RankShield Legal
Citation checker Request access
Governance frameworks

Applying the NIST AI Risk Management Framework and ISO 42001 in a Law Firm

Every AI governance essay tells law firms to align with the NIST AI Risk Management Framework or ISO 42001, and almost none explains what that means for a firm that is not a Fortune 500 company. The frameworks were written for organizations building and deploying AI at scale, not for a practice that mainly uses tools others built. This guide translates both into a practical path a firm can actually walk, mapped to the bar duties you already carry.

By Jamie Kloncz, Founder, RankShield 16 min read Published

Applying the NIST AI RMF in a law firm does not require an enterprise compliance team; it requires mapping the framework's functions onto duties you already have. The NIST AI Risk Management Framework, published in January 2023, organizes AI risk into four functions, Govern, Map, Measure, and Manage, and ISO/IEC 42001, published in December 2023 as the first international AI management system standard, provides an auditable structure for governing AI use [1][2]. For a firm, both are less a new burden than a scaffold for the confidentiality, competence, and supervision duties that ABA Formal Opinion 512 already imposes [3].

The reason these frameworks feel out of reach is that their language assumes an organization developing AI systems. A law firm is almost always a deployer of tools, not a builder, so most of the heaviest requirements, model development controls and the like, simply do not apply. What remains is a manageable set of governance practices, and mapping them to Model Rules you already follow turns an intimidating standard into a checklist you can staff.

This guide is written from the perspective of a verification vendor, not a law firm, and it is informational rather than legal advice. It explains what the two frameworks are, maps their functions to your ethics obligations, lays out a phased adoption path, describes what to document at each phase, and identifies where a small firm can stop and still be defensible.

NIST AI RMF and ISO 42001, briefly

The NIST AI RMF is a voluntary US framework organizing AI risk into four functions: Govern (set policy and accountability), Map (identify context and risks), Measure (assess and track them), and Manage (act on them). ISO/IEC 42001 is a certifiable international standard for an AI management system, the AI equivalent of ISO 27001 for security. One is a flexible framework; the other is an auditable management system [1][2].

The two are complementary rather than competing. The NIST AI RMF, released in January 2023, is voluntary and flexible: it does not certify anything, but it gives a common structure for thinking about AI risk through its Govern, Map, Measure, and Manage functions. Govern sits at the center, establishing policy, roles, and accountability that the other three functions operate within.

ISO/IEC 42001, published in December 2023, is the first international standard for an AI management system, and unlike the NIST framework it is certifiable, meaning an accredited auditor can assess conformance. It defines a managed, auditable process for how an organization develops, provides, and uses AI, in the same family as ISO/IEC 27001 for information security.

For a firm, the practical difference is intent. Use the NIST AI RMF as the thinking tool that structures your program, and treat ISO/IEC 42001 as the target if you ever want an external certification to show clients or insurers. Most firms start with the former and grow toward the latter only if the market demands it.

Mapping the frameworks to your ethics obligations

The frameworks map cleanly onto duties you already hold. Govern aligns with the supervision duty under Model Rules 5.1 and 5.3; Map aligns with competence under Rule 1.1, understanding the tools you use; Measure and Manage align with the confidentiality duty under Rule 1.6, tracking and controlling how client data is exposed. Framed this way, adoption is formalizing existing obligations, not adding new ones [3].

The fastest way to make these frameworks concrete for a firm is to stop treating them as foreign and map each function to the Model Rule it already serves. The table below does that.

Framework functionMaps to bar dutyWhat it means for a firm
Govern (NIST) / Leadership (ISO)Supervision, Rules 5.1 and 5.3A written AI policy, named accountability, staff oversight [3]
Map (NIST)Competence, Rule 1.1Know which tools are used and what they do with data
Measure (NIST)Confidentiality, Rule 1.6Track where client data goes and assess the exposure
Manage (NIST) / Operation (ISO)Confidentiality and competenceApply controls, log use, respond to incidents
Continual improvement (ISO)Ongoing competenceReview and update as tools and rules change
RANKSHIELD LEGAL NIST AI RMF and ISO 42001, sized for a law firm Both frameworks were written for AI builders. A firm deploys. That changes what applies. 4 functions NIST AI RMF: Govern, Map, Measure, Manage Voluntary, published January 202342001 ISO/IEC AI management system standard, certifiable Published December 2023Deployer A firm uses tools others built; model-level requirements do not apply to it 5 items The small-firm floor: written policy, named owner, tool inventory, risk classification, usage log Optional Full ISO 42001 certification is market-driven, not an ethical duty 4 answers Which tools, what data they touch, who approved them, what happens when they are wrong RankShield Legal rankshieldlegal.com
Source: NIST AI RMF 1.0 (2023); ISO/IEC 42001:2023; ABA Formal Opinion 512

A phased adoption path for a firm

Adopt in three phases. Phase one is Govern: write an AI policy, name an owner, and inventory the tools in use. Phase two is Map and Measure: classify each tool's data exposure and confidentiality risk. Phase three is Manage: apply controls, log use, and add incident response. A small firm can complete phase one in weeks and mature through the others rather than attempting everything at once.

