AI Security and Risk: Side-by-side Comparison of AI Compliance and Risk Frameworks
The rapid rise of AI is reshaping security and compliance, but what do the leading frameworks actually say about managing AI-related risks? In this expert-led panel, Tevora’s AI and compliance specialists break down key AI security and risk management frameworks, including ISO 42001, HITRUST AI Framework, and NIST AI Risk Management Framework. This session explores the latest AI-specific compliance requirements, highlights key differences and commonalities, and provides actionable steps for organizations looking to stay ahead of evolving regulations.
Key Takeaways:
- Specific requirements outlined by ISO 42001, HITRUST AI Framework, and NIST AI Risk Management Framework
- Differences and commonalities between these new standards
- Steps your organization should take to comply
If your organization is navigating AI risk and compliance, this discussion is a must-watch.
AI Security and Risk: Side-by-side Comparison of AI Compliance and Risk Frameworks
An interview-style recap of Tevora’s expert panel discussion on AI governance, security, and compliance
Artificial Intelligence is transforming nearly every industry, creating new opportunities for innovation, efficiency, and business growth. At the same time, it is introducing entirely new categories of security, privacy, governance, and compliance risks.
To help organizations navigate this rapidly evolving landscape, Charlotte Densham (Senior Manager, Tevora) moderated a panel discussion with:
- Bhavin Patel (Manager, ISO Practice, Tevora)
- Justin Graham
- Anir Desai (Senior Manager, Strategic Services, Tevora)
Together, they explored three of the most significant AI governance frameworks emerging today:
- ISO 42001
- HITRUST AI Security Certification
- NIST AI Risk Management Framework (AI RMF)
Why AI Governance Matters Now
Artificial Intelligence has moved beyond experimentation and into everyday business operations.
Organizations today are:
- Using tools such as ChatGPT, Copilot, Gemini, and Claude
- Building proprietary AI models
- Integrating AI into products and services
- Leveraging third-party AI-powered software
As adoption accelerates, organizations are facing critical questions:
- How do we govern AI usage?
- How do we protect sensitive data?
- What security controls should be implemented?
- How do we demonstrate AI trustworthiness to customers and regulators?
As Bhavin noted:
“AI is becoming part of every organization’s technology ecosystem. The challenge is no longer whether AI will be used, but how it should be governed securely and responsibly.”
ISO 42001: Building an AI Management System
One of the panel’s primary topics was ISO 42001, the first international standard focused specifically on Artificial Intelligence Management Systems (AIMS).
Published in December 2023, ISO 42001 is rapidly gaining traction across industries and geographies.
What Is ISO 42001?
According to Bhavin:
“ISO 42001 is focused on creating governance and operational processes around how organizations manage and use AI technologies.”
The framework helps organizations establish a structured AI management system that addresses:
- Governance
- Risk management
- Security
- Compliance
- Accountability
- Continuous improvement
Like other ISO standards, organizations can become formally certified.
Why Organizations Pursue ISO 42001
The certification provides several benefits:
Customer and Vendor Assurance
Organizations increasingly expect evidence that AI systems are properly managed.
ISO 42001 helps demonstrate that:
- Appropriate controls exist
- AI risks are being addressed
- Governance processes are established
Competitive Differentiation
Organizations with ISO 42001 certification may gain an advantage over competitors when pursuing new business opportunities.
Global Recognition
Because ISO standards are internationally recognized, the framework provides consistency across:
- North America
- Europe
- Asia-Pacific
- Other global markets
Who Should Consider ISO 42001?
One of the most attractive aspects of ISO 42001 is its flexibility.
The framework can apply to:
- Startups
- Mid-sized businesses
- Large enterprises
- Healthcare organizations
- Financial institutions
- Technology providers
- Manufacturing companies
It also supports organizations that:
- Use AI tools
- Develop AI solutions
- Train AI models
- Integrate third-party AI services
Key Components of ISO 42001
AI Management System (AIMS)
At the center of ISO 42001 is the requirement to establish an AI governance framework.
Organizations must define:
- Roles and responsibilities
- Governance processes
- Oversight mechanisms
- Decision-making structures
AI Risk Assessments
A significant component of compliance involves evaluating:
- AI-related risks
- Business impacts
- Regulatory implications
- Operational concerns
AI Asset Management
Organizations must understand:
- What AI technologies are in use
- Where they reside
- How they are being used
- What data they process
Data Protection Controls
Organizations must establish controls governing:
- Data classification
- Data usage
- Training datasets
- Data security
- Data privacy
HITRUST AI Security Certification: Security-Focused Assurance for AI Systems
While ISO 42001 emphasizes governance, HITRUST AI Security Certification focuses primarily on security controls.
What Is HITRUST AI?
According to Justin:
“HITRUST AI is one of the first certifications specifically designed to assess the security of AI systems.”
Unlike ISO 42001, HITRUST AI is:
- Security-focused
- Prescriptive
- Assessment-driven
- Tailored specifically to deployed AI systems
Who Is HITRUST AI Designed For?
