{"site":{"name":"Koji","description":"AI-native customer research platform that helps teams conduct, analyze, and synthesize customer interviews at scale.","url":"https://www.koji.so","contentTypes":["blog","documentation"],"lastUpdated":"2026-09-22T02:54:14.012Z"},"content":[{"type":"documentation","id":"64943f27-30cf-4e04-b33a-701411ada6ac","slug":"ai-governance-frameworks-research","title":"AI Governance for Customer Research: ISO 42001, the NIST AI RMF, and What Procurement Actually Asks","url":"https://www.koji.so/docs/ai-governance-frameworks-research","summary":"Procurement conflates three different things: the EU AI Act (binding law), ISO/IEC 42001 (a voluntary certifiable AI management system standard), and the NIST AI RMF (a voluntary framework). The key correction is that ISO 42001 is not a harmonised standard under the AI Act, so certification carries no presumption of conformity — prEN 18286 is the deliverable intended for that role. A second correction: NIST AI RMF was never legally mandatory, and guidance citing Executive Order 14110 is stale because that order was revoked in January 2025. Includes five overlapping control areas to build once, and seven checkable questions to ask an AI research vendor.","content":"## The short answer\n\n**ISO/IEC 42001 certification does not make you compliant with the EU AI Act, and the NIST AI RMF has never been a law.** Both are worth having. Neither is what most procurement questionnaires assume it is.\n\nIf you are buying or defending an AI-moderated research tool in 2026, three different things get conflated in the same email thread:\n\n| | What it is | Legal force | What it gives you |\n|---|---|---|---|\n| **EU AI Act** | Regulation | Binding law in the EU | Obligations you must meet, with penalties |\n| **ISO/IEC 42001:2023** | Certifiable management system standard | Voluntary | A third-party audited certificate that you govern AI systematically |\n| **NIST AI RMF 1.0** | Voluntary framework | None | A shared vocabulary and structure for AI risk work |\n\nGetting this hierarchy right saves a research team weeks. It also stops you paying for a certificate to solve a problem the certificate does not solve.\n\n## ISO/IEC 42001: the certifiable one\n\nPublished in December 2023, ISO/IEC 42001 is the first international standard for an **AI management system** (AIMS). It is structured like ISO 27001 — the same Annex SL management-system shape — but its subject is AI: how you inventory AI systems, assess their impact on the people they touch, assign accountability, and monitor behaviour across the lifecycle.\n\nCertification works the way ISO certification always works. An accredited certification body runs a Stage 1 (documentation readiness) and Stage 2 (implementation) audit. The certificate is valid for three years, with annual surveillance audits in between. Published cost and timeline estimates vary widely by scope and organisation size; consultancies commonly quote figures in the tens of thousands of dollars and four to nine months of preparation. Treat those as directional, not as a quote.\n\nTwo supporting standards arrived in 2025 and are worth knowing by name, because sophisticated buyers cite them:\n\n- **ISO/IEC 42005:2025** — guidance for conducting AI system impact assessments. It is guidance, not a certifiable requirement, and it complements 42001 with lifecycle-continuous assessment practice.\n- **ISO/IEC 42006:2025** — requirements for the bodies that audit and certify AIMS. This one matters indirectly: it is what makes one vendor's 42001 certificate comparable to another's.\n\n## The presumption-of-conformity trap\n\nHere is the point that most vendor questionnaires get wrong, and the single most useful thing to know in this whole area.\n\nUnder Article 40 of the EU AI Act, applying a **harmonised standard** — one cited in the Official Journal of the EU — gives you a presumption of conformity with the corresponding AI Act requirements. That is a real, valuable legal shortcut.\n\n**ISO/IEC 42001 is not a harmonised standard.** A 42001 certificate therefore carries no presumption of conformity with the AI Act. The European deliverable being developed to serve that role is **prEN 18286**; until it is cited in the Official Journal, nobody has the shortcut. Neither 42001 nor 42005 was designed to operationalise the full set of AI Act obligations in the first place.\n\nSo when a security reviewer writes \"we require ISO 42001 certification to satisfy the EU AI Act,\" the honest answer is that the two are complementary but not substitutes: the certificate is credible evidence of governance maturity, and the AI Act obligations still have to be met on their own terms.\n\nFor customer research specifically, those obligations are usually lighter than people fear. AI-moderated interviews sit in the AI Act's limited-risk transparency tier, where the core duty is to tell participants they are talking to an AI before the conversation starts. Our [EU AI Act guide](/docs/eu-ai-act-user-research-compliance) walks through the tiering and the narrow cases that escalate it.