Hael
Book a meeting
NIST AI RMF · Choosing a firm

Recommendations for a Good NIST AI RMF Compliance consultant

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 8 min read
Key takeaways
  • Score candidates on seven things: honesty about certification, target maturity, measurement capability, written work, crediting existing work, currency, and independence.
  • The certification question is the first filter and it eliminates firms quickly.
  • Measurement capability is the second. Ask how they would test a system like yours for bias.
  • Insist on an agreed target maturity, or the engagement has no completion test.
  • A good consultant will tell you when ISO/IEC 42001 is the better spend.

The seven marks

A good NIST AI RMF consultant does three things a weaker one does not. They tell you plainly that no certification exists and set out how you will demonstrate adoption instead. They agree a target maturity, so the work has a completion test. And they can design measurements that actually test something.

Everything below tests for those. Use it as a scorecard across two or three firms.

MarkWhat good looks likeHow to test it
Honesty about certificationStates plainly that none exists and explains the alternativesAsk whether they can certify you
Target maturityProposes a level and a completion testAsk what "done" looks like
Measurement capabilityCan specify a real test with data, metric, threshold and cadenceAsk how they would test a system like yours for bias
Written workPer-system records describing real systemsAsk for a redacted example
Crediting existing workMaps what you already have from ISO 27001, SOC 2 or GDPR workAsk what of ours transfers
CurrencyKnows the framework is being revised and what profiles are in developmentAsk what changed in the last year
IndependenceNo commission arrangements, and a separate practitioner for assessmentAsk directly, in writing

1. The certification question

Ask first, because it disqualifies fastest.

There is no NIST AI RMF certification: no accredited body, no scheme, no register. A firm that offers one has either misunderstood the framework or is willing to misrepresent it, and either way you should not have them writing documents a buyer will scrutinise.

A good answer is direct: no, none exists, and here are the ways organisations demonstrate adoption instead, being a self-attestation, a questionnaire answered from evidence, an independent assessment, or certification against ISO/IEC 42001 via the published crosswalk.

2. Target maturity

The framework has no endpoint. There is always another subcategory to deepen.

A good consultant proposes a target: this level of maturity, for these systems, by this date, because your buyers and your risk position require it. That target is what makes the engagement finite and the fee meaningful.

Ask what "done" looks like. A firm that cannot answer is selling open-ended effort.

3. Measurement capability

MEASURE is where implementations diverge sharply, and where most consultancies are thin.

Ask how they would test a system like yours for bias. A good answer names the approach, the data required, the metric, the threshold, the cadence, and what happens when the threshold is crossed. It also acknowledges what cannot be measured with the data available, which is often the more useful part.

A weak answer describes bias as an important topic. That firm can do GOVERN and MAP, which may be enough, but you should know you are buying a documentation exercise.

Ask also who does the engineering. Measurement infrastructure often does not exist, and building it sits with your teams or with a supplier.

4. What they write

Ask for a redacted per-system risk record.

Not a policy and not a framework summary. The document covering one real AI system: what it does, who it affects, what could go wrong, what was measured, what the results were, what was decided and why.

That single document shows whether the firm documents reality or produces templates, and whether the measurement section contains results or intentions.

5. Whether they credit what you have

Organisations holding ISO 27001 or SOC 2 already have parts of GOVERN and MANAGE: risk processes, supplier management, incident handling, decision records.

A good consultant asks what you hold and maps it across before proposing new work. A firm that starts from zero is either not looking or is selling more than you need.

Ask directly: what of ours transfers, and what genuinely has to be built.

6. Whether they are current

The framework was published in January 2023 and has moved since. The Generative AI Profile arrived in July 2024. NIST has confirmed version 1.0 is being revised, and 2026 has brought a draft profile connecting AI risk management to the Cybersecurity Framework, a concept note for a critical infrastructure profile, control overlay work under SP 800-53, and standards work on AI agents.

Ask what has changed in the past year. A consultant working from the 2023 text is not current, and a consultant who has not applied the Generative AI Profile while you run large language models is missing the part most relevant to you.

They should also be precise on the legal position: Texas gives substantial compliance an enforcement safe harbour; Colorado's affirmative defence did not survive the May 2026 repeal.

7. Independence

Ask whether the firm takes commission from platform vendors, and who would perform an independent assessment if you needed one. A firm that would assess its own implementation without separation is not offering independence, whatever the report says.

Our position is on the about page.

The answer that shows real judgement

Ask whether you should be doing ISO/IEC 42001 instead.

A good consultant gives an honest answer that depends on your buyers: the framework if they want a recognised structure, certification if they want something verifiable against a register. A firm that always recommends its own engagement, regardless of the question, is not advising.

What a good proposal contains

Scope stated as systems and functions. A target maturity with a completion test. Deliverables listed individually, including the measurement plan. Fees itemised per phase, with independent assessment shown separately. Dated milestones. A responsibility table. The named practitioner and committed hours. And a statement of how adoption will be demonstrated at the end.

What to do next

Draft a provisional inventory and a view of what your buyers need to see, then run the seven marks across two or three firms.

Our free AI impact assessment gives a first view, our readiness and gap assessment gives the full position for a fixed fee, and the NIST AI RMF service page sets out how we work.

References

FAQ

What makes a good NIST AI RMF consultant?

Honesty that no certification exists, an agreed target maturity, real measurement capability, per-system documentation, crediting your existing work, currency on the framework, and genuine independence.

What is the fastest disqualifier?

A firm offering to certify you against the framework.

How do I test measurement capability?

Ask how they would test a system like yours for bias, and expect an approach, a metric, a threshold and a cadence.

Why does target maturity matter?

Because the framework has no endpoint, so without an agreed target the engagement has no completion test and the cost drifts.

Should a consultant ever recommend ISO/IEC 42001 instead?

Yes, where your buyers need something verifiable. A firm that never recommends anything but its own engagement is not advising.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance, built on fifteen years of regulatory practice. Every engagement has a named practitioner, a written scope, an agreed target and a fixed fee. We do not offer certification against frameworks that cannot be certified, and we will tell you when a certifiable standard is the better investment. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on FCA authorisation and compliance since 2013.

This guide is general information and is not professional advice on your particular circumstances.

Free check

See where you stand on NIST AI RMF, free.

Answer a short set of questions and see what NIST AI RMF expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether NIST AI RMF applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to NIST AI RMF.

Or speak to us about your deadline. Book a meeting.