Quaintitative

AIRG in context

How the AIRG compares to the EU AI Act, NIST and ISO 42001

AI governance frameworks look like they are diverging, but they cover the same core areas. They differ mainly in two things: how prescriptive they are, and whether they are binding. The sharpest difference is how each one decides which AI gets the most scrutiny. The EU AI Act uses fixed risk tiers set in law; Singapore's AI Risk Management Guidelines (AIRG) use a materiality assessment. Implement one of these carefully and most of the work carries over to the others. I wrote the AIRG, and this is how I place it against the others.

The core areas every framework covers

Whatever the mechanism, most approaches to AI governance cover the same four areas:

  • Scope and applicability. Which institutions and AI systems are covered, and the thresholds that decide how much applies.
  • Risk classification. How the framework decides which AI carries the most risk: prescriptive tiers (the EU AI Act model) or a materiality assessment (the AIRG model).
  • Oversight and key systems. Board and senior management accountability, and the systems that support it, such as an AI inventory.
  • Lifecycle controls. Data governance, fairness, transparency and explainability, human oversight, third-party AI, evaluation and testing, and monitoring.

Because the areas are shared, the frameworks are more alike in substance than they look. What varies is form and force.

A spectrum from binding law to voluntary standard

The frameworks sit on a continuum from prescriptive legislation to voluntary, market-led assurance.

  • EU AI Act. The most comprehensive legislative approach. It classifies AI by risk level (unacceptable, high, limited, minimal), imposes binding obligations on providers and deployers of high-risk systems, requires conformity assessment, and carries significant penalties. For financial services, it designates AI used for creditworthiness and credit scoring as high-risk, requiring transparency, human oversight and documented risk management. (Regulation (EU) 2024/1689)
  • NIST AI Risk Management Framework. A voluntary, flexible US framework structured around four functions, Govern, Map, Measure and Manage, that adapts to different contexts and risk levels. (NIST AI RMF)
  • ISO/IEC 42001. An international standard for an AI management system, and one an organisation can be certified against. It provides the process wrapper (policy, objectives, controls, review) rather than sector-specific expectations. (ISO/IEC 42001)
  • MAS AIRG. Sector-specific supervisory expectations for financial institutions, risk-proportionate and built iteratively from the voluntary FEAT principles. (MAS AIRG)

At a glance

FrameworkWhat it isForceHow it scopes risk
MAS AIRGFinancial-sector supervisory guidanceSupervisory expectationMateriality assessment (impact, complexity, reliance)
EU AI ActHorizontal lawBinding, with penaltiesFixed risk tiers set in law
NIST AI RMFVoluntary frameworkVoluntaryContext-based, mapped case by case
ISO/IEC 42001Management-system standardVoluntary, certifiableOrganisation's own risk assessment

How does the AIRG compare to the EU AI Act?

The biggest practical difference is how each decides where to apply the heavier controls. The EU AI Act is categorical: a use case is high-risk or it is not, according to a list set in the law, and credit scoring is on that list. The AIRG is proportionate: a firm assesses each AI use on impact, complexity and reliance, and the depth of the lifecycle controls follows that assessment. The AIRG can therefore scale a control up or down within a use case, where the EU AI Act sorts the whole use case into a tier.

The other difference is force. The EU AI Act is binding law, with conformity assessment, documentation and registration obligations, and penalties for breach. The AIRG is supervisory guidance a regulator holds firms to. Underneath, the two ask for much the same things: accountable oversight, an inventory, documented risk management, human oversight, and transparency.

How does the AIRG compare to NIST and ISO 42001?

The NIST AI RMF is a voluntary scaffold rather than a set of requirements, and the AIRG maps onto its four functions cleanly. The AIRG's oversight and key systems correspond to Govern; its identification, inventory and materiality work to Map; its evaluation and testing to Measure; and its lifecycle controls and monitoring to Manage. Adopting one after the other is largely a matter of re-expression, not new work.

ISO/IEC 42001 sits at a different level. It defines a management system for AI, the policies, objectives, roles, controls and review cycle, that an organisation can be certified against. The AIRG expects similar governance and controls but is not a certification. In practice ISO 42001 gives the management-system wrapper, and the AIRG gives the supervisory expectations that go inside it for a financial institution.

If you implement the AIRG, how far are you toward the others?

Most of the way on substance. The shared core, an AI inventory, a materiality view, accountable oversight, and lifecycle controls, transfers across all four. What is left is mostly formality specific to each framework. The EU AI Act adds conformity assessment, technical documentation and registration for high-risk systems. ISO 42001 adds the formal management system and a certification audit. NIST adds little beyond mapping what you already do onto its functions. Doing the AIRG well is the substantive work; the rest is packaging it for a particular regime.

Help mapping across frameworks

I wrote the AIRG and led the 2024 thematic review it builds on. I train and advise financial institutions on the AIRG and on mapping their AI governance across the EU AI Act, NIST and ISO 42001. See the courses and workshops, read Governing AI at Scale, or get in touch.