AI Compliance Vendors
Voluntary standardVoluntary standardUS

NIST AI Risk Management Framework

The NIST AI Risk Management Framework (AI RMF 1.0) was published by the U.S. National Institute of Standards and Technology in January 2023, with a Generative AI Profile (NIST-AI-600-1) added in July 2024. It is a voluntary, sector-agnostic framework that organises AI risk management around four functions: Govern, Map, Measure, and Manage. Although adoption is voluntary, the AI RMF is referenced by the U.S. Executive Order on AI, several federal agency directives, and is increasingly cited by procurement teams and insurance carriers as a baseline expectation. NIST also publishes a companion AI RMF Playbook with concrete implementation suggestions and a Crosswalk that maps AI RMF actions to ISO/IEC 42001, ISO/IEC 23894, OECD AI Principles, and EU AI Act provisions.

Jurisdiction

US

Enforcement

January 26, 2023

Maximum penalty

Voluntary framework; no statutory penalties

Key obligations

  • 01Govern: establish AI policies, accountabilities, and a risk-tolerance posture that flows from board level through engineering teams.
  • 02Map: characterise the AI system's context, intended use, stakeholders, data, and known limitations before deployment.
  • 03Measure: select and apply quantitative and qualitative tests for trustworthiness characteristics — validity, reliability, safety, fairness, security & resilience, accountability & transparency, privacy, explainability.
  • 04Manage: prioritise, treat, and monitor risks; allocate resources; respond to incidents; and decommission systems that no longer meet the risk threshold.
  • 05For generative AI (GenAI Profile): address content provenance, hallucination/confabulation, harmful bias, IP and data integrity, CBRN/cyber misuse, and value-chain integration risks.
  • 06Maintain a living risk register and update Map/Measure/Manage outputs at material change events (data drift, model retraining, new use cases).
  • 07Treat AI RMF outputs as auditable artifacts even though the framework is voluntary — they are widely accepted as evidence in due diligence and procurement.

Vendors that support NIST AI RMF

Sorted by coverage level. Full coverage shown first.

34 vendors

VendorHQFoundedSizePricingCoverageLast verified
LatticeFlow AIZurich, Switzerland202011-50No public pricing. Enterprise platform sold via direct sales. Contact sales for demo and pricing.FullApr 22, 2026
EnzaiBelfast, United Kingdom20212-10SaaS platform, enterprise subscription. No public pricing listed. Contact sales via enz.ai.FullApr 22, 2026
Robust IntelligenceSan Francisco, United States201911-50Now integrated into Cisco AI Defense / Cisco Security Cloud. Standalone Robust Intelligence is no longer sold independently. Pricing through Cisco.FullApr 22, 2026
Collibra AI GovernanceNew York, United States20081000+Enterprise subscription; contact sales for custom quote based on users, assets, modules.FullApr 23, 2026
MonitaurBoston, United States201911-50Enterprise annual subscription; no public pricing listed. Forrester Wave cited 'pricing flexibility and transparency' as a highest-score criterion. Contact sales for quotes.FullApr 22, 2026
TrustibleArlington, United States202311-50Contact sales for enterprise pricing; no public plans listedFullApr 23, 2026
ModelOpChicago, United States201811-50No public pricing listed; contact sales for enterprise quotes.FullApr 23, 2026
Modulos AI GovernanceZurich, Switzerland201811-50Contact for pricingComprehensiveApr 24, 2026
Scrut AutomationPalo Alto, US202151-200Contact for pricingComprehensiveApr 24, 2026
Luminos.Law (ZwillGen AI Division)Washington, DC, US201951-200Contact for pricingComprehensiveApr 24, 2026
DataRobotBoston, US20121000+Contact for pricingComprehensiveApr 24, 2026
DrataSan Francisco, US2020501-1000Contact for pricingComprehensiveApr 24, 2026
SaidotHelsinki, Finland201811-50No public pricing listed; contact sales implied via demos and sign-ups.PartialApr 23, 2026
HiddenLayerAustin, United States202251-200Enterprise-only, contact sales for pricing. No public pricing listed on website.PartialApr 22, 2026
LakeraZurich, Switzerland202151-100Enterprise-focused SaaS. No public pricing listed. API-based pricing model expected. Contact sales.PartialApr 22, 2026
Prompt SecurityTel Aviv, Israel202311-50Now part of SentinelOne Singularity Platform. Continues as a standalone product. Enterprise pricing only; contact sales or SentinelOne.PartialApr 22, 2026
Protect AISeattle, United States202251-200Now integrated into Palo Alto Networks Prisma AIRS. Original standalone Protect AI pricing was enterprise-only, contact sales. Current pricing through Palo Alto Networks.PartialApr 22, 2026
Fairly AIKitchener, Canada202011-50On-premises or private-cloud deployments; quote-based.PartialApr 21, 2026
TrojAISaint John, Canada201911-50Enterprise-only, no public pricing. Contact sales at troj.ai.PartialApr 22, 2026
OneTrust AI GovernanceAtlanta, United States20161000+Enterprise platform; contact sales for quote, no public pricing listedPartialApr 23, 2026
VantaSan Francisco, USA2018500-1000Contact for pricingPartialApr 26, 2026
IBM watsonx.governanceArmonk, USA1000+Contact for pricingPartialApr 26, 2026
ServiceNow AI Control TowerSanta Clara, USA20041000+Contact for pricingPartialApr 26, 2026
Securiti Data Command CenterSan Jose, USA2018500-1000Contact for pricingPartialApr 26, 2026
BigIDNew York, USA2016500-1000Contact for pricingPartialApr 26, 2026
Credo AIPalo Alto, US202051-200Contact sales for enterprise subscription quote. Credo AI homepagePartialApr 26, 2026
Holistic AILondon, UK202051-200Enterprise platform; contact sales for quote.PartialApr 26, 2026
ValidMindPalo Alto, US202211-50Custom pricing plans; contact sales.PartialApr 26, 2026
FairNowMcLean, US202311-50Contact sales for quote; no public pricing listedPartialApr 26, 2026
Lasso SecurityTel Aviv, IL202311-50Enterprise pricing only. Not publicly listed.PartialApr 27, 2026
CraniumShort Hills, US202351-200Contact for pricingPartialApr 27, 2026
NaaiaLouveciennes, FR202111-50No public pricing tiers; demo and quote requested via website.PartialApr 27, 2026
2021.AICopenhagen, DK201651-200Contact for pricingPartialApr 27, 2026
KnosticHerndon, US202311-50Contact for pricingAdjacentApr 27, 2026

Buyer’s guide

Independent ranking with documented criteria.

See our top picks for NIST AI RMF

Frequently asked

In-depth answers about NIST AI RMF.

Compare across industries

See which vendors support NIST AI RMF in your sector.

Last verified April 28, 2026. Informational summary only — not legal advice. Consult qualified counsel for specific obligations.