Moviwa

Where do I start if I have nothing in place?

6 min read · Reviewed in September 2026

In short

The NIST AI Risk Management Framework is voluntary and not certifiable, which is exactly why it is the best starting point: it gives structure without opening an audit. It organises AI risk into four functions — govern, map, measure and manage — and what it produces is reused in ISO 42001 and the EU AI Act.

What it is, and what it is not

The NIST AI Risk Management Framework is published by the United States National Institute of Standards and Technology. It is voluntary, not certifiable and not prescriptive: it does not tell you which controls to implement, but how to structure the conversation about AI risk inside an organisation.

Those three characteristics tend to be read as weakness and are the opposite. A company that does not yet know which AI it uses is in no position to take on a certification. The NIST framework lets you start on Monday, with no auditor, no formal scope and no committed timeline.

It also includes a specific profile for generative AI, which is the part most organisations care about: it addresses risks such as information leaking through prompts, model confabulation, intellectual property and provider dependency.

The four functions

FunctionWhat it resolves
GovernCuts across the other three. Defines who is accountable, what policy exists, how decisions are taken and how they are documented. Without it, the others produce information nobody uses
MapIdentify the context: which AI systems exist, what they are used for, who is affected and what can go wrong. This is where almost every organisation discovers its mental map does not match reality
MeasureAnalyse and track the identified risks with concrete metrics. Here the framework separates from a theoretical exercise: it demands numbers and movement over time
ManagePrioritise and act: mitigate, transfer, accept or avoid each risk, and record the decision and its reason

Why it is useful even for a European company

It is a US framework, but it has become an international reference through three routes:

  • Supply chain. It arrives as a requirement from a parent company or a US customer.
  • Crosswalks to other frameworks. Published mappings exist between the NIST framework and ISO 42001. Work done for one carries over to the other.
  • Preparation for the EU AI Act. The inventory, the risk assessment and the documented decisions the European regulation requires are the same things this framework produces.

Put another way: it is the draft. ISO 42001 is the certifiable version and the EU AI Act is the legal obligation. Starting with the draft is not wasting time, it is doing it in the right order.

How does Moviwa help?

The framework asks for data almost no organisation has. Moviwa produces it.

  • Map. A real inventory of AI tools and use cases, drawn from activity rather than an internal survey. The gap between what is declared and what is real is usually the interesting part of the exercise.

  • Measure. Exposure indicators by team, data type and tool, tracked over time. It is what turns "we think there is risk" into a figure you can follow quarter by quarter.

  • Manage. Policies applied at the point of use, and alerts on relevant events. The management decision gets executed, not documented and forgotten.

  • Govern. Documentary evidence for the committee and the board, with the history of what was decided and what happened next.

See inside the platform

Checklist: five steps to start without consultants

  1. 1

    Name an owner. One person, not a committee. The govern function starts here.

  2. 2

    Draw the map. Which AI tools are used, in which teams and with what information. Measured.

  3. 3

    Pick three risks, not fifteen. Information leaking through prompts, dependency on one provider and unauthorised use are usually the first three.

  4. 4

    Define one metric per risk and measure it for a quarter.

  5. 5

    Take the results to management and document what was decided. Those minutes are the first real governance deliverable your organisation will have.

Frequently asked questions

Is the NIST AI RMF mandatory?
No. It is voluntary and not certifiable. It usually arrives as a contractual requirement, not a regulatory one.
Is it useful if I am a European company?
Yes, as a working structure. It does not replace the EU AI Act, which is a legal obligation, but it prepares much of what the Act requires.
How does it relate to ISO 42001?
They are complementary and crosswalks exist between them. The NIST framework organises; ISO 42001 certifies.
Can I start without external consultants?
Yes. That is precisely its advantage: the first steps — naming an owner, mapping and picking three risks — are done with internal resources.

Official sources

Mapping is the first step, and the one nobody has taken

The framework's four functions depend on the second. Without knowing which AI is used inside your organisation, governing, measuring and managing are exercises on a blank sheet.

No commitment · 15 minutes · No card

Related frameworks

Moviwa implements the technical and organisational controls these frameworks require, and produces the evidence to demonstrate them. Moviwa is not certified against these standards and does not certify your organisation: compliance remains your company's responsibility.

This content is informational and does not constitute legal advice. For decisions about your organisation's compliance, consult your legal adviser.