Trying to stand up a full AI management system in one project is how firms stall. Phase the work so each stage delivers something defensible on its own.

Phase one, Govern, is the foundation and the fastest win: a written AI policy, a named person accountable for it, and an inventory of the AI tools actually in use. Our guide on building a defensible AI policy covers the policy itself. Phase two, Map and Measure, classifies each tool by what data it touches and how much confidentiality risk it carries, which is where the audit work from a firm-wide AI inventory feeds in. Phase three, Manage, applies the controls: access rules, usage logging, vendor requirements, and an incident-response plan.

Because these frameworks are voluntary for a firm, you set the depth. The value is not a certificate; it is that each phase makes an existing duty operational, and the sequence lets a firm show steady, documented progress rather than an all-or-nothing effort.

What to document at each phase

Document enough to show the program is real: in Govern, the written policy and the accountable owner; in Map and Measure, the tool inventory and a risk classification per tool; in Manage, the controls applied, the usage log, and the incident-response plan. The documentation is both the governance and the evidence, because a framework you followed but cannot show is indistinguishable from one you skipped.

The documentation is not bureaucracy for its own sake; it is what converts a governance intention into something a client, insurer, or regulator can credit. Keep it proportionate to the firm, but keep it.

In the Govern phase, retain the written AI policy and a record of who owns it. In Map and Measure, keep the tool inventory and the risk classification you assigned to each tool, including which handle privileged data. In Manage, document the controls you applied, the log of AI use, and the incident-response plan, along with evidence that the plan has been tested. Where the program touches how AI acts on client matters, tie the documentation to the specific tools, which is where the agentic AI governance gap becomes concrete.

A living set of these documents is what an ISO/IEC 42001 auditor would look for and what an insurer increasingly asks about, so building them during adoption serves both the duty and any later external review.

Where a small firm can stop and still be defensible

A small firm can stop after Govern and a light Map and Measure and still be defensible: a written AI policy, a named owner, a current tool inventory, a basic risk classification, and a simple usage log. Full ISO/IEC 42001 certification is optional and market-driven, not a duty. The defensible minimum is showing you know your tools, control your client data, and supervise their use.

Not every firm needs the full framework, and pretending otherwise is how good governance gets abandoned as too heavy. The honest floor is lower than the frameworks imply, because most of their weight targets AI builders.

For a small firm, a defensible program is a written policy, a named owner, a current inventory of the AI tools in use, a basic classification of which tools touch privileged data, and a simple record of use and any incidents. That set demonstrates competence, confidentiality control, and supervision, which are the duties that actually bind you. Scale up toward ISO/IEC 42001 certification only if clients, insurers, or your own risk appetite call for it.

The goal is proportion. A frame that is right-sized and actually maintained protects the firm and its clients far better than an enterprise program that looks impressive on paper and is never kept current.

Deployer, not developer: why most of the framework does not apply to you

Both frameworks were written with AI builders in view. A law firm almost always deploys tools others built, which makes large parts of each framework inapplicable rather than deferred. Knowing which parts you can set aside is what separates a governance program a firm will maintain from one it abandons as unmanageable [1][2].

The most common failure in law firm AI governance is not neglect. It is a firm reading a framework designed for organizations that train and ship models, concluding the program is enormous, and doing nothing.

Much of the NIST AI RMF's substance addresses questions a deployer cannot answer: training data provenance, model architecture decisions, bias testing of the underlying system, and validation of model performance across populations. A firm licensing a commercial drafting tool has no access to any of that and no ability to change it.

What remains for a deployer is genuinely smaller and entirely actionable. Which tools are in use and who authorized them. What categories of client data may enter each one. Who is accountable when something goes wrong. What the firm does when output is wrong. Whether people using the tools understand their limits. That is a real program, and it maps to duties the firm already carries under ABA Formal Opinion 512 rather than to obligations the frameworks invent [3].

The deployer framing also redirects one question outward. Where a firm cannot assess model-level risk itself, the framework's demand becomes a procurement demand: require the vendor to show its own governance, its audit posture, and its AI management program. The firm is not excused from the risk; it discharges the obligation by contracting and verifying rather than by testing a model it cannot see.

