NIST AI RMF · AI 100-1 · FOUR FUNCTIONS

It’s voluntary. You’re going to do the work anyway.

Four functions, 19 categories and seven characteristics - and the framework your contracts and vendor questionnaires actually name.


A compliance professional seated at a desk in a warm, low-lit office, signing a printed document with a pen, further papers and a cup of coffee on the desk beside them and a window throwing daylight across the page.
Voluntary is not the same as optional
GOVERN MAP MEASURE MANAGE 19 categories

Our promise

“A framework is words. The profile is evidence.”

Every finding is written against a clause of the instrument itself — defensible line by line, to anyone who asks. The fee is fixed at $12,500, and nothing is charged until you approve it.

Each additional system
$3,000
Re-audit, same scope
$8,000
Renewal, every twelve months
$10,500 locked

This costs more than the estate ladder, and it should. The ladder is a private assessment written for you. A framework audit produces a published summary iDharma maintains for twelve months - a notice template where the law requires one, a 60-day expiry warning, and a quarterly check that the summary is still live and still linked.

Request this audit
The case file

NIST AI RMF, in three chapters

The Framework

NIST published the AI Risk Management Framework in January 2023 as AI 100-1. It sorts AI risk work into four functions — GOVERN, MAP, MEASURE and MANAGE — holding 19 categories, and names seven characteristics trustworthy AI has to demonstrate. It binds nobody at all.

The Gap

Most teams read “voluntary” and file it behind the things that are not. Then a federal contract clause names it, or a customer’s questionnaire does, or an insurer asks which AI risk framework you run. The work was never optional — only the label ever was, and it is what gets asked.

The Office

We are the independent assessor a voluntary framework has no way to appoint. iDharma works every category of all four functions, tests the seven characteristics rather than asserting them, and hands you a current profile, a target profile and the gap between the two.

What is NIST AI RMF?

A structure for work you are already doing.

A voluntary US framework: AI risk in four functions and 19 categories - and it certifies nobody, including us.

Who is asked for this № 01
  • Federal agencies, and suppliers reached through their terms
  • Finance, health and insurance supervisors
  • Enterprises also answering the EU AI Act or ISO 42001
  • Anyone deploying an AI system that reaches people
AI RMF 1.0 · iDharma · Presented for assay
What the four functions do № 02
  • GOVERN — the policy and ownership the rest runs inside
  • MAP — the context, so risk is read against real use
  • MEASURE — the methods and tracking, fixed in advance
  • MANAGE — the treatment, monitoring and response
AI RMF 1.0 · iDharma · Presented for assay
Why bother at all

The risk is yours. The framework is free.

You

Whoever deploys the system

AI RMF puts the risk with the organisation that puts a system in front of people. Knowing what your systems do, testing them, watching them and writing it down are yours whether or not you ever name the framework. None of it can be discharged by somebody else who sells you a tool.

NIST

The people who wrote it

Publishes the framework, the Playbook and the profiles, free, and certifies nobody. There is no NIST audit, no NIST certificate and no NIST register of conforming organisations. A vendor selling you one is selling you something the framework itself never defines, at any point in the document.

The catch

When voluntary stops being optional

Voluntary describes the document, not the ask that reaches you. Federal contract terms, enterprise vendor questionnaires and insurer diligence increasingly name AI RMF - and there it binds you contractually rather than legally, which spends in exactly the same way once the contract has been signed.

What most teams assume

“It’s voluntary, so it waits until something binds.”

What actually happens

The label is voluntary. The work never was.

By the time it is asked for, it is already late.

  • Who it is for
  • Federal suppliers
  • Regulated industries
  • Global enterprises
  • AI developers
  • Model deployers
Voluntary, and increasingly not optional
A row of dark leather-bound volumes on a shelf, one pulled forward at an angle with a cloth marker down its spine and a row of paper tabs standing out of the top edge - the reference everybody cites, opened by somebody at last.
01 No penalty, no certificate. What it carries is the vocabulary three other regimes settled on - which is why it keeps arriving in other people’s paperwork.
02

The EU AI Act is not optional where your AI reaches that market. AI RMF is not a substitute for it - it is the engine that feeds it.

03

ISO 42001 is the only one of the three you can hand somebody a certificate for. AI RMF is what you do in order to be ready for that audit.

04

For most enterprises all three of them are live at once - which is the argument for one mapped assessment rather than three overlapping ones.

The 60-second read

Three questions. Then you know where to start.

No email. No signup. There is no in-scope test to fail.

0 of 3

Who is asking -

Somebody usually is, before you notice. It rarely arrives as a letter - it is a clause in a renewal, a row on a questionnaire, or a board paper that wants a name in it.

