Your Secure and Responsible Technology Partner

The Frameworks Meant to Unify Governance Are Fragmenting It

ISO tried to solve fragmentation and solved only part of it. Sector bodies are now adding frameworks on top. Each one is separately written, separately purchased, and separately audited, and the organization at the center is left holding pieces that were never designed to form one picture.

Governance is taking criticism right now, and some of it is earned. Programs that generate findings nobody can act on, intake forms that run forty questions before anyone has decided whether a use case matters, and review boards that meet monthly for decisions a practitioner could make in an afternoon have all contributed to a reputation the discipline now has to work against.

The burden is not evidence that the risk is small. It is evidence that the program was built to demonstrate diligence rather than to reduce exposure. Those produce very different artifacts, and only one of them costs the business a week of engineering time.

Compliance should function as an enabler. It tells a team what it can deploy and under what conditions, early enough that the answer shapes the architecture rather than undoing it. Organizations that treat governance as a gate at the end of delivery will generate deviations continuously, because the only way to move is around the gate.

The obstacle is fragmentation, and it operates at two levels. Inside the organization, functions assess their own segments and nobody holds the whole. Across the industry, the standards intended to fix that are themselves multiplying, and the way they are written and distributed makes assembling them harder than it should be.

Fragmentation Inside the Organization

Most enterprises already have governance. What they lack is one picture of it.

Security assesses the infrastructure. Privacy assesses the data flows. Legal assesses the contracts. An AI team assesses model performance. Each function produces a competent assessment of its own segment, and each one signs off. The failures then live in the space between them, where no function has ownership and no artifact records the gap.

Governance works like a puzzle. When the picture is complete, the missing pieces become visible; when the picture is assembled from four separate boards, nobody can tell whether a piece is missing or simply belongs to someone else. That is why organizations so often do not know their problems exist. The information is present somewhere in the enterprise, distributed across functions that never combine it.

This is a solvable problem. An organization can decide to assess against one lens covering cybersecurity, privacy, AI, and ethics together, and produce the functional views from that single assessment rather than the reverse. What makes it harder than it needs to be is that the external landscape is fragmenting at the same time.

Fragmentation Across the Standards Landscape

Consider an ordinary transaction chain in mortgage finance. A lender governs its AI under a mortgage-specific framework. Its loan origination vendor governs under the NIST AI Risk Management Framework. Its cloud provider certifies to ISO/IEC 42001. Its analytics partner in another regulated sector follows something else. If any participant operates in Europe, the EU AI Act’s harmonised standards apply on a separate timeline. If any operates in Colorado, Texas, California, or New York City, state and municipal AI law applies on yet another.

Every organization in that chain has done credible work. No participant holds the complete picture, and no participant can construct it, because the pieces were authored by different bodies for different scopes with different vocabularies and different access terms.

The gaps between those frameworks look exactly like the gaps between internal silos, and they fail the same way. The difference is that an organization can fix its internal silos by decision. It cannot fix the external landscape at all.

Two cases show how this happens, and neither involves anyone acting badly.

Case One: ISO Solved Part of the Problem and Stopped

ISO understood the fragmentation problem and built a mechanism for it. Management system standards share a Harmonized Structure, so clauses four through ten of ISO/IEC 42001 cover context, leadership, planning, support, operation, performance evaluation, and improvement in the same numbering and sequence as ISO/IEC 27001 and ISO 9001.¹ Annex D of ISO/IEC 42001 explicitly addresses integration with information security, privacy, quality, and sector standards.² Organizations that already hold ISO/IEC 27001 do find 42001 easier to implement as a result.

That is real engineering, and it deserves credit. It also stops well short of unification.

The Harmonized Structure aligns the scaffolding, not the risk picture. ISO/IEC 27001 carries 93 Annex A controls across four themes. ISO/IEC 42001 carries 38 controls across nine objectives numbered A.2 through A.10, covering AI policy, internal organization, resources, impact assessment, the AI life cycle, data, transparency, use, and third-party relationships.¹ Both use a Statement of Applicability to select controls against a risk assessment. Neither tells an organization how a finding in one resolves against a finding in the other, because the control sets were built to answer different questions.

