Skip to main content

Responsible AI governance

How RAIUC fits with other Responsible AI frameworks

A practical place to start with responsible AI governance

Responsible AI can quickly become complicated. Organisations are faced with legislation, international standards, risk management frameworks and high-level principles. Each has its own terminology, purpose and level of detail.

RAIUC is designed to provide a simpler starting point. The 10 Responsible AI Commitments help organisations think practically about how artificial intelligence is being used in day-to-day work.

Management system standardLegislationRisk management frameworkInternational principles

From practical commitments to stronger AI governance

Many responsible AI themes appear, in different forms and at different levels of detail, across established standards, frameworks and regulations.

RAIUC does not replace those frameworks, and RAIUC certification does not demonstrate compliance with them. Instead, it gives organisations a practical way to begin developing the awareness, responsibilities and working practices that can support stronger AI governance over time.

For many organisations, the biggest challenge is simply knowing where to begin. A small business or individual department may not need a comprehensive AI management system from day one. What it may need first is a clear understanding of some basic questions:

  • Where are we using AI?
  • Are people told when AI is being used?
  • Who remains responsible for decisions?
  • Are important AI outputs reviewed by a person?
  • Is personal or confidential information properly protected?
  • Are bias and discrimination being considered?
  • Are suitable security safeguards in place?
  • Do employees have appropriate guidance and training?
  • Could an automated decision cause harm?
  • What happens if something goes wrong?

The 10 Responsible AI Commitments turn questions like these into a straightforward framework that organisations can adopt and apply.

As an organisation's use of AI grows, these foundations can support more detailed governance arrangements, including policies, risk assessments, documentation, controls, monitoring and formal management systems.

Management system standard

RAIUC and ISO/IEC 42001

ISO/IEC 42001 is the international standard for artificial intelligence management systems. It provides organisations with a structured approach to establishing, implementing, maintaining and continually improving the way they manage AI.

For an organisation that may eventually choose to implement ISO/IEC 42001, responsible AI does not begin on the day an ISO project starts. The groundwork usually begins much earlier.

People first need to recognise that the use of AI brings responsibilities with it. Organisations need to think about oversight, risk, accountability, transparency, privacy, security and appropriate use. Those responsibilities then need to become part of normal working practices.

This is where RAIUC can provide a useful starting point. The commitments encourage organisations to begin thinking about practical areas such as transparency, human oversight, data responsibility, bias, security, safe automation, workforce awareness, environmental impact and accountability.

These commitments are not a substitute for the requirements of ISO/IEC 42001. They can, however, help an organisation begin developing the culture, awareness and governance habits that a more formal AI management system may later build upon.

An organisation might start by adopting the 10 commitments and setting clear expectations for how AI should be used. Over time, it may introduce supporting policies, document its AI systems and use cases, assign responsibilities, carry out risk assessments and establish more formal monitoring and review processes.

Important: RAIUC certification is not ISO/IEC 42001 certification. It does not assess conformity with ISO/IEC 42001 and does not indicate that an organisation is ready for, or will achieve, ISO certification.

Learn more about ISO/IEC 42001 from the International Organization for Standardization (opens another website in a new tab)

Legislation

RAIUC and the EU AI Act

The EU Artificial Intelligence Act establishes a legal framework for artificial intelligence within the European Union. The obligations that apply depend on factors including the type of AI system involved, how it is used and the level of risk associated with it.

RAIUC is not a legal compliance framework, and RAIUC certification does not demonstrate compliance with the EU AI Act.

There are, however, themes common to both responsible AI practice and the wider regulatory environment around AI. These include human oversight, transparency, safe use, data responsibility, risk of harm, accountability, AI literacy and appropriate controls around automated decisions.

For organisations affected by the EU AI Act, adopting the RAIUC commitments may help build awareness of some of the issues that a more detailed legal compliance programme will need to consider.

RAIUC should therefore be seen as a starting point for responsible practice, rather than evidence that the requirements of the EU AI Act have been met. Organisations that may fall within the scope of the Act remain responsible for identifying their own legal obligations and should obtain appropriate professional advice where necessary.

Read the official EU Artificial Intelligence Act on EUR-Lex (opens another website in a new tab)

Risk management framework

RAIUC and the NIST AI Risk Management Framework

The US National Institute of Standards and Technology developed the Artificial Intelligence Risk Management Framework, commonly known as the NIST AI RMF, to help organisations manage risks associated with artificial intelligence.

NIST AI RMF 1.0 is voluntary and is intended to help organisations incorporate trustworthiness considerations into the design, development, use and evaluation of AI systems. Its core approach is organised around four functions: Govern, Map, Measure and Manage.