\n\n## NIST AI RMF: useful framework, frequently mis-cited\n\nNIST released the AI Risk Management Framework 1.0 in January 2023, organised around four functions — **GOVERN, MAP, MEASURE, MANAGE** — plus a companion Generative AI Profile (NIST AI 600-1) published in July 2024.\n\nIt is genuinely good structure, and it is free. But be careful with claims about its legal status. Much of the guidance still circulating online states that federal agencies are directed to align with the AI RMF under Executive Order 14110. **EO 14110 was revoked on 20 January 2025**, and replaced days later by a different executive order with a different posture. The framework itself is unaffected — NIST still publishes it, and enterprises still use it — but it remains what it always was: voluntary. If a vendor tells you AI RMF alignment is legally mandatory, they are working from stale material.\n\nWhat is true is that AI RMF vocabulary has become the lingua franca of enterprise AI questionnaires. Answering in its terms (here is our GOVERN evidence, here is our MEASURE evidence) makes a review go faster whether or not anyone is certified.\n\n## The overlap you can build once\n\nAcross the AI Act, ISO 42001, and the NIST AI RMF, the same five control areas keep appearing:\n\n1. **Risk and impact documentation** — what the system does, who it affects, what could go wrong\n2. **Data governance** — provenance, minimisation, retention, quality\n3. **Human oversight** — who can intervene, and how\n4. **Incident monitoring** — detection, logging, escalation\n5. **Transparency documentation** — disclosure to affected people, and system documentation for reviewers\n\nBuild the evidence once, tag each artefact against all three frameworks, and most questionnaires answer themselves.\n\n## What to actually ask an AI research vendor\n\nSkip the framework name-dropping and ask questions whose answers are checkable:\n\n- **Which model providers process interview data, and are they named as sub-processors?** AI interview tools route text and audio to model and transcription providers. Unnamed sub-processors are the real risk, not the absence of a certificate.\n- **Is participant data used to train models?** Get this in the contract, not in a sales email.\n- **How is AI disclosure handled in the participant flow?** Under the AI Act this is the operative obligation for research. Ask to see the actual screen.\n- **What human oversight exists over the AI interviewer?** Can a researcher review, correct, and re-run analysis?\n- **What is logged, and for how long?** This is where AI governance and your retention schedule meet — see [research data retention and deletion](/docs/research-data-retention-deletion).\n- **Do you hold ISO 42001, or have a dated roadmap?** A credible roadmap beats a vague yes. Ask which certification body and what scope — scope is where certificates get thin.\n- **What is your AI incident process?** Ask for one worked example.\n\nAsk the same seven of every vendor on the shortlist, including Koji. Answers that vary in specificity tell you more than answers that vary in confidence.\n\n## How Koji's architecture changes the governance conversation\n\nTwo structural properties of Koji make several of these questions easier to answer than they are for the tools research teams are migrating from.\n\n**Interviews are asynchronous, link-based, and transcript-first.** There is no third-party meeting recorder in the chain, which removes a sub-processor and the consent trail that comes with it. Participants receive the AI disclosure in the flow before the conversation begins, so the AI Act transparency duty is satisfied by the product's default path rather than by researcher discipline.\n\n**Analysis runs on transcripts, not on biometric signals.** This distinction does real work under the AI Act: emotion recognition obligations attach to *biometric* inference, so analysing what someone said sits in a materially different place from inferring affect from vocal tone. A transcript-first architecture keeps you out of the harder tier by design rather than by configuration.\n\nOn the research-quality side, Koji's six structured question types — `open_ended`, `scale`, `single_choice`, `multiple_choice`, `ranking`, and `yes_no` — matter more for governance than they first appear. Structured questions produce predictable, typed data with a stable question ID from interview plan through to report. When a reviewer asks what data you collect and how it is processed, \"these six typed fields plus transcript\" is a far easier answer than \"free-text, variably\" — and it is the same property that makes deletion and access requests tractable.\n\n## Common mistakes\n\n- **Buying a certificate to answer a regulation.