NIST AI RMF vCISO Services
- Under this framework the fractional role owns a cycle rather than a certificate: inventory, risk documentation, measurement cadence and decision records.
- Retainers commonly run £3,000 to £15,000 a month, with most mid-market arrangements between £4,000 and £9,000.
- Because there is no audit date, the retainer needs an agreed target maturity or the scope drifts.
- Ask whether measurement design and independent assessment sit inside or outside the fee.
- The person needs authority to stop a system, because MANAGE assumes someone can act.
What the role covers
A virtual CISO, fractional CISO or fractional AI officer is senior governance leadership engaged part time. Under the NIST AI Risk Management Framework that role owns a continuing cycle rather than a project with a certificate at the end.
That distinction shapes the engagement. In a certification framework the retainer holds a system between audits, and the audit provides the discipline. Here there is no audit, so the discipline has to be built into the arrangement.
| Area | What the person owns |
|---|---|
| AI inventory | Keeping it current as systems are added, changed or retired |
| GOVERN | The AI policy, named accountability, risk tolerance, third-party AI process, decision records |
| MAP | Context and risk documentation for each system, refreshed when purpose or deployment changes |
| MEASURE | The measurement cadence: what gets tested, when, and what the results mean |
| MANAGE | Prioritisation, treatment decisions, accepted risks with reasoning, incident response |
| Generative AI Profile | Applying the twelve generative risks where large language models are in use |
| Buyer questionnaires | Answering AI sections of security reviews from the evidence base |
| Board reporting | Explaining the AI risk position to leadership and customers |
Why this arrangement needs a target
With no audit date, a NIST AI RMF retainer can expand indefinitely. There is always another subcategory to deepen, another system to document more thoroughly, another metric to add.
A well-structured retainer therefore states a target maturity and a review point: this is the level we are maintaining, for these systems, and we will reconsider it at this date. Without that, you are buying open-ended effort, and the cost drifts upward without anyone deciding it should.
Ask any firm proposing a retainer what maturity they are maintaining and how you would know if it slipped.
What it costs
| Model | Typical range |
|---|---|
| Monthly retainer, small organisation, few systems | £3,000 to £5,000 |
| Monthly retainer, mid-market | £4,000 to £9,000 |
| Monthly retainer, large estate or multiple regimes | £9,000 to £15,000 |
| Day rate | £700 to £1,600 |
| Fixed-fee implementation project | £15,000 to £45,000 |
For comparison, a full-time head of AI governance in the UK generally costs £120,000 to £220,000 fully loaded, and considerably more in the United States. A retainer at £6,000 a month is £72,000 a year.
What sits outside the fee
Measurement infrastructure. Building bias testing, performance monitoring or evaluation pipelines is engineering work, and it usually sits outside a governance retainer. Ask explicitly, because it is the largest source of surprise cost.
Independent assessment. If the same person runs your programme, they cannot independently assess it. Expect a separate practitioner or a separate firm at £8,000 to £25,000. This is covered in NIST AI RMF - Independent Assessment Consultants.
ISO/IEC 42001 certification. If you decide you need something verifiable, certification body fees are separate again.
The initial implementation where nothing exists yet. A retainer maintains a position; it does not build one from nothing.
Ask for exclusions in writing, along with hour caps and overage rates.
Authority matters
MANAGE assumes someone can act. Prioritising risks, allocating resources, and responding to incidents all require decisions, and a fractional officer who can only recommend is a reporting line rather than a governance function.
Agree at the outset what the person decides alone, what they escalate, and to whom. In particular, agree whether they can take a system out of service, because that is the decision that matters when something goes wrong and the one most often left undefined.
Fractional, project, or a hire?
| Best suited to | |
|---|---|
| Fractional retainer | Systems in production, models changing, buyer questionnaires arriving, multiple regimes, no internal owner |
| Project consultant | Building the first implementation to an agreed maturity, with someone internal maintaining it |
| Full-time hire | A large AI estate, a regulated firm, or a business where AI is the product |
Many organisations do best with a fixed-fee implementation followed by a smaller ongoing arrangement. That is how our implementation and continuous governance and assurance services fit together.
What to do next
Decide the target maturity before you decide the engagement model. A retainer without one is an open-ended commitment, and a project without one has no completion test.
Our free AI impact assessment gives a first view, and the NIST AI RMF service page sets out how we work.
References
FAQ
What does a vCISO do under the NIST AI RMF?
Owns the AI inventory, the governance layer, the per-system risk documentation, the measurement cadence, decision records and buyer questionnaire responses.
How much does it cost?
Commonly £3,000 to £15,000 a month, with most mid-market arrangements between £4,000 and £9,000.
Why does a target maturity matter?
Because there is no audit date to define completion, so without an agreed target the scope and the cost drift upward.
Can the vCISO perform our independent assessment?
No, not if they run the programme. Expect a separate practitioner or a separate firm.
Is measurement infrastructure included?
Usually not. Building testing and monitoring pipelines is engineering work. Ask explicitly, because it is the largest source of unexpected cost.
About Hael
Hael is an advisory firm specialising in AI governance and security compliance. We take companies through the NIST AI Risk Management Framework and maintain the position afterwards through our continuous assurance service, using a separate practitioner where an independent assessment is needed. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on FCA authorisation and compliance since 2013.
This guide is general information and is not professional advice on your particular circumstances.