The certification is intended for organizations that provide AI-powered products or platforms.
Examples include:
- SaaS providers
- AI model developers
- AI platform vendors
- Software companies incorporating AI into products
Organizations simply using AI tools internally typically would not pursue HITRUST AI certification.
HITRUST AI Is Not a Standalone Assessment
One important distinction is that HITRUST AI functions as an extension of traditional HITRUST assessments.
Organizations generally pursue:
- e1 Assessments
- i1 Assessments
- r2 Assessments
and then layer the AI Security certification onto those efforts.
Areas Covered by HITRUST AI
The framework evaluates numerous AI-specific security requirements, including:
AI Governance
Organizations must establish:
- AI security policies
- Governance processes
- Accountability structures
AI Model Protection
Controls address:
- Model security
- Model integrity
- Protection from unauthorized modifications
Training Data Security
Requirements focus on protecting:
- Training datasets
- Validation datasets
- Testing environments
AI Change Management
Organizations must manage:
- Model updates
- Version control
- Deployment processes
AI Security Testing
Requirements include activities such as:
- Threat modeling
- Security testing
- Penetration testing
NIST AI Risk Management Framework (AI RMF)
Unlike ISO 42001 and HITRUST AI, the NIST AI RMF is not a certification framework.
Instead, it provides organizations with a structured approach for managing AI risk.
What Is the NIST AI RMF?
Released in January 2023, the framework was designed to help organizations:
- Identify AI risks
- Assess AI risks
- Measure AI risks
- Manage AI risks
According to Anir:
“NIST AI RMF is risk-focused. It helps organizations understand and manage the risks AI introduces throughout its lifecycle.”
Why Organizations Are Adopting It
The framework addresses many of today’s most pressing AI concerns, including:
Bias
Organizations must evaluate whether AI systems produce unfair or discriminatory outcomes.
Explainability
Can AI decisions be understood and defended?
Reliability
Can organizations trust the outputs being generated?
Compliance
How do AI systems align with evolving regulations?
The Four Core Functions
The NIST AI RMF revolves around four functions:
Govern
Establishing:
- Accountability
- Oversight
- Policies
- Governance structures
Map
Identifying:
- AI use cases
- Risks
- Impacts
- Dependencies
Measure
Evaluating:
- Risk levels
- Model behavior
- System performance
Manage
Implementing:
- Mitigation strategies
- Monitoring programs
- Ongoing risk management processes
How the Frameworks Compare
Throughout the discussion, the panel emphasized that these frameworks are not mutually exclusive.
ISO 42001
Best suited for organizations seeking:
- Formal governance
- International certification
- Structured AI management
HITRUST AI
Best suited for:
- AI platform providers
- Healthcare technology organizations
- Security-focused certification needs
NIST AI RMF
Best suited for:
- Risk management
- Program development
- AI governance foundations
- Regulatory preparation
Many organizations may ultimately leverage all three.
Common Challenges Organizations Are Facing
Several recurring challenges emerged during the discussion.
AI Asset Discovery
One of the biggest questions organizations struggle with is:
“What AI systems are actually being used?”
Before risks can be managed, organizations must understand:
- What models exist
- Where AI is being used
- What data is being processed
Data Classification and Protection
AI systems depend heavily on data.
Organizations increasingly need visibility into:
- Sensitive data
- Training data
- Customer information
- Intellectual property
Proper classification and protection become foundational requirements.
Vendor AI Management
As organizations adopt third-party AI solutions, due diligence becomes increasingly important.
The panel recommended evaluating vendors based on:
- AI governance maturity
- Framework alignment
- Security controls
- Data handling practices
- Transparency around AI decision-making
Best Practices for Organizations Getting Started
For organizations early in their AI journey, the panel recommended several practical first steps.
1. Conduct an AI Risk Assessment
Identify:
- AI technologies in use
- Associated risks
- Regulatory considerations
- Business impacts
2. Establish Governance
Define:
- Ownership
- Responsibilities
- Decision-making authority
3. Create AI Policies
Document:
- Acceptable AI usage
- Data handling requirements
- Security expectations
4. Inventory AI Assets
Understand:
- What AI is being used
- Where it resides
- What information it accesses
5. Build Common Controls
Rather than treating each framework separately, create a unified control structure that supports:
- ISO 42001
- HITRUST AI
- NIST AI RMF
- Emerging regulations
Final Takeaways
The panel’s overarching message was clear:
Artificial Intelligence is not a separate discipline that exists outside traditional governance, security, privacy, and risk programs.
Instead, organizations should view AI as an extension of their existing capabilities.
As Bhavin summarized:
“Think of AI as another layer on top of your existing security, privacy, and governance programs—not a completely separate initiative.”
Organizations that establish strong governance, understand their AI assets, manage risk proactively, and build common control frameworks today will be in the strongest position to adapt as AI technologies, regulations, and threats continue to evolve.