RAIUC takes a considerably simpler approach. Its primary purpose is to give organisations accessible principles they can apply to the everyday use of AI.

RAIUC asks organisations to think about who is responsible for AI, how people are protected, whether important outputs are reviewed, how bias and security risks are considered and what should happen when concerns arise.

Building these habits can help an organisation develop the awareness and governance culture needed before more detailed risk management processes are introduced.

RAIUC certification does not constitute implementation of the NIST AI RMF and does not assess an organisation against NIST guidance or requirements.

Learn more about the NIST Artificial Intelligence Risk Management Framework (opens another website in a new tab)

International principles

RAIUC and the OECD AI Principles

The OECD AI Principles are an intergovernmental standard on AI. Adopted in 2019 and updated in 2024, they promote innovative and trustworthy artificial intelligence that respects human rights and democratic values.

Their themes include inclusive growth and well-being, human rights and fairness, transparency and explainability, robustness, security and safety, and accountability.

RAIUC takes several similar broad ideas and translates them into straightforward commitments intended for organisations using AI in everyday work. The commitments address transparency, human oversight, bias, privacy, security, accountability and environmental awareness.

The purpose is not to claim equivalence with the OECD AI Principles. It is to make some of the wider ideas associated with responsible AI easier for organisations to understand and begin putting into practice.

Learn more about the OECD AI Principles (opens another website in a new tab)

At a glance

How the themes compare

These standards, frameworks and regulations serve different purposes and operate at very different levels of detail. Even so, a number of responsible AI themes appear across them.

Responsible AI themes compared across RAIUC, ISO/IEC 42001, the EU AI Act, NIST AI RMF and the OECD AI Principles
Responsible AI themeRAIUC starting pointISO/IEC 42001 focusEU AI Act focusNIST AI RMF focusOECD principle
TransparencyDisclose key AI uses and handle AI-generated content responsiblyTransparency, information and communication within the AI management systemTransparency duties for specified systems, providers and deployersAccountable and transparent AITransparency and explainability
Human oversightHuman review for important decisions involving peopleHuman oversight within AI governance and risk treatmentHuman oversight requirements for high-risk AI systemsHuman-AI configuration and oversightHuman agency and oversight
Privacy and data responsibilityUse AI systems in line with data protection lawData management and impact considerationsData governance and fundamental-rights safeguards in applicable casesPrivacy-enhanced AIPrivacy and data protection
Fairness and biasMonitor AI outputs for bias or discriminationRisk and impact assessmentFundamental-rights and data-governance requirements in applicable casesFairness with harmful bias managedFairness and non-discrimination
Security and safetyUse reasonable security and privacy safeguardsAI risk treatment and operational controlsAccuracy, robustness and cybersecurity duties for high-risk AISafe, secure and resilient AIRobustness, security and safety
Risk and harmKeep human oversight where automation could cause serious harmRisk assessment and treatment across the management systemRisk-management duties for high-risk AI systemsCore purpose of the frameworkRisk management throughout the AI lifecycle
AI literacy and workforceInform employees and provide training where appropriateCompetence, awareness and organisational rolesAI literacy obligation for providers and deployersGovernance, roles and organisational practiceCapacity-building and responsible stewardship
AccountabilityPublish a contact point for concerns about AI useLeadership, roles and management responsibilityDefined responsibilities for providers, deployers and other actorsAccountable and transparent AIAccountability
Environmental impactPrefer efficient computing and sustainable infrastructure where possibleEnvironmental impact within organisational context and impact assessmentEnvironmental information and considerations in specified parts of the ActBroader impacts on people, communities and the environmentSustainable development and environmental sustainability
Review and improvementRAIUC reviews the commitments as AI, regulation and good practice developPlan-Do-Check-Act and continual improvementPost-market monitoring and review in applicable casesContinuous risk monitoring and managementLifecycle risk management and ongoing stewardship
01

Transparency

RAIUC starting point
Disclose key AI uses and handle AI-generated content responsibly
ISO/IEC 42001 focus
Transparency, information and communication within the AI management system
EU AI Act focus
Transparency duties for specified systems, providers and deployers
NIST AI RMF focus
Accountable and transparent AI
OECD principle
Transparency and explainability
02

Human oversight

RAIUC starting point
Human review for important decisions involving people
ISO/IEC 42001 focus
Human oversight within AI governance and risk treatment
EU AI Act focus
Human oversight requirements for high-risk AI systems
NIST AI RMF focus
Human-AI configuration and oversight
OECD principle
Human agency and oversight
03

Privacy and data responsibility

RAIUC starting point
Use AI systems in line with data protection law
ISO/IEC 42001 focus
Data management and impact considerations
EU AI Act focus
Data governance and fundamental-rights safeguards in applicable cases
NIST AI RMF focus
Privacy-enhanced AI
OECD principle
Privacy and data protection
04