The result in practice is multiple management systems rather than one. Separate scopes, separate Statements of Applicability, separate certification audits, separate surveillance cycles, and separate annual costs. An organization can hold both certificates and still lack a single view of its AI risk, which is the outcome unification was supposed to prevent.

The harmonization also stops at the ISO boundary. It offers nothing for the NIST AI RMF, nothing for the EU AI Act, nothing for state AI law, and nothing for any sector framework. Those crosswalks exist only where someone has built them, and building one requires reading both sides.

That brings in the second issue. ISO/IEC 42001:2023 sells for CHF 225 through the ISO store.³ The same standard also circulates under separate national and regional designations, each sold by a different body at a different price: CEN adopted it as EN ISO/IEC 42001:2026, which appears as BS ISO/IEC 42001:2026 in the United Kingdom and DIN EN ISO/IEC 42001 in Germany, with UK resale prices around £285 before VAT.⁴ The content is the same document. The purchasing decision is four different transactions depending on where an organization sits.

The purchase price is also the smallest number in the sequence. ISO/IEC 42006, which sets requirements for the bodies that audit and certify AI management systems, is a further paid document in the same stack.⁵ Certification itself runs into five and six figures once implementation, audit, and surveillance are counted. Published estimates from certification bodies and implementation consultancies vary widely and should be read as indicative rather than surveyed, but they commonly place small and mid-sized organizations somewhere between roughly fifteen thousand and eighty thousand dollars in year one, with complex scopes considerably higher.⁶

None of that is unreasonable on its own terms. Together it means the reference point most likely to serve as a common vocabulary for AI governance is one that a meaningful share of the ecosystem will never read, and that arrives under four different names depending on the reader’s jurisdiction.

Case Two: Sector Bodies Are Adding Frameworks on Top

On June 11, 2026, MISMO released the Framework for Responsible AI in the Mortgage Ecosystem, or FRAME, developed with its AI Community of Practice at the request of the Mortgage Bankers Association’s Residential Board of Governors.⁷ It incorporates the NIST AI RMF and narrows the focus to mortgage operations.⁸

The work is sound. FRAME includes a governance policy template, an AI system inventory, an AI system risk assessment, implementation guidance, and a getting started guide.⁷ Inventory appears first, which is correct. You cannot assess what you have not enumerated, and an organization that cannot list its deployed AI systems has no basis for any downstream analysis.

MISMO is explicit that FRAME creates no new regulatory obligations. Existing law already applies to lenders whether a decision is made by a person or influenced by an AI-enabled system, including ECOA, the Fair Housing Act, FCRA, GLBA, OCC guidance, and existing GSE requirements.⁸ The vendor-oversight emphasis is right as well, because most mortgage companies are not building models. They are consuming AI capabilities embedded inside loan origination systems, CRM platforms, servicing technology, and quality control tools.⁸ A lender that does not own the model still owns the outcome.

Sector specificity is genuinely valuable here. Mortgage lending has fair lending obligations, disparate impact exposure, and servicing requirements that generic guidance handles poorly, and translating broad standards into that context is work no international standard was going to do.

MBA’s Rick Hill framed the purpose in a single line: “Organizations cannot manage risk they cannot see.”⁷

I agree with that sentence completely, and it is the reason the distribution model matters. FRAME is available to MISMO member companies through MISMO Connect, the organization’s members-only site, with access included as a membership benefit.⁷

MISMO is a nonprofit operating on a member-funded model, and that model pays for the work. The point is not that any organization here is acting in bad faith. The point is what the combination produces.

What Access Does to Unification

Mapping requires reading both sides. That sentence carries the whole argument.

An organization cannot build a crosswalk between ISO/IEC 42001 and a sector framework unless it can read both. It cannot reconcile a vendor’s NIST-based attestation against a lender’s sector requirements unless both are legible to both parties. It cannot tell whether two controls are duplicates, complements, or contradictions without the text of each.

Now count the access terms across one transaction chain. NIST is free to anyone. ISO/IEC 42001 requires purchase, and understanding it well requires purchasing neighbors. The EU harmonised standards are still in draft and will be distributed through national bodies at national prices. A sector framework requires association membership. State AI law is public. Somewhere in that chain is a small vendor with a real obligation and access to exactly one of those documents.

