AI governance
Put AI risk management into daily decisions.
The NIST AI Risk Management Framework helps organizations govern, map, measure, and manage AI risks. We help translate those outcomes into an inventory, decision rights, assessment methods, monitoring, and documented treatment.
Our implementation focus
Make the requirements operational.
- 01
Define AI risk ownership and tolerance
- 02
Map systems, contexts, affected parties, and dependencies
- 03
Select proportionate evaluation and monitoring methods
- 04
Prioritize treatment and escalation paths
- 05
Connect risk records to ISO/IEC 42001 governance where useful
NIST AI RMF is voluntary guidance, not an independent certification scheme or proof of legal compliance.
Questions we hear
Get the distinctions right.
Is NIST AI RMF a certification?
No. It is voluntary risk management guidance. An organization can use it to structure practices, but it does not itself yield a certificate.
Can it complement ISO/IEC 42001?
Yes. The NIST AI RMF can inform AI risk methods inside an ISO/IEC 42001 management system, while each framework retains its own structure and purpose.
Work with Normstone
Build a defensible path to readiness.
Tell us the outcome you need and the markets involved. We’ll help define the work.