NIST AI RMF for Procurement
A procurement-focused guide to using NIST AI RMF without treating it as certification or a substitute for UK requirements.
The NIST AI Risk Management Framework is a voluntary framework for managing AI risk. Its core functions — Govern, Map, Measure and Manage — can help procurement teams organise questions and evidence, but it is not a certification and does not replace UK legal, public-procurement or sector requirements.
Govern
Establish accountable ownership, policies, risk tolerances, roles and escalation. In procurement, ask suppliers who owns AI risk, how decisions are documented, how incidents are governed and how material product changes are approved.
Map
Understand the system in context: intended purpose, users, affected people, data, dependencies, deployment environment and foreseeable harms. Procurement should capture those facts before selecting controls or comparing vendors.
Measure
Require evidence showing how relevant risks and system characteristics are tested. Depending on use, this can include performance, robustness, security, privacy, bias/fairness, reliability, human oversight and task-specific evaluations. Supplier benchmarks should not be assumed to represent the buyer's context.
Manage
Translate findings into treatment: supplier remediation, buyer controls, contractual conditions, monitoring, acceptance thresholds, restrictions or a decision not to proceed. Residual risk should remain visible.
Evidence quality matters
For every material claim, distinguish supplier assertion from documented, demonstrated and independently verified evidence. Record scope, date and limitations.
Connect the framework to the procurement lifecycle
NIST AI RMF can support:
- Plan — context and risk ownership;
- Specify — evidence and control requirements;
- Evaluate — structured comparison of claims and evidence;
- Contract — enforceable risk treatments and change controls;
- Deploy — production validation;
- Monitor — ongoing measurement and reassessment.
Use alongside other requirements
For UK procurement, cross-reference relevant government, NCSC, ICO and legal requirements rather than substituting NIST terminology for them.
How AI TrustMark fits
AI TrustMark can map independently checked supplier and product evidence to relevant risk-management themes. It does not provide NIST certification or imply US government endorsement.
Organisation-specific NIST crosswalks, risk mappings, tender matrices, evidence assessments and contract controls remain professional services.
Return to the AI Procurement Framework Crosswalks or the AI Procurement Knowledge Base.