That vendor is not going to build the crosswalk. Neither is the small lender, the regional servicer, or the two-person technology supplier whose product is embedded in someone’s origination workflow. Crosswalks get built by organizations large enough to buy every input, and everyone else operates on secondhand summaries and questionnaire transcription.

This is how fragmentation becomes structural rather than accidental. It is not only that the frameworks multiply. It is that the ability to reconcile them is distributed unevenly, and it correlates almost perfectly with the resources that already determine which organizations have decent governance.

The organizations best positioned to unify are the ones that least need help. The organizations where AI risk concentrates, because they are deploying vendor AI into consequential decisions without a compliance function, are the ones holding one document out of five.

The European Situation Compounds It

The EU AI Act relies on harmonised standards to give organizations a presumption of conformity with its high-risk requirements. CEN and CENELEC’s Joint Technical Committee 21 has been developing them under Commission standardisation request M/593, adopted in May 2023 with an original deadline of April 2025, then repealed and replaced by Amendment M/613 in June 2025 with the mandate running to February 2027.⁹ The committee missed the original deadline and agreed in October 2025 to accelerate, including allowing direct publication after a positive enquiry vote so that prioritized deliverables would be available by the fourth quarter of 2026.¹⁰ The Commission’s guidance says the first harmonised standards are expected in 2026, with citation in the Official Journal following a separate review.¹¹

Until that citation happens, no presumption of conformity attaches. Organizations are preparing for obligations whose implementing detail sits in draft, moves through national standards bodies, and carries a price when it arrives. JTC 21 brings together more than three hundred experts across five working groups from over twenty countries, which is a serious effort producing a serious output.¹² The difficulty is not the quality of the work. It is that another substantial framework is entering an already crowded picture, on a timeline organizations cannot plan against, through a channel not everyone can reach.

The Courts Have Been Narrowing This Ground

Access to standards that carry legal weight is not merely a policy preference. It has been litigated repeatedly, and the rulings run one direction.

In 2020, the Supreme Court held in Georgia v. Public.Resource.Org that the annotations in the Official Code of Georgia Annotated are ineligible for copyright, because under the government edicts doctrine legislators cannot be the authors of works produced in their official duties.¹³ Narrow in subject, broad in principle: no private party owns the law.

In 2023, the D.C. Circuit decided American Society for Testing and Materials v. Public.Resource.Org, holding that non-commercial dissemination of standards incorporated by reference into law constitutes fair use.¹⁴

In April 2026, the Third Circuit extended the reasoning further in American Society for Testing and Materials v. UpCodes, Inc. The court affirmed the denial of a preliminary injunction, finding UpCodes likely to succeed on a fair use defense because publishing incorporated standards makes the law freely accessible, a purpose distinct from ASTM’s own.¹⁵ Two features matter. UpCodes is a for-profit company rather than a nonprofit, which extends the doctrine beyond the Public Resource fact pattern. And the ruling is preliminary rather than final; the case continues, and many factual questions remain open on remand. The direction is clear even though the destination is not yet fixed.

Europe went further. On March 5, 2024, the Grand Chamber of the Court of Justice of the European Union decided Case C-588/21 P, Public.Resource.Org and Right to Know v Commission, holding that harmonised standards form part of EU law by virtue of their legal effects and that an overriding public interest requires their disclosure.¹⁶ The case began in 2018, when two nonprofits asked the Commission for access to harmonised standards on toy safety covering chemistry games and sets. The request was made under the EU regulation governing public access to Commission documents.¹⁷ The Commission refused on the grounds that disclosure would undermine commercial interests including intellectual property, and the General Court upheld that refusal in 2021.¹⁶ On appeal the Court of Justice set the judgment aside, reasoning that EU legislation confers legal effects on such standards, that a harmonised standard may therefore specify rights and obligations, and that citizens must be able to acquaint themselves with them.¹⁶ The Court grounded that in the rule of law and the principle of free access to the law.

None of these rulings reaches ISO/IEC 42001 or FRAME today. The doctrine attaches where a standard has been incorporated into law or carries legal effect, and neither currently occupies that position. The direction of travel is nonetheless clear, and AI standards are moving toward exactly that position through harmonised-standards regimes, examiner expectations, and certification practices that regulators come to treat as baseline.

The Counterargument, Taken Seriously

Standards organizations have a real answer, and it deserves to be stated properly.

