Aligned with the NIST AI Risk Management Framework.
Every iDharma audit is structured around the four functions of the NIST AI RMF 1.0 (NIST AI 100-1, January 2023) — Govern, Map, Measure, Manage — and we track the NIST Center for AI Standards and Innovation (CAISI) as its guidance evolves. Here is the mapping, function by function, and exactly what we do and don't claim.
Straight talk first
- The AI RMF is a voluntary framework.
- Neither NIST nor CAISI certifies anyone — no "NIST certified" or "CAISI certified" programme exists, so we will never claim one.
- Our alignment is self-attested and documented — every audit's working record is kept in a tamper-evident trail you can verify.
NIST, the AI RMF, and CAISI — who publishes what
AI RMF 1.0 (NIST AI 100-1)
Released January 2023 by NIST's Information Technology Laboratory; still the operative framework. It is officially under revision — we pin our citations to AI RMF 1.0 and will re-verify this page when the update lands.
CAISI
The Center for AI Standards and Innovation (formerly the U.S. AI Safety Institute, renamed June 2025) is industry's primary federal contact for AI testing. It publishes the NIST AI 800 series and model evaluations — it does not own the AI RMF, and we cite the two precisely.
Companion documents we use
NIST AI 600-1 (Generative AI Profile, July 2024), the AI RMF Playbook, and — flagged as drafts — NIST AI 800-1 (misuse risk for dual-use foundation models, 2nd public draft) and AI 800-2 (automated benchmark evaluations, initial public draft).
Four functions, one audit methodology
What each AI RMF function asks, and where the iDharma audit delivers it.
GOVERN
What the framework asks: A culture of risk management: policies and processes in place (Govern 1), clear accountability (Govern 2), engagement with relevant actors (Govern 5), and third-party / supply-chain AI risk handled (Govern 6).
Where iDharma delivers it: The audit opens with a governance review — AI policies, ownership and accountability structures, and third-party model/vendor dependencies are examined and gaps recorded as findings. Our own governance is held to the same bar: every audit step is recorded in an append-only, hash-chained Article 12-style trail that survives scrutiny.
MAP
What the framework asks: Context established and understood (Map 1), the AI system categorised (Map 2), capabilities and usage understood against benchmarks (Map 3), risks mapped across components including third-party elements (Map 4), and impacts to people and society characterised (Map 5).
Where iDharma delivers it: Our scoping phase is the Map function in practice: we inventory the client's AI systems, categorise each by use and exposure (including EU AI Act risk class where relevant), agree the scope in a written proposal the client approves, and collect the evidence that grounds everything later.
MEASURE
What the framework asks: Appropriate methods and metrics applied (Measure 1), systems evaluated for trustworthy characteristics (Measure 2), risk-tracking mechanisms in place (Measure 3), and measurement efficacy fed back (Measure 4).
Where iDharma delivers it: The audit itself: evidence-based findings only — where evidence is absent we record an explicit gap rather than inventing specifics. Each finding carries a severity rating, affected area, observed risk and standards mapping; risk-tier audits add structured threat scenarios. Agentic-AI test patterns are informed by CAISI's published agent-hijacking evaluation work.
MANAGE
What the framework asks: Risks prioritised and acted on (Manage 1), benefit-maximising strategies (Manage 2), third-party risks managed (Manage 3), and documented treatment, response and communication plans that are monitored (Manage 4).
Where iDharma delivers it: Every report closes with a remediation roadmap prioritised Immediate / Short-term / Medium-term, deliverable through iDharma Remediation Services or the client's own team. Continuous Monitoring then re-checks the findings checklist monthly — report currency, control health, regulatory watch — so Manage stays a practice, not a paragraph.
What we say — and won't say
We say: our methodology is aligned with and mapped to the NIST AI RMF 1.0 (NIST AI 100-1, January 2023), informed by the NIST AI 600-1 Generative AI Profile and by CAISI's draft AI 800-series guidance and published evaluations.
We won't say: "NIST certified", "CAISI certified", "CAISI compliant", or "compliant with the AI RMF". A voluntary framework has no compliance state and no government certification programme — any vendor claiming one is overreaching, and we'd rather you know that.
Audit reports state the framework version they were assessed against. When the AI RMF revision is published, this page and our mapping will be re-verified against it.