"What compliance framework do we need?" usually gets answered by whoever is asking you for it, a customer's security questionnaire, an enterprise procurement team, or a regulator. Three names come up most often for teams running AI agents: ISO 42001, NIST AI RMF, and SOC 2. They're not interchangeable, and they're not competing with each other, they answer different questions.
ISO 42001: do you manage AI responsibly, as an organization?
ISO/IEC 42001 is a certifiable standard for an AI management system, the organizational processes around how you develop, deploy, and monitor AI systems. It's closer in spirit to ISO 27001 for information security than to a technical checklist: an external auditor can certify that your organization has the governance processes ISO 42001 requires. Enterprise customers increasingly ask for this certification the same way they ask for SOC 2, as a signal that AI risk is being managed, not improvised.
NIST AI RMF: a risk framework, not a certification
The NIST AI Risk Management Framework is voluntary guidance from the U.S. National Institute of Standards and Technology. There's nothing to get "certified" against, it's a structured way to think about identifying, measuring, and managing AI risk (organized around functions like Govern, Map, Measure, and Manage). U.S. government contractors and vendors selling into regulated U.S. industries encounter this one most, either directly or because a customer has adopted it internally.
SOC 2: does your service organization have good controls?
SOC 2 predates the current wave of AI regulation, it's a general trust-services audit (security, availability, confidentiality, and related criteria) that most B2B SaaS companies already encounter in vendor security reviews. It's not AI-specific, but if your AI agent touches customer data or makes decisions inside a product you sell to other businesses, your SOC 2 auditor will ask about it, because agent behavior is now part of your service's control environment.
Where audit logs fit into all three
Every one of these frameworks, in different language, asks the same underlying question about an AI system: can you show what it actually did, and can you show that record is trustworthy? ISO 42001 asks it as part of operational monitoring. NIST AI RMF asks it under the Measure and Manage functions. SOC 2 asks it as part of your logging and monitoring controls. A single tamper-evident record of agent actions, mapped against each framework's specific requirements, is what turns "we think the agent behaved correctly" into something an auditor can check.
Picking one
In practice, the framework you need is usually the one your customer, investor, or regulator is asking about, not the one that sounds most rigorous. If nobody's asked yet, start with whichever is native to your market: SOC 2 for U.S. B2B SaaS, ISO 42001 for anyone selling into Europe or dealing with enterprise procurement globally, NIST AI RMF if you sell to U.S. government or regulated industries.