Development costs money. Multi-year consensus processes involve hundreds of experts, staff coordination, translation, maintenance, and revision. Sales revenue and membership fees fund that work, and no alternative funding mechanism has emerged at scale.

There is a subtler risk as well. When the CJEU ruling landed, Small Business Standards, the European association representing SMEs in standardisation, welcomed the outcome while cautioning that it must not undermine SME participation in standards development.¹⁸ If free access reduces the revenue funding committee work, the organizations least able to fund participation independently may lose their seat at the table, and standards written without small-organization input tend to encode large-organization assumptions.

Access and sustainability are in genuine tension. It does not follow that the tension has been resolved correctly, or that every framework should default to the most restrictive posture available while the question is worked out.

Where the Line Sits

A workable test does not require solving standards economics. It requires distinguishing two categories of document.

Guidance that tells an organization what is expected of it should be readable by anyone the expectation touches. That includes governance policy expectations, inventory scope, and risk assessment criteria, because those are the terms on which a vendor, a partner, or a small participant will be judged. If a lender will hold its vendors to a standard, the vendor must be able to read the standard. If a certification is becoming a market expectation, the requirements behind it are approaching the status of rules.

Implementation assets that help an organization do the work faster are a defensible member benefit. Templates, tooling, worked examples, training, certification, and the community of practice around them carry real value a membership or purchase model can reasonably fund.

There is a third category worth naming. Crosswalks between frameworks should be public by default, whoever writes them. A mapping between ISO/IEC 42001 and the NIST AI RMF, or between a sector framework and the EU harmonised standards, is not a competitive asset. It is the connective tissue that lets an ecosystem hold one picture instead of six. Every crosswalk that stays proprietary is a place where fragmentation becomes permanent.

What Unification Actually Requires

Unified governance is not another control catalog stacked on the ones already in the building. It is a single operating picture into which every external requirement resolves as detail.

The ARISE Framework™ is built for that purpose, unifying cybersecurity, privacy, AI, and ethics into one lens rather than four assessments. It does not replace NIST or ISO requirements and is not a competitor to them; it maps to them, and to the regulatory regimes organizations satisfy in parallel, including the EU AI Act, California’s SB 53, the Colorado AI Act, the Texas AI Act, and New York City’s Local Law 144. Ethics sits inside that structure as a core tenet rather than an appendix, which matters because ethical failures in AI systems rarely announce themselves as ethical failures. They surface as a model performing differently across populations, or a data flow nobody scoped, and those are findings a unified assessment catches and a siloed one routes to the wrong desk.

FRAME’s mortgage-specific controls belong inside a picture like that. So do ISO/IEC 42001’s Annex A controls, and the harmonised standards when they arrive. None of them should require a parallel program, and an organization holding four programs has already lost the thread.

What Organizations Should Do

The practical response does not depend on how any standards body chooses to distribute its work.

Build the inventory first, and build it once. Every framework in this space starts with knowing what is deployed. An organization maintaining one authoritative AI system inventory can map it to ISO/IEC 42001, the NIST AI RMF, or a sector framework as needed. An organization maintaining three has three chances to be wrong.

Assess against one internal picture, then map outward. Run the assessment through a unified lens covering security, privacy, AI, and ethics together, then produce the sector-specific and regulator-specific views from it. The reverse order, where each external framework generates its own assessment, is how organizations end up with four sign-offs and no coverage.

Treat certification as an output, not a program. ISO/IEC 42001 certification should fall out of a governance program that already works. Organizations that build the program around the certificate get the certificate and little else.

Make expectations legible to vendors. Whatever governs internally, the requirements a vendor must meet should be stated in terms the vendor can read and build against without purchasing access to anything. This is within every organization’s control regardless of what any standards body decides.

Do not wait on harmonised standards. The European timeline has already moved once and citation in the Official Journal remains pending.⁹ ¹¹ Treating a deferred deadline as a reason to defer work converts a manageable engineering task into a discovery exercise conducted on a regulator’s timeline.

Upskill before writing policy. Most people deploying AI are not reckless; they are moving quickly with an incomplete picture of what the technology can reach and what it does when it fails. Give them that picture in language tied to their own systems, and a substantial share of risky decisions stop being made without a single new control.

