Most companies that pick up the NIST AI Risk Management Framework make the same mistake in the first thirty days. They open the document, see four functions sitting side by side in a circle diagram, and treat them as four workstreams to divide among four people. A 200-person company doesn't have four people to spare for this. It has one compliance lead, maybe a fractional CISO, and a handful of engineers who are already busy shipping the product the AI risk program is supposed to be governing.
NIST published the AI RMF 1.0 on January 26, 2023. The framework's own text describes Govern, Map, Measure, and Manage as functions meant to operate continuously and in parallel once a program matures. That's a fair description of an organization with a standing AI governance office. It is not a useful starting instruction for a company your size, and treating it as one is how these programs stall out after an enthusiastic kickoff meeting and nothing else.
What you actually need is a sequence: an order of operations that respects the fact that you have limited people, a finite budget, and real deadlines from customers or regulators who are starting to ask AI governance questions in due diligence. In my view, the order that holds up under those constraints is Govern first, Map second, Measure third, Manage fourth. Not because NIST ranks them that way in the document, but because each one produces the input the next one needs, and skipping ahead produces work you'll redo.
Why the Framework's Own Structure Misleads Smaller Companies
The AI RMF Core is organized into four functions, and each one breaks down into categories with specific subcategories underneath them. Govern contains six categories. Map contains five. Measure and Manage contain four each. That structure is comprehensive, and it's also the reason a 200-person company's first attempt usually fails.
Here's the typical pattern. Someone assigns each function to a different owner. Four parallel efforts start with four different levels of urgency. Six months later, Govern has produced a polished AI policy document. Map, Measure, and Manage have produced nothing, because nobody could inventory or assess risk in systems nobody had governance authority to even ask about.
The fix is sequencing, not parallelizing. Govern establishes who has authority to make AI risk decisions and what the company's risk tolerance actually is. Without that settled first, Map produces an inventory nobody has the authority to act on, Measure produces metrics nobody agreed matter, and Manage produces a response plan with no budget behind it. Each function downstream depends on a decision the function upstream was supposed to make.
The Sequence, Function by Function
| Function | What it actually produces | Realistic owner at 200 people | Typical duration |
|---|---|---|---|
| Govern | Policy, accountability structure, risk tolerance, roles | Compliance/legal lead + an executive sponsor | 4–8 weeks |
| Map | AI system inventory, context, and use-case risk classification | IT/engineering lead, informed by Govern's risk tiers | 4–6 weeks |
| Measure | Metrics and testing methods tied to the risks Map identified | A named technical owner (often the same engineering lead) | 6–10 weeks |
| Manage | Response plans, monitoring cadence, and incident procedures | Cross-functional, chaired by the Govern sponsor | Ongoing, first pass in 3–4 weeks |
A 200-person company running this sequence deliberately, with one person driving it part-time and executive sponsorship behind it, should expect a first full pass in four to five months. That's not a NIST-mandated timeline; the framework doesn't prescribe one. It's what tends to hold up as realistic when the person driving the sequence is also doing their regular job.
Phase One: Govern, Before You Inventory Anything
Govern is where the company decides, in writing, who owns AI risk decisions and what "acceptable risk" means for this business. Skip this and every later function has to guess. The core Govern deliverables for a company your size are narrower than the six-category structure implies:
- A one-page AI risk policy naming an accountable executive, not a committee, a person, who signs off on new AI use cases before they go into production.
- A documented risk tolerance statement: what kinds of AI use the company will not accept regardless of business case (say, fully automated decisions on employment or credit without human review), and what kinds it accepts with conditions.
- A short intake process: any team proposing to build or buy an AI system routes through a single form or channel before procurement or deployment, not after.
- Assigned ownership for the rest of the sequence, in writing, with the hours actually budgeted against it.
Notice what's absent from that list: a lengthy AI ethics charter, a named "AI Center of Excellence," or a board-level AI committee. Those things have their place in a much larger organization. At 200 people, they're overhead that delays the work Govern actually needs to unlock, which is giving Map something to map against.
Phase Two: Map, Now That There's Somewhere to Route the Findings
Map is the inventory function: what AI systems does the company actually use, build, or embed in a vendor's product, and what's the context of use for each. This is where most companies discover they have more AI in production than anyone tracked, because a SaaS vendor quietly shipped a generative feature into a tool the company has used for years.
The practical Map exercise for 200 people is a structured survey, not a technical audit of every model. Ask every department head three questions: what tools does your team use that make predictions, generate content, or make recommendations; who's the vendor; and does the output touch a customer, an employee decision, or a regulated process. Cross-reference against procurement and IT asset records, because self-reported surveys undercount by a wide margin. Nobody thinks of the resume-screening feature buried in their applicant tracking system as "AI" until you name it for them.
Once you have the inventory, classify each system into a risk tier using the tolerance statement Govern already wrote. A three-level tier scheme works better than NIST's more granular category structure for a company this size:
- Systems that touch regulated decisions or customer-facing, high-stakes outputs.
- Systems that are internal-facing but consequential.
- Systems that are low-stakes productivity tools.
That tiering is what Measure needs next.
Phase Three: Measure, Scoped to What Map Flagged as High-Risk First
Measure is where a lot of smaller companies want to start, because it sounds the most technical and the most like "real" AI governance: bias testing, performance monitoring, red-teaming. It's also the function that produces the least value if you run it before Map tells you which systems are worth the effort. You do not need the same testing rigor for an internal meeting-notes summarizer that you need for a system that screens loan applications or flags employees for performance review.
