Understanding the relationship
NIST AI RMF & ISO/IEC 23894
Structural governance frameworks. They define what organisations should have in place: policies, processes, accountability structures, and measurement systems. They operate at scale, across sectors, and are rightly considered the gold standard for AI governance architecture.
Prime 7 & Drift Literacy
Human diagnostic frameworks. They identify what is happening to people when governance structures are in place but the human layer beneath them is failing quietly. They sit in the space NIST itself describes as requiring "further studies" and "future activities."
The relationship is additive, not competitive. An organisation can be fully NIST-compliant and still have invisible harm accumulating in its workforce, not because the framework has failed, but because that layer is explicitly outside its scope. Both standards acknowledge this in their own text, as shown below.
What NIST & ISO cover on human risk
NIST AI RMF: Human Risk Provisions
GOVERN 3.1: Diverse team requirement across all AI risk decisionsDemographic, disciplinary, and experiential diversity mandated throughout the lifecycle
GOVERN 4.1: Safety-first culture and critical thinking policyOrganisational practices to minimise negative impacts in design and deployment
Appendix C: Human-AI interaction limits acknowledgedCognitive bias, oversight complexity, and variation in human-AI teaming results
Three categories of AI bias named and definedSystemic, computational/statistical, and human-cognitive bias across the lifecycle
Affected communities distinguished from direct usersHarms extend to those who never interact with the system directly
ISO/IEC 23894: Human Risk Provisions
Principle (d) Inclusive: stakeholder dialogue on harms and benefitsDiverse internal and external groups must be engaged throughout risk management
Principle (g) Human and cultural factorsOrganisations must monitor the human and cultural landscape for societal impacts
Leadership commitment to visible, communicated accountabilityStakeholder confidence requires demonstrated commitment to AI risk management
Stakeholders help define fairness criteria and identify biasWhat constitutes bias in a working system is a human and social judgement
Dynamic risk management: AI systems adapt and evolveOngoing monitoring required; historical data is limited in a fast-moving field
Where NIST and ISO call for further work, in their own words
NIST AI 100-1 · §1.2.4 · Organisational integration
"Use of the AI RMF alone will not lead to these changes or provide the appropriate incentives. Effective risk management is realized through organizational commitment at senior levels and may require cultural change."
NIST AI 100-1 · Appendix C · Human empowerment
"The degree to which humans are empowered and incentivized to challenge AI system output requires further studies. Data about the frequency and rationale with which humans overrule AI system output in deployed systems may be useful to collect and analyze."
NIST AI 100-1 · Appendix C · Context and human phenomena
"Representing complex human phenomena with mathematical models can come at the cost of removing necessary context. This loss of context may in turn make it difficult to understand individual and societal impacts that are key to AI risk management efforts."
NIST AI 100-1 · §1.2.1 · Measurement limits
"AI risks or failures that are not well-defined or adequately understood are difficult to measure quantitatively or qualitatively. The inability to appropriately measure AI risks does not imply that an AI system necessarily poses either a high or low risk."
Five areas where Prime 7 and Drift Literacy extend the frameworks into practice
| Area |
What NIST / ISO provide |
Where further work is called for |
Prime 7 / Drift Literacy contribution |
Harm to staff who are still performing Prime 7 |
NIST names psychological harm to individuals. MEASURE tracks performance metrics and trustworthiness indicators. |
No instrument exists for harm to a person whose metrics remain green. Invisible suffering and compliant performance can coexist; this is structural, not an oversight. |
Invisible Suffering names the mechanism: erosion of professional identity beneath a functional performance signal. Gives practitioners language and observable signs for what dashboards cannot show. |
Erasure of expert knowledge Prime 7 |
NIST names human-cognitive bias. ISO calls for stakeholders to help identify bias. Both assume expert knowledge remains present in decision chains. |
Neither addresses the structural removal of expertise by the architecture of the AI system itself, not through intent, but through design. |
Epistemic Violence provides a forensic name, a signal set, and a business risk classification. Extends beyond "bias" into the structural erasure of institutional knowledge. |
Erosion of collective understanding Prime 7 |
NIST requires feedback loops and diverse teams. ISO requires stakeholder dialogue. Both assume channels, once built, continue to carry meaningful signal. |
Neither addresses the gradual erosion of an organisation's collective interpretive capacity as AI narrows inputs over time. |
Distributed Sensemaking Loss names this: leaders surprised by crises frontline staff saw months earlier. A governance and escalation failure with direct legal implications. |
Expertise pipeline destruction Prime 7 |
NIST acknowledges negative economic impacts on individuals. ISO lists employment under human and cultural factors. |
Neither asks who absorbs the cost of displacement, or what happens to senior capability when entry-level roles that build it are eliminated. |
Economic Displacement reframes this from job loss to pipeline destruction. Actionable at board level for workforce planning and industrial relations strategy. |
Human recovery capacity Drift Literacy |
NIST addresses system recovery controls and human oversight roles. ISO includes human factors as a risk principle throughout the lifecycle. |
Neither framework has a concept of human recovery time: what people need to return to effective judgement after cognitive or ethical stress. No human equivalent of mean time to repair. |
Time to Human Repair (TTHR) is a calibrated, role-sensitive recovery index grounded in recovery science. Fills a complete blank in both frameworks' operational toolkits. |
In plain terms
What Prime 7 and Drift Literacy are not
A challenge to NIST or ISO: they operate at a different layer entirely
A replacement for compliance architecture: organisations still need both standards
Entirely new discoveries: the contribution is synthesis, reframing, and practitioner-level diagnostic tools
Exaggeration: every gap above is referenced within NIST's own text as unresolved or deferred to future work
What they genuinely contribute
Forensic vocabulary for harms NIST acknowledges but cannot name or measure in practice
Operational diagnostics for the human layer NIST explicitly defers to further research
A detection toolkit for leaders who are governance-compliant but still blind to ground-level harm
TTHR: a human recovery metric with no equivalent in either governance standard
Harm categories with legal and IR relevance that neither framework currently names
Take the next step
See how prepared your organisation really is for AI adoption.
Book an AI Workforce & Governance Review to identify risks related to workforce readiness, governance
implementation, leadership confidence, and human factors across your existing AI programme.
Book an AI Workforce & Governance Review