** ISO 42001 is evidence of governance maturity, not a conformity shortcut under the AI Act.\n- **Citing EO 14110.** It was revoked in January 2025. Cite the framework, not the executive order.\n- **Accepting \"we're SOC 2\" as an AI governance answer.** SOC 2 addresses information security controls. It says nothing about model behaviour, training use, or human oversight. Both matter; they are not interchangeable.\n- **Ignoring certificate scope.** A 42001 certificate covering a parent company's internal tooling tells you little about the product you are buying.\n- **Treating AI governance as a one-time procurement gate.** All three frameworks assume ongoing monitoring, and the EDPB expects controllers to re-verify processing chains over time.\n\n## Frequently asked questions\n\n**Does ISO 42001 certification make me EU AI Act compliant?**\nNo. ISO/IEC 42001 is not a harmonised standard under the Act, so a certificate carries no presumption of conformity. The European deliverable intended for that role is prEN 18286. The certificate is still strong evidence of governance maturity in a vendor review.\n\n**Is the NIST AI RMF mandatory?**\nNo. It is and always has been a voluntary framework. Guidance claiming a federal mandate typically traces to Executive Order 14110, which was revoked on 20 January 2025.\n\n**Do we need ISO 42001 to run AI-moderated customer research?**\nNo. Customer research generally sits in the AI Act's limited-risk transparency tier, where the operative duty is disclosing to participants that they are interacting with an AI. Certification becomes relevant when your own enterprise buyers demand it of you.\n\n**What is the difference between ISO 42001 and ISO 42005?**\n42001 is the certifiable management system standard. 42005 is guidance for conducting AI system impact assessments and is not certifiable; it complements 42001.\n\n**What is the difference between SOC 2 and ISO 42001 for an AI vendor?**\nSOC 2 attests to information security controls — access, encryption, availability. ISO 42001 attests to how the organisation governs AI systems specifically. Enterprise buyers increasingly want both, for different reviewers.\n\n**How should a small research team answer an AI governance questionnaire?**\nAnswer in NIST AI RMF terms even without certification: document what the AI does, who it affects, what human oversight exists, what is logged, and what you disclose to participants. That covers most of what the questionnaire is reaching for.\n\n## Related Resources\n\n- [Structured Questions Guide](/docs/structured-questions-guide) — the six question types and the typed, predictable data they produce\n- [The EU AI Act and User Research](/docs/eu-ai-act-user-research-compliance) — the binding obligations, and which tier research falls into\n- [Enterprise Security for AI Research Platforms](/docs/enterprise-security-ai-research-platforms) — SOC 2, SSO, and the wider vendor security review\n- [AI Interview Data Privacy & Security](/docs/ai-interview-data-privacy-security) — how interview data is protected end to end\n- [DPIA for User Research](/docs/dpia-user-research) — when an impact assessment is legally required, and how to write it\n- [Research Data Retention and Deletion](/docs/research-data-retention-deletion) — the logging and retention half of AI governance\n- [User Research for AI Products](/docs/user-research-for-ai-products) — researching AI features, as distinct from governing them","category":"Research Operations","lastModified":"2026-08-05T03:24:45.421037+00:00","metaTitle":"AI Governance for Research: ISO 42001, NIST AI RMF, EU AI Act (2026)","metaDescription":"ISO 42001 is not a harmonised standard, so it buys no EU AI Act presumption of conformity. What each AI governance framework covers, and the seven questions to ask a research vendor.","keywords":["ai governance customer research","iso 42001 certification","nist ai rmf","eu ai act presumption of conformity","pren 18286","iso 42005","ai vendor questionnaire","ai management system","ai governance framework comparison","responsible ai research platform"],"aiSummary":"Procurement conflates three different things: the EU AI Act (binding law), ISO/IEC 42001 (a voluntary certifiable AI management system standard), and the NIST AI RMF (a voluntary framework). The key correction is that ISO 42001 is not a harmonised standard under the AI Act, so certification carries no presumption of conformity — prEN 18286 is the deliverable intended for that role. A second correction: NIST AI RMF was never legally mandatory, and guidance citing Executive Order 14110 is stale because that order was revoked in January 2025. Includes five overlapping control areas to build once, and seven checkable questions to ask an AI research vendor.","aiDifficulty":"intermediate","aiEstimatedTime":"12 min"}],"pagination":{"total":1,"returned":1,"offset":0}}