Shadow AI Guide

Shadow AI Governance Frameworks

Voluntary and certifiable AI governance standards provide the structural backbone for any organization's sanctioned AI program. Understanding them is also the prerequisite to recognizing exactly what gap shadow AI creates.

Last reviewed: July 1, 2026

Why Governance Frameworks Matter for Shadow AI

AI governance frameworks—both voluntary and certifiable—define what a responsible, sanctioned AI program looks like. Their relevance to shadow AI is direct: shadow AI is, by definition, AI use that falls outside the governance structures these frameworks describe. Understanding the frameworks is therefore essential both for building a sanctioned program and for articulating precisely what risk shadow AI creates within it.

An organization that can point to a structured NIST AI RMF or ISO/IEC 42001 implementation has a defensible baseline. An organization that cannot—particularly one in a regulated industry—faces amplified exposure when shadow AI incidents surface, because it cannot demonstrate that a governance program existed that the unsanctioned usage circumvented.

NIST AI Risk Management Framework (AI RMF 1.0)

The NIST AI Risk Management Framework was published by the National Institute of Standards and Technology as NIST AI 100-1 on January 26, 2023, under authority of the National AI Initiative Act of 2020. Development involved approximately 400 comment sets from over 240 organizations across government, industry, and academia. The framework is voluntary and non-certifiable—organizations cannot receive formal AI RMF certification, though alignment is increasingly referenced in regulatory and procurement contexts.

Four Core Functions

The AI RMF organizes AI risk management into four functions:

  • Govern — Cross-cutting function. Establishes the organizational policies, culture, accountability structures, and processes that make the other three functions possible. Govern is foundational: without it, Map/Measure/Manage activities lack the authority and consistency to be effective.
  • Map — Identifies and categorizes the AI risks present in a specific context: what AI systems are in use, what they do, who uses them, and what data they process.
  • Measure — Analyzes and assesses the identified risks using appropriate metrics, testing, and evaluation methods.
  • Manage — Prioritizes, responds to, and monitors AI risks on an ongoing basis. Includes risk treatment decisions (accept, mitigate, transfer, avoid) and continuous improvement loops.

Shadow AI and the NIST AI RMF: Shadow AI directly undermines the Map function—it is, by definition, AI in use that has not been inventoried. An organization cannot Map risks it does not know exist, and cannot Measure or Manage those risks without a complete inventory. The Govern function is equally implicated: shadow AI signals that the governance policies and culture the Govern function requires are not yet effective at the employee level.

NIST GenAI Profile (AI 600-1)

NIST published a companion Generative AI Profile as NIST AI 600-1 in July 2024. This profile maps 12 generative-AI-specific risk categories to the AI RMF’s core functions, providing more granular guidance for the specific risks posed by large language models, image generators, and other generative AI systems.

The 12 risk categories in AI 600-1 include: confabulation (hallucination), data privacy, data provenance, harmful content generation, homogenization, human–AI configuration risks, information security, intellectual property, obscene content, operational and business risks, societal risks, and value chain/third-party risks. Several of these—data privacy, data provenance, information security, intellectual property, and value chain risks—map directly to the risks created when employees use unsanctioned AI tools.

ISO/IEC 42001:2023 — AI Management Systems Standard

ISO/IEC 42001:2023 was published in December 2023 as the first certifiable international standard for AI management systems (AIMS). Unlike the NIST AI RMF, which is voluntary and non-certifiable, ISO/IEC 42001 supports formal third-party certification, making it the primary standard for organizations that need to demonstrate AI governance maturity to external stakeholders—clients, regulators, auditors, and insurers.

Structure

ISO/IEC 42001 follows the Plan-Do-Check-Act (PDCA) structure common to other ISO management system standards (ISO 27001, ISO 9001). It includes an Annex A control library specifying the controls an AI management system should implement, covering areas including AI policy, organizational roles, risk assessment, AI impact assessment, resources, and operational controls.

Relevance to Shadow AI

ISO/IEC 42001 requires that an organization’s AI management system apply to the AI systems it deploys. Shadow AI—by definition not subject to any organizational management system—represents a direct gap in ISO/IEC 42001 coverage. An organization pursuing certification would need to address shadow AI as part of its scope definition and risk treatment process, because unmanaged AI systems in the environment could affect the conformity of the AIMS certification scope.

Some US state AI legislation (notably Colorado’s AI Act) and emerging procurement requirements treat alignment with NIST AI RMF or ISO/IEC 42001 as an affirmative defense or compliance signal—a concrete regulatory hook that makes framework adoption consequential beyond voluntary best practice.

