NIST AI RMF 1.0 · VOLUNTARY · SELF-ATTESTED

Aligned with the NIST AI Risk Management Framework.

Every audit we run is built on its four functions - and nobody on earth certifies it, including us.


A reviewer with a beard, in a navy blazer, a closed notebook at the edge of the desk, seated at a dark stone desk by a window in a warm, low-lit office, signing a printed page with further papers and a stoneware cup beside them.
Aligned with. Not certified by. There is a difference
Govern Map Measure Manage NIST AI 100-1

Our promise

“A framework is words. The profile is evidence.”

Every finding is written against a clause of the instrument itself — defensible line by line, to anyone who asks. The fee is fixed at $12,500, and nothing is charged until you approve it.

Each additional system
$3,000
Re-audit, same scope
$8,000
Renewal, every twelve months
$10,500 locked

This costs more than the estate ladder, and it should. The ladder is a private assessment written for you. A framework audit produces a published summary iDharma maintains for twelve months - a notice template where the law requires one, a 60-day expiry warning, and a quarterly check that the summary is still live and still linked.

Request this audit
The case file

The AI RMF, in three chapters

The Framework

Four functions, published by NIST in January 2023 as AI 100-1: Govern, Map, Measure and Manage. It sorts AI risk work by what an organisation actually does about that risk rather than by what it happens to build, and it is voluntary from its first page through to its very last one.

The Gap

Most teams assume there is a certificate waiting at the end of it, because somebody offered them one. There is not: neither NIST nor CAISI certifies anybody, at any tier, at any price whatsoever. A voluntary framework has no compliance state for anyone to be in.

The Office

Our audit is built on the four functions and says so in public, category by category. We map each finding to the one that it answers, record an explicit gap wherever the evidence is missing, and keep the entire working record in a hash-chained trail you can check for yourself later.

The four functions

Four functions. You run all of them.

The Core sorts work by what you do about risk, not by what you happen to build.

The two that set direction № 01
  • Govern - the culture the other three run inside
  • Policies, named owners, workforce, third-party risk
  • Map - context established before anything is tested
  • Purpose, categorisation, capabilities, impacts on people
NIST AI 100-1 · iDharma · Presented for assay
The two that prove it № 02
  • Measure - evidence, or an explicit gap. Never a guess
  • Methods, trustworthy characteristics, tracking, efficacy
  • Manage - what actually gets done about what you found
  • Prioritised treatment, vendor risk, monitoring, records
NIST AI 100-1 · iDharma · Presented for assay
Know who is speaking

The framework is theirs. The claim is ours.

NIST

Publishes the framework itself

The AI RMF 1.0 came out of NIST's Information Technology Laboratory in January 2023 as NIST AI 100-1, with the Playbook and the AI 600-1 Generative AI Profile beside it. It is voluntary by design, it is officially under revision, and it confers no status at all on anyone who follows it.

CAISI

Runs the testing, not the framework

The Center for AI Standards and Innovation - the U.S. AI Safety Institute until it was renamed in June 2025 - is industry's primary federal contact for AI testing. It publishes the AI 800 series and its model evaluations. It does not own the AI RMF, which is why we cite the two of them separately every time.

The catch

Neither of them certifies anyone

There is no “NIST certified” and no “CAISI certified” programme, in any tier, at any price. A voluntary framework has no compliance state for anyone to be in. A vendor selling you one is selling something that does not exist, and we would rather you heard that here than from them later.

What a vendor will tell you

“We’re NIST certified — and we’ll certify you.”

What is actually true

No such programme exists. Alignment is self-attested.

Including ours — which is why this page shows its working.

  • Who it is for
  • AI product teams
  • Boards & risk committees
  • Banking & insurance
  • Federal contractors
  • Procurement & vendor risk
What we say & won’t say
A row of dark leather-bound volumes standing on a shelf in low light, one of them leaning open with pale ribbon markers hanging from its pages: the published framework itself, read rather than cited.
01 We say our methodology is aligned with and mapped to the NIST AI RMF 1.0 — AI 100-1, January 2023. Those two verbs, and no stronger one.
02

We won’t say “NIST certified”, “CAISI certified”, “CAISI compliant”, or “compliant with the AI RMF”. None of them exists.

03

Reports state the framework version they were assessed against. A voluntary framework has no compliance state to be in.

04

When the AI RMF revision publishes, this page and our mapping get re-verified against it. Our alignment is self-attested, and the working record is verifiable.

The 60-second check

Three questions. Then you’ll know.

No email, no signup. A starting point, not a determination.

0 of 3

Govern -

Govern 1 and Govern 2, in one question. The framework asks for policies that are followed and accountability that lands on a person - not for a document that exists.

Map -

Bought-in and embedded AI counts. Map 1 and Map 2 ask what each system is for and who it is used on. A model inside a tool you licensed is still a system on your estate.

Measure -

A vendor’s benchmark is not your measurement. Measure 1 asks for a method appropriate to your system, applied to it. A published score for the base model does not answer it.

