Recommendations for a Good NIST AI RMF Compliance consultant
- Score candidates on seven things: honesty about certification, target maturity, measurement capability, written work, crediting existing work, currency, and independence.
- The certification question is the first filter and it eliminates firms quickly.
- Measurement capability is the second. Ask how they would test a system like yours for bias.
- Insist on an agreed target maturity, or the engagement has no completion test.
- A good consultant will tell you when ISO/IEC 42001 is the better spend.
The seven marks
A good NIST AI RMF consultant does three things a weaker one does not. They tell you plainly that no certification exists and set out how you will demonstrate adoption instead. They agree a target maturity, so the work has a completion test. And they can design measurements that actually test something.
Everything below tests for those. Use it as a scorecard across two or three firms.
| Mark | What good looks like | How to test it |
|---|---|---|
| Honesty about certification | States plainly that none exists and explains the alternatives | Ask whether they can certify you |
| Target maturity | Proposes a level and a completion test | Ask what "done" looks like |
| Measurement capability | Can specify a real test with data, metric, threshold and cadence | Ask how they would test a system like yours for bias |
| Written work | Per-system records describing real systems | Ask for a redacted example |
| Crediting existing work | Maps what you already have from ISO 27001, SOC 2 or GDPR work | Ask what of ours transfers |
| Currency | Knows the framework is being revised and what profiles are in development | Ask what changed in the last year |
| Independence | No commission arrangements, and a separate practitioner for assessment | Ask directly, in writing |
1. The certification question
Ask first, because it disqualifies fastest.
There is no NIST AI RMF certification: no accredited body, no scheme, no register. A firm that offers one has either misunderstood the framework or is willing to misrepresent it, and either way you should not have them writing documents a buyer will scrutinise.
A good answer is direct: no, none exists, and here are the ways organisations demonstrate adoption instead, being a self-attestation, a questionnaire answered from evidence, an independent assessment, or certification against ISO/IEC 42001 via the published crosswalk.
2. Target maturity
The framework has no endpoint. There is always another subcategory to deepen.
A good consultant proposes a target: this level of maturity, for these systems, by this date, because your buyers and your risk position require it. That target is what makes the engagement finite and the fee meaningful.
Ask what "done" looks like. A firm that cannot answer is selling open-ended effort.
3. Measurement capability
MEASURE is where implementations diverge sharply, and where most consultancies are thin.
Ask how they would test a system like yours for bias. A good answer names the approach, the data required, the metric, the threshold, the cadence, and what happens when the threshold is crossed. It also acknowledges what cannot be measured with the data available, which is often the more useful part.
A weak answer describes bias as an important topic. That firm can do GOVERN and MAP, which may be enough, but you should know you are buying a documentation exercise.
Ask also who does the engineering. Measurement infrastructure often does not exist, and building it sits with your teams or with a supplier.
4. What they write
Ask for a redacted per-system risk record.
Not a policy and not a framework summary. The document covering one real AI system: what it does, who it affects, what could go wrong, what was measured, what the results were, what was decided and why.
That single document shows whether the firm documents reality or produces templates, and whether the measurement section contains results or intentions.
5. Whether they credit what you have
Organisations holding ISO 27001 or SOC 2 already have parts of GOVERN and MANAGE: risk processes, supplier management, incident handling, decision records.
A good consultant asks what you hold and maps it across before proposing new work. A firm that starts from zero is either not looking or is selling more than you need.
Ask directly: what of ours transfers, and what genuinely has to be built.
6. Whether they are current
The framework was published in January 2023 and has moved since. The Generative AI Profile arrived in July 2024. NIST has confirmed version 1.0 is being revised, and 2026 has brought a draft profile connecting AI risk management to the Cybersecurity Framework, a concept note for a critical infrastructure profile, control overlay work under SP 800-53, and standards work on AI agents.
Ask what has changed in the past year. A consultant working from the 2023 text is not current, and a consultant who has not applied the Generative AI Profile while you run large language models is missing the part most relevant to you.
They should also be precise on the legal position: Texas gives substantial compliance an enforcement safe harbour; Colorado's affirmative defence did not survive the May 2026 repeal.
7. Independence
Ask whether the firm takes commission from platform vendors, and who would perform an independent assessment if you needed one. A firm that would assess its own implementation without separation is not offering independence, whatever the report says.
Our position is on the about page.
The answer that shows real judgement
Ask whether you should be doing ISO/IEC 42001 instead.
A good consultant gives an honest answer that depends on your buyers: the framework if they want a recognised structure, certification if they want something verifiable against a register. A firm that always recommends its own engagement, regardless of the question, is not advising.
What a good proposal contains
Scope stated as systems and functions. A target maturity with a completion test. Deliverables listed individually, including the measurement plan. Fees itemised per phase, with independent assessment shown separately. Dated milestones. A responsibility table. The named practitioner and committed hours. And a statement of how adoption will be demonstrated at the end.
What to do next
Draft a provisional inventory and a view of what your buyers need to see, then run the seven marks across two or three firms.
Our free AI impact assessment gives a first view, our readiness and gap assessment gives the full position for a fixed fee, and the NIST AI RMF service page sets out how we work.
References
- National Institute of Standards and Technology, AI Risk Management Framework. https://www.nist.gov/itl/ai-risk-management-framework
- National Institute of Standards and Technology, AI Resource Center. https://www.nist.gov
- International Organization for Standardization, ISO/IEC 42001. https://www.iso.org
FAQ
What makes a good NIST AI RMF consultant?
Honesty that no certification exists, an agreed target maturity, real measurement capability, per-system documentation, crediting your existing work, currency on the framework, and genuine independence.
What is the fastest disqualifier?
A firm offering to certify you against the framework.
How do I test measurement capability?
Ask how they would test a system like yours for bias, and expect an approach, a metric, a threshold and a cadence.
Why does target maturity matter?
Because the framework has no endpoint, so without an agreed target the engagement has no completion test and the cost drifts.
Should a consultant ever recommend ISO/IEC 42001 instead?
Yes, where your buyers need something verifiable. A firm that never recommends anything but its own engagement is not advising.
About Hael
Hael is an advisory firm specialising in AI governance and security compliance, built on fifteen years of regulatory practice. Every engagement has a named practitioner, a written scope, an agreed target and a fixed fee. We do not offer certification against frameworks that cannot be certified, and we will tell you when a certifiable standard is the better investment. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on FCA authorisation and compliance since 2013.
This guide is general information and is not professional advice on your particular circumstances.