
Operate
NIST AI Risk Management Framework
The NIST framework applied to your systems — Govern, Map, Measure, Manage — producing a risk profile per system and a practice your own people can run. For organisations that need a defensible AI risk position without a certification.
Duration
4–6 weeks
Built on
NIST AI RMF 1.0 · NIST Generative AI Profile · ISO/IEC 42001
Indicative price
€8,500–19,000 per engagement
Who this is for
CISO
Already speaks NIST for cyber and is being asked the same questions about AI.
Chief risk officer
Needs AI risk expressed in the language the rest of the risk framework uses.
CEO with US exposure
Is asked by customers or investors how AI risk is managed.
Head of product
Ships AI features and needs a defensible position on what was tested.
A framework, deliberately not a checklist
The NIST AI Risk Management Framework is voluntary and it is not certifiable. That is both its strength and the reason it frustrates people: it does not tell you what to do, it tells you what you should be able to answer. For organisations with US exposure, federal or enterprise customers, or investors who ask how AI risk is managed, it is the vocabulary the question tends to arrive in.
It has four functions. Govern — culture, accountability and policy, which cuts across the other three. Map — context: what the system does, for whom, and what could go wrong for the people affected. Measure — analysis, testing and tracking, including the uncomfortable requirement to measure things that resist measurement. Manage — prioritising, responding, recovering.
Measure is where most attempts stall, and the failure is predictable. Teams measure accuracy, because accuracy is measurable, and quietly skip robustness, bias, explainability, privacy and security. The framework does not require a perfect metric for each. It requires a documented decision about what you will measure, what you will not, and why — which is a far more honest artefact than a dashboard of the convenient numbers.
It complements ISO/IEC 42001 rather than competing with it. The standard certifies that you operate a management system; the framework helps you reason about risk inside it. Where a client needs both, we run one body of work and map the outputs to each, because the underlying evidence is largely the same.
The output is a profile per system — current position against target — plus a practice: who does what, on what cadence, and what gets recorded. A framework that produces a report and no practice has not been implemented.
How we do it
- 01
Govern
1 week
Accountability, policy and culture. Who owns AI risk, where it reports, and how it connects to your existing risk framework rather than sitting beside it.
- 02
Map
1–1.5 weeks
Context per system: purpose, users, the people affected, the assumptions, the ways it could fail and what that failure would cost — to you and to them.
- 03
Measure
1–1.5 weeks
What is measured today and what is not. Test methods for the dimensions that matter, and a written decision, with reasoning, about anything you choose not to measure.
- 04
Manage
1 week
Prioritisation, response, escalation and recovery. Including the decision to decommission, which most frameworks in practice never make.
- 05
Profile and target
3–5 days
Current profile per system against the target profile you choose, with the gap sequenced and costed.
- 06
Handover
2 days
The practice: cadence, owners, templates and records, so it runs without us.
Named artefacts
What you receive
- Govern position — accountability, policy and reporting line
- Map documentation per system, including effects on affected people
- Measurement plan, with a recorded decision on what is not measured and why
- Test results for the dimensions in scope
- Manage procedures: prioritisation, response, escalation, decommissioning
- Current and target profile per system
- Gap plan, sequenced and costed
- Mapping to ISO/IEC 42001 where you also pursue the standard
- Generative AI considerations where generative systems are in scope
- Operating cadence, templates and records for your own team
What we need from you
- Your existing enterprise risk framework. This should extend it rather than stand alone.
- Technical access to the systems in scope, and the people who built or run them.
- A decision on target profile. Risk appetite is yours; we will not set it for you.
- Someone to own the practice after handover.
What changes
- 01AI risk expressed in the framework your stakeholders are asking in.
- 02A documented, defensible position on what is measured and what is not.
- 03Profiles per system rather than a single organisational assertion.
- 04A practice that runs on a cadence, with records.
- 05Reusable evidence if you later pursue ISO/IEC 42001.
What it costs
€8,500–19,000 per engagement
All prices exclude VAT.
Questions
Is it certifiable?
No. There is no certificate, and any offer of one is a misunderstanding. What you get is a documented, defensible position — which is what the people asking the question usually want. If you need a certificate, that is ISO/IEC 42001.
We are doing ISO 42001. Do we need this too?
Not necessarily. The standard covers the management system; the framework is a way of thinking about risk that many find more practical than the standard's risk clauses. Where both are wanted we run one body of work and map it to both, rather than billing twice for the same evidence.
Does it apply outside the United States?
It is a US framework and it is used worldwide, because it arrived early and it is well built. In Europe it does not replace anything the EU AI Act requires. It is common to use the framework for how you manage risk and the Act for what you are obliged to do.
What about generative AI specifically?
NIST publishes a profile for generative AI that identifies risks distinctive to those systems. Where generative systems are in scope we work through it as part of Map and Measure rather than treating it as separate work.
How long does it stay valid?
The profiles should be revisited when a system materially changes and at least annually. The practice is the durable part — once your own people run the cadence, the refresh is a fraction of the first pass.

Leave with your top three risks documented
Thirty minutes with a senior practitioner. No slideware, no sales engineer.