Skip to Content

Discover Our Newest Resources Resource Center

Dark teal and black gradient

Webinar

AI Security and Risk: Side-by-side Comparison of AI Compliance and Risk Frameworks

The rapid rise of AI is reshaping security and compliance, but what do the leading frameworks actually say about managing AI-related risks? In this expert-led panel, Tevora’s AI and compliance specialists break down key AI security and risk management frameworks, including ISO 42001, HITRUST AI Framework, and NIST AI Risk Management Framework. This session explores the latest AI-specific compliance requirements, highlights key differences and commonalities, and provides actionable steps for organizations looking to stay ahead of evolving regulations.

Key Takeaways:

  • Specific requirements outlined by ISO 42001, HITRUST AI Framework, and NIST AI Risk Management Framework
  • Differences and commonalities between these new standards
  • Steps your organization should take to comply

If your organization is navigating AI risk and compliance, this discussion is a must-watch.

AI Security and Risk: Side-by-side Comparison of AI Compliance and Risk Frameworks

An interview-style recap of Tevora’s expert panel discussion on AI governance, security, and compliance

Artificial Intelligence is transforming nearly every industry, creating new opportunities for innovation, efficiency, and business growth. At the same time, it is introducing entirely new categories of security, privacy, governance, and compliance risks.

To help organizations navigate this rapidly evolving landscape, Charlotte Densham (Senior Manager, Tevora) moderated a panel discussion with:

  • Bhavin Patel (Manager, ISO Practice, Tevora)
  • Justin Graham 
  • Anir Desai (Senior Manager, Strategic Services, Tevora)

Together, they explored three of the most significant AI governance frameworks emerging today:

  • ISO 42001
  • HITRUST AI Security Certification
  • NIST AI Risk Management Framework (AI RMF)

Why AI Governance Matters Now

Artificial Intelligence has moved beyond experimentation and into everyday business operations.

Organizations today are:

  • Using tools such as ChatGPT, Copilot, Gemini, and Claude
  • Building proprietary AI models
  • Integrating AI into products and services
  • Leveraging third-party AI-powered software

As adoption accelerates, organizations are facing critical questions:

  • How do we govern AI usage?
  • How do we protect sensitive data?
  • What security controls should be implemented?
  • How do we demonstrate AI trustworthiness to customers and regulators?

As Bhavin noted:

“AI is becoming part of every organization’s technology ecosystem. The challenge is no longer whether AI will be used, but how it should be governed securely and responsibly.”

ISO 42001: Building an AI Management System

One of the panel’s primary topics was ISO 42001, the first international standard focused specifically on Artificial Intelligence Management Systems (AIMS).

Published in December 2023, ISO 42001 is rapidly gaining traction across industries and geographies.

What Is ISO 42001?

According to Bhavin:

“ISO 42001 is focused on creating governance and operational processes around how organizations manage and use AI technologies.”

The framework helps organizations establish a structured AI management system that addresses:

  • Governance
  • Risk management
  • Security
  • Compliance
  • Accountability
  • Continuous improvement

Like other ISO standards, organizations can become formally certified.

Why Organizations Pursue ISO 42001

The certification provides several benefits:

Customer and Vendor Assurance

Organizations increasingly expect evidence that AI systems are properly managed.

ISO 42001 helps demonstrate that:

  • Appropriate controls exist
  • AI risks are being addressed
  • Governance processes are established

Competitive Differentiation

Organizations with ISO 42001 certification may gain an advantage over competitors when pursuing new business opportunities.

Global Recognition

Because ISO standards are internationally recognized, the framework provides consistency across:

  • North America
  • Europe
  • Asia-Pacific
  • Other global markets

Who Should Consider ISO 42001?

One of the most attractive aspects of ISO 42001 is its flexibility.

The framework can apply to:

  • Startups
  • Mid-sized businesses
  • Large enterprises
  • Healthcare organizations
  • Financial institutions
  • Technology providers
  • Manufacturing companies

It also supports organizations that:

  • Use AI tools
  • Develop AI solutions
  • Train AI models
  • Integrate third-party AI services

Key Components of ISO 42001

AI Management System (AIMS)

At the center of ISO 42001 is the requirement to establish an AI governance framework.

Organizations must define:

  • Roles and responsibilities
  • Governance processes
  • Oversight mechanisms
  • Decision-making structures

AI Risk Assessments

A significant component of compliance involves evaluating:

  • AI-related risks
  • Business impacts
  • Regulatory implications
  • Operational concerns

AI Asset Management

Organizations must understand:

  • What AI technologies are in use
  • Where they reside
  • How they are being used
  • What data they process

Data Protection Controls

Organizations must establish controls governing:

  • Data classification
  • Data usage
  • Training datasets
  • Data security
  • Data privacy

HITRUST AI Security Certification: Security-Focused Assurance for AI Systems

While ISO 42001 emphasizes governance, HITRUST AI Security Certification focuses primarily on security controls.

What Is HITRUST AI?

According to Justin:

“HITRUST AI is one of the first certifications specifically designed to assess the security of AI systems.”

Unlike ISO 42001, HITRUST AI is:

  • Security-focused
  • Prescriptive
  • Assessment-driven
  • Tailored specifically to deployed AI systems

Who Is HITRUST AI Designed For?

