Organisations selling into the US
Federal procurement and many enterprise buyers ask how AI risk is managed in NIST terms; a profile is the answer they recognise.
Nobody is required to. These are the organisations for which the standard answers a question someone is already asking.
Federal procurement and many enterprise buyers ask how AI risk is managed in NIST terms; a profile is the answer they recognise.
Before a management system, a shared way to name intended purpose, context, impacts and metrics — the Map and Measure functions give one.
Art. 9 asks for a risk management system across the lifecycle; the framework organises it, and nothing in it substitutes for the Act's own duties.
Nobody certifies the NIST AI RMF — no scheme exists, and Veritome never implies one. The output is a profile document.
| Date | Event | What it means |
|---|---|---|
| 26.01.2023 | AI RMF 1.0 released | NIST AI 100-1, with the companion Playbook. Voluntary from the first page. |
| 26.07.2024 | Generative AI Profile | NIST AI 600-1, a companion profile for generative AI risks — the same four functions, applied. |
| 02.12.2027 | EU AI Act Annex III | The date most Annex III high-risk duties apply from. The framework organises Art. 9 risk management; it is not a harmonised standard and gives no presumption of conformity. |
The Core is four functions broken into categories and subcategories: Govern sets policies, roles, culture and third-party handling; Map establishes context, purpose, capabilities and impacts; Measure defines metrics and evaluates trustworthiness; Manage prioritises, responds and learns. NIST publications are public domain, so Veritome's catalogue carries a one-line paraphrase of every subcategory and a step names the ranges it closes.
4 phases, one per function — Govern · Map · Measure · Manage — gate-locked in that order, 12 steps in all. 4 of them — the Map steps and the trustworthiness evaluation — are answered per AI system and the rest once for the organisation, and they reuse what the EU AI Act journey already recorded about purpose, context and risk rather than asking again. The last step assembles the AI RMF profile — the document the framework itself describes as its output — as a generated PDF.
No NIST step is credited against another framework: the framework is a set of outcomes, not clauses, and the owner's verified matrix relates rather than credits. Every step carries related links to the EU AI Act's risk-management, data-governance and monitoring articles and to ISO/IEC 42001's risk and impact clauses — shown in the drawer, never counted as coverage.
| With | Records credited in both | Related only — shown, never credited | Page |
|---|---|---|---|
| EU AI Act | 0 | 21 | EU AI Act → |
| GDPR | 0 | 4 | GDPR → |
| ISO 42001 | 0 | 23 | ISO 42001 → |
| ISO 27001 | 0 | 7 | ISO 27001 → |
12 of the 12 steps carry a related link to an EU AI Act article. A related link is a supporting candidate the owner's verified matrix did not check against source text; the product shows it beside the step and never counts it as coverage. The full matrix for all five frameworks is on the frameworks page; the EU AI Act itself, article by article, is at /eu-ai-act.
The answers below are the ones the page marks up for search engines and AI assistants — the same text, nothing hidden.
A voluntary framework published by the US National Institute of Standards and Technology in January 2023 for managing the risks of AI systems. Its Core has four functions — Govern, Map, Measure, Manage — with categories and subcategories describing outcomes, and a companion Playbook suggests how to reach them.
No. No certification scheme exists for the framework and NIST does not accredit one; anyone offering a 'NIST AI RMF certificate' is offering their own badge. The framework's own output is a profile: a description of how your organisation applies the functions to its AI. Veritome generates that profile and never calls it a certificate.
No. It is a voluntary US framework and the Act does not refer to it; it is not a harmonised standard and gives no presumption of conformity. The overlap is real — Art. 9's risk-management system, Art. 10's data governance and Art. 72's post-market monitoring cover the same ground as Map, Measure and Manage — and Veritome shows those as related links beside each step without crediting them.
A description of how an organisation implements the framework's functions for a given context — its current state, its target and the gap. NIST publishes companion profiles such as the Generative AI Profile (NIST AI 600-1). In Veritome the profile is the last step of the programme, assembled from the 12 records into a PDF.
ISO/IEC 42001 is a certifiable management-system standard with auditable clauses; the NIST AI RMF is a voluntary framework of outcomes with no certification. Many organisations use the RMF's vocabulary inside an ISO/IEC 42001 system — the Map and Measure functions read naturally as the AI risk and impact assessments the standard requires.
As 12 steps across the four functions, 4 of them answered per AI system and the rest once for the organisation, closing all 72 subcategories. The programme ends in a generated profile PDF. Programmes come with a workspace; the free check shows which EU AI Act and GDPR duties a system carries first.