For the systems Map tiered as highest-risk, Measure means establishing three things: what accuracy or error rate is acceptable, how the company will test for that on a recurring schedule rather than just at launch, and who reviews the results. NIST's Generative AI Profile, published as NIST AI 600-1 in July 2024, adds measurement considerations the original 2023 framework didn't fully anticipate, including testing for content provenance and confabulation. It's worth pulling in directly if any of your Map-tiered high-risk systems are generative rather than purely predictive.
For everything Map tiered as low-risk, Measure can be a lightweight annual review rather than continuous monitoring. Spending the same testing budget on a chatbot that drafts internal meeting notes as on a system making customer credit decisions is a common resource misallocation in this phase, and an avoidable one, simply by respecting the tiering Map already did.
Phase Four: Manage, Which Only Works Once the First Three Are Real
Manage is response and monitoring: what happens when a Measure test fails, when a system behaves unexpectedly in production, or when a vendor changes a model underneath a tool you already approved. This function is genuinely ongoing rather than a one-time project. But the first pass, building the incident response procedure and assigning the monitoring cadence, is fast if Govern, Map, and Measure already did their jobs. If they didn't, Manage becomes a fire drill invented on the spot the first time something goes wrong. That's exactly the scenario this whole sequence exists to prevent.
A workable first-pass Manage deliverable has three parts:
- A one-page incident procedure: who's notified, what gets paused, what gets documented.
- A recurring review meeting on the calendar. Quarterly is reasonable for a 200-person company; monthly is usually more than the workload justifies.
- A change-management trigger, so a vendor's model update to an already-approved system re-enters the Govern intake process rather than getting waved through.
A Note on ISO 42001 and the Regulatory Back-and-Forth
Companies that go through this sequence often ask whether they should aim for ISO/IEC 42001:2023 certification once the NIST-based program is running. NIST AI RMF is a voluntary framework with no certification body behind it: a risk-management approach you implement internally, at whatever pace fits your resources.
ISO 42001 is a different kind of document. It's a certifiable management system standard, structured like ISO 9001 and ISO 27001 around a Plan-Do-Check-Act cycle, and an accredited body audits and certifies against it. Its clause 6.1.2 requires a documented AI risk assessment process. A company that completes the Govern-Map-Measure-Manage sequence described above has already built most of what that clause requires. Formal certification is a reasonable next step if customers or contracts start asking for third-party proof rather than a self-attestation, and it's usually not worth pursuing before that demand actually shows up.
It's also worth naming the regulatory backdrop, because it's shifted since the framework launched. Executive Order 14110, signed October 30, 2023, directed federal agencies toward AI risk practices built substantially on the NIST framework. Executive Order 14179, signed January 23, 2025, revoked it. What hasn't changed, in my experience reviewing customer security questionnaires and vendor due-diligence requests, is that NIST AI RMF is still the name that comes up most often as a reference baseline, with or without a federal mandate behind it. Building the sequence above doesn't depend on which administration's executive order is currently in force. It depends on whether your company can show a customer, insurer, or regulator that AI risk decisions get made deliberately rather than by accident.
Common Ways This Sequence Gets Derailed
The most frequent failure isn't a company that ignores the framework. It's a company that starts strong on Govern, produces a genuinely good policy document, and then lets Map slip for months because nobody wants to do the unglamorous work of surveying every department about their software stack. A policy with no inventory behind it is a shelf document.
The second most frequent failure is the reverse: a technically-minded team skips straight to Measure because bias testing sounds like the real work. They build an impressive testing harness for one system and have nothing to say when asked about the other dozen AI tools the company is quietly running.
Sequence discipline is the whole point here. A readiness assessment before you start can surface which of these two failure modes your company is more prone to, based on how the last cross-functional compliance project actually went. A documented AI strategy roadmap is where the Govern-Map-Measure-Manage timeline should live, so it survives the inevitable turnover on whoever's driving it.
FAQ
Do the four NIST AI RMF functions have to be implemented in order? NIST's own documentation describes Govern, Map, Measure, and Manage as functions meant to operate continuously and in parallel in a mature program. For a resource-constrained company building its first program, a sequential Govern-then-Map-then-Measure-then-Manage order produces usable outputs faster, because each function depends on decisions the previous one settles.
How long does a full NIST AI RMF implementation take for a company around 200 employees? A realistic first full pass, with one part-time owner and executive sponsorship, runs four to five months: four to eight weeks for Govern, four to six weeks for Map, six to ten weeks for Measure on the highest-risk systems, and an initial three to four weeks to stand up Manage's response procedures. Ongoing monitoring under Manage continues after that.
Is NIST AI RMF a legal requirement? No. NIST AI RMF 1.0, published January 26, 2023, is a voluntary framework with no certification or enforcement mechanism attached to it. It's referenced by procurement questionnaires, customer due-diligence processes, insurers, and some state-level AI statutes as an evidence baseline, but adopting it is a business decision, not a legal mandate.
What's the difference between NIST AI RMF and ISO 42001 for a mid-size company? NIST AI RMF is a self-implemented risk management framework with no third-party audit. ISO/IEC 42001:2023 is a certifiable management system standard that an accredited body audits against, including a documented risk assessment process under its clause 6.1.2. Companies typically build their internal program against NIST AI RMF first and pursue ISO 42001 certification later if a customer or contract specifically requires third-party proof.
Should the AI inventory in the Map phase include vendor tools, or only systems the company builds itself? It has to include vendor tools. Most 200-person companies discover during the Map phase that a majority of their AI exposure comes from features vendors added to existing SaaS tools rather than from anything built in-house, and those features often ship without an announcement the procurement team would notice.
Last updated: 2026-08-18
Jared Clark
AI Strategy Consultant, AI Strategies Consulting
Jared Clark is the founder of AI Strategies Consulting, helping organizations design and implement practical AI systems that integrate with existing operations.