Four AI Frameworks Landed on Your Desk. They Are Not Competing.
Four documents arrive inside a quarter and every one appears to govern AI. The instinct is to compare them and pick one. Two weeks later the comparison is a four-column spreadsheet, no AI system is named in any row, and nobody has decided which one the program answers to.
Four documents, four different questions
They arrive from four directions. SAIL 2.0 comes in from an engineering lead who went looking. The NIST AI Risk Management Framework comes down from a board that wants the risk in terms it can hold. ISO/IEC 42001 turns up inside a customer's procurement questionnaire. The EU AI Act arrives from counsel.
Read side by side they look like four attempts at the same document. Each contains something that amounts to an inventory, and something that amounts to a risk assessment. Each expects a named person accountable for the outcome. So the reasonable conclusion is that one of them must be the best one, and that conclusion sends a small team into a comparison nobody can act on.
They answer different questions, and each answer is a different kind of thing.
- SAIL 2.0, the Secure AI Lifecycle Framework, answers how an AI system gets built and operated, phase by phase, so a finding lands on the team working in that phase. CWS contributed to it and anchors delivery on it.
- The NIST AI Risk Management Framework answers how to describe and organize the risk work. It is voluntary, and its four core functions are GOVERN, MAP, MEASURE and MANAGE. What it gives you is a structure and a vocabulary that carry weight outside the security team.
- ISO/IEC 42001 answers how to demonstrate to an outside party that a management system for AI exists and runs. It is certifiable, it carries a set of Annex A controls, and certification requires a defined scope for that management system. CWS writes the scope so that it names the AI systems and the parts of the organization inside the boundary, which is a bar CWS sets above what the clause itself asks for.
- The EU AI Act answers what the law requires. Obligations are tiered by the risk a system presents, they attach differently depending on the role your organization occupies in relation to that system, and application is phased. Every specific belongs to your counsel, and the specifics stay out of this article deliberately.
They ask your estate the same questions
The overlap is real and it sits underneath all four. Every one of them needs to know which AI systems exist, who owns each of them, what data each one touches, what it is used to decide, and what happens when the output is wrong. That is the same evidence, gathered four times by four groups who then compare notes and disagree.
That is why the comparison exercise feels productive and then stalls. You are reading four descriptions of the same facts about your own estate. The redundancy lives in what these documents consume. What they produce diverges: engineering work, a risk narrative a board can follow, a certificate, and a legal determination.
So the thing to organize is the evidence. Get one register right and the four become four readings of it. A row has to carry enough to support all four.
- The system, named, with an owner who has a job title and a manager
- What it is used to decide or produce, and who is affected when it gets that wrong
- The data classes it touches, and whether any of them leave the organization
- Whether you built it, bought it, or inherited it inside a product you already ran
- Where it sits in its own lifecycle, because the phase decides which controls apply to it at all
One set of facts about the estate, read four ways. The alternative is four teams collecting the same evidence and disagreeing about it by the second quarter.
Which one anchors the program
One of the four has to anchor the work. The anchor is the framework whose structure the register uses and whose stage or function names the gap list is filed under. The other three become views produced from that register.
The choice follows from whatever forced the program to exist, because that is also what will fund it and judge it a year from now.
Which of the four anchors the program is a choice, and CWS makes it the same way every time. Treat the rule below as a recommendation. All four leave the decision open.
- Engineering is already shipping AI features and the exposure sits in how systems get built. Anchor on the lifecycle, because a gap filed against a phase arrives at a team that recognizes the phase it is working in.
- A customer contract or a procurement questionnaire is asking for a certificate. Anchor on ISO/IEC 42001, because the scope boundary and third-party certification impose constraints that everything else then fits inside.
- The board wants to understand what is being managed and in what terms. The AI RMF functions give you that frame. In our view it works best sitting over one of the other two: the functions give the conversation its shape, and the evidence it runs on comes from the register underneath.
- The EU AI Act sits outside this choice. It states what has to be true of systems in certain roles and tiers, and it leaves the organizing of the work to whichever of the other three you pick. The determinations it turns on are legal ones. The security team prepares the input. Counsel makes the call.
The anchor is the framework your findings get filed under. Everything else is a reading of the same file.
One program, four readings
CWS works from all four in delivery. That comes down to one assessment, one register, one gap list, and four views generated from them, each written for the person who asked the question.
The lifecycle view goes to engineering, because it says what to change and where in the build. The AI RMF view goes to the board, because the four functions give the work a shape a non-specialist can carry into a meeting. The ISO/IEC 42001 view goes to whoever is preparing for certification. The role and tier determination goes to counsel as a scoping input for them to confirm.
Generating four views from one register takes discipline about what the register holds. The register stays the single record, and every view is regenerated from it each time it is needed. A gap is written once, with one owner and one position in the sequence, and the four views reference it. That costs far less calendar time than four assessments, and it removes the failure that eats these programs: two documents describing the same system with different facts in them.
Where these programs lose the thread
Five failure modes follow from the shape of the problem: four documents landing on desks that report to different people.
- Four workstreams with four owners, each collecting its own evidence. By the second quarter the four descriptions of the estate disagree, and the disagreement surfaces in front of an auditor.
- A control-to-control crosswalk built between all four before a single system has been examined. The crosswalk is real work and it earns its place once there is something to map.
- A board deck that names all four while no system has been assessed under any of them. It survives one meeting.
- The legal question handled as a framework question. Role and tier carry legal consequences, and a security team that settles them informally has created an exposure of its own.
- The program stalled waiting for the anchor decision. The register is worth building under any of the four, because the facts it holds are the same facts.
Settle the anchor before the first assessment
Each of these documents was written to be read on its own, by an audience that cares about one question. How they sit together inside a single program is the part every organization works out for itself.
The ordering above is a position CWS argues, formed from working against all four, and someone reasonable could put them in a different order. The mechanics are harder to argue with. One register, one gap list, four views, and one framework the program answers to.
Picking the anchor is a short conversation once somebody says out loud what forced the program to exist. It is an expensive one to reopen after months of findings have been filed under a structure. Settle these five before anybody starts.
- Which framework the register and the gap list are structured by
- Who receives each of the four views, by name and by role
- Whether certification is a goal inside the next year
- Who makes the legal determinations, what the security team owes them, and by when
- What is out of scope, written down first, so the first review reads it as a decision
An anchor chosen in an hour costs an hour. An anchor changed after two quarters of filings costs the filings.