Responsible AI frameworks hiring managers expect you to know
A working summary of the EU AI Act, ISO/IEC 42001, the NIST AI Risk Management Framework and the UK approach, written for people preparing for AI governance interviews.
You will not be asked to recite a regulation at interview. You may well be asked which frameworks you have worked with and how you would choose between them. This guide gives a working summary of the four that appear most often in job descriptions.
EU AI Act
The EU’s Artificial Intelligence Act is a regulation that sorts AI systems by risk. A small number of practices are prohibited. Systems classed as high-risk, such as those used in recruitment, credit decisions or essential services, carry the heaviest obligations, covering risk management, data quality, documentation, human oversight and accuracy. There are separate duties for providers of general-purpose AI models and transparency rules for certain other uses.
The Act entered into force in August 2024 and applies in stages over several years. The timetable for some obligations has been subject to proposed changes, so check the current position with the European Commission before relying on a date. It can apply to organisations outside the EU whose systems are placed on the EU market or whose output is used there, which is why UK employers ask about it.
ISO/IEC 42001
ISO/IEC 42001 is an international standard for an AI management system. If you know ISO/IEC 27001 for information security, the structure will be familiar: policy, roles, risk assessment, controls, monitoring and continual improvement. Organisations can be certified against it. It tells you how to run governance, and leaves the organisation to decide what its own acceptable level of risk is.
NIST AI Risk Management Framework
Published by the US National Institute of Standards and Technology, the AI RMF is voluntary guidance organised around four functions: govern, map, measure and manage. It is widely used as a practical reference, including in the UK, because it is free, detailed and comes with a playbook of suggested actions.
The UK approach
The UK has not passed a single AI law. Its approach asks existing regulators to apply five cross-sector principles within their own remits: safety, security and robustness; transparency and explainability; fairness; accountability and governance; and contestability and redress. In practice, this means AI governance work in the UK draws on data protection law, equality law, consumer protection and sector rules, together with guidance from the relevant regulators.
Data protection remains central. UK GDPR applies whenever personal data is used to train or run a system, and the rules on automated decision-making were amended by the Data (Use and Access) Act 2025.
How they fit together
- The EU AI Act sets legal requirements for particular systems.
- ISO/IEC 42001 gives you an auditable way to organise governance.
- The NIST AI RMF offers practical detail on identifying and treating risk.
- UK regulators’ guidance tells you how existing law applies to AI in a given sector.
A good interview answer explains which of these you used, why it suited the organisation, and what you would do differently next time.
This guide is a general summary for career purposes. It does not constitute legal advice.