MiddlebrookData & AI Governance← All insights
Insight · Frameworks

NIST AI RMF, ISO 42001 & the EU AI Act: what a finance leader actually has to do

By Barry Middlebrook · Middlebrook Data & AI Governance

Three names dominate every AI-governance conversation, and they're easy to conflate. Here's the plain-English version, and — more usefully — what they actually require you to do.

The three, demystified

Two are voluntary maps; one is law. But they converge on the same handful of disciplines — which is good news, because you can satisfy all three with one program.

What you actually have to do

Strip away the acronyms and the practical work is consistent:

Do that, and you're substantially aligned to all three at once. The frameworks aren't five separate projects — they're one governance program, described in three vocabularies.

Is your data ready for AI reporting?

Take the free 4-minute readiness assessment and get your maturity level with prioritized fixes — instantly.

Take the free assessment Or request a full, expert-led assessment →