AIAI Governance StackFree kit

NIST AI RMF

Voluntary framework

What NIST AI RMF requires

The NIST AI Risk Management Framework is voluntary in the United States and organises AI risk work into four functions: Govern, Map, Measure and Manage. Govern is cross-cutting, establishing policy, accountability and risk tolerance. Map builds context — intended purpose, stakeholders, potential impacts. Measure applies quantitative and qualitative assessment of bias, explainability, security and performance. Manage allocates resources, implements controls and maintains post-deployment monitoring. Its strength is methodology: it tells you how to reason about AI risk without prescribing specific controls, which makes it a common backbone under other, more prescriptive regimes.

Who it applies to

Any organisation building or deploying AI that wants a defensible risk methodology; frequently required by US federal procurement.

46 tools that map to NIST AI RMF

Grouped by what the tool actually does, because a documentation platform and a runtime guardrail both claiming support are solving different halves of the problem.

Policy, Compliance & GRC (30)

Govern your AI and automate GRC for EU AI Act and ISO 42001 compliance

EU AI ActISO/IEC 42001NIST AI RMF

Compliance automation platform that extended into ISO 42001 and EU AI Act governance

ISO/IEC 42001EU AI ActNIST AI RMF

Security compliance automation platform, an early mover in supporting NIST AI RMF and ISO 42001

NIST AI RMFISO/IEC 42001GDPR

AI-driven GRC platform pairing compliance automation with human experts for ISO 42001 and EU AI Act

ISO/IEC 42001EU AI ActNIST AI RMF

Multi-framework GRC and compliance operations platform with NIST AI RMF and ISO 42001 templates

NIST AI RMFISO/IEC 42001EU AI Act

AI-powered, modular GRC platform that operationalizes AI governance alongside security compliance

EU AI ActNIST AI RMFISO/IEC 42001

Autonomous compliance platform bringing ISO 42001 and EU AI Act governance onto its security GRC engine

EU AI ActNIST AI RMFISO/IEC 42001

Enterprise agentic GRC platform running on structured live-systems data, ISO 42001 certified

NIST AI RMFISO/IEC 42001GDPR

European responsible-AI platform unifying MLOps, model registry, and enterprise AI governance

EU AI ActGDPRNIST AI RMFOpen-source

European AI Management System built on ISO/IEC 42001 for AI Act compliance

EU AI ActISO/IEC 42001NIST AI RMF

Enabling enterprise AI by quantifying its quality and risk

EU AI ActNIST AI RMFISO/IEC 42001

Enterprise AI governance and enablement across global regulatory frameworks

EU AI ActNIST AI RMFISO/IEC 42001

Govern all your AI in one connected graph

EU AI ActNIST AI RMFISO/IEC 42001

End-to-end AI governance with registry, risk assessment and automated compliance

EU AI ActNIST AI RMFISO/IEC 42001

AI-powered GRC platform, rebranded from AuditBoard, with AI governance via the FairNow acquisition

SOC 2NIST AI RMFISO/IEC 42001

No-code GRC platform with AI governance agents that triage and assess AI use cases

EU AI ActNIST AI RMFISO/IEC 42001

AI inventory, assessment and monitoring built on OneTrust's privacy and trust platform

EU AI ActNIST AI RMFISO/IEC 42001

Enterprise AI governance to operationalize oversight, risk and compliance

EU AI ActNIST AI RMFISO/IEC 42001

Board governance and GRC platform embedding AI risk and compliance into enterprise oversight

EU AI ActNIST AI RMFISO/IEC 42001

AI governance platform to discover, assess and manage AI risk at scale

EU AI ActNIST AI RMFISO/IEC 42001

Enterprise AI governance and model lifecycle automation as a system of record

EU AI ActNIST AI RMFISO/IEC 42001

Automated AI governance and EU AI Act compliance workflow management

EU AI ActNIST AI RMFISO/IEC 42001

Model governance and ML assurance for highly regulated industries

NIST AI RMFEU AI ActISO/IEC 42001

AI governance embedded in an integrated risk management platform

EU AI ActNIST AI RMFISO/IEC 42001

AI governance, risk and compliance with rapid audits, now operating as Asenion

EU AI ActNIST AI RMFISO/IEC 42001

AI-first connected GRC platform with a built-in AI governance and trust framework

NIST AI RMFISO/IEC 42001SOC 2

AI governance platform for regulated enterprises to manage risk and compliance

EU AI ActNIST AI RMFISO/IEC 42001

Ethical AI governance and use-case risk assessment, now part of Asenion

EU AI ActNIST AI RMFISO/IEC 42001

AI governance, risk and compliance platform for tracking AI use cases, models and vendors

EU AI ActNIST AI RMFISO/IEC 42001

All-in-one enterprise AI governance for ethical, transparent and compliant AI

EU AI ActNIST AI RMFISO/IEC 42001

Observability & Monitoring (2)

AI performance, evaluation, and governance platform for ML, generative, and agentic systems

NIST AI RMFEU AI ActSOC 2Open-source

Enterprise AI observability, security, and governance control plane for models and agents

EU AI ActNIST AI RMFGDPR

Runtime Enforcement & Guardrails (4)

Customizable runtime guardrails, evaluation, and red-teaming for enterprise generative and agentic AI

EU AI ActNIST AI RMF

AI-native security platform guarding GenAI apps against prompt attacks and data loss

EU AI ActNIST AI RMF

Runtime security for enterprise GenAI usage, applications, and AI agents

NIST AI RMFEU AI ActGDPR

Full-lifecycle inference-layer security and guardrails for enterprise AI

NIST AI RMFEU AI Act

Red-Teaming & AI Security (5)

End-to-end AI security and governance platform to discover, monitor, red-team and prove enterprise AI

EU AI ActNIST AI RMFISO/IEC 42001

Open-source and enterprise platform for testing and red-teaming LLM agents

EU AI ActNIST AI RMFOpen-source

End-to-end security for the AI and machine-learning supply chain

NIST AI RMFSOC 2Open-source

Automated evaluation, guardrails, and judges for LLM and agent reliability

NIST AI RMF

AI Firewall and automated model validation to secure AI from build to production

NIST AI RMF

Enterprise Incumbents (5)

Enterprise AI platform unifying model and agent development, deployment, and governance across any environment

EU AI ActNIST AI RMF

Lifecycle governance, risk and compliance for models and agentic AI, built on IBM's GRC heritage

EU AI ActNIST AI RMFISO/IEC 42001

AI governance layered on Collibra's data catalog and lineage for trusted, compliant AI

EU AI ActNIST AI RMF

A single command center to discover, observe, govern, secure and measure enterprise AI

EU AI ActNIST AI RMF

AI Governance Tool Selection Kit

A vendor-comparison worksheet plus EU AI Act, NIST AI RMF and ISO/IEC 42001 requirement checklists — so you can shortlist tools against the obligations that actually apply to you.

Free. No spam — unsubscribe anytime.