Why Use a Framework
"Use AI ethically" is too abstract to work in the field. Adopting a framework you can apply in practice gives you a common language for internal-rule setting, risk assessment, and external-audit response. Here's a comparison of 3 representative ones.
NIST AI RMF 1.0 (US, Practice-Leaning)
Published by NIST in 2023. Not legally binding, but a practice-oriented frame also mappable to the EU AI Act's high-risk requirements. Composed of 4 core functions.
- Govern: set up the organization's risk culture, policy, responsibility structure
- Map: grasp the AI system's context, stakeholders, potential impact
- Measure: quantitatively evaluate accuracy, fairness, robustness, transparency
- Manage: prioritize risks, respond, monitor, communicate
Each function has categories/subcategories defined, easy to handle with the same structure as the CSF (NIST's cybersecurity framework). The style is to concretize via Profiles (per-industry profiles).
ISO/IEC 42001 (International, Certification Standard)
The world's first AI-management-system certification standard, effective December 2023. It follows the same HLS (High Level Structure) as ISO 27001 (ISMS), so firms already operating an ISMS connect easily.
- Plan: AI policy, objectives, risk assessment
- Support: competence, awareness, documented information
- Operation: AI-system lifecycle management (requirements, design, verification, deploy, operation, retire)
- Performance evaluation: internal audit, management review
- Improvement: corrective action, continual improvement
A feature is the ability to obtain third-party certification. Cases of partners requiring AI-related certification (especially finance/medical) are increasing, becoming a differentiator in competitive bids.
OECD AI Principles (International, Values)
Adopted by the OECD in 2019 (including Japan). Not legally binding, but referenced as a common base for national AI strategies.
- Inclusive growth and sustainable development, well-being
- Human-centered values and fairness
- Transparency and explainability
- Robustness, security, safety
- Accountability
High abstraction makes it hard to use alone, but it's usable as a base to articulate "what we value" in internal policy or customer-facing explanation.
Selective Use of the 3
| Use | Recommended |
|---|---|
| Concretize what to do in practice | NIST AI RMF |
| Want third-party certification | ISO/IEC 42001 |
| Policy ideal statement | OECD AI Principles |
Many firms use them in a 3-layer stack: "OECD principles in the corporate creed → ISO 42001 for the operating frame → NIST RMF for concrete risk assessment."
Other Reference Frames
- EU AI Act conformity assessment: mandatory if providing high-risk AI
- Singapore AI Verify: a test kit for technical verification and explainability
- UK AI Assurance Roadmap: an assurance scheme linked with UK regulators
- WEF Responsible AI Playbook: practical-checklist centric
Summary
Choosing an AI-ethics framework depends on "where you use it." Want concrete measures → NIST RMF, certification → ISO 42001, ideal statement → OECD Principles. If you provide within the EU, considering the AI Act's conformity assessment as a set is efficient.



