Your AI problem isn’t technology. It’s governance.
Nobody wakes up looking for an AI risk framework. They wake up after finding out how much AI is already running inside the business — and realizing nobody can say who approved any of it.
The challenge was never adopting AI. It’s managing it responsibly once you have.
30 minutes, no prep. You’ll leave knowing which of the four AI RMF functions you already cover and where the gaps are.
What the NIST AI RMF actually is.
A voluntary framework from the National Institute of Standards and Technology for managing risks associated with AI systems across their lifecycle. Unlike a security framework, it’s aimed at making AI systems trustworthy: accountable, transparent, safe, secure, privacy-enhanced and fair.
Nobody will fine you for skipping the AI RMF. What happens instead is that a customer’s security team, an insurer at renewal or your own board asks how AI is governed — and “we have a policy” stops being a sufficient answer. Greypike doesn’t certify you against the AI RMF, because nobody can. We align you to it and make the work evidenced.
Four functions, and the first one holds up the other three.
The framework is organized around GOVERN, MAP, MEASURE and MANAGE. GOVERN isn’t step one of four — it’s the foundation the rest sit on. Programs that skip it end up measuring things nobody owns.
Establish the policies, accountability, oversight, roles, training and risk tolerance that everything else depends on. Without this, the other three functions produce findings nobody is responsible for acting on.
WHAT IT LOOKS LIKE AS WORK- AI acceptable use policy
- Named accountability for AI risk
- An AI system inventory
- Risk tolerance, stated
- Role definitions and oversight
- Workforce training on AI use
Understand how AI is actually being used, who is affected by it, what risks exist and what context surrounds each system. In most organizations this step reveals considerably more AI than leadership expected.
WHAT IT LOOKS LIKE AS WORK- Discovery of AI already in use
- Use case documentation
- Impact on people and customers
- Data each system can reach
- Third-party AI in your supply chain
- Context and intended purpose
Assess the risks you mapped, monitor outcomes, evaluate impacts and determine whether your controls are actually working — rather than whether they exist.
WHAT IT LOOKS LIKE AS WORK- AI risk assessments
- Outcome monitoring
- Control effectiveness review
- Documented evaluation criteria
- Testing before deployment
- Reassessment as models change
Prioritize what you found, respond to it, track it to closure and keep improving across the AI lifecycle. This is the function that turns an assessment into a program.
WHAT IT LOOKS LIKE AS WORK- Risk prioritization and response
- Use case approval workflow
- Vendor and tool review cycle
- Incident and issue handling
- Governance reporting to leadership
- Continuous improvement
None of the four is a document you produce once. Each one turns into activities with owners and dates — which is the entire reason AI governance fails when it lives in a committee rather than in a task list.
What AI governance actually involves.
Most organizations assume it means writing a policy, approving a chatbot and forming a committee. The reality is broader, and considerably more operational.
“We’ll write an AI policy and put it on the intranet.”
The policy is one of eight activities, and the one that takes the least time.
AI system inventory
Documenting where AI is actually being used across the organization — usually more places than anyone expected.
AI risk assessments
Evaluating legal, operational, security, privacy and business risk for each use case, not for AI in general.
Acceptable use policy
What employees can and cannot put into an AI system — specific enough that people can follow it.
Vendor reviews
Evaluating AI providers and third-party AI baked into tools you already bought.
Data governance
Understanding what data each AI system can reach and process. This is where most real exposure sits.
Human oversight
Defining who is accountable, who reviews outputs, and where a human has to stay in the loop.
Monitoring and reviews
Evaluating outcomes and updating risk assessments as model capabilities change underneath you.
Executive governance
Giving leadership genuine visibility into AI risk and the decisions being made on their behalf.
AI governance isn’t a project. The ground keeps moving.
New tools appear every month. Vendors ship capabilities you didn’t ask for. Employees adopt things before the policy catches up. Four ordinary events from a single quarter, and the twenty things they set off between them.
