Hael
Book a meeting
NIST AI RMF · Consultancy

NIST AI RMF consultancy services

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 7 min read
Key takeaways
  • Six workstreams: inventory, gap assessment, governance build, measurement design, documentation, and ongoing monitoring.
  • Measurement design is the workstream that separates real implementations from documentation exercises, and it usually needs engineering involvement.
  • No consultancy can certify you, because no certification exists.
  • Fees commonly run £15,000 to £45,000 for a first implementation, with independent assessment priced separately.
  • Ask who designs and runs the measurements, because that is where most proposals are thin.

The six workstreams

NIST AI RMF consultancy services cover the work of taking an organisation from "we use AI" to a documented, defensible position across the four functions. That work divides into six workstreams.

One thing distinguishes this from certification frameworks: there is nothing to pass. No audit sets the standard, so the discipline has to come from the practitioner. Good firms impose it by documenting to a standard a supervisor or a sceptical buyer would accept.

Inventory. Finding every AI system built, bought or used, including AI features inside purchased software, and recording owner, purpose, data, decisions influenced and affected people.

Gap assessment. A subcategory-by-subcategory position across the 72 subcategories, stating what is in place, what is not, and what closes each gap. This is our readiness and gap assessment, delivered as a fixed fee with a delivery call.

Governance build. The AI policy, named accountability, risk tolerance, third-party AI process and decision-recording mechanism that make up GOVERN. Covered by our implementation service.

Measurement design. Deciding what gets tested, how, how often, and what the results mean. Performance, bias, robustness, and monitoring in production. This is the workstream most often underdelivered.

Documentation. The per-system records that constitute the evidence: context, risks, measurements, treatment decisions, accepted risks with reasoning.

Ongoing monitoring. Re-measuring as models change, adding new systems, and keeping the record current. The framework is a cycle, so this is not optional.

The workstream to interrogate

Ask who designs and runs the measurements.

MEASURE is where implementations diverge sharply. A documentation-led engagement names metrics in a table. A real one specifies what will be tested, on what data, at what cadence, by whom, and what threshold triggers action. The second usually requires engineering involvement, because the measurement infrastructure often does not exist.

If a proposal covers GOVERN and MAP in detail and treats MEASURE in a sentence, you are buying documentation. That may be all you need. It should be a decision rather than a surprise.

What consultancy services cannot do

Certify you. No certification exists. Any firm offering NIST AI RMF certification is describing something outside the framework, and a well-informed buyer will notice.

Give you a legal safe harbour outside Texas. The framework creates no legal position of its own, and Colorado's affirmative defence did not survive the repeal of its original AI Act in May 2026.

Run the measurements permanently. Testing and monitoring happen inside your systems. A consultancy designs, builds and reviews.

Typical fees

ServiceTypical fee
Inventory and current-state assessment£5,000 to £15,000
Gap assessment across the 72 subcategories£6,000 to £20,000
Full implementation£15,000 to £45,000
Generative AI Profile overlay£4,000 to £12,000
Independent assessment£8,000 to £25,000, separate supplier or separate team
Ongoing monitoringRetainer, scope dependent
Independent practitioner day rate£700 to £1,600

Ask for the fee itemised per system where you have several, since that is how the work scales.

How it fits with certifiable frameworks

Many organisations implement the NIST framework and certify to ISO/IEC 42001, because the substance overlaps heavily and NIST publishes a crosswalk between them. The framework gives structure and vocabulary; the certificate gives a buyer something verifiable.

Where that is your plan, say so at the start. The documentation is written differently when it will support a certification audit, and retrofitting is more expensive than building for it. See our ISO/IEC 42001 service page.

The same applies to the EU AI Act, where the framework's MAP and MEASURE work feeds directly into the Act's risk management and technical documentation requirements.

Advisory or delivery?

An advisory engagement gives you guidance while your team does the work. Suitable where you have people who can write to a regulatory standard and design tests.

A delivery engagement means the firm writes the policy, builds the risk documentation, designs the measurement approach and produces the per-system records.

The question that separates them: who writes the per-system documentation, and who specifies the tests. Ask both directly.

What to do next

Build a first-pass inventory before requesting proposals. Cost scales with system count, so no firm can quote sensibly without it.

Our free AI impact assessment gives an immediate first view, and the NIST AI RMF service page sets out how we run each workstream.

References

FAQ

What do NIST AI RMF consultancy services include?

Inventory, gap assessment, governance build, measurement design, per-system documentation, and ongoing monitoring.

How much do they cost?

Commonly £15,000 to £45,000 for a first implementation, with independent assessment at £8,000 to £25,000 priced separately.

Can a consultancy certify us?

No. There is no NIST AI RMF certification. A firm offering one is describing something outside the framework.

Which workstream matters most?

Measurement design. It is where documentation-led engagements and real implementations diverge, and it usually needs engineering involvement.

Should we also certify to ISO/IEC 42001?

If a buyer needs something verifiable, usually yes. The substance overlaps heavily and NIST publishes a crosswalk, so decide at the start rather than retrofitting.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance. We do the work, hold the deadline and stand behind the evidence, across the NIST AI Risk Management Framework, ISO/IEC 42001, the EU AI Act, SOC 2 and ISO 27001. We do not offer certification against frameworks that cannot be certified. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.

This guide is general information and is not professional advice on your particular circumstances.

Free check

See where you stand on NIST AI RMF, free.

Answer a short set of questions and see what NIST AI RMF expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether NIST AI RMF applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to NIST AI RMF.

Or speak to us about your deadline. Book a meeting.