ISO/IEC 23894 — AI Risk Management Guidance

ISO/IEC 23894 is a companion guidance standard focused specifically on AI risk management, intended to complement ISO/IEC 42001 and the broader ISO/IEC AI standards series. Unlike ISO/IEC 42001, it is a guidance document rather than a certifiable management system standard—it provides methodology and interpretation, not certification criteria. Verify current publication and amendment status at the ISO website before citing in formal documents, as this standard was undergoing revision work as of mid-2026.

The Shadow AI Gap in Current Frameworks

Neither the NIST AI RMF nor ISO/IEC 42001 includes shadow-AI-specific controls as a named category. This is a real, citable gap. Both frameworks assume the organization is governing AI systems it knows about and has formally assessed. Neither framework provides explicit guidance on how to discover, inventory, or govern AI systems that employees are using without organizational awareness.

The practical implication: an organization could achieve strong alignment with NIST AI RMF’s Map/Measure/Manage functions for its sanctioned AI systems while having no visibility into shadow AI at all—and both the framework alignment and the shadow AI gap could coexist without the framework flagging the contradiction. The Govern function’s requirement for organizational culture and policy provides the closest hook, but it is not operationalized into specific shadow AI discovery controls.

For organizations building AI governance programs, this gap means that shadow AI inventory, monitoring, and policy enforcement must be explicitly added as program components rather than assumed to be covered by standard framework alignment.

Regulatory Hooks: When Framework Alignment Becomes Required

While both NIST AI RMF and ISO/IEC 42001 are voluntary at the federal level in the United States, regulatory and contractual hooks are creating de facto requirements in specific contexts:

  • Colorado AI Act: Colorado’s AI Act (signed May 2024, with employer obligations phasing in) references NIST AI RMF and ISO/IEC 42001 alignment as relevant to the affirmative defense available to developers and deployers of high-risk AI systems—making framework alignment directly consequential for Colorado-regulated entities.
  • EU AI Act: The EU AI Act does not mandate NIST AI RMF specifically, but its deployer obligations for high-risk AI systems (Article 26) require documented risk management processes that ISO/IEC 42001 is well-suited to evidence. See the International AI Regulations page for EU AI Act detail.
  • Federal procurement: US federal agency AI procurement guidance increasingly references NIST AI RMF alignment as a vendor requirement or evaluation criterion, affecting organizations contracting with the federal government.
  • Cyber insurance: A growing number of cyber insurance underwriters are beginning to ask about AI governance program maturity as part of application questionnaires, making framework alignment a factor in policy pricing and coverage terms.

Free Resource

Shadow AI Assessment Checklist

A practical checklist for evaluating your organization's Shadow AI exposure across discovery, policy, controls, training, and compliance. Download and use it as a starting point for your governance review.

Frequently Asked Questions

Is the NIST AI RMF a legal requirement?

No. The NIST AI RMF (AI 100-1) is voluntary at the federal level in the United States. However, some US state laws (e.g., Colorado's AI Act), federal procurement requirements, and EU AI Act compliance contexts create de facto requirements to demonstrate AI risk management maturity, for which NIST AI RMF alignment is one recognized approach.

Can an organization get certified against the NIST AI RMF?

No. The NIST AI RMF is not certifiable. ISO/IEC 42001:2023 is the certifiable AI management system standard. The two frameworks are complementary — NIST AI RMF provides a risk-function model; ISO/IEC 42001 provides a certifiable management system structure.

Does ISO/IEC 42001 certification cover shadow AI?

An ISO/IEC 42001 management system applies to the AI systems within its defined scope. Shadow AI — AI use outside the organization's knowledge and control — represents a gap in that scope. An organization seeking certification would need to address shadow AI discovery and governance as part of its scope definition and risk treatment process.

What is the NIST GenAI Profile and how does it relate to the AI RMF?

NIST AI 600-1 (the GenAI Profile, published July 2024) is a companion document that maps 12 generative-AI-specific risk categories to the four core functions of the AI RMF (Govern, Map, Measure, Manage). It provides more granular guidance for generative AI systems specifically, addressing risks like confabulation, data provenance, and intellectual property that are particularly relevant to the shadow AI context.

Cite This Page

APA-style

Shadow AI Guide. (2026). Shadow AI Governance Frameworks: NIST AI RMF, ISO/IEC 42001 & More. Retrieved from https://www.shadowaiguide.com/shadow-ai-governance-frameworks

About This Guide

Reviewed for clarity, accuracy, and practical business relevance.

Content team: Shadow AI Guide Editorial Team