The certification is intended for organizations that provide AI-powered products or platforms.

Examples include:

  • SaaS providers
  • AI model developers
  • AI platform vendors
  • Software companies incorporating AI into products

Organizations simply using AI tools internally typically would not pursue HITRUST AI certification.

HITRUST AI Is Not a Standalone Assessment

One important distinction is that HITRUST AI functions as an extension of traditional HITRUST assessments.

Organizations generally pursue:

  • e1 Assessments
  • i1 Assessments
  • r2 Assessments

and then layer the AI Security certification onto those efforts.

Areas Covered by HITRUST AI

The framework evaluates numerous AI-specific security requirements, including:

AI Governance

Organizations must establish:

  • AI security policies
  • Governance processes
  • Accountability structures

AI Model Protection

Controls address:

  • Model security
  • Model integrity
  • Protection from unauthorized modifications

Training Data Security

Requirements focus on protecting:

  • Training datasets
  • Validation datasets
  • Testing environments

AI Change Management

Organizations must manage:

  • Model updates
  • Version control
  • Deployment processes

AI Security Testing

Requirements include activities such as:

  • Threat modeling
  • Security testing
  • Penetration testing

NIST AI Risk Management Framework (AI RMF)

Unlike ISO 42001 and HITRUST AI, the NIST AI RMF is not a certification framework.

Instead, it provides organizations with a structured approach for managing AI risk.

What Is the NIST AI RMF?

Released in January 2023, the framework was designed to help organizations:

  • Identify AI risks
  • Assess AI risks
  • Measure AI risks
  • Manage AI risks

According to Anir:

“NIST AI RMF is risk-focused. It helps organizations understand and manage the risks AI introduces throughout its lifecycle.”

Why Organizations Are Adopting It

The framework addresses many of today’s most pressing AI concerns, including:

Bias

Organizations must evaluate whether AI systems produce unfair or discriminatory outcomes.

Explainability

Can AI decisions be understood and defended?

Reliability

Can organizations trust the outputs being generated?

Compliance

How do AI systems align with evolving regulations?

The Four Core Functions

The NIST AI RMF revolves around four functions:

Govern

Establishing:

  • Accountability
  • Oversight
  • Policies
  • Governance structures

Map

Identifying:

  • AI use cases
  • Risks
  • Impacts
  • Dependencies

Measure

Evaluating:

  • Risk levels
  • Model behavior
  • System performance

Manage

Implementing:

  • Mitigation strategies
  • Monitoring programs
  • Ongoing risk management processes

How the Frameworks Compare

Throughout the discussion, the panel emphasized that these frameworks are not mutually exclusive.

ISO 42001

Best suited for organizations seeking:

  • Formal governance
  • International certification
  • Structured AI management

HITRUST AI

Best suited for:

  • AI platform providers
  • Healthcare technology organizations
  • Security-focused certification needs

NIST AI RMF

Best suited for:

  • Risk management
  • Program development
  • AI governance foundations
  • Regulatory preparation

Many organizations may ultimately leverage all three.

Common Challenges Organizations Are Facing

Several recurring challenges emerged during the discussion.

AI Asset Discovery

One of the biggest questions organizations struggle with is:

“What AI systems are actually being used?”

Before risks can be managed, organizations must understand:

  • What models exist
  • Where AI is being used
  • What data is being processed

Data Classification and Protection

AI systems depend heavily on data.

Organizations increasingly need visibility into:

  • Sensitive data
  • Training data
  • Customer information
  • Intellectual property

Proper classification and protection become foundational requirements.

Vendor AI Management

As organizations adopt third-party AI solutions, due diligence becomes increasingly important.

The panel recommended evaluating vendors based on:

  • AI governance maturity
  • Framework alignment
  • Security controls
  • Data handling practices
  • Transparency around AI decision-making

Best Practices for Organizations Getting Started

For organizations early in their AI journey, the panel recommended several practical first steps.

1. Conduct an AI Risk Assessment

Identify:

  • AI technologies in use
  • Associated risks
  • Regulatory considerations
  • Business impacts

2. Establish Governance

Define:

  • Ownership
  • Responsibilities
  • Decision-making authority

3. Create AI Policies

Document:

  • Acceptable AI usage
  • Data handling requirements
  • Security expectations

4. Inventory AI Assets

Understand:

  • What AI is being used
  • Where it resides
  • What information it accesses

5. Build Common Controls

Rather than treating each framework separately, create a unified control structure that supports:

  • ISO 42001
  • HITRUST AI
  • NIST AI RMF
  • Emerging regulations

Final Takeaways

The panel’s overarching message was clear:

Artificial Intelligence is not a separate discipline that exists outside traditional governance, security, privacy, and risk programs.

Instead, organizations should view AI as an extension of their existing capabilities.

As Bhavin summarized:

“Think of AI as another layer on top of your existing security, privacy, and governance programs—not a completely separate initiative.”

Organizations that establish strong governance, understand their AI assets, manage risk proactively, and build common control frameworks today will be in the strongest position to adapt as AI technologies, regulations, and threats continue to evolve.