Hael
Book a meeting
NIST AI RMF · Overview

NIST AI RMF compliance

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 8 min read
Key takeaways
  • An implementation runs in five stages: inventory, govern, map, measure and manage, then ongoing monitoring.
  • The 72 subcategories are outcomes, not controls. You decide how to achieve each one, which is why judgement matters more here than in a checklist framework.
  • Typical first implementations run £15,000 to £45,000, driven by system count rather than headcount.
  • Apply the Generative AI Profile on top wherever large language models are involved.
  • There is no certificate, so decide early how you will demonstrate the work to a buyer.

Stage 1: Inventory

Implementing the NIST AI Risk Management Framework means applying its four functions to the AI systems you actually run, and holding the documentation that shows you did. This overview covers each stage, the numbers attached, and how organisations demonstrate the result.

For the plain explanation of what the framework is, see NIST AI RMF Explained. For what "compliance" means when nothing is certifiable, see What Is NIST AI RMF Compliance?.

You cannot govern what you have not found. List every AI system your organisation builds, buys or uses, including AI features inside purchased software, which is where most omissions sit.

For each: what it does, who owns it, what data it uses, what decisions it influences, who it affects, and whether it is generative.

Stage 2: GOVERN

The layer that sits across everything else. An AI policy. Named accountability, so each system has an owner and the organisation has someone answerable overall. A stated risk tolerance, which is what allows later decisions to be consistent. A process for third-party AI, covering the models and tools you buy. And a record of governance decisions.

This is the function that most often exists on paper and not in practice. A policy with no named owners and no recorded decisions satisfies nobody who looks closely.

Stage 3: MAP

Context for each system. What is the intended purpose. What is foreseeable misuse. Who is affected and how. What are the benefits and the potential harms. What are the system's limits. What assumptions were made about the data and the deployment environment.

This is where most of the useful thinking happens, and where teams that treat it as a form produce documentation that fails the first serious question from a buyer.

Stage 4: MEASURE

Analysing and tracking what MAP identified. Test and evaluation approaches, performance metrics, bias testing where the system affects people, robustness checks, and monitoring in production.

Two practical points. Measurement has to continue after launch, because model behaviour changes. And where you bought the system rather than built it, some measurements sit with your supplier, so ask what they will share before you commit to a metric you cannot obtain.

Stage 5: MANAGE

Acting on it. Prioritising the risks identified, deciding treatment, allocating resources, documenting decisions including accepted risks, planning response and recovery, and handling incidents.

Then continuing. The framework is a cycle, not a project, and the loop from MANAGE back into MAP and MEASURE is what makes it credible over time.

The Generative AI Profile

Where large language models or other generative systems are involved, apply NIST AI 600-1 alongside the base framework. It sets out twelve generative-specific risks including confabulation, information integrity, data privacy, harmful bias, information security and misuse, mapped to the four functions.

Applying both is not double work. The profile tells you what additional risks to consider inside the same structure you are already using.

What it costs

ComponentTypical range
Inventory and current-state assessment£5,000 to £15,000
Gap assessment against the 72 subcategories£6,000 to £20,000
Full implementation£15,000 to £45,000
Independent assessment by a third party£8,000 to £25,000
Ongoing monitoring and upkeepRetainer, scope dependent

Cost is driven by how many AI systems you have, how many are generative, and how many affect people. A company with forty employees and six AI systems costs more than one with four hundred employees and one.

How long it takes

Two to four weeks for inventory and current-state assessment. Two to four months for a first implementation covering a modest estate. Longer where measurement infrastructure has to be built, because bias and performance testing often requires engineering work that did not previously exist.

Where implementations go wrong

A policy without per-system records. The most common failure. GOVERN is done well, MAP and MEASURE are done thinly, and the documentation collapses under a specific question.

Bought systems left out. AI inside purchased software is in scope, and the third-party provisions in GOVERN apply to it.

Measurement defined but not performed. Metrics named in a document with no results behind them.

Subcategories treated as a checklist. They are outcomes. Ticking all 72 without evidence of how each was achieved produces a document nobody believes.

No decision record. Accepted risks with no recorded reasoning are indistinguishable from unnoticed risks when someone reviews the file later.

The Generative AI Profile ignored while the organisation runs large language models in production.

How to demonstrate it

There is no certificate. The options are a self-attestation, a completed buyer questionnaire answered from real evidence, an independent third-party assessment, or certification against ISO/IEC 42001 using the published crosswalk.

Decide which you need before you start, because it changes how you document the work. Our buyer assurance and security reviews service covers questionnaire response from the evidence base.

What to do next

Build the inventory. It is free, it is the input everything else needs, and it usually surfaces systems the leadership team did not know about.

Our free AI impact assessment gives an immediate first view, and the NIST AI RMF service page sets out how we run the implementation.

References

FAQ

How long does a NIST AI RMF implementation take?

Two to four weeks for inventory and assessment, two to four months for a first implementation covering a modest estate.

How much does it cost?

Commonly £15,000 to £45,000 for a first implementation, driven by system count and how many systems are generative or affect people.

Do we have to address all 72 subcategories?

You address the ones relevant to your context and record why others do not apply. They are outcomes rather than mandatory controls.

Do we need the Generative AI Profile?

If you run large language models or other generative systems, yes. Apply it alongside the base framework rather than instead of it.

How do we show a buyer we have done it?

Documentation, a questionnaire answered from evidence, an independent assessment, or certification to ISO/IEC 42001 via the crosswalk.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance. We do the work, hold the deadline and stand behind the evidence, across the NIST AI Risk Management Framework, ISO/IEC 42001, the EU AI Act, SOC 2 and ISO 27001. Every engagement has a named practitioner and an agreed scope, timetable and fee. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.

This guide is general information and is not professional advice on your particular circumstances.

Free check

See where you stand on NIST AI RMF, free.

Answer a short set of questions and see what NIST AI RMF expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether NIST AI RMF applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to NIST AI RMF.

Or speak to us about your deadline. Book a meeting.