Exam Room · AI Business Strategist

Flash Card: Four Frameworks, Four Different Questions

· 5 min read

AI for the Business · part of The Exam Room

These four get named in the same meeting, usually by four different people, and the argument that follows is about which question is on the table rather than which document is best. One is about the organisation, one about a system, one about proof, one about words.

AWS still describes responsible AI as eight dimensions, pairing privacy with security and veracity with robustness. The Lens separates those pairs and counts ten. Either list names the same ground.

The register of undeclared AI subscriptions in a firm that found forty-one of them in one expenses review hangs off CAF’s governance perspective; 42001 is what somebody proposes certifying against in a governance programme.

Flash card

Four references that blur together in an AI governance conversation, each answering a different question.

  1. The AWS Cloud Adoption Framework is the organisational instrument: six perspectives (business, people, governance, platform, security and operations) across four transformation phases (envision, align, launch and scale). It maps capability gaps across an organisation, not how one system was built.
  2. The Well-Architected Responsible AI Lens is the workload instrument, a custom lens for the Well-Architected Tool published in November 2025: ten responsible AI dimensions across eight focus areas of the machine learning lifecycle. Cite it for how one AI workload was designed, reviewed and run.
  3. ISO/IEC 42001 is the AI management system standard, 27001’s sibling, and it is certifiable: an accredited body audits the management system and issues a certificate. Cite it when a customer or regulator wants evidence of how AI is governed across the organisation. AWS holds one covering services including Amazon Bedrock, Amazon Textract and Amazon Transcribe; that does not certify your organisation.
  4. ISO/IEC 23053 is a framework and shared vocabulary for describing an AI system that uses machine learning. It is not a management system standard, so nothing is certified against it, and citing it as evidence of governance is the common mistake.
  5. The NIST AI Risk Management Framework gets named alongside these four and is not one of them: voluntary, non-certifiable, four functions (govern, map, measure and manage). ISO/IEC 42001 is the certifiable one.

Pick it when

Missing capability before we scale: AWS CAF. How this workload was built, reviewed and operated: the Responsible AI Lens. How AI is governed across the organisation, provably, to an outside party: ISO/IEC 42001. What we call the parts: ISO/IEC 23053.

It's the wrong answer when

CAF is wrong for a single workload’s design review; the Lens is wrong for an organisational readiness assessment. ISO/IEC 23053 is wrong whenever certification, audit or an assurance claim is in the sentence; 42001 is wrong when the need is common terminology. None of the four is a law. AWS says the Lens is not a compliance or assurance checklist, and a 42001 certificate shows that a management system exists and runs; neither tells you what the EU AI Act or a sector regulator requires.

These posts are LLM-aided. Backbone, original writing, and structure by Craig. Research and editing by Craig + LLM. Proof-reading by Craig.