NIST AI RMF — a profile, not a certificate
The US framework a counterparty may ask for: Govern, Map, Measure, Manage. Veritome produces the profile document from approved records; there is no certification to obtain.
The NIST AI Risk Management Framework 1.0 (January 2023) is voluntary guidance from the US National Institute of Standards and Technology: four functions — Govern, Map, Measure, Manage — broken into categories and subcategories, with a companion Playbook of suggested actions.
Why you would switch it on
Because a US customer, investor or partner asked. It is the vocabulary US procurement speaks, and most of what it asks for you will already have produced for the EU AI Act and ISO/IEC 42001 — a governance structure, an inventory, a risk method, measurement and monitoring.
What you get, and what you do not
You get a NIST AI RMF profile: a document that states, function by function, what your organisation does and where the evidence is. You do not get a certificate — no certification exists for the NIST AI RMF, no body accredits against it, and Veritome will not imply one. The programme ends in the profile, not in a readiness gate.
In Veritome
Switch it on under Frameworks: a programme in four phases named for the functions — Govern · Map · Measure · Manage — with some steps scoped to a system rather than the organisation. Every step produces a section of one document, the AI RMF Profile, which is composed from the approved records on every request, hashed, minted as organisation evidence and downloadable as a PDF from Documents and from the step drawer. Where a requirement is the same as one the EU AI Act journey already evidenced, the step arrives done by overlap.
Price and timing. The NIST AI RMF crosswalk is included from the Govern plan up — there is no per-framework fee. It is not going out with the launch: while the cross-mapping is switched off the programme is absent from the rail, and the pricing page states the date it lands.