Trust & Standards

Aligned with the NIST AI Risk Management Framework.

Every iDharma audit is structured around the four functions of the NIST AI RMF 1.0 (NIST AI 100-1, January 2023) — Govern, Map, Measure, Manage — and we track the NIST Center for AI Standards and Innovation (CAISI) as its guidance evolves. Here is the mapping, function by function, and exactly what we do and don't claim.

Straight talk first

  • The AI RMF is a voluntary framework.
  • Neither NIST nor CAISI certifies anyone — no "NIST certified" or "CAISI certified" programme exists, so we will never claim one.
  • Our alignment is self-attested and documented — every audit's working record is kept in a tamper-evident trail you can verify.
The landscape

NIST, the AI RMF, and CAISI — who publishes what

AI RMF 1.0 (NIST AI 100-1)

Released January 2023 by NIST's Information Technology Laboratory; still the operative framework. It is officially under revision — we pin our citations to AI RMF 1.0 and will re-verify this page when the update lands.

CAISI

The Center for AI Standards and Innovation (formerly the U.S. AI Safety Institute, renamed June 2025) is industry's primary federal contact for AI testing. It publishes the NIST AI 800 series and model evaluations — it does not own the AI RMF, and we cite the two precisely.

Companion documents we use

NIST AI 600-1 (Generative AI Profile, July 2024), the AI RMF Playbook, and — flagged as drafts — NIST AI 800-1 (misuse risk for dual-use foundation models, 2nd public draft) and AI 800-2 (automated benchmark evaluations, initial public draft).

The mapping

Four functions, one audit methodology

What each AI RMF function asks, and where the iDharma audit delivers it.

GOVERN

What the framework asks: A culture of risk management: policies and processes in place (Govern 1), clear accountability (Govern 2), engagement with relevant actors (Govern 5), and third-party / supply-chain AI risk handled (Govern 6).

Where iDharma delivers it: The audit opens with a governance review — AI policies, ownership and accountability structures, and third-party model/vendor dependencies are examined and gaps recorded as findings. Our own governance is held to the same bar: every audit step is recorded in an append-only, hash-chained Article 12-style trail that survives scrutiny.

MAP

What the framework asks: Context established and understood (Map 1), the AI system categorised (Map 2), capabilities and usage understood against benchmarks (Map 3), risks mapped across components including third-party elements (Map 4), and impacts to people and society characterised (Map 5).

Where iDharma delivers it: Our scoping phase is the Map function in practice: we inventory the client's AI systems, categorise each by use and exposure (including EU AI Act risk class where relevant), agree the scope in a written proposal the client approves, and collect the evidence that grounds everything later.

MEASURE

What the framework asks: Appropriate methods and metrics applied (Measure 1), systems evaluated for trustworthy characteristics (Measure 2), risk-tracking mechanisms in place (Measure 3), and measurement efficacy fed back (Measure 4).

Where iDharma delivers it: The audit itself: evidence-based findings only — where evidence is absent we record an explicit gap rather than inventing specifics. Each finding carries a severity rating, affected area, observed risk and standards mapping; risk-tier audits add structured threat scenarios. Agentic-AI test patterns are informed by CAISI's published agent-hijacking evaluation work.

MANAGE

What the framework asks: Risks prioritised and acted on (Manage 1), benefit-maximising strategies (Manage 2), third-party risks managed (Manage 3), and documented treatment, response and communication plans that are monitored (Manage 4).

Where iDharma delivers it: Every report closes with a remediation roadmap prioritised Immediate / Short-term / Medium-term, deliverable through iDharma Remediation Services or the client's own team. Continuous Monitoring then re-checks the findings checklist monthly — report currency, control health, regulatory watch — so Manage stays a practice, not a paragraph.

Claims discipline

What we say — and won't say

We say: our methodology is aligned with and mapped to the NIST AI RMF 1.0 (NIST AI 100-1, January 2023), informed by the NIST AI 600-1 Generative AI Profile and by CAISI's draft AI 800-series guidance and published evaluations.

We won't say: "NIST certified", "CAISI certified", "CAISI compliant", or "compliant with the AI RMF". A voluntary framework has no compliance state and no government certification programme — any vendor claiming one is overreaching, and we'd rather you know that.

Audit reports state the framework version they were assessed against. When the AI RMF revision is published, this page and our mapping will be re-verified against it.

Request an AI audit Verify a report