Generative AI -

Bought-in counts. A wrapper around somebody else’s model is your generative system here. So is the assistant a team stood up on a corporate card.

What exists -

Written down, and findable. A policy nobody can produce on the day is not evidence. Nor is a model list that stops at what was built in-house.

The 24-week roadmap

Four functions, and the order is the argument.

One function per phase, in the order the framework runs them - govern, then map, then measure, then manage.

  1. GOVERN

    Weeks 1-4

    Ownership, a written risk tolerance and the inventory. Six categories, and the rest measures against it.

  2. MAP

    Weeks 5-10

    Purpose, data, setting and affected groups, per system. Five categories, and done badly the rest measures little.

  3. MEASURE

    Weeks 11-18

    Methods fixed before the results exist, then the seven characteristics tested. Four categories, and the longest.

  4. MANAGE

    Weeks 19-24

    Treatments owned, monitoring running, incidents routed. Four categories, most skipped, the one others see.

The trap

The weeks above are elapsed position, not effort, and the phases overlap. Read as four consecutive sprints to be added up they come to well over 24 - and a plan built on that arithmetic will be a year long before anyone has tested anything.

Ask & coverage

What the framework asks, what we ship

12 asks across all four functions, and the artefact that answers each one.

A named framework to point at What a questionnaire or a board is actually asking for
A written statement of which framework you run and how far - so the answer is a document, not a claim.
Evidence that counts more than once The same work read against the EU AI Act and ISO 42001
Each finding tagged to its AI RMF category, its Act article and its ISO control.
GOVERN 1 - policy and risk tolerance A documented position, not an implied one
The tolerance you have actually set, who set it, and when it was last revisited.
GOVERN 2-5 - accountability and people Owners, competency, and engagement with affected groups
Named owners with escalation paths, a competency read across the roles, and the engagement record.
GOVERN 6 - third-party AI Buying a model in does not move the risk off you
Vendor terms and inherited-risk records - the weakest area in most programmes we assess.
MAP 1-5 - context and categorisation EU AI Act Article 11 and Annex IV cover the same ground
A context record per system: purpose, data, setting, limits, and who the output reaches.
MEASURE 1 - methods and metrics Chosen before the results are known, or they are not methods
A plan naming a test, a threshold and an owner per characteristic - a series, not a one-off.
MEASURE 2 - the seven characteristics Valid, safe, secure, accountable, explainable, private, fair
Independent testing against all seven, with the test conditions recorded beside every figure.
MEASURE 2 - harmful bias managed Systemic, computational and human-cognitive, by name
Subgroup performance rather than aggregate accuracy, with the group definitions stated.
MEASURE 3-4 - tracking and feedback The mechanism, not the intention
Monitoring on the same metrics the assessment used, so a change means a change in the system.
MANAGE 1-3 - treatment and priority Ranked by consequence to people, not by ease of fixing
A treatment register with owners and dates - including the risks you accepted, and why.
MANAGE 4 - response and recovery EU AI Act Articles 72-73 ask for the same records
An incident path with severity, owner and closure, plus the re-assessment cadence.

The EU AI Act and ISO 42001 references above are iDharma's working map, not NIST's published crosswalk. NIST maintains its own, and where the two differ, NIST's counts.

The engagement

Your AI, independently assessed

From a single scoring model to an estate nobody has counted.

  1. Intake

    Which systems are in scope, and which categories each one engages.

  2. Assess

    All four functions, and the seven characteristics tested rather than asserted.

  3. Profile and hand over

    You see the draft first. Then both profiles and the gap - ranked by consequence.

Request an assessment
An auditor in a charcoal trouser suit and cream blouse, with dark hair pinned back, standing against a warm pale wall and pointing into the open space alongside.
A series you can re-run, not a score you have to trust.
Struck in your favour

Why teams choose iDharma as their AI RMF assessor

Genuinely independent

We build, resell and operate no AI systems, and we take no fee tied to what the assessment finds.

Written to the framework

Each finding lands on a named category, so a reviewer can check it against NIST's own wording.

One assessment, three asks

Findings carry their EU AI Act article and ISO 42001 control too, so the work counts once, not thrice.

GenAI read separately

Generative systems are also read against NIST AI 600-1, not squeezed into the base Core alone.

Four marks, struck on every assessment.

Deliverables

What you get

Concrete artefacts, each with a name and a format - you know what lands before you buy.

AI RMF assessment report

The full assessment: scope, method, every category read and what was found - all four functions and all 19 categories, results against the seven trustworthiness characteristics, the evidence behind each finding, and every judgement call recorded as a judgement call, signed by an independent assessor.

