Our ISO credential demonstrates our commitment to quality standards for our overall Responsible AI governance program. Our NIST AI RMF attestation validates our leading risk-based approach to AI governance. The concepts of quality and risk of AI systems are not mutually exclusive, in fact they are inherently linked. Our effort at Workday is to maintain, and continuously improve upon, an RAI governance program that is robust and industry-leading. As such, we choose to hold ourselves accountable to the highest and most comprehensive standards available today.
What Are NIST AI RMF and ISO 42001?
The US-based National Institute of Standards and Technology (NIST) AI Risk Management Framework (AI RMF) is a voluntary risk management framework directed by Congress that provides a how-to guide for organizations of all sizes, industries, and geographies to develop and deploy trustworthy AI. The NIST AI RMF was developed through a multi-stakeholder process in collaboration with civil society, academia, and industry. Workday was an early champion of its creation, providing technical expertise throughout its development, and was featured as NIST’s first-ever case study highlighting industry adoption of the framework.
The Swiss-headquartered International Organization for Standardization (ISO) is a leading global standards development organization that provides foundational technical standards underpinning widely-adopted privacy and cybersecurity certifications. Over the past decade, Workday has demonstrated our commitment to leadership in these areas by obtaining multiple ISO certifications, including ISO 27001, ISO 27017, and ISO 27018. ISO 42001 is a technical standard that “specifies requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System (AIMS) within organizations,” designed for entities that both develop and deploy AI products and services. Like other voluntary consensus technical standards, ISO 42001 was developed in collaboration with stakeholders from across industry, civil society, academia, and government, and reflects a widely-agreed upon approach for AI risk management.
NIST and the ISO are leading organizations, widely respected for technical standards and measurement science. Workday is proud to demonstrate our alignment to each as it relates to our Responsible AI program. NIST has developed a crosswalk between its RMF and the 42001 ISO Standard, which can be accessed and reviewed here. See below for Workday’s condensed version, highlighting areas of overlap and differences.