grecta

What Is NIST AI RMF?

A plain-language introduction to the NIST AI Risk Management Framework 1.0 — what it is, where it came from, who it is for, and what adopting it actually means for an organisation. The framework is voluntary, non-certifiable, and structured around four functions. Our guide explains each of those features and what they imply in practice.

NIST AI RMF Implementation and Organisational Adoption

A practical guide to using the framework inside an organisation — how to scope adoption, assess current maturity, sequence implementation across the four functions, allocate ownership across teams, and document AI RMF use for external attestation.

Characteristics of Trustworthy AI

A reference guide to the seven characteristics the NIST AI RMF treats as the substantive goals of AI risk management — what each characteristic means, what it requires in practice, where tensions between them arise, and how the framework expects organisations to balance them in design and deployment decisions.

NIST AI RMF and the EU AI Act

How the voluntary US framework relates to the binding EU regulation — where the two align on substantive AI risk management, where they diverge in legal effect and scope, and how organisations operating in both jurisdictions use the AI RMF as substantive methodology alongside Act compliance work.

Using the AI RMF Playbook and Profiles

How the AI RMF’s supporting resources work in practice — what the Playbook provides for each subcategory of the four functions, what profiles add for specific use cases and sectors, and how organisations combine the two to convert the framework’s general guidance into context-specific operational practice.

ISO 42001 vs ISO 27001, ISO 9001 and NIST AI RMF

How ISO 42001 sits alongside the adjacent frameworks organisations most often run in parallel — what is shared, what is distinct, and where evidence produced for one framework can be reused for another.

ISO 42001 Certification Process and Audit Readiness

What certification against ISO/IEC 42001:2023 actually involves — from selecting an accredited certification body to producing the evidence auditors expect to see, the structure of Stage 1 and Stage 2 audits, the three-year cycle, and the nonconformities that most frequently surface.

ISO 42001 Annex A Controls Explained

A control-by-control walkthrough of the 38 reference controls in Annex A of ISO/IEC 42001:2023, organised under the nine control objectives. For each control: what it requires, what evidence demonstrates implementation, and where it sits in certification audits.

ISO 42001 and the EU AI Act

How the voluntary international management system standard maps to the binding EU regulation — where the two align, where they diverge, and how certification to ISO 42001 supports conformity with the Act without substituting for it.