Read that way, ISO/IEC 42001 becomes most useful to a firm as a vendor-evaluation vocabulary rather than as a certification target. A vendor holding it, or documenting a program against it, is telling you something checkable about how it manages AI risk [2].

What makes a governance program survive its first year

A program fails between the policy and the practice. The three things that keep one alive are a named owner with actual authority, a review cadence tied to events rather than to good intentions, and an inventory that updates when tools change. Without those, a firm ends up with a current document describing a program nobody runs.

Most abandoned governance programs were not badly designed. They were designed once, adopted, and then not touched, while the tools they described kept changing underneath them.

A named owner is the first requirement, and the name has to belong to a person rather than a committee. The owner needs enough authority to say no to a tool, which is the test of whether the role is real. If the answer to "who decides whether we adopt this" is nobody in particular, the policy is descriptive rather than governing.

A review cadence works better when tied to events than to the calendar. An annual review will slip. A rule that any new AI tool requires an inventory entry and a data classification before use, and that any incident triggers a review of the relevant control, fires when something has actually changed and is therefore worth doing.

The inventory is where programs quietly die. A tool list assembled once and never updated becomes actively misleading, because it reads like knowledge while describing a state of the world that has passed. Tie inventory updates to the events that change it: procurement, a new integration in an existing product, and departure or role change for anyone who administered a tool.

The point is not to build toward certification. It is to be able to answer, on any given day, which tools the firm uses, what client data they touch, who approved them, and what happens when they are wrong. A firm that can answer those four questions has a defensible program, whatever it is called [3].

4 answers a defensible program can state, on any day: which tools are in use, what data they touch, who approved them, and what happens when they are wrong
Test yourself

Test yourself on right-sizing AI governance

Five questions on what these frameworks actually ask of a law firm.

  1. 1What are the four functions of the NIST AI Risk Management Framework?

    Answer: Govern, Map, Measure, Manage

    Govern sets policy and accountability, Map identifies context and risks, Measure assesses and tracks them, and Manage acts on them. The framework is voluntary and certifies nothing; it supplies a common structure.

  2. 2Why does much of each framework not apply to a law firm?

    Answer: The frameworks target organizations that build and ship models, and a firm deploys

    Training data provenance, model architecture, and bias testing of the underlying system are questions a deployer cannot answer or change. What remains for a firm is smaller and entirely actionable.

  3. 3What does the deployer framing do with model-level risk a firm cannot assess?

    Answer: Converts it into a procurement demand on the vendor

    The firm is not excused. It discharges the obligation by requiring the vendor to show its governance, audit posture, and AI management program, then verifying, rather than by testing a model it cannot see.

  4. 4What is the defensible floor for a small firm?

    Answer: Written policy, named owner, tool inventory, risk classification, usage log

    That set demonstrates competence, confidentiality control, and supervision, which are the duties that actually bind a firm. Certification is optional and market-driven rather than an ethical requirement.

  5. 5What most often kills a governance program in its first year?

    Answer: An inventory that stops being updated while the tools keep changing

    A tool list assembled once becomes actively misleading, because it reads like knowledge while describing a state of the world that has passed. Tie updates to events, procurement, new integrations, and administrator changes, rather than to the calendar.

Honest self-check. There is no sign-up, and nothing is stored.

Questions answered

Straight answers to the common questions

The questions readers ask about this topic, answered directly. No forms, no sales pitch.

JAMIE KLONCZ · SEO AGENCY NAPLES ONLINE

Pick a question on the left, or search above. You will get the direct answer, the way an answer engine would give it.

REQUEST ACCESS →

References

  1. National Institute of Standards and Technology. AI Risk Management Framework (AI RMF 1.0). January 2023. https://www.nist.gov/itl/ai-risk-management-framework
  2. International Organization for Standardization. ISO/IEC 42001:2023 Artificial Intelligence Management System. December 2023. https://www.iso.org/standard/81230.html
  3. American Bar Association. Formal Opinion 512: Generative Artificial Intelligence Tools. July 2024. https://www.americanbar.org/news/abanews/aba-news-archives/2024/07/aba-issues-first-ethics-guidance-ai-tools/
Written by

Jamie Kloncz

Founder, RankShield

Jamie Kloncz is the founder of RankShield, the verifiable AI and quantum security platform behind RankShield Legal. An engineer by training, he built RankShield after his own devices and business were attacked, including an AI voice-cloning scam that targeted his family, on one conviction: unverifiable security is the real danger, so every consequential action should leave a receipt anyone can independently check.

More about Jamie →
Try it · Free

Check a citation against live case-law

Paste a citation from an AI-drafted brief and see whether the case actually exists, resolved against live case-law. Free, no sign-up. Then request early access to certify a full filing.

Try the citation checker