AI governance · NIST
NIST AI Risk Management Framework 1.0
Govern, map, measure and manage AI risk, including the AI your staff already use without asking.
Who it applies to
The businesses that carry NIST AI RMF, and the pages written for them.
Each industry page names the regulation, the obligation and the clock, tells the story of an owner in that trade, and shows what we protect for them.
Which packages satisfy it
Cyber and Data Protection Assessment
Any business of 10 to 500 people that has never had a real assessment, or has not had one in a year
SOC 2 Readiness: Type 1 and Type 2
SaaS, AI and technology companies of 5 to 300 people, and professional firms whose clients require it
Practice Cybersecurity, Data Protection and HIPAA Package
Medical and dental practices, clinics, surgery centers, hospital departments and the business associates that serve them
What it asks for
In plain English, what NIST AI RMF expects you to have in place.
- An AI inventoryEvery model, tool and vendor service in use, including the ones staff adopted without asking.
- GovernanceWho owns AI risk, a policy for acceptable use, and a review path before a new use goes live.
- Risk mappingFor each use: what data goes in, who is affected, what could go wrong and how you would know.
- MeasurementTesting for accuracy, bias, security and drift, with results recorded.
- Human oversightA person who can intervene, and a way for affected people to question a decision.
- Transparency and recordsDocumentation of the system, its limits and its training or supplier lineage, kept current.
A note on authority: the regulator, auditor or certifying body has the final say on whether you comply. We help interpret the requirements, scope what applies, gap-assess against what is published today, and keep you compliance-ready and secure as the guidance evolves. We hold no regulatory authority and do not certify.
Questions we get about NIST AI RMF
Do you certify NIST AI RMF compliance?
Where do we start with NIST AI RMF?
We also need other frameworks. Do we do NIST AI RMF separately?
Also in ai governance: ISO 42001 · every framework by industry
Next step
Thirty minutes, an engineer, a written scope for NIST AI RMF.
Book the demo and see how one control set carries NIST AI RMF and everything else you owe. Or leave your details and an engineer replies within one business day.