Build feedback loops rather than review cycles. Point-in-time assessment is inadequate for technology that changes between assessments. Organizations need continuous understanding of an evolving risk profile, which means instrumenting for drift rather than scheduling another review.

The Standard Worth Holding

Frameworks are how an industry encodes what it has learned. That function only operates when the people who need the lesson can read it, and when the lessons fit together.

ISO built a real integration mechanism and it works within ISO. MISMO produced practical sector guidance through genuine collaboration. CEN and CENELEC are doing serious work under a difficult mandate. None of these organizations is at fault, and all of them face a funding problem with no clean answer.

What has changed is the stakes. AI governance guidance is not toy safety documentation. It sits between a technology moving faster than the institutions governing it and the organizations least equipped to catch up alone. Every additional framework written in a different vocabulary, priced on different terms, and distributed through a different channel makes the picture harder to assemble for exactly the organizations that most need it assembled.

Organizations cannot manage risk they cannot see. They also cannot unify what they are not permitted to read.


References

  1. ISO/IEC 42001:2023 structure and Annex A control set: 38 controls across nine objectives, A.2 through A.10; clauses 4 through 10 follow the ISO Harmonized Structure shared with ISO/IEC 27001 (93 Annex A controls across four themes) and ISO 9001.
  2. ISO/IEC 42001:2023, Annex D, on integrating an AI management system with information security, privacy, quality, and sector-specific management system standards.
  3. ISO/IEC 42001:2023, listed at CHF 225 through the ISO store.
  4. EN ISO/IEC 42001:2026, the CEN adoption of ISO/IEC 42001:2023, published nationally as BS ISO/IEC 42001:2026 (BSI) and DIN EN ISO/IEC 42001, 2026-08 (DIN Media); UK resale listed at £285 plus VAT.
  5. ISO/IEC 42006, “Requirements for bodies providing audit and certification of artificial intelligence management systems,” Edition 1, 2025.
  6. Published cost estimates for ISO/IEC 42001 certification from accredited certification bodies and implementation consultancies, 2026. These are provider estimates rather than survey data and vary widely; treat the ranges as indicative.
  7. MISMO, “MISMO Releases FRAME: Framework for AI Governance in Mortgage Lending,” June 11, 2026, distributed via the Mortgage Bankers Association newsroom.
  8. Vieaux, B., “The Mortgage Industry Needs Practical AI Governance, Not Just AI Ambition,” National Mortgage Professional and MBA NewsLink, May 2026.
  9. Commission Implementing Decision C(2023)3215 (standardisation request M/593), adopted May 22, 2023 with an original deadline of April 30, 2025, repealed and replaced by Commission Implementing Decision C(2025)3871 (M/613), adopted June 23, 2025; Article 4 repeals the earlier decision and Article 5 sets expiry at February 28, 2027.
  10. CEN-CENELEC, “Update on CEN and CENELEC’s Decision to Accelerate the Development of Standards for Artificial Intelligence,” October 23, 2025.
  11. European Commission, “Understanding the standardisation of the AI Act,” Shaping Europe’s Digital Future, updated 2026.
  12. CEN-CENELEC, Joint Technical Committee 21 on Artificial Intelligence, established June 1, 2021 with secretariat at Danish Standards; committee composition and scope.
  13. Georgia v. Public.Resource.Org, Inc., 590 U.S. 255 (2020).
  14. American Society for Testing and Materials v. Public.Resource.Org, Inc., 82 F.4th 1262 (D.C. Cir. 2023).
  15. American Society for Testing and Materials v. UpCodes, Inc., No. 24-2965 (3d Cir. Apr. 7, 2026) (Restrepo, J.), affirming denial of preliminary injunction; below, 752 F. Supp. 3d 480 (E.D. Pa. 2024).
  16. Court of Justice of the European Union (Grand Chamber), Case C-588/21 P, Public.Resource.Org Inc. and Right to Know CLG v European Commission, judgment of March 5, 2024, ECLI:EU:C:2024:201; CJEU Press Release No 41/24. Below: General Court, T-185/19, judgment of July 14, 2021.
  17. Regulation (EC) No 1049/2001 on public access to European Parliament, Council and Commission documents, the instrument under which access was sought in Case C-588/21 P.
  18. Small Business Standards, “SBS responds to European Court of Justice ruling on public access to harmonised standards,” March 6, 2024.