The calendar

Four moments, and one has not arrived.

Three of these are published and one is still ahead - so they cannot be cited as one body of guidance, and the version you read is part of the claim.

  1. AI RMF 1.0

    January 2023

    NIST AI 100-1 published, with the Playbook beside it. Still the operative version, and the one we cite.

  2. GenAI Profile

    July 2024

    NIST AI 600-1 adds the cross-sectoral profile for generative AI, and it is where our agentic tests begin.

  3. CAISI

    June 2025

    The AI Safety Institute becomes the Center for AI Standards and Innovation. Same body, broader remit.

  4. AI RMF 2.0

    Under revision

    A revision to AI 100-1 is in progress with no published date. We re-verify this page when it lands.

The trap

Two more documents get cited as if they were settled: NIST AI 800-1 and AI 800-2 are public drafts. We read both and use them, and we flag them as drafts every time — because a draft quoted as guidance is how a careful page starts overclaiming.

The mapping

What the function asks, what we do

20 categories, and the audit step that answers each one. Paired, so every claim on this page can be checked against AI 100-1 beside it.

Policies and processes Govern 1 - risk management is a culture, not a file
The audit opens on your AI policies: what exists, what is followed, and where the two differ.
Accountability structures Govern 2 - somebody owns each system, by name
Ownership traced per system to a named role, with the gaps recorded as findings rather than assumed.
Workforce capability Govern 3 - the people running it can run it
Whether the teams operating each system hold the training the policy says they do, evidenced.
Engagement with actors Govern 5 - the people affected have a route in
Feedback and complaint routes for affected users tested end to end, not read off a policy page.
Third-party AI risk Govern 6 - your supply chain is your risk
Model and vendor dependencies inventoried, with what each contract actually discharges written down.
A risk-aware culture Govern 4 - considered, and communicated
How an AI risk actually gets raised and escalated, traced through your incidents rather than your policy.
Context established Map 1 - what the system is for, and for whom
Intended purpose, users and operating context agreed in writing before any testing begins.
System categorised Map 2 - the task, the method, the deployment
Each system categorised by use and exposure, including its EU AI Act risk class where relevant.
Capabilities understood Map 3 - benchmarked, not assumed
What the system can and cannot do, checked against the benchmarks its own documentation cites.
Risks mapped Map 4 - across components, bought-in ones included
Risk mapped over the whole chain - your code, your data, and every third-party element inside it.
Impacts characterised Map 5 - to individuals, groups and society
Who is affected and how badly, ranked by consequence to those people rather than by ease of fixing.
Methods and metrics Measure 1 - appropriate to the system, and applied
The test method stated per finding, so a reviewer can repeat it rather than take our word for it.
Trustworthy characteristics Measure 2 - valid, safe, secure, fair, explainable
Each characteristic evaluated where evidence exists - and an explicit gap recorded where it does not.
Risk tracking Measure 3 - mechanisms in place and running
Whether you can detect a new risk between audits, and what happens when one of your controls fires.
Measurement efficacy Measure 4 - the measuring is measured too
Findings fed back against your own metrics, so a control that looks green is checked for why it does.
Risks prioritised Manage 1 - acted on in order of consequence
Every report closes on a roadmap ranked Immediate, Short-term and Medium-term, with owners named.
Benefit maximised Manage 2 - strategies that keep the value
Where a control would cost more than the risk it treats, the report says so instead of piling on.
Third-party risk managed Manage 3 - the bought-in parts, actively
Vendor risk carried into the roadmap with a re-check date, not closed at contract signature.
Documented and monitored Manage 4 - treatment, response and communication
Continuous Monitoring re-checks the findings monthly: report currency, control health, regulatory watch.
Our own working record Govern 1, turned back on the auditor
Every audit step written to an append-only, hash-chained trail that you can verify after the fact.
The engagement

The four functions, run in order

Their sequence, not one we invented to fit a rail.

  1. Govern

    Policies, ownership and third-party dependencies, examined first.

  2. Map

    Every AI system inventoried, categorised by use and by exposure.

  3. Measure

    Evidence-based findings only, each with a severity and a source.

  4. Manage

    A prioritised roadmap, then a monthly re-check - dated each time.

Request an AI RMF assessment
An auditor in a charcoal suit and white shirt, with grey hair, standing against a warm pale wall and pointing into the open space alongside.
The mapping is what you are buying.
Struck in your favour

Why teams choose iDharma to read the framework with them

Genuinely independent

We build, resell and operate no AI systems of our own, and take no fee tied to what we find.

Mapped, not asserted

Every finding names the AI RMF category it answers, so a reviewer can check it against 100-1.

We say what we are not

No certificate, no seal, no compliance claim - the framework has no such thing to give anyone.

Our own record is open

The trail behind your report is hash-chained and verifiable: the bar we hold you to, held to us.

Four marks, struck on every report.

