Voluntary AI Safety Standard, ISO/IEC 42001 and the NIST AI RMF compared
Should we use the Voluntary AI Safety Standard, ISO/IEC 42001 or the NIST AI RMF?
Use Australia's Voluntary AI Safety Standard to define what good looks like locally, ISO/IEC 42001 if you need something certifiable, and the NIST AI Risk Management Framework as the method for assessing individual systems. They operate at different levels, so anchoring on one does not mean discarding the others.
This question usually arrives as a procurement problem. A customer asks which standard you follow, and the honest answer is that the three most commonly named are not alternatives to each other.
How do the three actually differ?
| Voluntary AI Safety Standard | ISO/IEC 42001 | NIST AI RMF | |
|---|---|---|---|
| Origin | Australian government | International standards body | US government agency |
| Status | Guidance, not law | Certifiable management system standard | Voluntary framework |
| Operates at | Organisation | Organisation | System |
| Answers | What should we be doing, in Australia? | Can we prove we run this properly? | How do we assess this particular system? |
| Independent audit | No | Yes, through accredited certification | No |
| Best used for | Setting local expectations | Demonstrating maturity to a third party | Doing the assessment work |
The important row is the third. The Australian standard and ISO/IEC 42001 both describe how an organisation governs AI. The NIST framework describes how you reason about the risk of a system. Comparing the first two to the third is a category error, and it is why teams end up arguing past each other.
Which one should an Australian enterprise anchor on?
Anchor on the Voluntary AI Safety Standard, for three reasons.
It is the expectation your local regulators, customers and procurement teams will reference. It is the closest available signal of what mandatory obligations for high-risk AI would require, so work done against it is unlikely to be wasted. And it is written in language your executive team can read without a translator, which matters more than it sounds when you need a decision.
Then borrow. Use the NIST framework's structure for the assessment itself, and adopt ISO/IEC 42001 when a customer or a board actually needs certified evidence rather than your assurance.
When is ISO/IEC 42001 worth the effort?
When someone is going to ask for the certificate.
Certification is a genuine undertaking: a management system, defined processes, internal audit, management review, and an external audit that will find things. The value is not the improvement in governance, which you could achieve without certifying. The value is that a third party will accept it without doing their own assessment of you.
That trade is worth it if you sell AI-enabled products into large enterprises or government, or if you operate in a sector where your customers are themselves being assessed. It is usually not worth it if your AI is entirely internal and nobody outside your organisation is asking.
Does following all three mean doing the work three times?
No, and a control mapping is how you avoid it.
Most of the underlying controls are the same: accountability, risk assessment, data governance, testing, human oversight, documentation. What differs is the vocabulary and the evidence each framework expects. Build your controls once, then maintain a mapping that shows which control satisfies which requirement in which framework.
The mapping is also the artefact that answers procurement questionnaires quickly, which is often the thing that prompted the question in the first place.
What none of them do
None of the three tells you whether a use of AI is lawful. Privacy obligations, anti-discrimination law and sector regulation sit underneath all of them and are where enforceable risk currently lives in Australia.
A well-run AI management system makes those obligations easier to meet and easier to demonstrate. It does not replace advice on what they require.