The EU AI Act says what to comply with, ISO/IEC 42001 says how to prove it in an audit, and NIST AI RMF says how to manage AI risk day to day.
El EU AI Act dice qué hay que cumplir, ISO/IEC 42001 dice cómo demostrarlo ante una auditoría, y NIST AI RMF dice cómo gestionar el riesgo de IA en el día a día.
EU AI Act
If you operate in the European Union, it's not optional. It defines what is banned, what counts as high risk, and what documentation you must produce on request, with penalties up to €35M or 7% of global turnover.
Si operas en la Unión Europea, no es opcional. Define qué está prohibido, qué es alto riesgo y qué documentación tienes que poder enseñar, con sanciones de hasta 35 M€ o el 7% de la facturación global.
ISO/IEC 42001
The international AI management system standard. It's auditable, so it lets you prove compliance to a client, a regulator or an investor through third-party certification.
El estándar internacional de sistema de gestión de IA. Es auditable, así que permite demostrar cumplimiento ante un cliente, un regulador o un inversor mediante certificación.
NIST AI RMF
Neither certifiable nor mandatory, but the best available tool for structuring day-to-day risk management, through its four functions: Govern, Map, Measure, Manage.
Ni certificable ni obligatorio, pero la mejor herramienta disponible para estructurar la gestión de riesgos diaria, con sus cuatro funciones: Govern, Map, Measure y Manage.
The comparison, side by side
La comparativa, lado a lado
| EU AI Act | ISO/IEC 42001 | NIST AI RMF | |
|---|---|---|---|
| NatureNaturaleza | Law (EU Regulation 2024/1689)Ley (Reglamento UE 2024/1689) | International certifiable standardNorma internacional certificable | Voluntary framework (US)Marco voluntario (EE. UU.) |
| MandatoryObligatorio | Yes, in the EUSí, en la UE | No, but auditable and certifiableNo, pero auditable y certificable | No |
| What it gives youQué aporta | Risk-tier obligations and penaltiesObligaciones por nivel de riesgo y sanciones | How to structure an AI management system (Annex A controls)Cómo estructurar un sistema de gestión de IA (controles del Anexo A) | Four functions to manage risk: Govern, Map, Measure, ManageCuatro funciones para gestionar riesgo: Govern, Map, Measure, Manage |
| It's forSirve para | Not being fined and operating in the EUNo ser sancionado y poder operar en la UE | Proving compliance to clients, regulators and investorsDemostrar cumplimiento ante clientes, reguladores e inversores | Structuring your team's internal practiceEstructurar la práctica interna del equipo |
| Proven withSe demuestra con | Technical documentation, conformity assessment, registrationDocumentación técnica, evaluación de conformidad, registro | Third-party certification auditAuditoría de certificación por tercera parte | Internal self-assessmentAutoevaluación interna |
How mature organizations use all three
Cómo los usa a la vez una organización madura
In practice the three work as a stack: you classify your AI systems under the EU AI Act (the law defines your obligations), you build your management system following ISO/IEC 42001 (which doubles as evidence of AI Act compliance), and you run your risk team's daily work with the NIST AI RMF functions. And all of it rests on a foundation that is usually the weak spot: data governance, because there is no governed AI on ungoverned data.
En la práctica los tres funcionan como una pila: clasificas tus sistemas según el EU AI Act (la ley define tus obligaciones), montas tu sistema de gestión siguiendo ISO/IEC 42001 (que además sirve como evidencia de cumplimiento del propio AI Act), y organizas el día a día del equipo de riesgos con las funciones del NIST AI RMF. Y todo se apoya en una base que suele estar coja: el gobierno del dato, porque no hay IA gobernada sobre datos sin gobernar.
Want to go deeper on the law itself, its risk tiers, timeline, roles and penalties? That's exactly what our interactive EU AI Act guide covers.
¿Quieres profundizar en la ley: niveles de riesgo, calendario, roles y sanciones? Es justo lo que cubre nuestra guía interactiva del EU AI Act.
Learn to apply all three
Aprende a aplicar los tres
Our flagship course covers the EU AI Act, ISO/IEC 42001 and NIST AI RMF with the roles, controls and templates to implement them, built by practitioners.
Nuestro curso insignia cubre el EU AI Act, ISO/IEC 42001 y NIST AI RMF con los roles, controles y plantillas para implementarlos. Creado por profesionales, 4.4★ y más de 24.000 estudiantes.
View the course →Ver el curso →Frequently asked questions
Preguntas frecuentes
Do I need ISO/IEC 42001 to comply with the EU AI Act?
¿Necesito ISO/IEC 42001 para cumplir el EU AI Act?
No, ISO/IEC 42001 is voluntary. But building your AI management system on it is the most direct way to generate the evidence the AI Act requires, and certification is increasingly requested by enterprise clients as proof of responsible AI practice.
No: ISO/IEC 42001 es voluntaria. Pero montar tu sistema de gestión sobre ella es la vía más directa para generar las evidencias que exige el AI Act, y la certificación la piden cada vez más los clientes enterprise como prueba de práctica responsable.
Which one should I learn first?
¿Cuál aprendo primero?
If you operate in the EU, start with the AI Act, the one with legal deadlines and penalties. Then NIST AI RMF for internal practice, and ISO/IEC 42001 when you need external proof.
Si operas en la UE, empieza por el AI Act, que es el que tiene plazos legales y sanciones. Después NIST AI RMF para la práctica interna, e ISO/IEC 42001 cuando necesites demostrarlo fuera.
AI Governance: The Fundamentals of AI Governance
Nuestro curso insignia desarrolla en profundidad lo que aquí se resume, con marcos, plantillas y casos reales.Our flagship course develops in depth what is summarized here, with frameworks, templates and real cases.
El EU AI Act, hecho navegable8 min · ES · EN
Gobierno del dato: guía completa10 min · ES
DATA UNIVERSE