The US voluntary framework for governing AI risk, structured around Govern, Map, Measure and Manage. The practical counterpart to ISO 42001.
The NIST Artificial Intelligence Risk Management Framework is voluntary guidance published by the US National Institute of Standards and Technology for managing risks arising from AI systems. It is organised around four functions:
It is not certifiable. There is no NIST AI RMF certificate and no assessment scheme. Its value is as a structure for doing the risk work well.
The most useful way to hold these two: the RMF is the risk framework and ISO/IEC 42001 is the certifiable management system. They cover much of the same ground with different purposes. The RMF is often the more practical guide to actually doing AI risk assessment; 42001 is what produces something a buyer or regulator can be shown.
Organisations frequently use both — the RMF to structure the work, 42001 to certify the result.
Particularly where decisions affect individuals and the governance questions are real rather than theoretical.
Where the RMF is a recognised reference point and US counterparties expect familiarity with its language.
The RMF's risk methodology feeds directly into a 42001 management system, so it is a sound way to start the substantive work before committing to certification.
Where the objective is genuinely managing AI risk rather than demonstrating it to a third party.
The GOVERN function comes first and underpins the rest: who is accountable for AI risk, how decisions are made and escalated, and what the organisation's risk tolerance actually is.
Context, intended use, and an inventory of AI systems in use or development — including models embedded in third-party products. This step consistently surfaces more than expected.
Analyse and track risks, including the ones that resist measurement: bias, explainability, robustness. The framework is honest that some of these are difficult, which is more useful than pretending otherwise.
Prioritise and treat risks, with human oversight designed into consequential decisions rather than asserted after the fact.
AI risk changes as models, data and usage change. Point-in-time assessment ages faster here than in almost any other domain.
Where a buyer or regulator wants evidence, the RMF work feeds directly into an ISO 42001 management system.
Soveriq uses the AI RMF as the practical structure for AI risk work — governance, inventory, impact assessment, oversight design — and then maps it into ISO 42001 where a certificate is needed. Doing them in that order means the risk work drives the management system rather than the other way round.
For organisations operating across Australian and US markets, one AI governance programme can answer both, and we scope it that way.
Being direct about what this is. There is no NIST AI RMF certificate. The framework's value is in the quality of the risk work, not in a credential. If what you need is something to show a buyer, we will say so and point you at 42001 rather than selling you a framework adoption you cannot evidence externally.
Modules 03 and 04 do not apply in the certification sense. Where the work supports ISO 42001 certification, those modules apply to that programme.
Engagements in this area are scoped and priced in writing after a scoping call, usually within one business day.
No. It is voluntary guidance with no certification scheme. If you need a certificate a buyer or regulator will recognise, that is ISO 42001.
Both, usually, and in that order. Use the RMF to structure the risk work because it is more practically written; use 42001 to certify the resulting system. They are complementary rather than competing, and organisations that treat them as alternatives generally end up doing the work twice.
No. The EU AI Act is legislation. The RMF is voluntary guidance. There is overlap in what they ask for, so RMF work is a reasonable foundation, but neither the RMF nor any certificate constitutes legal compliance.
Yes. The governance questions are not jurisdiction-specific. Where it particularly helps is with US counterparties, where the RMF is a recognised reference point and speaking its language shortens the conversation.
Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.
Book to Scope