Hael
Book a meeting
NIST AI RMF · Independent assessment

NIST AI RMF - Independent Assessment Consultants

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 8 min read
Key takeaways
  • There is no NIST AI RMF certification, so an independent assessment is the closest available equivalent.
  • It produces a report describing what was found. It is not a certificate and must never be presented as one.
  • The assessor must be independent of whoever built the implementation, or the report carries no weight.
  • Assessments typically cost £8,000 to £25,000 and take two to four weeks.
  • Where a buyer needs something verifiable rather than credible, ISO/IEC 42001 certification is the better answer.

What an independent assessment is, and is not

Because nobody certifies against the NIST AI Risk Management Framework, organisations that need to give a buyer more than their own word commission an independent assessment: a third party reviews the implementation against the framework and issues a report describing what it found.

It is not a certificate. There is no accredited scheme behind it, no register, and no standard form. What it is, done properly, is a documented external opinion from someone with no stake in the answer, which is a materially stronger position than a self-attestation.

It isIt is not
A structured review against the four functions and 72 subcategoriesA certification
A report describing what was found, with evidence citedA pass or fail
An external, documented opinionAccredited or registered anywhere
Useful in a buyer's vendor reviewSomething to claim as "NIST certified"

The distinction matters commercially as well as ethically. A sophisticated buyer who sees "NIST AI RMF certified" on a website knows immediately that either the supplier or its adviser does not understand the framework, and the claim damages exactly the credibility it was meant to build.

Who can perform one

Anyone competent and independent. There is no licensing.

Independence is the part that determines whether the report is worth anything. An assessment of an implementation the same team built is a self-review with a cover page, and any buyer who reads carefully will spot it.

That leaves three workable arrangements. A different firm entirely. A separate practitioner within the same firm, with the separation stated plainly in the report. Or an internal audit function, where you have one with genuine independence from the AI programme.

Competence matters too. The assessor needs to understand the framework, and enough about AI systems to judge whether the measurements described actually test what they claim to test. An assessor who accepts a metrics table at face value adds nothing.

What a good assessment produces

OutputWhat it should contain
Scope statementWhich systems, which functions, which subcategories were assessed, and what was excluded
MethodWhat was reviewed, who was interviewed, what evidence was sampled and from what period
Findings per subcategoryWhat is in place, what the evidence shows, and where it falls short
Evidence citationsSpecific documents and records, not general assertions
ObservationsThings that hold today but will not survive the next model change
RecommendationsOrdered by risk, distinguishing what is material from what is tidying
LimitationsWhat the assessor did not examine, and what could not be verified

The limitations section is the mark of a serious assessment. One that claims complete coverage of everything is not describing a real engagement.

What it costs

ItemTypical range
Independent assessment, small to mid-sized organisation£8,000 to £25,000
Duration2 to 4 weeks including reporting
Repeat cadenceAnnually, or after material change
Combined with an ISO/IEC 42001 internal auditUsually cheaper than separate engagements

Cost scales with the number of systems in scope and how many are generative or affect people.

When an assessment is the right answer, and when it is not

Right where a buyer has asked how you manage AI risk, will read a substantive answer, and does not require a certificate. Also right where a board wants external validation before making public claims.

Not right where the buyer's procurement process requires a verifiable credential. No amount of assessment quality changes the fact that there is nothing for them to check against a register. In that situation ISO/IEC 42001 certification is the better investment, because the substance overlaps heavily and NIST publishes a crosswalk between them. See our ISO/IEC 42001 service page.

Many organisations do both over time: implement the framework, commission an assessment to test the implementation, then certify to ISO/IEC 42001 once the position is solid.

How to commission one

State the scope precisely: which systems, which functions, what period of evidence.

Require independence in writing, and require the report to state the relationship between the assessor and whoever built the implementation.

Ask for evidence citations rather than conclusions, so a buyer reading the report can see what was actually examined.

Ask what happens to findings. An assessment that produces a list nobody closes is an expense rather than an investment.

And agree in advance how the report may be shared, since it will usually go to customers.

Our approach

We perform independent assessments, including for organisations whose implementation we did not build. Where we did build it, we use a separate practitioner and state that relationship in the report rather than leaving a reader to infer it. That is covered by our internal audit service.

We do not describe the output as certification, and we advise clients not to.

What to do next

Ask your buyer what they actually need to see. If the answer is a certificate, plan for ISO/IEC 42001. If the answer is a credible account of how you manage AI risk, an independent assessment is proportionate and considerably cheaper.

Our free AI impact assessment gives a first view, and the NIST AI RMF service page sets out how we work.

References

FAQ

Is an independent assessment the same as certification?

No. It is a report describing what an external party found. There is no accredited certification for the NIST AI RMF.

Can we say we are NIST AI RMF certified?

No. The claim is inaccurate and informed buyers recognise it, which undermines the credibility it was meant to create.

Who can perform an assessment?

Anyone competent and independent of the implementation. There is no licensing, so independence and evidence quality are what make the report worth anything.

How much does an assessment cost?

Typically £8,000 to £25,000 for a small to mid-sized organisation, taking two to four weeks.

Should we get an assessment or certify to ISO/IEC 42001?

An assessment where the buyer will read a substantive answer. ISO/IEC 42001 where they need something verifiable against a register.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance. We perform independent assessments against the NIST AI Risk Management Framework, including for organisations whose implementation we did not build, and where we did build it we use a separate practitioner and state the relationship in the report. We do not describe assessment as certification. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.

This guide is general information and is not professional advice on your particular circumstances.

Free check

See where you stand on NIST AI RMF, free.

Answer a short set of questions and see what NIST AI RMF expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether NIST AI RMF applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to NIST AI RMF.

Or speak to us about your deadline. Book a meeting.