Resources · Standards reference

How we use the NIST AI RMF.

Our work is aligned with the NIST AI Risk Management Framework and informed by ISO/IEC 42001. This page explains exactly what that means, because the phrase gets used loosely and a buyer deserves the precise version.

All resources

The two documents

What each one actually is.

NIST AI Risk Management Framework 1.0

Published by the U.S. National Institute of Standards and Technology as NIST AI 100-1 in 2023. It is organized around four functions — Govern, Map, Measure, and Manage — and it is voluntary by design. NIST offers no certification program against it, and no accreditation body issues one. It is a framework for organizing risk work, not a bar to clear.

ISO/IEC 42001:2023

Information technology — Artificial intelligence — Management system. Published December 2023 as a first edition and not currently under revision. Unlike the NIST framework, it is a management system standard, structured like ISO 27001 — policies, objectives, and the processes that deliver them, in a form an external auditor can examine.

We use the NIST framework as the public backbone and ISO/IEC 42001 as a management-system crosswalk. The framework gives leadership a shared vocabulary for AI risk that does not require anyone to become a specialist. The ISO standard supplies the discipline of an actual management system for organizations that will eventually need to demonstrate one.

The crosswalk

The four RMF functions, against our five Checkpoints.

  • GovernCultivating a risk-management culture across those who design, develop, deploy, evaluate, or acquire AI systems. Sits primarily in Checkpoint 2, Risk & Governance, and reaches into Checkpoint 3 wherever accountability lands on managers.
  • MapEstablishing context and identifying impacts across the AI lifecycle. This is Checkpoint 1, Opportunity & Readiness, together with Checkpoint 4, where we map the workflows the change will actually pass through.
  • MeasureAnalyzing, assessing, benchmarking, and monitoring risk and impact. Checkpoint 5, Adoption & Value Realization — and the reason we insist on a baseline before launch rather than after.
  • ManageAllocating resources to mapped and measured risks, and planning to respond, recover, and communicate. Distributed across Checkpoints 2 and 4, and carried into the Day 30/60/90 reviews.

The mapping is ours, not NIST’s. It is how we organize our work against the framework, offered so you can see the reasoning rather than take the alignment claim on faith.

What alignment does and does not mean

The part most vendors leave vague.

Aligned means our work is organized around the framework’s functions and vocabulary. It means the governance artifacts we build — charters, acceptable-use policies, data classification, vendor assessment, escalation paths — are structured so that someone familiar with the framework recognizes what they are looking at.

It does not mean conformity, and it cannot mean certification. There is no certification program for the NIST AI RMF; the framework is voluntary and NIST does not issue one. So if any firm offers you certification against the NIST framework, it is offering something that does not exist. ISO/IEC 42001 is a different case — it is auditable by design — but we are not an accredited certification body and we do not perform audits for that purpose.

What we do is translate both documents into organizational action: decisions, owners, workflows, and measures. That translation is the work. The frameworks support credibility; they are not the product.

We do not provide certification, legal, accounting, or investment advice. Nothing here is legal advice, and any AI-related obligation carrying regulatory weight in your jurisdiction should be reviewed by counsel.