NIST AI Risk Management Framework Becomes De Facto Standard in Contracts, Audits and Procurement: Why Organisations Must Act Now to Protect Their Reputation
The National Institute of Standards and Technology’s (NIST) Artificial Intelligence (AI) Risk Management Framework (RMF) has become a de facto benchmark for organisations operating in regulated industries. As a result, AI buyers across healthcare, insurance, and financial services are increasingly asked to demonstrate RMF alignment. This development demands immediate action from executives and decision-makers in these sectors, particularly in Canada and the UK.
What is happening: NIST’s RMF provides a structured framework for managing AI risks, which can be applied throughout the lifecycle of an AI system, including design, development, testing, deployment, operation, and maintenance. Organisations are now expected to demonstrate compliance with this framework as part of their contracts, audits, and procurement processes.
Why it demands action now: The lack of RMF alignment poses significant risks for organisations in regulated industries. Capability risk arises from the possibility that AI systems do not perform as claimed, leading to inaccurate diagnoses, poor treatment recommendations, or inadequate risk assessments. Governance risk is heightened due to the potential inability to defend AI-related decisions before regulatory bodies and courts when asked questions about accountability and liability. Moreover, the organisation may be held liable for any harm caused by an AI system that does not function correctly.
Action: A prudent organisation should take immediate steps to address these risks. This includes:
1. Reviewing current AI systems against the NIST RMF framework.
2. Conducting independent assessments of proposed AI solutions against the RMF criteria.
3. Ensuring compliance with regulatory requirements and industry standards.
However, organisations often struggle to validate AI capabilities independently due to vendor information asymmetry, internal teams being too close to the decision-making process, and the absence of a neutral way to test AI claims. This is where Straven & Co comes in: an independent AI validation firm that helps clients map proposed systems against the NIST RMF framework.
How Straven helps: At Straven & Co, we assess proposed AI solutions by examining them against our clients’ real operations, people, governance and legal exposure, and vendor claims. Our assessment results in a plain verdict – proceed, proceed with conditions, or do not. As an independent firm with no product to sell, we are committed solely to providing trustworthy recommendations that align with our clients’ interests.
Straven & Co examines AI decisions before they are acted on: stravenandco.com