Hael
Book a meeting
NIST AI RMF · Cost

The budget-friendly ways to implement NIST AI RMF

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 8 min read
Key takeaways
  • The framework is free. Everything you spend is on your own effort, so scope and target maturity are the only real levers.
  • Set a target maturity. With no audit date, unmanaged scope is the main cost risk.
  • Prioritise by risk, not by subcategory number. Systems that affect people first.
  • Reuse ISO 27001, SOC 2 and GDPR work rather than starting from zero.
  • Do not economise on measurement or on the Generative AI Profile if you run large language models.

Where the money goes

The framework itself costs nothing. NIST publishes it free, along with the Playbook and the crosswalks. Everything you spend goes on your own effort and on whatever help you buy.

That makes this different from certification frameworks, where audit fees are fixed and preparation is the variable. Here everything is variable, which is both the opportunity and the risk. A realistic first implementation runs £15,000 to £45,000; without a target it can run considerably more without producing a better result.

LineTypical costAvoidable?
The framework itselfFreeNot applicable
Inventory£0 if done internally, £5,000 to £15,000 with helpLargely, by doing it yourself
Gap assessment£6,000 to £20,000Partly, by scoping to systems that matter
Governance build£5,000 to £15,000Partly, by reusing existing policy structures
Per-system documentationScales with system countPartly, through prioritisation
Measurement design and infrastructureFrequently the largest lineRarely, and not wisely
Independent assessment£8,000 to £25,000Yes, if your buyers do not need it
Internal team timeUsually underestimatedPartly, through project management

1. Set a target maturity

The single most important cost control, and the one most often missing.

There is no audit date, so nothing declares the work finished. Without a stated target the implementation deepens indefinitely, because there is always another subcategory to strengthen.

Decide explicitly: this level, for these systems, by this date, because this is what our buyers and our risk position require. Write it down and hold the engagement to it.

2. Do the inventory yourself

Free, and only your people can do it properly. List every AI system built, bought or used, including AI features inside purchased software, with owner, purpose, data, decisions influenced and affected people.

An accurate inventory turns every subsequent quote from an estimate into a price, and it usually surfaces systems the leadership team did not know about.

3. Prioritise by risk, not by structure

You do not have to address all 72 subcategories at the same depth simultaneously. Work outward from the systems that matter: those that affect people, those that are customer-facing, those that are generative.

An implementation covering three high-impact systems thoroughly is more defensible, and cheaper, than one covering twelve superficially. It also answers a buyer's question better, because buyers ask about the systems that touch them.

4. Reuse what you already hold

Organisations with ISO 27001 or SOC 2 have parts of GOVERN and MANAGE already: risk processes, supplier management, incident handling, change control, decision records.

Organisations that have done GDPR work have parts of MAP: data inventories, impact assessments, records of processing, lawful basis analysis.

Map those across before commissioning new work. A gap assessment that starts from an accurate picture of what exists produces a shorter remediation list.

5. Use the free NIST material

The Playbook offers suggested actions and references for each subcategory. The crosswalks map the framework to ISO/IEC 42001 and the EU AI Act. The Generative AI Profile is published in full.

None of this replaces judgement, but a team that has read the Playbook before the first meeting spends less of a consultant's time being taught the framework and more of it on decisions.

6. Build the documentation once, for several audiences

The same per-system record can serve a NIST implementation, an ISO/IEC 42001 Statement of Applicability, an EU AI Act technical file and an enterprise security questionnaire, if it is written with all of them in view.

Decide at the start which audiences you need to serve. Retrofitting documentation for certification or for the EU AI Act is more expensive than writing it once with the destination known.

7. Skip the independent assessment if your buyers do not need it

An independent assessment costs £8,000 to £25,000 and is worth it where a buyer will read a substantive external opinion.

Where nobody is asking, it is money spent on reassurance. And where a buyer needs something verifiable against a register, an assessment does not deliver that and ISO/IEC 42001 certification does. Match the spend to the actual requirement.

8. Name an internal owner

The most expensive arrangement is the implicit one, where AI governance belongs to everybody and nobody. Naming an owner with protected hours costs nothing and is the highest-return decision available.

What not to cut

Measurement. An implementation with strong GOVERN and MAP and nothing behind MEASURE fails the first specific question from a serious buyer. It is also the part that would have caught a real problem.

The Generative AI Profile, if you run large language models in production. Twelve risks specific to generative systems, published free, and ignoring them while running the technology they cover is not a saving.

Per-system records. A policy without them is not a defensible position, whatever the policy says.

Decision reasoning. An accepted risk with no recorded reasoning is indistinguishable from an unnoticed risk when someone reviews the file later.

What to do next

Set the target maturity and build the inventory. Both are free, both take days, and together they determine most of what you will spend.

Our free AI impact assessment gives an immediate first view, and our readiness and gap assessment produces the full position for a fixed fee.

References

FAQ

How much does NIST AI RMF implementation cost?

Commonly £15,000 to £45,000 for a first implementation. The framework itself is free; the cost is effort.

Do we have to address all 72 subcategories?

Not at the same depth simultaneously. Prioritise by risk, starting with systems that affect people and systems that are generative.

What is the biggest cost risk?

No target maturity. Without one the work expands indefinitely, because nothing declares it finished.

Do we need an independent assessment?

Only where a buyer will read one. Where they need something verifiable against a register, ISO/IEC 42001 certification is the better spend.

Does holding ISO 27001 reduce the cost?

Yes. Parts of GOVERN and MANAGE already exist. MAP and MEASURE are the genuinely new work.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance. Every engagement has a named practitioner, an agreed target and a fixed fee, and we credit the governance work you already hold rather than starting from zero. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.

This guide is general information and is not professional advice on your particular circumstances.

Free check

See where you stand on NIST AI RMF, free.

Answer a short set of questions and see what NIST AI RMF expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether NIST AI RMF applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to NIST AI RMF.

Or speak to us about your deadline. Book a meeting.