NIST AI RMF

Extensive experience in supporting organisations conform and certify to existing ISO management system standards

Speak to Information Security Expert

Having assisted over 400 organisations to achieve ISO 27001 certification URM are the ideal experts and partners to help you certify.

Speak to one of our experts for more information on how we can help. Simply call 0118 206 5410 or use the contact form.

Contact us

NIST AI RMF

In 2023, the National Institute of Science and Technology (NIST) released its Artificial Intelligence Risk Management Framework (AI RMF), which is aimed at managing risks to individuals, organisations and society that are posed by AI.  Whilst alignment with the NIST AI RMF is voluntary, its adoption is extremely valuable in demonstrating to existing and prospective clients that your organisation’s systems are secure, trustworthy, and ethical, as well as supporting your compliance with regulations such as the EU AI Act.

The NIST AI RMF is organised into 4 Core Functions (Govern, Manage, Map and Measure), each of which address similar topics from different perspectives, covering governance activities, implementation and measurement of activities.  It is designed to be sector agnostic, and therefore applies broadly across industries that develop, deploy or use AI systems.

The Framework is considered a living document and will be updated as technologies and risks evolve.  As such, alignment with the NIST AI RMF will enable you to continuously adapt your organisation’s use of AI to emerging challenges, stay ahead of regulatory developments, and implement best practices that reflect the latest advancements in AI governance and risk management.

We were incredibly impressed with our consultant’s attention to detail during the reworking of many documents and the in-year assessment last month. He stood up and had his finger on the pulse and was a great help. He is liked by our team, and we look forward to a long working relationship with him.
Waste management company

Gap Analysis

URM’s consultants can conduct a gap analysis to facilitate your alignment with the NIST AI RMF. Our approach involves a comprehensive evaluation of your current AI systems and risk management practices to both identify where you are already following the guidance set out in the Framework, and any areas requiring improvement.  The output of the analysis is a report, in which we provide a detailed breakdown of your current alignment status and recommend appropriate actions your organisation can take to achieve full alignment with the Framework.

I am pleased to recognise the work of the URM internal auditor we have worked. Throughout all the audits carried out, he has consistently demonstrated professionalism, diligence, and a commitment to excellence in every task undertaken. Thanks to his efforts, we have achieved a very successful first stage ISO 27001:2022 certification audit, with zero findings noted, which has positioned us on track for the second stage audit and for long-term success.
Utilities solutions provider

Get in touch

Please note, we can only process business email addresses.

Why URM for NIST AI RMF?

Track record

URM has a 20-year track record of providing high-quality training and consultancy services, assisting organisations to improve their governance and risk management programmes.  Whilst the NIST AI RMF is a relatively new framework and AI an emerging and rapidly evolving field, URM’s extensive experience supporting organisations to implement other NIST frameworks, such as the NIST Cybersecurity Framework (CSF), means we are ideally positioned to support your alignment with the AI RMF.  

Tailored solutions

We at URM appreciate that the use and development of AI will never be the same across any two organisations and, therefore, neither will the AI risk management programme.  The unique requirements of your organisation, its industry, size and structure, risk appetite, products and services provided, legal and obligatory requirements, etc., will always shape the approach we take in supporting your alignment with the NIST AI RMF.  Meanwhile, we will ensure the advice and guidance we offer you reflects your existing culture and working practices, enabling you to integrate AI risk management into business-as-usual operations as seamlessly as possible.

Knowledge transfer

One of the most fundamental aspects of the way we work at URM is our ‘real world’ knowledge transfer philosophy.  This enables you to benefit from our large team of consultants’ extensive practical experience and knowledge of AI best practice and, ultimately, independently improve your AI risk management by virtue of what you have learned from them, without needing to rely on ongoing consultancy support.

Without doubt, URM helped us to achieve our planned objectives a lot sooner than expected. The engagement was a huge success and couldn’t have gone any better.
Postal service company
We were incredibly impressed with our consultant’s attention to detail during the reworking of many documents and the in-year assessment last month. He stood up and had his finger on the pulse and was a great help. He is liked by our team, and we look forward to a long working relationship with him.
Waste management company

Establishing Organisational Control Over Artificial Intelligence

Published on
22/11/2024

URM’s blog discusses the need for policy in relation to the use of AI, real-world cases where AI has caused organisations issues & how to create an AI policy.

Read more
Thumbnail of the Blog Illustration
Information Security
Published on
8/8/2025
ISO 27001: How Certification Works

URM’s blog breaks down the ISO 27001 certification process, the roles of certification bodies and UKAS, what auditors look for during assessments, and more.

Read more
Thumbnail of the Blog Illustration
Information Security
Published on
18/7/2025
ISO 27001:2022 - A.5 Organisational Controls (Business Continuity)

URM’s blog explores the ISO 27001 business continuity controls, why they matter, & how they can be effectively implemented to ensure conformance to the Standard

Read more
Thumbnail of the Blog Illustration
Information Security
Published on
3/7/2025
ISO 27001:2022 - A.5 Organisational Controls (Incident Management)

URM’s blog breaks down the six incident management-related controls in Annex A of ISO 27001, providing key guidance on how to implement each control.

Read more
"
URM were super helpful and knowledgeable, talking and walking me through each one of the tests and providing some useful information on security and how to improve things in the future.