Fairness and bias

RAIUC starting point
Monitor AI outputs for bias or discrimination
ISO/IEC 42001 focus
Risk and impact assessment
EU AI Act focus
Fundamental-rights and data-governance requirements in applicable cases
NIST AI RMF focus
Fairness with harmful bias managed
OECD principle
Fairness and non-discrimination
05

Security and safety

RAIUC starting point
Use reasonable security and privacy safeguards
ISO/IEC 42001 focus
AI risk treatment and operational controls
EU AI Act focus
Accuracy, robustness and cybersecurity duties for high-risk AI
NIST AI RMF focus
Safe, secure and resilient AI
OECD principle
Robustness, security and safety
06

Risk and harm

RAIUC starting point
Keep human oversight where automation could cause serious harm
ISO/IEC 42001 focus
Risk assessment and treatment across the management system
EU AI Act focus
Risk-management duties for high-risk AI systems
NIST AI RMF focus
Core purpose of the framework
OECD principle
Risk management throughout the AI lifecycle
07

AI literacy and workforce

RAIUC starting point
Inform employees and provide training where appropriate
ISO/IEC 42001 focus
Competence, awareness and organisational roles
EU AI Act focus
AI literacy obligation for providers and deployers
NIST AI RMF focus
Governance, roles and organisational practice
OECD principle
Capacity-building and responsible stewardship
08

Accountability

RAIUC starting point
Publish a contact point for concerns about AI use
ISO/IEC 42001 focus
Leadership, roles and management responsibility
EU AI Act focus
Defined responsibilities for providers, deployers and other actors
NIST AI RMF focus
Accountable and transparent AI
OECD principle
Accountability
09

Environmental impact

RAIUC starting point
Prefer efficient computing and sustainable infrastructure where possible
ISO/IEC 42001 focus
Environmental impact within organisational context and impact assessment
EU AI Act focus
Environmental information and considerations in specified parts of the Act
NIST AI RMF focus
Broader impacts on people, communities and the environment
OECD principle
Sustainable development and environmental sustainability
10

Review and improvement

RAIUC starting point
RAIUC reviews the commitments as AI, regulation and good practice develop
ISO/IEC 42001 focus
Plan-Do-Check-Act and continual improvement
EU AI Act focus
Post-market monitoring and review in applicable cases
NIST AI RMF focus
Continuous risk monitoring and management
OECD principle
Lifecycle risk management and ongoing stewardship

This matrix highlights broad thematic relationships only. It is not a legal or technical crosswalk and should not be used to determine compliance or conformity with any law, framework or standard.

Different tools for different stages

Responsible AI governance does not have to begin with a complex compliance programme. The level of governance an organisation needs will depend on factors such as its size, activities, use of AI, risk profile, industry and legal obligations.

One way to think about the journey is as a series of stages.

  1. Start with responsible principles

    Understand the main responsibilities that come with using AI and establish clear expectations for how it should be used. RAIUC is designed to make this first step straightforward and accessible.

  2. Put those principles into practice

    Develop appropriate policies, provide guidance and training, identify where AI is being used, assign responsibilities and introduce proportionate safeguards. RAIUC provides practical resources intended to help organisations develop these areas.

  3. Introduce structured risk management

    As AI use becomes more important or complex, organisations may need more detailed assessment, documentation, monitoring, testing and risk management processes. Frameworks such as the NIST AI RMF can support a more structured approach.

  4. Address applicable regulation

    Organisations need to understand and meet the laws and regulations that apply to their activities, systems and jurisdictions. For organisations operating within its scope, this may include obligations under the EU AI Act.

  5. Consider a formal AI management system

    Organisations that require a comprehensive and internationally recognised management-system approach may decide to work towards ISO/IEC 42001. The responsible AI culture and working practices developed during the earlier stages can provide a useful foundation for that journey.

You do not have to start with complexity

Responsible AI governance should develop in proportion to an organisation's use of AI and the risks it faces.

RAIUC exists to make the starting point accessible. The 10 Responsible AI Commitments give organisations a practical way to begin, establish clear expectations and publicly demonstrate that responsible AI use matters to them.

For some organisations, that may be all they need at this stage. For others, it may become the first step towards more detailed risk management, regulatory compliance programmes and, eventually, a formal Artificial Intelligence Management System.

What matters is having somewhere practical to begin.

A practical first step

Start your responsible AI journey

RAIUC certification is free and declaration-based. By adopting the 10 Responsible AI Commitments, your organisation can establish a clear starting point for responsible AI use and publicly demonstrate its commitment to responsible practice.

No payment details required.

Get certified for free