Authors :
Mohamed Riyaz M. Meera Rawuthar; Ahmad M. Al-Ali
Volume/Issue :
Volume 11 - 2026, Issue 8 - August
Google Scholar :
https://tinyurl.com/5vadrksz
DOI :
https://doi.org/10.38124/ijisrt/26aug1605
Note : A published paper may take 4-5
working days from the publication date to appear in PlumX Metrics, Semantic Scholar, and
ResearchGate.
Abstract :
Small and medium-sized enterprises (SMEs) are deploying large language model (LLM) features without the
governance capacity of larger firms. This paper synthesizes the NIST AI Risk Management Framework (AI RMF 1.0) and
its 2024 Generative AI Profile with ISO/IEC 23894:2023 and ISO/IEC 42001:2023 to produce a concise, citable one-page
checklist mapped to auditable clauses. The artifact was developed under a design-science method using a structured, rulegoverned mapping protocol applied to the two standards and to the official National Institute of Standards and Technology
- NIST crosswalks. Organized by the RMF functions (Govern, Map, Measure, Manage), the result is a set of sixteen
minimum-viable controls, each mapped to specific ISO/IEC clauses, together with a gap analysis contrasting typical SME
practice with framework expectations, a framework crosswalk matrix, and a risk-lifecycle role allocation. The artifact
further contributes a worked example of release-gate thresholds, a procedure for deriving local gate values from a measured
baseline, and a lightweight eight-to-twelve-week validation plan suited to resource-constrained organizations. The example
threshold values are illustrative and have not been empirically validated. We conclude that the distance between voluntary
framework guidance and auditable management-system requirements can be closed for SMEs by a small, clause-mapped
control set with explicit evidence requirements, and that the principal remaining barrier is threshold calibration rather than
control selection. The significance is practical: SMEs obtain a short and defensible route from RMF guidance toward
ISO/IEC 42001 certification practices. Empirical validation across multiple SMEs is planned as future work.
Keywords :
AI Governance; Content Provenance; Incident Response; ISO/IEC 23894; ISO/IEC 42001; Large Language Models; NIST AI RMF; Smes.
References :
- NIST, “Artificial Intelligence Risk Management Framework (AI RMF 1.0),” NIST AI 100-1, National Institute of Standards and Technology, Gaithersburg, MD, USA, Jan. 2023, doi: 10.6028/NIST.AI.100-1.
- NIST, “Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile,” NIST AI 600-1, National Institute of Standards and Technology, Gaithersburg, MD, USA, Jul. 2024, doi: 10.6028/NIST.AI.600-1.
- NIST, “Reducing Risks Posed by Synthetic Content: An Overview of Technical Approaches to Digital Content Transparency,” NIST AI 100-4, National Institute of Standards and Technology, Gaithersburg, MD, USA, Nov. 2024, doi: 10.6028/NIST.AI.100-4.
- NIST, “Crosswalks to the NIST Artificial Intelligence Risk Management Framework (AI RMF 1.0),” Dec. 17, 2024. [Online]. Available: https://www.nist.gov/itl/ai-risk-management-framework/crosswalks-nist-artificial-intelligence-risk-management-framework
- Information Technology — Artificial Intelligence — Guidance on Risk Management, ISO/IEC 23894:2023, International Organization for Standardization, Geneva, Switzerland, 2023.
- Information Technology — Artificial Intelligence — Management System, ISO/IEC 42001:2023, International Organization for Standardization, Geneva, Switzerland, 2023.
- E. M. Bender, T. Gebru, A. McMillan-Major, and S. Shmitchell, “On the dangers of stochastic parrots: Can language models be too big?,” in Proc. ACM Conf. Fairness, Accountability, and Transparency (FAccT), 2021, pp. 610–623, doi: 10.1145/3442188.3445922.
- N. Carlini et al., “Extracting training data from large language models,” in Proc. 30th USENIX Security Symp., 2021, pp. 2633–2650, doi: 10.48550/arXiv.2012.07805.
- P. Liang et al., “Holistic evaluation of language models,” arXiv:2211.09110, 2022, doi: 10.48550/arXiv.2211.09110.
- I. D. Raji et al., “Closing the AI accountability gap: Defining an end-to-end framework for internal algorithmic auditing,” in Proc. ACM Conf. Fairness, Accountability, and Transparency (FAccT), 2020, pp. 33–44, doi: 10.1145/3351095.3372873.
- L. Weidinger et al., “Taxonomy of risks posed by language models,” in Proc. ACM Conf. Fairness, Accountability, and Transparency (FAccT), 2022, pp. 214–229, doi: 10.1145/3531146.3533088.
- A. R. Hevner, S. T. March, J. Park, and S. Ram, “Design science in information systems research,” MIS Quarterly, vol. 28, no. 1, pp. 75–105, 2004, doi: 10.2307/25148625.
Small and medium-sized enterprises (SMEs) are deploying large language model (LLM) features without the
governance capacity of larger firms. This paper synthesizes the NIST AI Risk Management Framework (AI RMF 1.0) and
its 2024 Generative AI Profile with ISO/IEC 23894:2023 and ISO/IEC 42001:2023 to produce a concise, citable one-page
checklist mapped to auditable clauses. The artifact was developed under a design-science method using a structured, rulegoverned mapping protocol applied to the two standards and to the official National Institute of Standards and Technology
- NIST crosswalks. Organized by the RMF functions (Govern, Map, Measure, Manage), the result is a set of sixteen
minimum-viable controls, each mapped to specific ISO/IEC clauses, together with a gap analysis contrasting typical SME
practice with framework expectations, a framework crosswalk matrix, and a risk-lifecycle role allocation. The artifact
further contributes a worked example of release-gate thresholds, a procedure for deriving local gate values from a measured
baseline, and a lightweight eight-to-twelve-week validation plan suited to resource-constrained organizations. The example
threshold values are illustrative and have not been empirically validated. We conclude that the distance between voluntary
framework guidance and auditable management-system requirements can be closed for SMEs by a small, clause-mapped
control set with explicit evidence requirements, and that the principal remaining barrier is threshold calibration rather than
control selection. The significance is practical: SMEs obtain a short and defensible route from RMF guidance toward
ISO/IEC 42001 certification practices. Empirical validation across multiple SMEs is planned as future work.
Keywords :
AI Governance; Content Provenance; Incident Response; ISO/IEC 23894; ISO/IEC 42001; Large Language Models; NIST AI RMF; Smes.