Hael
Book a meeting
NIST AI RMF · Readiness

NIST AI RMF Readiness and Compliance Services

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 7 min read
Key takeaways
  • Readiness establishes what you have against the 72 subcategories and what each gap would take to close.
  • The deliverable is a subcategory-by-subcategory position and a prioritised plan, not an opinion that you are compliant.
  • Run it before committing to a target maturity, because the framework has no fixed endpoint and scope creep is the main cost risk.
  • Readiness typically costs £6,000 to £20,000 and takes three to five weeks.
  • The most common finding is strong GOVERN documentation with almost nothing behind MEASURE.

What a readiness assessment should contain

NIST AI RMF readiness services establish where you stand across the framework's four functions and 72 subcategories. The output is a subcategory-by-subcategory position, an AI system inventory, and a prioritised plan showing what closes each gap and roughly what it takes.

Compliance services then cover the build: governance, per-system documentation, measurement design, and the ongoing cycle.

Because the framework has no certification and no fixed endpoint, readiness serves an additional purpose here that it does not in certifiable frameworks. It sets the target. Without one, implementations expand indefinitely, which is the main way organisations overspend on this.

ElementWhat good looks like
Scope and target maturityWhich systems and which functions, and how far you intend to go. This is a decision, not a default
AI system inventoryEvery system built, bought or used, with owner, purpose, data and affected people
Subcategory-by-subcategory positionAll 72 assessed, with current evidence and a judgement on sufficiency
Generative AI Profile overlayWhere large language models are in use, the twelve generative risks assessed alongside
Prioritised planWhat closes each gap, who does it, roughly how long, ordered by risk rather than by function
Measurement planWhat will be tested, how, by whom, and at what cadence
Demonstration routeHow you will show a buyer: attestation, questionnaire, independent assessment, or ISO/IEC 42001 certification
Delivery callA conversation where the target maturity and the trade-offs get discussed

Findings should be stated as findings. "These subcategories are addressed, these are not, here is what closes each" is defensible. "You are NIST compliant" is not a statement anyone is entitled to make, since nothing confers that status.

Why setting a target matters more here

Certifiable frameworks have a natural endpoint: the audit. This one does not.

An organisation can keep deepening its implementation indefinitely, and without a stated target the work expands to fill whatever budget exists. Readiness should end with an explicit decision: this is the maturity we are aiming for, for these systems, by this date, because this is what our buyers and our risk position require.

That decision is worth making with someone who has seen several implementations, because the right target is not obvious from the framework text.

What readiness commonly finds

GOVERN done, MEASURE empty. The single most common pattern. There is an AI policy, sometimes a good one, and almost no evidence that anything has been tested.

Systems nobody had recorded. Usually AI features inside purchased software, used by teams who never thought of them as AI systems.

Third-party AI unmanaged. GOVERN includes managing AI you buy. Most organisations have contracts and no risk assessment of the models inside the tools.

Metrics named but not produced. A monitoring plan with no results behind it.

Generative systems in production with no profile applied. Large language models running while the Generative AI Profile has not been looked at.

No decision record. Risks accepted informally, so a reviewer cannot distinguish an accepted risk from an unnoticed one.

Existing work not credited. Organisations with ISO 27001 or SOC 2 already have parts of GOVERN and MANAGE in place and often do not realise it.

Cost and timing

ServiceTypical costTypical duration
Inventory and current-state assessment£5,000 to £15,0002 to 3 weeks
Full readiness including subcategory gap assessment£6,000 to £20,0003 to 5 weeks
Implementation£15,000 to £45,0002 to 4 months
Independent assessment£8,000 to £25,0002 to 4 weeks

Cost scales with system count and with how many systems are generative or affect people.

What compliance services cover after readiness

Writing the AI policy and establishing named accountability. Setting risk tolerance. Building the third-party AI process. Producing per-system context and risk documentation. Designing and standing up the measurement approach. Establishing the decision record. Then running the cycle: re-measuring, adding new systems, and keeping documentation current.

That is our implementation service, with the ongoing cycle covered by continuous governance and assurance.

What to do next

Build a first-pass inventory yourself. It costs nothing, it is the input every proposal needs, and it usually surfaces two or three systems the leadership team did not know about.

Our free AI impact assessment gives an immediate first view, and our readiness and gap assessment produces the full position for a fixed fee.

References

FAQ

What is a NIST AI RMF readiness assessment?

A subcategory-by-subcategory position across the framework, with an AI system inventory and a prioritised plan for closing gaps.

Why does readiness matter more without certification?

Because there is no audit to define the endpoint. Readiness sets the target maturity, without which implementations expand indefinitely.

How long does it take?

Three to five weeks for most organisations, including the delivery call.

What does it cost?

Typically £6,000 to £20,000, scaling with system count rather than headcount.

Do we need it if we hold ISO 27001?

It is usually shorter, because parts of GOVERN and MANAGE already exist, but the AI-specific mapping and measurement work is new.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance. Our readiness and gap assessment is delivered as a fixed fee with a delivery call, and states findings subcategory by subcategory rather than issuing an opinion. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.

This guide is general information and is not professional advice on your particular circumstances.

Free check

See where you stand on NIST AI RMF, free.

Answer a short set of questions and see what NIST AI RMF expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether NIST AI RMF applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to NIST AI RMF.

Or speak to us about your deadline. Book a meeting.