Home All services
Start a project → Call Now

NIST AI RMF consulting and gap assessment

Know where you stand against the NIST AI RMF — and how you'll close the gap.

Nobody certifies companies against the NIST AI Risk Management Framework (AI RMF), not even NIST. It gives you a Profile instead: where you stand now (Current), where you've decided to be (Target), and the gap between. We build both, plus an index of the evidence behind each answer, so they hold up in a customer's security review.

  • All 72 subcategories scored
  • An owner and a date on every gap
  • No certificate, because none exists
  • NIST AI 100-1
  • NIST AI 600-1
  • ISO/IEC 42001 crosswalk
Illustration: four glass tiles around an AI core, showing a compass, a map pin, a ruler and a steering wheel, joined by a glowing looping path that ends at a neat profile document

In brief

What it is
Help aligning with the NIST AI RMF, a voluntary US framework for AI risk. We score you on its 72 subcategories (the outcomes it describes) and help set your target.
Why it matters
No law requires it, but enterprise security questionnaires ask which AI risk framework you follow. A scored Profile is your answer.
What you get
A Current Profile, a Target Profile you sign, and a ranked gap register with an owner and date per line, tied to an evidence index.

The deliverable

No one can certify you, so you measure against your own target.

The framework document, NIST AI 100-1, defines three kinds of Profile in Section 6: use-case, cross-sectoral and temporal. NIST AI 600-1, the Generative AI Profile, is a cross-sectoral one. The temporal kind, a "now" and a "target" pair, matters here:

  • Current Profile. How you handle each subcategory today, with evidence or an honest blank.
  • Target Profile. Where you've decided to be: a risk appetite decision (how much risk you accept), not a technical one.
  • The gap between them. Ranked and owned. This is the deliverable; everything else supports it.

Unsure which framework fits? See AI governance.

What you end up with

Every artifact, who produces it and who signs it.

Testing runs alongside the governance work.

  1. AI system inventory

    Every AI system and use case, with build-or-buy, model access level and data sensitivity on each row. Allow extra time: this is where you settle what counts as an AI system.

  2. Current Profile

    All 72 subcategories, GOVERN 1.1 to MANAGE 4.3, each with an evidence reference or a stated gap.

  3. Target Profile and gap register

    Each gap between the target and your Current Profile gets a rank, an owner and a date.

  4. Your Generative AI Profile

    AI 600-1 applied to you, with a written ruling on each of its 12 risks, including those you rule out. A matrix maps each applicable action, by ID (GV-1.1-001 format), to a control, evidence, owner and status.

  5. Testing, incident and supplier procedures

    We write a TEVV plan (test, evaluation, verification and validation) for each MEASURE subcategory, and three procedures that follow AI 600-1's appendices: a pre-deployment testing protocol (A.1.4); AI incident response and disclosure (A.1.8), folded into your existing incident response plan; and supplier vetting with an AI supplier questionnaire (A.1.3). We can run the protocol's prompt-injection, jailbreak and data-leakage tests as LLM security testing; open-ended adversarial exercises go to a provider you appoint. Only calling AI through APIs? Then most of your AI 600-1 work is supplier vetting: see AI vendor risk.

  6. Charter and Statement of Alignment

    A charter naming the accountable owner, review board and decision rights, and a Statement of Alignment (a management self-attestation) with its evidence index. No outside auditor will make you close the gaps, so we write a dated internal review into the statement of work.

Where AI 600-1 stops

The Generative AI Profile covers only 49 of the 72 subcategories, so we score all 72.

NIST AI 600-1, published 26 July 2024, names 12 generative-AI risks and 212 suggested actions, and NIST says not every subcategory is included. Build from it alone and 23 subcategories get no actions, yet a questionnaire about the AI RMF means all 72.

Two functions need extra care. NIST draws Govern in the middle because it runs through the other three functions, which aren't strictly sequential either. Close it out in month two and nobody is obliged to act on the test results. Measure holds 22 subcategories and 72 of the 212 actions, and needs real testing, not documents. With no auditor forcing it, it's usually cut first.

The AI RMF core: 72 subcategories in 19 categories.
FunctionSubcategoriesWith AI 600-1 actions
Govern1915
Map189
Measure2216
Manage139
All four7249

Where these programs go wrong

Four mistakes you can check for in an afternoon.

Each misreads NIST's own documents. Open one to see what they actually say.

Quoting 13 risks instead of 12

NIST's generative-AI working-group page still says 13 risks and more than 400 actions. That matches nothing you can download: the April 2024 initial public draft had 12 risks and 466 Action IDs, and the final July 2024 publication has 12 and 212.

Assuming the Generative AI Profile died with US Executive Order (EO) 14110

AI 600-1 was produced under EO 14110, which EO 14148 revoked on 20 January 2025; EO 14179 followed three days later as the replacement policy. NIST never withdrew the profile. Its publication page, refreshed on 8 April 2026, still shows it as current.

