirement, and maps each stage to what the Microsoft 365 Agent Registry, Microsoft Agent 365, Entra Agent ID and Power Platform inventory actually do as of September 2026, including where the tooling stops.

10 min read

AI Architecture

Microsoft Copilot Studio vs Microsoft Foundry: Which AI Agent Platform Should Your Business Choose?

Copilot Studio and Microsoft Foundry are not competitors — they sit at different levels of abstraction, and three changes in 2026 have quietly retired most of the advice written about choosing between them. A decision framework built on who owns the runtime, where the data already lives, and who operates the agent on day ninety, with the cost shapes, governance asymmetries and interop paths verified against Microsoft's own documentation.

15 min read