The challenge behind the engagement.
This service is for an organization that must show how it manages AI risk and has no written answer yet. We find the AI in use across the business, including the tools teams adopted on their own, and build an inventory with owner, purpose, data sensitivity, and decision impact. We measure your current practice against every part of the NIST AI RMF, using its recommended actions as the evidence checklist, and re-check generative systems against the Generative AI Profile. We set a target from leadership’s risk tolerance and overlay the state and EU AI obligations that actually bind you. You receive the inventory, a scored workbook, risk register entries, and a prioritized roadmap. No conformity program exists for these frameworks, so we never call you certified or compliant.
CISOs and compliance leads at companies that mostly buy AI, and a few that build it. The trigger is usually a customer questionnaire with an AI section, an insurer asking about AI at renewal, or counsel flagging a new state or EU deadline.
What we do.
What you can use.
Find every AI system, including the ones nobody registered
We start with an executive sponsor, the business units known to use AI, and read access to sign-in records, endpoint and browser data, and procurement lists. We interview legal, HR, product, data, and security owners. From that we build the inventory: owner, purpose, data sensitivity, model and provider, and whether the system touches a high-stakes decision.
Rate each area against evidence, not intent
For every part of the NIST AI RMF we ask for the artifact that proves it, inspect it, and rate it not implemented, partial, implemented, or not applicable, naming the evidence. Systems that generate text, code, or images get a second pass against the generative AI risks in the Profile. The state and EU obligations that apply to you are overlaid system by system.
Deliver the roadmap and the workbook behind it
You receive the scored workbook and risk register entries with likelihood, impact, and owner. The roadmap names an owner, an effort band, and dependencies for each gap, with high-stakes and regulated-data systems first. The executive summary answers the customer, insurer, and regulator questions you arrived with. Closed gaps are re-checked and the workbook updated with dated evidence.
Who it’s for.
When you need it.
- Organizations deploying vendor AI tools with no written account of how they manage AI risk
- Compliance and security leads who own the answer to customer AI questionnaires
- Companies fielding SIG or AI-CAIQ sections they currently answer from intent, not evidence
- Firms selling into Texas, the EU, or Colorado where AI obligations now carry dates
- A customer sends a questionnaire with an AI section you cannot yet answer
- An insurer asks about AI use during a cyber policy renewal
- Counsel flags your exposure under a new state or EU AI law
- Leadership approves an AI initiative and wants the risk picture first
What the scope can include.
- 01
AI inventory built from sign-in records, endpoint and browser data, procurement records, and owner interviews
- 02
Current-practice rating against every part of the NIST AI RMF, using its recommended actions as the evidence checklist
- 03
Second pass on generative systems against the risks in the Generative AI Profile
- 04
Target set from leadership risk tolerance, prioritizing high-stakes decisions, regulated data, and autonomous action
- 05
Overlay of the state and EU AI obligations that bind you, mapped to the systems they affect
- 06
Optional crosswalk of gaps to ISO/IEC 42001 for teams heading toward certification
What it typically costs.
One rate: $150/hour.
Every engagement is priced by the hours it takes at one flat rate, with scoping, the work, and the final deliverables included. Find the size closest to yours.
A handful of AI tools, mostly purchased rather than built
About 30–60 hoursSeveral AI uses across departments, including one built or customized in-house
About 60–110 hoursAI built into products or used across many business units
About 110–200 hours- Number of AI systems and use cases in scope
- Whether AI is bought, customized, or built in-house
- Number of teams and stakeholders to interview
- Existing risk, privacy, and security documentation
4–8 weeks
The NIST AI RMF has no certification; there is no separate audit fee.
Get a fixed quote for your scopeRanges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.
What you take forward.
- AI system inventory with owner, purpose, data classification, model and provider, and decision impact per entry
- Scored workbook with a cited artifact or a stated gap for every part of the framework
- Risk register entries with likelihood, impact, and owner, ready to merge into your enterprise register
- Prioritized roadmap naming owner, effort band, and dependency per gap, with an executive summary for customers and insurers
Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.
Before we get started.
We only buy AI features from vendors. Do we still need a gap assessment?
Yes, and it is usually shorter. The NIST AI RMF is written for organizations that deploy AI, not only those that build it. It still asks who approved the tool and under what rules, what data flows to it and which decisions it informs, and how you would respond if it leaked or misled. The Generative AI Profile covers exactly the risk of relying on someone else’s model. Most of your evidence will be settings, contract terms, and sign-in records rather than model testing, and the roadmap will lean toward policy, vendor review, and logging.
Does aligning with the NIST AI RMF help us with new state AI laws?
It can. Some state AI laws provide an affirmative defense for organizations that follow a recognized framework such as the NIST AI RMF, including its Generative AI Profile, and that find issues through their own testing. It is a defense your counsel argues, not a certificate anyone issues, and no conformity program exists for these frameworks. What this engagement gives you is the documentation that argument needs: a dated record of your current practice with evidence, a defined target, and a roadmap showing gaps being closed. Whether it satisfies a regulator in a given matter is a legal question we do not answer.
- AI Risk Management Framework | NIST
- Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1)
- NIST AI RMF Playbook
- ISO/IEC 42001:2023 Information technology — Artificial intelligence — Management system
- NIST SP 800-61 Rev. 3, Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile
- GenAI Incident Response Guide 1.0 - OWASP Gen AI Security Project
- AI Act | Shaping Europe’s digital future
