Hael
Book a meeting
NIST AI RMF · Compliance

What Is NIST AI RMF Compliance?

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 7 min read
Key takeaways
  • There is no NIST AI RMF certification, no accredited body and no audit. "Compliant" is not a status anyone confers.
  • What organisations mean by compliance is that they have adopted the framework, applied it to their AI systems, and can show the work.
  • The evidence is the product: an AI inventory, risk documentation per system, measurement results, and records of decisions.
  • Independent assessment by a third party is how organisations give a buyer something checkable. It is an assessment, not a certificate.
  • Texas is the one place substantial compliance carries a defined legal benefit.

So what does compliance mean?

There is no such thing as being certified compliant with the NIST AI Risk Management Framework. No accredited body issues a certificate, no audit exists, and NIST does not assess anyone.

That is not a technicality. It changes what you are buying, what you can claim to customers, and how you should think about the whole exercise. Any supplier offering NIST AI RMF certification is describing something they invented, and a well-informed buyer will notice.

In practice, when an organisation says it is NIST AI RMF compliant, it means four things.

It has adopted the framework as its approach to AI risk, formally and with leadership behind it.

It has applied the four functions to its actual AI systems, rather than to a policy document.

It holds documentation showing the work: what was mapped, what was measured, what was managed, and what was decided.

It can produce that documentation when a customer, an investor or a regulator asks.

The framework is outcome-based rather than prescriptive, so there is no single correct implementation. What makes a claim credible is the evidence behind it, not the claim itself.

What evidence to hold

FunctionEvidence that demonstrates it
GOVERNAI policy, named accountability, risk tolerance statement, third-party AI management process, records of governance decisions
MAPAI system inventory, context documentation per system, intended use and foreseeable misuse, affected people identified, impact assessment
MEASURETest and evaluation results, performance and bias metrics, monitoring outputs, records of what was measured and when
MANAGERisk prioritisation, treatment decisions with reasoning, incident records, recovery plans, evidence of resources allocated

The inventory and the per-system records are the core. An organisation that can list its AI systems, name an owner for each, and produce the risk documentation for any one on request is in a defensible position. One with a strong AI policy and no per-system record is not, whatever the policy says.

How organisations prove it to buyers

This is the practical problem the framework does not solve, and it is where most of the real work sits.

A self-attestation. A written statement describing how you have adopted the framework, at what maturity, with what scope. Cheap, fast, and worth exactly what the reader thinks your word is worth.

A completed questionnaire. Many enterprise security reviews now include AI sections structured around the framework's functions. Answering them from a real evidence base is faster and more convincing than answering them from memory.

An independent assessment. A third party assesses your implementation against the framework and issues a report describing what it found. It is not a certificate and should never be presented as one, but it is checkable, and for buyers who care it is the difference between a claim and a finding. This is covered in NIST AI RMF - Independent Assessment Consultants.

A certification against something adjacent. ISO/IEC 42001 is certifiable, covers substantially overlapping ground, and produces a certificate a buyer can verify. Organisations that need something checkable often implement the NIST framework and certify to ISO/IEC 42001, using the NIST crosswalk. See our ISO/IEC 42001 service page.

What compliance does not give you

It does not satisfy the EU AI Act. The Act attaches per-system obligations with fixed dates that no voluntary framework discharges, although the work transfers. See our EU AI Act service page.

It does not satisfy state privacy or automated decision laws, which impose their own notice, review and disclosure duties.

It does not cover information security. That is ISO 27001 or SOC 2 territory, and buyers usually ask for one of those alongside.

What to do next

Decide what you actually need to produce. If the answer is "something a buyer can check", plan for either an independent assessment or ISO/IEC 42001 certification from the start, because both shape how you document the work.

Our free AI impact assessment gives a first view, and our readiness and gap assessment produces a subcategory-by-subcategory position for a fixed fee.

References

FAQ

Is there a NIST AI RMF certification?

No. There is no accredited body, no certificate and no audit. Any supplier offering certification is describing something outside the framework.

How do we prove we follow the framework?

Through documentation, a completed questionnaire, an independent third-party assessment, or by certifying to an adjacent standard such as ISO/IEC 42001.

Is NIST AI RMF compliance legally required?

No. Texas gives substantial compliance an enforcement safe harbour. Elsewhere it is recommended practice with no direct legal effect.

Does it cover generative AI?

Yes, through the Generative AI Profile, NIST AI 600-1, which adds twelve generative-specific risks mapped to the four functions.

Does it replace ISO 27001 or SOC 2?

No. Those cover information security. The AI framework covers AI risk, and buyers commonly ask for both.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance, built on fifteen years of regulatory practice advising firms through authorisation, supervision and examination. We take companies through the NIST AI Risk Management Framework, ISO/IEC 42001, the EU AI Act, SOC 2 and ISO 27001. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on FCA authorisation and compliance since 2013.

This guide is general information and is not professional advice on your particular circumstances.

Free check

See where you stand on NIST AI RMF, free.

Answer a short set of questions and see what NIST AI RMF expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether NIST AI RMF applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to NIST AI RMF.

Or speak to us about your deadline. Book a meeting.