2 min read
Why NIST AI RMF Is Now a Federal Procurement Filter
Most contractors treat the NIST AI Risk Management Framework as a suggestion. That was true in 2023. It is not true now.
- ai-compliance
- nist-ai-rmf
- federal-procurement
Most contractors treat the NIST AI Risk Management Framework as a suggestion. That was true in 2023. It is not true now.
What Changed
OMB M-24-10, signed in March 2024, required federal agencies to implement AI governance frameworks consistent with NIST AI RMF by December 2024. That guidance survived the administration change. Every agency buying AI systems after that date is, in practice, filtering vendors through this framework whether the RFP says so or not.
If you sell AI-adjacent anything to the federal government and you cannot hand a procurement officer a one-page document describing how your system addresses each trustworthy characteristic, you are already behind the vendors who can.
The Seven Characteristics
The framework defines seven trustworthy AI characteristics that every AI system is supposed to be assessed against:
- Valid and Reliable
- Safe
- Secure and Resilient
- Accountable and Transparent
- Explainable and Interpretable
- Privacy-Enhanced
- Fair, with harmful bias managed
Notice what is missing from that list. Performance. Accuracy. Speed. Cost. The framework treats those as assumed. If your system is not valid or reliable, it is not really an AI system, it is a random number generator with a marketing department. The framework starts where the technical conversation usually ends.
What We See in Practice
We audit AI systems against this framework for federal contractors. The most common gap is not technical. It is documentation. Teams build systems that quietly do the right thing but have no artifacts to show an auditor. The fix is rarely to rebuild the system. It is to produce the evidence.
The second most common gap is organizational. Who owns AI governance inside the company? Most of our first conversations end in a silent look across the conference table. That silence is the single strongest predictor of a failed audit.
Where to Start
The framework has four core functions: GOVERN, MAP, MEASURE, MANAGE. Start with GOVERN. It does not require new technology. It requires policy decisions, role assignments, and escalation paths. Most of our engagements open with a two-day GOVERN workshop and a policy draft. That alone moves the needle more than any tooling we could install later.
After GOVERN, the sequencing usually goes MAP (inventory everything), MEASURE (test it against the seven characteristics), MANAGE (set the controls). It is a loop, not a waterfall. You will revisit GOVERN after MEASURE shows you what you missed.
The Part That Is Not In The Framework
The framework tells you what to measure. It does not tell you how to produce a defensible test plan, how to structure an evidence package that an auditor will accept on the first pass, or how to map your NIST AI RMF work to ISO 42001 so you are not doing the same work twice.
That is the part we spend most of our time on.