- Add it to the AI inventory
MAP - Run a risk assessment on the use case
MEASURE - Review the vendor and its data handling
GOVERN - Decide whether it is approved, and record why
MANAGE - Check it against the acceptable use policy
GOVERN
- Inventory the capability you did not buy
MAP - Determine what data it can now reach
MAP - Reassess the vendor on the new footing
MEASURE - Update the use policy if staff can access it
GOVERN - Tell leadership it happened
MANAGE
- Reassess risk against the new capability
MEASURE - Re-check what data it can process
MAP - Confirm human oversight is still adequate
GOVERN - Update the documented use case
MANAGE
- Run it through the approval workflow
MANAGE - Assess the risk for this specific use
MEASURE - Confirm the data involved is permitted
MAP - Define who reviews the outputs
GOVERN - Record the decision and the reasoning
MANAGE - Add it to the inventory once approved
MAP
Every one of those events invalidates part of what you wrote down. An AI governance program that was accurate in March and untouched since is not a governance program — it’s a snapshot, and a customer asking today will find that out faster than you will.
Governance, turned into assigned work.
Every governance activity becomes one or more tasks with an owner, a due date and the evidence it needs. Instead of maintaining AI governance through spreadsheets and a standing meeting, the program runs as a workflow that keeps moving between meetings.
Almost nobody has an AI governance team, an AI risk office or a dedicated AI compliance specialist. Greypike includes a named person who reviews completed work and makes sure governance activities are being documented in a way that will stand up when somebody asks.
Publish and acknowledge the AI acceptable use policy
Publish the approved AI acceptable use policy, route it to every member of staff for acknowledgement, and export the completion record by name and date.
- Owner
- Dana Whitfield, Operations
- Due
- 30 September 2026
- Evidence
- Acknowledgement report, by name and date
- Accepted when
- Every current employee acknowledged, leavers excluded
- Also satisfies
- ISO/IEC 42001, SOC 2 awareness
Accepted, with one note. Contractors and interns aren’t in the acknowledgement list and they have Copilot access — I’ve raised a follow-up task to cover them. That gap is exactly what a customer questionnaire asks about.
Most programs start after the tools are already in.
Governance work usually begins the month after a deployment, not before it. That’s normal — and it’s recoverable, provided somebody starts answering these five questions.
No configuration setting tells you who approves a use case. Every one of those five is a governance answer, not a technical one — and they have to hold up when a customer asks for them in writing.
You have already built most of this. It just wasn’t called AI governance.
The strongest AI programs start from work that already exists. If you run any of the disciplines on the left, you are further along than you think.
Build a second governance program that runs in parallel.
Extend the governance program you already have to include AI.
Organizations pursuing ISO/IEC 42001, SOC 2, ISO 27001, CMMC or FTC Safeguards find substantial overlap with AI governance. A vendor review is a vendor review whether the vendor sells you a database or a model. Greypike maps the work across so you extend a program rather than starting a second one.
Who’s doing the work.
AI governance is new. Building risk programs that survive an outside examination is not.
- 20+ years across government and the Defense Industrial Base
- 14 years as a cybersecurity and fraud investigator
- Cyber AB Registered Practitioner (RP) and Registered Practitioner Advanced (RPA)
- MIT Sloan certificate in artificial intelligence for business strategy and governance
Greypike is a Veteran-Owned Small Business supporting 20+ Defense Industrial Base contractors on active contracts that support defense missions. We build and run compliant environments rather than only advising on them, and we bring the same evidence discipline to AI governance that a CMMC assessment demands.
That matters here because the AI RMF has no certificate to hide behind. There is no auditor to pass and no badge to display — the only thing that counts is whether you can answer a customer’s questions with records instead of assurances. We have spent two decades producing exactly that kind of record under regulators who do not accept good intentions.
The same posture we take on CMMC and SOC 2 applies here: we align you to the framework and make the work provable. Nobody certifies anyone against the AI RMF, and any firm telling you otherwise is selling something that does not exist.
