Back to blog

AI Governance · Plain-English Operator's Guide

NIST AI RMF for small business: the plain-English operator's guide.

May 20, 2026 9 min readJohn Utley

Direct Answer

Small businesses deploying AI in revenue and finance workflows are subject to the same legal exposure as enterprises, with fewer resources to absorb it. NIST AI RMF is voluntary in the US but functions as the default benchmark of due care. The EU AI Act reaches US SMBs that touch EU buyers. ISO/IEC 42001 is the only currently certifiable AI management standard. Documented alignment to all three, in plain English, is the minimum viable governance posture.

The counterargument runs first. Most small businesses believe AI governance is enterprise theater. It is not. The carriers underwriting your cyber policy, the buyers signing your master agreement, and the state attorneys general writing 2026 enforcement actions all use the same playbook. They ask for written AI policy, named risk owners, and a logged risk register. If you cannot produce them, you are uninsurable, unsellable, or unprosecutable in your own defense.

The good news is that the minimum viable governance posture is cheap, fast, and aligned to the three frameworks that matter. This guide explains all three in operator language and tells you what to document this quarter.

4

NIST AI RMF functions

7%

Max EU AI Act fine, global revenue

$8.5K

Sophizo Governance-Ready Sprint

What is NIST AI RMF in one paragraph?

The NIST AI Risk Management Framework is a voluntary US framework published in January 2023 that organizes responsible AI deployment into four functions. Govern sets the policy. Map identifies the AI systems and their context. Measure quantifies the risks. Manage handles ongoing monitoring and incident response. The framework is not law. It is the reference text every US regulator, insurance carrier, and enterprise procurement team now uses as the default benchmark of due care.

What do the four functions actually mean for a 50-person company?

Govern. A written AI policy signed by the CEO. It names the policy owner, the escalation path, the approved AI systems, and the prohibited use cases. Two pages is fine. Two pages signed beats forty pages drafted.

Map. A risk register. One row per AI system in use. Columns for system name, vendor, data flowing in, output produced, business function affected, risk classification, and named owner. A 12-row spreadsheet is enough for a 50-person company.

Measure. A quarterly review where the named owners log incidents, near-misses, and material changes to any AI system. Sixty minutes per quarter. Documented.

Manage. An incident response procedure. Who gets called when an AI system produces a bad output that reaches a customer or a regulator. Which customers get notified. Which logs get preserved. Which insurer gets called. One page.

Does the EU AI Act actually apply to a US small business?

Article 2 of Regulation (EU) 2024/1689 establishes extraterritorial scope. The Act applies to any provider or deployer whose AI system output is used in the EU, regardless of where the provider or deployer is established. A US SMB sending AI-generated outbound emails to EU prospects is in scope. A US SMB whose AI-scored candidate evaluations are used by an EU subsidiary is in scope. A US SMB with no EU customers and no EU partners is out of scope.

The phased applicability timeline matters. Prohibited practices were enforceable in February 2025. General-purpose AI obligations were enforceable in August 2025. High-risk AI obligations are enforceable in August 2026. Most SMB use cases (lead triage, proposal drafting, meeting summary) fall into the minimal-risk or limited-risk category and require transparency disclosures rather than conformity assessment. The transparency disclosures are still mandatory. Most SMBs have not implemented them.

What about state-level US legislation?

Three pieces of state-level legislation already reach companies of any size. Colorado SB24-205, effective February 2026, regulates high-risk AI systems making consequential decisions about consumers. California SB 942, effective January 2026, regulates AI-generated content disclosures. New York City Local Law 144 regulates automated employment decision tools and applies to any employer hiring in NYC.

None of these is conditioned on company size. A 30-person company hiring in NYC has the same Local Law 144 obligations as a 30,000-person company. The cost of compliance for a small company is low, but only if the system is configured for it from the start. Retrofitting compliance into a poorly configured AI deployment is expensive.

What is ISO/IEC 42001 and should an SMB pursue certification?

ISO/IEC 42001:2023 is the first international management system standard for AI. It is structured the same way ISO 27001 is structured for information security. The standard defines requirements for an AI Management System (AIMS) and is certifiable through accredited bodies. Annex A defines 38 specific controls covering data, lifecycle, third-party relationships, and impact assessment.

