NIST AI RMF consultancy services
- Six workstreams: inventory, gap assessment, governance build, measurement design, documentation, and ongoing monitoring.
- Measurement design is the workstream that separates real implementations from documentation exercises, and it usually needs engineering involvement.
- No consultancy can certify you, because no certification exists.
- Fees commonly run £15,000 to £45,000 for a first implementation, with independent assessment priced separately.
- Ask who designs and runs the measurements, because that is where most proposals are thin.
The six workstreams
NIST AI RMF consultancy services cover the work of taking an organisation from "we use AI" to a documented, defensible position across the four functions. That work divides into six workstreams.
One thing distinguishes this from certification frameworks: there is nothing to pass. No audit sets the standard, so the discipline has to come from the practitioner. Good firms impose it by documenting to a standard a supervisor or a sceptical buyer would accept.
Inventory. Finding every AI system built, bought or used, including AI features inside purchased software, and recording owner, purpose, data, decisions influenced and affected people.
Gap assessment. A subcategory-by-subcategory position across the 72 subcategories, stating what is in place, what is not, and what closes each gap. This is our readiness and gap assessment, delivered as a fixed fee with a delivery call.
Governance build. The AI policy, named accountability, risk tolerance, third-party AI process and decision-recording mechanism that make up GOVERN. Covered by our implementation service.
Measurement design. Deciding what gets tested, how, how often, and what the results mean. Performance, bias, robustness, and monitoring in production. This is the workstream most often underdelivered.
Documentation. The per-system records that constitute the evidence: context, risks, measurements, treatment decisions, accepted risks with reasoning.
Ongoing monitoring. Re-measuring as models change, adding new systems, and keeping the record current. The framework is a cycle, so this is not optional.
The workstream to interrogate
Ask who designs and runs the measurements.
MEASURE is where implementations diverge sharply. A documentation-led engagement names metrics in a table. A real one specifies what will be tested, on what data, at what cadence, by whom, and what threshold triggers action. The second usually requires engineering involvement, because the measurement infrastructure often does not exist.
If a proposal covers GOVERN and MAP in detail and treats MEASURE in a sentence, you are buying documentation. That may be all you need. It should be a decision rather than a surprise.
What consultancy services cannot do
Certify you. No certification exists. Any firm offering NIST AI RMF certification is describing something outside the framework, and a well-informed buyer will notice.
Give you a legal safe harbour outside Texas. The framework creates no legal position of its own, and Colorado's affirmative defence did not survive the repeal of its original AI Act in May 2026.
Run the measurements permanently. Testing and monitoring happen inside your systems. A consultancy designs, builds and reviews.
Typical fees
| Service | Typical fee |
|---|---|
| Inventory and current-state assessment | £5,000 to £15,000 |
| Gap assessment across the 72 subcategories | £6,000 to £20,000 |
| Full implementation | £15,000 to £45,000 |
| Generative AI Profile overlay | £4,000 to £12,000 |
| Independent assessment | £8,000 to £25,000, separate supplier or separate team |
| Ongoing monitoring | Retainer, scope dependent |
| Independent practitioner day rate | £700 to £1,600 |
Ask for the fee itemised per system where you have several, since that is how the work scales.
How it fits with certifiable frameworks
Many organisations implement the NIST framework and certify to ISO/IEC 42001, because the substance overlaps heavily and NIST publishes a crosswalk between them. The framework gives structure and vocabulary; the certificate gives a buyer something verifiable.
Where that is your plan, say so at the start. The documentation is written differently when it will support a certification audit, and retrofitting is more expensive than building for it. See our ISO/IEC 42001 service page.
The same applies to the EU AI Act, where the framework's MAP and MEASURE work feeds directly into the Act's risk management and technical documentation requirements.
Advisory or delivery?
An advisory engagement gives you guidance while your team does the work. Suitable where you have people who can write to a regulatory standard and design tests.
A delivery engagement means the firm writes the policy, builds the risk documentation, designs the measurement approach and produces the per-system records.
The question that separates them: who writes the per-system documentation, and who specifies the tests. Ask both directly.
What to do next
Build a first-pass inventory before requesting proposals. Cost scales with system count, so no firm can quote sensibly without it.
Our free AI impact assessment gives an immediate first view, and the NIST AI RMF service page sets out how we run each workstream.
References
FAQ
What do NIST AI RMF consultancy services include?
Inventory, gap assessment, governance build, measurement design, per-system documentation, and ongoing monitoring.
How much do they cost?
Commonly £15,000 to £45,000 for a first implementation, with independent assessment at £8,000 to £25,000 priced separately.
Can a consultancy certify us?
No. There is no NIST AI RMF certification. A firm offering one is describing something outside the framework.
Which workstream matters most?
Measurement design. It is where documentation-led engagements and real implementations diverge, and it usually needs engineering involvement.
Should we also certify to ISO/IEC 42001?
If a buyer needs something verifiable, usually yes. The substance overlaps heavily and NIST publishes a crosswalk, so decide at the start rather than retrofitting.
About Hael
Hael is an advisory firm specialising in AI governance and security compliance. We do the work, hold the deadline and stand behind the evidence, across the NIST AI Risk Management Framework, ISO/IEC 42001, the EU AI Act, SOC 2 and ISO 27001. We do not offer certification against frameworks that cannot be certified. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.
This guide is general information and is not professional advice on your particular circumstances.