Deliverables

What you get

Concrete artefacts, each with a name and a format - you know what lands before you buy.

AI RMF alignment profile

The full assessment in one document: every AI system placed against Govern, Map, Measure and Manage, each category either answered or recorded as an explicit gap, the trustworthy characteristics evaluated wherever evidence exists, and the whole of it written in plain language rather than the framework's.

Workbook

AI system register

Every system, its purpose, its owner and its status, in a workbook your own team can keep current after we hand it over.

Matrix

Function-by-function map

Each AI RMF category set against what you hold today, so a thin function shows as thin rather than averaging into one score.

Findings

Governance gap list

Policies, ownership and vendor dependencies read against Govern 1 to 6, each gap with a severity and the evidence for it.

Memo

Scope memo

Which systems were in scope, which were not, and why each call was made - the Map function's written record, and yours to keep.

Ranked

Remediation roadmap

Where the gaps sit and what to do first, ranked Immediate, Short-term and Medium-term by consequence to the people affected.

Hash chain

Verifiable audit trail

The append-only record of every audit step, hash-chained and checkable, so our Govern claim can be tested rather than believed.

Format & fee

Real numbers, upfront.

Scope
All four functions, every category
Input
Your systems and what exists on them
Re-read
Annually, or on material change - $10,500 against your known baseline

The Core fixed the scope, not us, so the fee is flat - nothing to meter, and nothing charged until you approve it.

Request this assessment
NIST AI RMF · Alignment profile $12,500 flat
  • Profile across all four functions
  • System register, purpose by purpose
  • Function-by-function gap map
  • Verifiable audit trail included
Show your hand

Four things you have to be able to produce

A voluntary framework is still evidenced or not evidenced. Each of these is either in your hand on the day a board asks, or it is not.

The estate,
inventoried

A list of every AI system you build, buy or embed, with an owner against each. Map 1 and Map 2 both start here, and nothing after them is worth more than this is.

The purpose,
written down

What each system is for, who it is used on, and what it is explicitly not for. An intended purpose held only in somebody's head cannot be governed or measured at all.

The testing,
dated

Evidence that the trustworthy characteristics were actually tested, with the method and the date on each result. Measure 1 to 4 are a practice, not a policy.

The record,
underneath

The logs, the sign-offs and the oversight decisions the report asserts, each of them dated. The record is the evidence; the report is only ever the claim about it.

Four cards, and the date on each one is part of the card.

FAQ

Plain answers

Certification, standing, and what the mapping is worth.

Request this assessment
Can we get NIST AI RMF certified?

No, and nobody can. Neither NIST nor CAISI runs a certification programme for the AI RMF - it is a voluntary framework, so there is no compliance state for anyone to certify against.

What does “aligned with the AI RMF” actually mean here?

That the engagement runs in the framework's four functions, that every finding names the category it answers, and that the mapping is published on this page for you to check rather than asserted in a deck.

Is the AI RMF mandatory for us?

Not by itself - it creates no legal obligation. What makes it feel mandatory is downstream: procurement questionnaires, boards, insurers and contract flow-downs increasingly ask for it by name.

What do you actually produce at the end?

An alignment profile across all four functions, an AI system register, a function-by-function map, a governance gap list, a scope memo, a ranked roadmap, and the hash-chained trail behind all of it.

How long does it take?

Typically two to four weeks from hand-over for a first profile, longer where the system count turns out to be bigger than expected - which it usually does. Scope is agreed before anything is charged.

Get started

Request an AI RMF assessment

Tell us about your AI systems and we come back with a scoping call within one business day.

What we need from you

Nothing you do not already have. Most of this is a folder someone can assemble in an afternoon, and we name every document first, in writing, before you commit.

  1. Which AI systems you build or use, and what each decides
  2. Any AI policy, however partial, and who signed it off
  3. Any documentation - model cards, contracts, DPIAs
  4. Whether you built the system, bought it, or modified one
  5. Your target readiness date, if you have one

What happens next

  1. You send the five items we need.
  2. You get a scoping call within one business day.
  3. Nothing is charged until you approve the scope.
Request an AI RMF assessment
Sources & standing

Where this page gets its facts

Where the claims on this page come from, and what they are worth - stated, not assumed.

What it is drawn from

  • NIST AI 100-1 - the AI RMF 1.0
  • NIST AI 600-1 - Generative AI Profile
  • NIST AI 800-1 - 2nd public draft
  • NIST AI 800-2 - initial public draft
Published
January 2023
Revision due
No date announced

What it means

  • An alignment statement, not a certification — nobody certifies the AI RMF, and our mapping is self-attested. It determines nothing about your own systems.
  • Where a mapping is arguable, our reports say so rather than the convenient thing.

Scope & limitation

  • Do not rest a binding decision on it; engage qualified counsel.
  • It covers AI RMF 1.0 alone - the EU AI Act and sectoral rules reach the same system.
  • Use it as a starting point for a scoping conversation, not as your final word.

Something on this page out of date?

Tell us