By HumanAudit Inc. editorial teamLast reviewed 5 August 2026
VerifiedLast reviewed 5 August 2026 by the HumanAudit Inc. editorial team.Corrections logEditorial policy
On this page
  1. NHI vs IGA vs PAM vs ITDR
  2. Where the overlap causes real failures
  3. ISO 42001 vs NIST AI RMF vs EU AI Act
  4. Which to anchor to
  5. FAQ

NHI vs IGA vs PAM vs ITDR

These four are not competitors, and treating them as such is how coverage gaps form. Each was designed around a different primitive.

DisciplineDesigned aroundCore questionCovers NHIs?Blind spot
IGA
Identity governance and administration
The human joiner-mover-leaver lifecycleShould this person still have this access?Partially. Access-review concepts extend; the lifecycle model does not, because NHIs have no HR recordScale and primitives. Reviewing 100,000 machine identities through processes built for 1,000 humans does not work
PAM
Privileged access management
The privileged sessionWho used this elevated account, and what did they do?Yes, for privileged service accounts. Genuinely deep hereSaaS-to-SaaS OAuth grants, CI/CD tokens, cloud workload identities, agent credentials. None of which are sessions
ITDR
Identity threat detection and response
Anomalous identity behaviourIs this identity being abused right now?Increasingly yes, as a detection layerDetection is not governance. It tells you an identity is behaving oddly, not whether it should have existed
NHI governanceThe non-human credential and its ownerShould this identity exist, who owns it, and what may it reach?By definitionMaturity. The discipline is young, the tooling consolidated in 2026, and the vocabulary is still unsettled

Where the overlap causes real failures

  • "Our PAM covers this." The most common and most expensive assumption. PAM covers privileged accounts, typically well. The Salesloft/Drift pattern, a third-party OAuth integration with broad scope, is invisible to it.
  • "Access reviews already cover it." They cover the human population the review was scoped to. Extending scope is a configuration decision nobody has made.
  • "ITDR will catch it." Detection assumes a baseline. An over-privileged service account behaving exactly as configured produces no anomaly, right up until an attacker uses it exactly as configured.
  • Ownership falls between teams. IGA sits with identity, PAM with security operations, ITDR with the SOC, and NHIs with nobody. This is the single most reliable predictor of a stalled programme.

ISO/IEC 42001 vs NIST AI RMF vs EU AI Act

ISO/IEC 42001NIST AI RMF 1.0EU AI Act
TypeManagement system standardVoluntary risk frameworkRegulation, legally binding
StatusRatified 2023, certifiablePublished Jan 2023, not certifiableIn force, phased application
Obliges you toOperate and evidence an AI management systemNothing. It is guidance you elect to followMeet specific obligations if you place or use in-scope AI in the EU
Key dates, , Art. 5 prohibitions 2 Feb 2025 · GPAI 2 Aug 2025 · Annex III high-risk 2 Dec 2027 · Annex I 2 Aug 2028
Says about NHINothing by name; evidence lands in clauses 6.1, 8.1, 9.1, 10Nothing by name; Govern and Measure functions imply itNothing by name; logging and human-oversight duties require it
Best used asThe operating spine and the certifiable proof pointRisk vocabulary and a structure for the risk registerThe obligation set that defines what must be evidenced

None of the three mentions non-human identity. All three effectively require it, because each demands that you can say what an AI system did and under whose authority. That gap between what the frameworks say and what they require is the reason this site exists.

Which to anchor to

  1. If you sell into enterprises or the EU: anchor on ISO/IEC 42001. It is the only certifiable option, and certification is the artefact procurement teams actually ask for. See ISO/IEC 42001 and NHI.
  2. If you are US-based and not EU-exposed: anchor on NIST AI RMF for vocabulary, and use 42001's management-system structure even without certifying. The structure is the valuable part.
  3. If you have EU exposure: the AI Act defines the floor regardless of what else you adopt. The Digital Omnibus deferred the high-risk dates; it did not remove the obligations, and the co-legislators were explicit that preparation should already be under way.
  4. In all cases, the evidence machinery is the same. Inventory, ownership, bounded credentials, delegation logging, tested revocation. Build once, map to whichever framework the buyer or regulator asks about.

Frequently asked questions

What is the difference between NHI governance and IGA?

IGA was designed around the human joiner-mover-leaver lifecycle, driven by an HR record. Non-human identities have no HR record, no manager and no leaving date, so the lifecycle model does not extend even though access-review concepts do. The other difference is scale: reviewing 100,000 machine identities through processes designed for 1,000 humans does not work operationally.

Does PAM cover non-human identities?

Partially and deeply, for privileged service accounts, particularly in regulated on-premise environments. PAM was designed around the privileged session, so it does not natively cover SaaS-to-SaaS OAuth grants, CI/CD pipeline tokens, cloud workload identities or AI agent credentials, none of which are sessions. Assuming PAM coverage is one of the most common gaps found in assessments.

Should we adopt ISO 42001 or the NIST AI RMF?

ISO/IEC 42001 if you need a certifiable artefact, which is what enterprise procurement and EU-exposed buyers ask for. The NIST AI RMF is valuable as risk vocabulary and as a structure for the risk register but is voluntary and not certifiable. Many organisations use both: NIST language inside a 42001 management system.

Do any AI governance frameworks mention non-human identity?

None of ISO/IEC 42001, the NIST AI RMF or the EU AI Act uses the term. All three effectively require it, because each demands that you can demonstrate what an AI system did and under whose authority, which is not answerable without identity, ownership and delegation records.

Deciding which framework to anchor to?

A free 18-question assessment scores your ISO 42001 documentation position in about two minutes, and a free classifier maps your systems against the AI Act.

Score your documentation

Assess your own NHI programme.

Run the free maturity assessment or the OWASP NHI Top 10 self-audit, get your score in the browser, and unlock the full written report.