Waiting for AI RMF 2.0

America's AI Action Plan asked NIST to revise the framework and remove references to misinformation, diversity, equity and inclusion, and climate change, the themes behind three of the 12 generative-AI risk labels. The AI RMF Development page lists no milestone after March 2023.

Treating the Playbook as rules

The AI RMF Playbook, first completed on 30 March 2023, is voluntary companion material with illustrative suggestions. Map controls one-to-one against it and you'll defend choices NIST never asked you to make.

Scope and limits

Need a certificate? Then this is the wrong framework, and we'll say so.

ISO/IEC 42001 is the certifiable one: an accredited certification body audits you and issues a certificate, with a validity period and surveillance audits behind it.

Heading there? We map your Profile against it and list the gaps, starting from the AI RMF crosswalk (a mapping) on airc.nist.gov. That maps to the final draft, ISO/IEC FDIS 42001, and carries NIST's non-endorsement note, so we re-check each clause against the published 2023 standard.

The EU AI Act is law, with risk-tier obligations and penalties; the AI RMF has neither. Doing the AI RMF well doesn't make you AI Act compliant, though much of the evidence carries across.

What we won't do

  • No audit opinions. A self-attestation, including the Statement of Alignment, is never presented as one.
  • No full program for one shared chatbot account. That needs an acceptable use policy and an inventory.
  • No promised date for a revised AI RMF, no federal-mandate claim. The FAQ explains both.
  • No on-site work. Every engagement runs remotely from India.

We are not a certification body or an accredited auditor. We issue no certificates, marks or seals, and we're not ISO 27001 certified ourselves. For other standards, see GRC and compliance.

FAQ

Questions about NIST AI RMF consulting.

For anything else, ask us directly.

No, and neither can anyone else. NIST runs no certification scheme, accredits no assessors and recognizes no certificate against the AI RMF, so a "NIST AI RMF Certified" document carries only its issuer's authority. What does exist is a scored Current Profile, a signed Target Profile, a gap register with owners, and a management self-attestation with an evidence index. If a questionnaire demands a certificate, the route is ISO/IEC 42001, audited and issued by an accredited certification body.

No. The AI RMF has no statute, regulator or penalty behind it anywhere. The July 2024 date buyers half-remember was NIST's deadline to publish AI 600-1, not a deadline for anyone else. The real pressure is commercial: enterprise security questionnaires now ask which AI risk framework you follow, and "none" loses deals. Treat this as procurement readiness, not compliance.

Not any more. The White House Office of Management and Budget (OMB) memo M-24-10 did reference the AI RMF. M-25-21, issued 3 April 2025, rescinded and replaced it, and directs agencies to implement OMB's own minimum risk management practices for high-impact AI. Search either 2025 memo for NIST and you'll find nothing. The AI RMF is still the most widely recognized voluntary reference and maps well onto those practices.

No. AI 100-1, published 26 January 2023, is still the only released version. The AI Action Plan of 23 July 2025 directed a revision without a deadline, and as of today there's no draft, no request for information and no comment window. Build against 1.0 and map controls to the underlying harm rather than to NIST's risk labels, particularly Information Integrity, Harmful Bias or Homogenization, and Environmental Impacts. A revision then means relabeling, not rewriting.

The opposite. ISO/IEC 42001 asks whether your management system works and says little about which AI risks you carry. The AI RMF names them, and AI 600-1 gives you 212 tagged actions to answer with, so Profile work first produces most of the risk-assessment material a certification auditor will ask to see. Expect roughly two to four extra months for the certification track on top. The certificate comes from an accredited certification body: we prepare you for it, but we can't issue it.

No. NIST IR 8596, the Cyber AI Profile, is a Cybersecurity Framework 2.0 profile, released as a preliminary draft on 16 December 2025 with comments closed on 30 January 2026. Security teams pick it up because the name sounds close, but its structure and purpose differ. If you map to both, pick one as your system of record, or nobody outside your team can follow the gap analysis.

For a mid-sized company with a handful of use cases, four to seven months: roughly three to four weeks on the inventory, four to six on the Current Profile, six to ten to stand up the governance layer, and eight to twelve in parallel on TEVV and pre-deployment testing. Two things move it most: whether you train models or only call them through APIs, and whether an ISO 27001 security management system already exists to hang governance on. The real risk is drift, since no audit date forces closure. We set one.

The India AI Governance Guidelines from MeitY, India's IT ministry, published 5 November 2025, reference the NIST AI RMF as one voluntary framework among others: a reference point, not an obligation. The binding law nearby is the DPDP Act and the DPDP Rules 2025, which commence in tranches rather than on a single date. AI 600-1's Data Privacy risk maps onto that work cleanly.

Let's talk

Bring us your AI inventory, or tell us you haven't got one.

Tell us roughly how many AI use cases you have, and whether you train models or call them through APIs. That usually shows whether you need a full Profile pair or just an acceptable use policy and a register. We reply within one working day.