AI GRC is in early access.
We’d rather tell you that plainly than imply it ships today. The AI GRC module has its own connectors into your AI stack, and it’s being built with the organizations using it.
Early access customers help decide what ships first, and get in before general availability.
It will be, the same way everything else on this site is. Until the module reaches general availability, quoting a number would be a guess.
NIST AI RMFISO/IEC 42001AI inventories and risk assessmentsInternal AI governance programsEnterprise AI risk managementCompliance manager review
The NIST AI RMF, answered.
The questions we get asked most often, before anyone signs anything.
What is the NIST AI Risk Management Framework?
The NIST AI Risk Management Framework (AI RMF 1.0) is a voluntary framework published by the National Institute of Standards and Technology for managing risks associated with artificial intelligence systems across their lifecycle. It is organized around four functions — GOVERN, MAP, MEASURE and MANAGE — and is aimed at making AI systems trustworthy: accountable, transparent, safe, secure, privacy-enhanced and fair.
Can you get certified against the NIST AI RMF?
No. There is no certification for the NIST AI RMF and no accredited body issues one, because the framework is voluntary and has nothing to certify against. Any firm offering NIST AI RMF certification is selling something that does not exist. What you can do is align to it and keep evidence of the work, which is what customers, insurers and boards are actually asking to see.
If a customer specifically requires a certificate, ISO/IEC 42001 is the certifiable AI standard.
Is the NIST AI RMF mandatory?
It is voluntary. Nobody will fine you for skipping it. In practice it stops being optional the moment a customer’s security team, an insurer at renewal or your own board asks how AI is governed — at which point “we have a policy” is no longer a sufficient answer. For defense contractors, AI governance questions are increasingly appearing in the same questionnaires that ask about CMMC and NIST 800-171.
What are the four functions of the NIST AI RMF?
GOVERN establishes policies, accountability, oversight, roles, training and risk tolerance. MAP establishes where AI is used, who it affects and what context surrounds each system. MEASURE assesses risk and determines whether controls are actually working. MANAGE prioritizes, responds, tracks to closure and improves.
GOVERN is not step one of four. It is the foundation the other three sit on, and programs that skip it end up measuring things nobody owns.
Does the NIST AI RMF apply if we only use AI tools rather than build them?
Yes. Deploying Microsoft Copilot, ChatGPT Enterprise, Google Gemini, Claude, AI coding assistants or any internal AI application creates AI risk you now own. The framework asks where AI is used, what data it can reach, who approved it and who reviews the outputs — questions that apply just as much to a tool you bought as to a model you trained.
How does the NIST AI RMF compare to ISO 42001?
They are complementary. The AI RMF gives you a risk framework quickly and without an audit timeline attached. ISO/IEC 42001 gives you an auditable management system and a path to a certificate a customer can verify independently.
Most organizations start with the AI RMF and move toward 42001 later, and nothing built for the AI RMF is wasted if you certify afterwards.
We already do CMMC. Does that help with AI governance?
Considerably. Risk assessment, policy lifecycle, access control, vendor review, training, incident response and evidence discipline are already in place and already being examined by an assessor. The AI RMF extends that machinery to a new category of system rather than starting a second program. The genuinely new work is usually the AI inventory and the use case approval workflow.
Where do we start with the NIST AI RMF?
With GOVERN and MAP, in that order. Name who owns AI risk, write an acceptable use policy people can actually follow, then find out where AI is already being used — which in most organizations turns up considerably more than leadership expected. Risk assessment and monitoring come after you know what you are assessing.
Build the program before someone asks for it.
Most AI governance efforts start after a customer, an insurer or the board asks an uncomfortable question. The organizations that move fastest already know where AI is being used, who owns the risk, and how the decisions were documented. That’s a much better position to be asked from.
30 minutes, no prep. You’ll leave knowing which of the four AI RMF functions you already cover and where the gaps are.
Early access · NIST AI RMF and ISO/IEC 42001 · No certification claimed, because none exists