⚠ Official Notice: www.ijisrt.com is the official website of the International Journal of Innovative Science and Research Technology (IJISRT) Journal for research paper submission and publication. Please beware of fake or duplicate websites using the IJISRT name.



Shipping Safer LLM Features in SMEs: A OnePage Checklist Mapped to NIST AI RMF and ISO/IEC 23894/42001


Authors : Mohamed Riyaz M. Meera Rawuthar; Ahmad M. Al-Ali

Volume/Issue : Volume 11 - 2026, Issue 8 - August


Google Scholar : https://tinyurl.com/5vadrksz

DOI : https://doi.org/10.38124/ijisrt/26aug1605

Note : A published paper may take 4-5 working days from the publication date to appear in PlumX Metrics, Semantic Scholar, and ResearchGate.


Abstract : Small and medium-sized enterprises (SMEs) are deploying large language model (LLM) features without the governance capacity of larger firms. This paper synthesizes the NIST AI Risk Management Framework (AI RMF 1.0) and its 2024 Generative AI Profile with ISO/IEC 23894:2023 and ISO/IEC 42001:2023 to produce a concise, citable one-page checklist mapped to auditable clauses. The artifact was developed under a design-science method using a structured, rulegoverned mapping protocol applied to the two standards and to the official National Institute of Standards and Technology - NIST crosswalks. Organized by the RMF functions (Govern, Map, Measure, Manage), the result is a set of sixteen minimum-viable controls, each mapped to specific ISO/IEC clauses, together with a gap analysis contrasting typical SME practice with framework expectations, a framework crosswalk matrix, and a risk-lifecycle role allocation. The artifact further contributes a worked example of release-gate thresholds, a procedure for deriving local gate values from a measured baseline, and a lightweight eight-to-twelve-week validation plan suited to resource-constrained organizations. The example threshold values are illustrative and have not been empirically validated. We conclude that the distance between voluntary framework guidance and auditable management-system requirements can be closed for SMEs by a small, clause-mapped control set with explicit evidence requirements, and that the principal remaining barrier is threshold calibration rather than control selection. The significance is practical: SMEs obtain a short and defensible route from RMF guidance toward ISO/IEC 42001 certification practices. Empirical validation across multiple SMEs is planned as future work.

Keywords : AI Governance; Content Provenance; Incident Response; ISO/IEC 23894; ISO/IEC 42001; Large Language Models; NIST AI RMF; Smes.

References :

  1. NIST, “Artificial Intelligence Risk Management Framework (AI RMF 1.0),” NIST AI 100-1, National Institute of Standards and Technology, Gaithersburg, MD, USA, Jan. 2023, doi: 10.6028/NIST.AI.100-1.
  2. NIST, “Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile,” NIST AI 600-1, National Institute of Standards and Technology, Gaithersburg, MD, USA, Jul. 2024, doi: 10.6028/NIST.AI.600-1.
  3. NIST, “Reducing Risks Posed by Synthetic Content: An Overview of Technical Approaches to Digital Content Transparency,” NIST AI 100-4, National Institute of Standards and Technology, Gaithersburg, MD, USA, Nov. 2024, doi: 10.6028/NIST.AI.100-4.
  4. NIST, “Crosswalks to the NIST Artificial Intelligence Risk Management Framework (AI RMF 1.0),” Dec. 17, 2024. [Online]. Available: https://www.nist.gov/itl/ai-risk-management-framework/crosswalks-nist-artificial-intelligence-risk-management-framework
  5. Information Technology — Artificial Intelligence — Guidance on Risk Management, ISO/IEC 23894:2023, International Organization for Standardization, Geneva, Switzerland, 2023.
  6. Information Technology — Artificial Intelligence — Management System, ISO/IEC 42001:2023, International Organization for Standardization, Geneva, Switzerland, 2023.
  7. E. M. Bender, T. Gebru, A. McMillan-Major, and S. Shmitchell, “On the dangers of stochastic parrots: Can language models be too big?,” in Proc. ACM Conf. Fairness, Accountability, and Transparency (FAccT), 2021, pp. 610–623, doi: 10.1145/3442188.3445922.
  8. N. Carlini et al., “Extracting training data from large language models,” in Proc. 30th USENIX Security Symp., 2021, pp. 2633–2650, doi: 10.48550/arXiv.2012.07805.
  9. P. Liang et al., “Holistic evaluation of language models,” arXiv:2211.09110, 2022, doi: 10.48550/arXiv.2211.09110.
  10. I. D. Raji et al., “Closing the AI accountability gap: Defining an end-to-end framework for internal algorithmic auditing,” in Proc. ACM Conf. Fairness, Accountability, and Transparency (FAccT), 2020, pp. 33–44, doi: 10.1145/3351095.3372873.
  11. L. Weidinger et al., “Taxonomy of risks posed by language models,” in Proc. ACM Conf. Fairness, Accountability, and Transparency (FAccT), 2022, pp. 214–229, doi: 10.1145/3531146.3533088.
  12. A. R. Hevner, S. T. March, J. Park, and S. Ram, “Design science in information systems research,” MIS Quarterly, vol. 28, no. 1, pp. 75–105, 2004, doi: 10.2307/25148625.

Small and medium-sized enterprises (SMEs) are deploying large language model (LLM) features without the governance capacity of larger firms. This paper synthesizes the NIST AI Risk Management Framework (AI RMF 1.0) and its 2024 Generative AI Profile with ISO/IEC 23894:2023 and ISO/IEC 42001:2023 to produce a concise, citable one-page checklist mapped to auditable clauses. The artifact was developed under a design-science method using a structured, rulegoverned mapping protocol applied to the two standards and to the official National Institute of Standards and Technology - NIST crosswalks. Organized by the RMF functions (Govern, Map, Measure, Manage), the result is a set of sixteen minimum-viable controls, each mapped to specific ISO/IEC clauses, together with a gap analysis contrasting typical SME practice with framework expectations, a framework crosswalk matrix, and a risk-lifecycle role allocation. The artifact further contributes a worked example of release-gate thresholds, a procedure for deriving local gate values from a measured baseline, and a lightweight eight-to-twelve-week validation plan suited to resource-constrained organizations. The example threshold values are illustrative and have not been empirically validated. We conclude that the distance between voluntary framework guidance and auditable management-system requirements can be closed for SMEs by a small, clause-mapped control set with explicit evidence requirements, and that the principal remaining barrier is threshold calibration rather than control selection. The significance is practical: SMEs obtain a short and defensible route from RMF guidance toward ISO/IEC 42001 certification practices. Empirical validation across multiple SMEs is planned as future work.

Keywords : AI Governance; Content Provenance; Incident Response; ISO/IEC 23894; ISO/IEC 42001; Large Language Models; NIST AI RMF; Smes.

Paper Submission Last Date
30 - September - 2026

SUBMIT YOUR PAPER CALL FOR PAPERS
Video Explanation for Published paper

Never miss an update from Papermashup

Get notified about the latest tutorials and downloads.

Subscribe by Email

Get alerts directly into your inbox after each post and stay updated.
Subscribe
OR

Subscribe by RSS

Add our RSS to your feedreader to get regular updates from us.
Subscribe