Workbook

Current and target profiles

Where you are and where you intend to be, category by category, in a workbook your own team can re-score next year without asking us.

Matrix

Cross-framework map

Each finding against its EU AI Act article and ISO 42001 control, so the same evidence answers a regulator, a certifier and a customer.

Templates

Policy and record pack

The governance documents the framework names - tolerance statement, roles, testing procedure, incident plan - drafted for your setup.

Records

AI system context records

One record per system carrying what MAP asks for: purpose, data, deployment setting, capabilities, limits, and who the output reaches.

Ranked

Remediation shortlist

What to close first and why, ranked by consequence to the people a system reaches rather than by how easy the fix would be to write up.

Memo

Generative AI Profile read

Your generative systems against NIST AI 600-1 - confabulation, leakage, provenance, over-reliance - rather than squeezed into the base Core.

Format & fee

Real numbers, upfront.

Scope
All four functions, all 19 categories
Evidence
Your systems, records and test data
Re-assay
Every rolling twelve months - $10,500 against your known baseline

The framework fixes the read, so only the estate is counted at intake - nothing charged until you approve it.

Request this assessment
AI RMF · Named engagement $12,500 flat
  • All four functions, all 19 categories
  • The seven characteristics, tested
  • Current and target profiles, with gaps
  • GenAI Profile overlay where it applies
Show your hand

Four things you have to be able to produce

Nobody grades an AI RMF programme on intent either. Each of these is either in your hand on the day someone asks, or it is not.

The register,
current

Every AI system you run, with the context MAP asks for. A register that stops at what was built in-house and never reaches what was bought is the commonest gap.

The tolerance,
set

How much AI risk this organisation has decided to accept, who decided it and when. GOVERN asks for a documented position, not one implied by what teams do.

The tests,
by method

Results against the seven trustworthiness characteristics, with the method fixed before the results existed. That order is what makes them evidence at all.

The gap,
ranked

Current profile, target profile, and the distance between them. The framework is explicit that the gap, and not a score out of five, is what an assessment produces.

Four cards, and the date on each one is part of the card.

FAQ

Plain answers

Mandatory, certification, ISO 42001 and timing. Answered straight.

Request this assessment
Is NIST AI RMF mandatory?

No. It is voluntary and carries no penalty of its own. What makes it feel mandatory is where it gets referenced - federal contract terms, vendor questionnaires, insurer diligence - and there it binds you contractually rather than legally.

If it is voluntary and there is no certificate, what do we get out of it?

A structure the other regimes accept as evidence, in a vocabulary your auditors, customers and board already recognise. The work itself is not optional under any regime that might reach you. Only the label is.

What is the difference between NIST AI RMF and ISO 42001?

Certifiability, mostly. ISO/IEC 42001 is a management-system standard you can hold a certificate for; AI RMF has no certification scheme at all. AI RMF is better at structuring the risk work, ISO 42001 at proving the system around it is managed.

Can we be certified against NIST AI RMF?

No, and nobody can offer it: there is no conformity assessment scheme, no accredited body, no NIST register. What you can have is an independent assessment saying what was tested and what was found.

How long does implementation take?

The roadmap on this page runs 24 weeks for an organisation with a few systems and no existing AI governance. The weeks are elapsed position rather than effort, and the phases overlap. A single high-stakes system takes weeks.

Get started

Request your assessment

Tell us what you run, and we come back with a scoping call within one business day.

What we need from you

Nothing you do not already have. Most of this is an afternoon with whoever knows where the models are, and we tell you exactly what we need before you commit.

  1. Which AI systems you run, and what each of them decides
  2. Whether any are generative, and who they are in front of
  3. Any policy, risk tolerance or ownership doc you have
  4. Whatever testing has been done, however informal
  5. Which other framework is also in play, if one is

What happens next

  1. You send the five items we need.
  2. We call to scope it within one business day.
  3. Nothing is charged until you approve the scope.
Request an assessment
Sources & standing

Where this page gets its facts

Where the claims on this page come from, and what they are worth - stated, not assumed.

What it is drawn from

What it means

  • General information about what the framework describes — not legal advice, and no professional relationship.
  • Where a reading is genuinely arguable, our reports say so rather than pick the convenient answer.

Scope & limitation

  • The EU AI Act and ISO 42001 references above are iDharma's working map, not NIST's published crosswalk. NIST maintains its own, and where the two differ, NIST's counts.
  • It covers AI RMF alone - the EU AI Act, ISO 42001 and your sector regulator bind you separately.
  • Nothing here is a certification, because none exists. Use it as a starting point for a scoping conversation, not as your final word.

Something on this page out of date?

Tell us