NIST AI RMF Readiness and Compliance Services
- Readiness establishes what you have against the 72 subcategories and what each gap would take to close.
- The deliverable is a subcategory-by-subcategory position and a prioritised plan, not an opinion that you are compliant.
- Run it before committing to a target maturity, because the framework has no fixed endpoint and scope creep is the main cost risk.
- Readiness typically costs £6,000 to £20,000 and takes three to five weeks.
- The most common finding is strong GOVERN documentation with almost nothing behind MEASURE.
What a readiness assessment should contain
NIST AI RMF readiness services establish where you stand across the framework's four functions and 72 subcategories. The output is a subcategory-by-subcategory position, an AI system inventory, and a prioritised plan showing what closes each gap and roughly what it takes.
Compliance services then cover the build: governance, per-system documentation, measurement design, and the ongoing cycle.
Because the framework has no certification and no fixed endpoint, readiness serves an additional purpose here that it does not in certifiable frameworks. It sets the target. Without one, implementations expand indefinitely, which is the main way organisations overspend on this.
| Element | What good looks like |
|---|---|
| Scope and target maturity | Which systems and which functions, and how far you intend to go. This is a decision, not a default |
| AI system inventory | Every system built, bought or used, with owner, purpose, data and affected people |
| Subcategory-by-subcategory position | All 72 assessed, with current evidence and a judgement on sufficiency |
| Generative AI Profile overlay | Where large language models are in use, the twelve generative risks assessed alongside |
| Prioritised plan | What closes each gap, who does it, roughly how long, ordered by risk rather than by function |
| Measurement plan | What will be tested, how, by whom, and at what cadence |
| Demonstration route | How you will show a buyer: attestation, questionnaire, independent assessment, or ISO/IEC 42001 certification |
| Delivery call | A conversation where the target maturity and the trade-offs get discussed |
Findings should be stated as findings. "These subcategories are addressed, these are not, here is what closes each" is defensible. "You are NIST compliant" is not a statement anyone is entitled to make, since nothing confers that status.
Why setting a target matters more here
Certifiable frameworks have a natural endpoint: the audit. This one does not.
An organisation can keep deepening its implementation indefinitely, and without a stated target the work expands to fill whatever budget exists. Readiness should end with an explicit decision: this is the maturity we are aiming for, for these systems, by this date, because this is what our buyers and our risk position require.
That decision is worth making with someone who has seen several implementations, because the right target is not obvious from the framework text.
What readiness commonly finds
GOVERN done, MEASURE empty. The single most common pattern. There is an AI policy, sometimes a good one, and almost no evidence that anything has been tested.
Systems nobody had recorded. Usually AI features inside purchased software, used by teams who never thought of them as AI systems.
Third-party AI unmanaged. GOVERN includes managing AI you buy. Most organisations have contracts and no risk assessment of the models inside the tools.
Metrics named but not produced. A monitoring plan with no results behind it.
Generative systems in production with no profile applied. Large language models running while the Generative AI Profile has not been looked at.
No decision record. Risks accepted informally, so a reviewer cannot distinguish an accepted risk from an unnoticed one.
Existing work not credited. Organisations with ISO 27001 or SOC 2 already have parts of GOVERN and MANAGE in place and often do not realise it.
Cost and timing
| Service | Typical cost | Typical duration |
|---|---|---|
| Inventory and current-state assessment | £5,000 to £15,000 | 2 to 3 weeks |
| Full readiness including subcategory gap assessment | £6,000 to £20,000 | 3 to 5 weeks |
| Implementation | £15,000 to £45,000 | 2 to 4 months |
| Independent assessment | £8,000 to £25,000 | 2 to 4 weeks |
Cost scales with system count and with how many systems are generative or affect people.
What compliance services cover after readiness
Writing the AI policy and establishing named accountability. Setting risk tolerance. Building the third-party AI process. Producing per-system context and risk documentation. Designing and standing up the measurement approach. Establishing the decision record. Then running the cycle: re-measuring, adding new systems, and keeping documentation current.
That is our implementation service, with the ongoing cycle covered by continuous governance and assurance.
What to do next
Build a first-pass inventory yourself. It costs nothing, it is the input every proposal needs, and it usually surfaces two or three systems the leadership team did not know about.
Our free AI impact assessment gives an immediate first view, and our readiness and gap assessment produces the full position for a fixed fee.
References
FAQ
What is a NIST AI RMF readiness assessment?
A subcategory-by-subcategory position across the framework, with an AI system inventory and a prioritised plan for closing gaps.
Why does readiness matter more without certification?
Because there is no audit to define the endpoint. Readiness sets the target maturity, without which implementations expand indefinitely.
How long does it take?
Three to five weeks for most organisations, including the delivery call.
What does it cost?
Typically £6,000 to £20,000, scaling with system count rather than headcount.
Do we need it if we hold ISO 27001?
It is usually shorter, because parts of GOVERN and MANAGE already exist, but the AI-specific mapping and measurement work is new.
About Hael
Hael is an advisory firm specialising in AI governance and security compliance. Our readiness and gap assessment is delivered as a fixed fee with a delivery call, and states findings subcategory by subcategory rather than issuing an opinion. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.
This guide is general information and is not professional advice on your particular circumstances.