Govern your AI and automate GRC for EU AI Act and ISO 42001 compliance
NIST AI RMF
Voluntary frameworkWhat NIST AI RMF requires
The NIST AI Risk Management Framework is voluntary in the United States and organises AI risk work into four functions: Govern, Map, Measure and Manage. Govern is cross-cutting, establishing policy, accountability and risk tolerance. Map builds context — intended purpose, stakeholders, potential impacts. Measure applies quantitative and qualitative assessment of bias, explainability, security and performance. Manage allocates resources, implements controls and maintains post-deployment monitoring. Its strength is methodology: it tells you how to reason about AI risk without prescribing specific controls, which makes it a common backbone under other, more prescriptive regimes.
Who it applies to
Any organisation building or deploying AI that wants a defensible risk methodology; frequently required by US federal procurement.
46 tools that map to NIST AI RMF
Grouped by what the tool actually does, because a documentation platform and a runtime guardrail both claiming support are solving different halves of the problem.
Policy, Compliance & GRC (30)
Compliance automation platform that extended into ISO 42001 and EU AI Act governance
Security compliance automation platform, an early mover in supporting NIST AI RMF and ISO 42001
AI-driven GRC platform pairing compliance automation with human experts for ISO 42001 and EU AI Act
Multi-framework GRC and compliance operations platform with NIST AI RMF and ISO 42001 templates
AI-powered, modular GRC platform that operationalizes AI governance alongside security compliance
Autonomous compliance platform bringing ISO 42001 and EU AI Act governance onto its security GRC engine
Enterprise agentic GRC platform running on structured live-systems data, ISO 42001 certified
European responsible-AI platform unifying MLOps, model registry, and enterprise AI governance
European AI Management System built on ISO/IEC 42001 for AI Act compliance
Enabling enterprise AI by quantifying its quality and risk
Enterprise AI governance and enablement across global regulatory frameworks
End-to-end AI governance with registry, risk assessment and automated compliance
AI-powered GRC platform, rebranded from AuditBoard, with AI governance via the FairNow acquisition
No-code GRC platform with AI governance agents that triage and assess AI use cases
AI inventory, assessment and monitoring built on OneTrust's privacy and trust platform
Enterprise AI governance to operationalize oversight, risk and compliance
Board governance and GRC platform embedding AI risk and compliance into enterprise oversight
AI governance platform to discover, assess and manage AI risk at scale
Enterprise AI governance and model lifecycle automation as a system of record
Automated AI governance and EU AI Act compliance workflow management
Model governance and ML assurance for highly regulated industries
AI governance embedded in an integrated risk management platform
AI governance, risk and compliance with rapid audits, now operating as Asenion
AI-first connected GRC platform with a built-in AI governance and trust framework
AI governance platform for regulated enterprises to manage risk and compliance
Ethical AI governance and use-case risk assessment, now part of Asenion
AI governance, risk and compliance platform for tracking AI use cases, models and vendors
All-in-one enterprise AI governance for ethical, transparent and compliant AI
Observability & Monitoring (2)
AI performance, evaluation, and governance platform for ML, generative, and agentic systems
Enterprise AI observability, security, and governance control plane for models and agents
Runtime Enforcement & Guardrails (4)
Customizable runtime guardrails, evaluation, and red-teaming for enterprise generative and agentic AI
AI-native security platform guarding GenAI apps against prompt attacks and data loss
Runtime security for enterprise GenAI usage, applications, and AI agents
Full-lifecycle inference-layer security and guardrails for enterprise AI
Red-Teaming & AI Security (5)
End-to-end AI security and governance platform to discover, monitor, red-team and prove enterprise AI
Open-source and enterprise platform for testing and red-teaming LLM agents
End-to-end security for the AI and machine-learning supply chain
AI Firewall and automated model validation to secure AI from build to production
Enterprise Incumbents (5)
Enterprise AI platform unifying model and agent development, deployment, and governance across any environment
Lifecycle governance, risk and compliance for models and agentic AI, built on IBM's GRC heritage
AI governance layered on Collibra's data catalog and lineage for trusted, compliant AI
A single command center to discover, observe, govern, secure and measure enterprise AI
Data security and compliance controls for Copilot and generative AI across the Microsoft estate
AI Governance Tool Selection Kit
A vendor-comparison worksheet plus EU AI Act, NIST AI RMF and ISO/IEC 42001 requirement checklists — so you can shortlist tools against the obligations that actually apply to you.
Free. No spam — unsubscribe anytime.