For B2B SMBs selling into the enterprise, ISO 42001 alignment will show up in RFPs the same way SOC 2 did between 2018 and 2020. Alignment (self-attested) is achievable in 90 days. Certification (third-party audited) is a 9-to-12 month engagement and is premature for most companies under 100 seats. The Sophizo Governance-Ready Sprint produces ISO 42001 aligned documentation. Certification, when it is the right move, is a separate engagement.

What is the difference between aligned and certified, and why does it matter?

Aligned means the organization has implemented the framework's controls and self-attested to that implementation. Certified means an accredited third-party body has audited the implementation and issued a formal certificate. NIST AI RMF does not have a certification scheme. All NIST alignment is self-attested. ISO 42001 does have a certification scheme. The EU AI Act has a conformity assessment process for high-risk systems but no general AI certification.

Honest service providers say aligned when they mean aligned. Providers who claim NIST certification are misrepresenting the framework. This matters because the misrepresentation itself becomes a discoverable item in a regulatory action or breach litigation. The cheapest insurance is precise language.

FAQ

What is the NIST AI Risk Management Framework?

The NIST AI Risk Management Framework (AI RMF 1.0) is a voluntary framework published by the US National Institute of Standards and Technology in January 2023. It organizes AI risk management into four functions: Govern, Map, Measure, and Manage. It is not law. It is the most widely adopted reference standard for responsible AI deployment in the US and is being cited by state regulators and insurance carriers as a benchmark of due care.

Does NIST AI RMF apply to small businesses?

Technically, NIST AI RMF is voluntary for all organizations regardless of size. Practically, any small business deploying AI in a revenue or finance workflow benefits from aligning to it because it is the framework state regulators, the FTC, the EEOC, and major insurance carriers are using as their default reference. A small business with documented NIST AI RMF alignment is materially more defensible than one without.

What is the difference between aligned and certified?

Aligned means the organization has implemented the framework's controls and documented its compliance. Certified means an accredited third-party auditor has verified that implementation against a formal standard. NIST AI RMF does not currently offer a certification scheme, so all NIST alignment is self-attested. ISO/IEC 42001 does offer certification through accredited bodies. Honest service providers say aligned. Providers who say certified for NIST are misrepresenting.

Does the EU AI Act apply to US small businesses?

Yes, in two cases. First, if the small business places AI-driven output into the EU market, for example sending AI-generated proposals to EU buyers or running AI-scored applications for EU candidates. Second, if the small business sells through a partner that resells into the EU. Article 2 establishes extraterritorial scope. The fines for non-compliance with prohibited practices reach 35 million euros or 7 percent of global revenue, whichever is greater.

What is ISO/IEC 42001 and why is it different?

ISO/IEC 42001:2023 is the first international management system standard specifically for artificial intelligence. It is structured like ISO 27001 for information security: it defines requirements for an AI Management System (AIMS) and is certifiable through accredited bodies. For B2B SMBs selling to enterprise buyers, ISO 42001 certification is increasingly showing up in RFPs the same way SOC 2 did in 2018 to 2020.

What is the minimum viable AI governance for a 50-person company?

A written AI policy, a risk register naming each AI system in use, an escalation and incident response procedure, a quarterly review cadence, and named owners for each function (Govern, Map, Measure, Manage). The Sophizo Governance-Ready Sprint tier produces all of this in three weeks for $8,500 as part of a Claude for Small Business activation. It is the cheapest defensible documentation an SMB can put on the shelf.

Sources

  1. NIST, "Artificial Intelligence Risk Management Framework (AI RMF 1.0)," NIST AI 100-1, January 2023.
  2. NIST, "Generative AI Profile," NIST AI 600-1, July 2024.
  3. European Commission, Regulation (EU) 2024/1689 (EU AI Act), Articles 2, 9, 26, and 99, Official Journal of the EU, July 2024.
  4. ISO/IEC 42001:2023, "Information technology, Artificial intelligence, Management system," International Organization for Standardization, December 2023.
  5. Colorado General Assembly, SB24-205, "Consumer Protections for Artificial Intelligence," effective February 1, 2026.
  6. California Legislature, SB 942, "California AI Transparency Act," effective January 1, 2026.
  7. New York City Department of Consumer and Worker Protection, "Automated Employment Decision Tools (Local Law 144)," rules effective July 5, 2023.

The Governance-Ready Sprint

Documented governance, shelf-ready in 21 days.

Three-week fixed-fee sprint produces written AI policy, NIST AI RMF risk register, EU AI Act applicability assessment, ISO 42001 aligned documentation, and incident response protocol. $8,500 as part of a Claude for Small Business activation.