Skip to content
#small language model Open access

Shipping Safer LLM Features in SMEs: A OnePage Checklist Mapped to NIST AI RMF and ISO/IEC 23894/42001

Sep 2026 · International Journal of Innovative Science and Research Technology · 0 citations · 12 references

TL;DR

It is concluded that the distance between voluntary framework guidance and auditable management-system requirements can be closed for SMEs by a small, clause-mapped control set with explicit evidence requirements, and that the principal remaining barrier is threshold calibration rather than control selection.

Abstract

Small and medium-sized enterprises (SMEs) are deploying large language model (LLM) features without the governance capacity of larger firms. This paper synthesizes the NIST AI Risk Management Framework (AI RMF 1.0) and its 2024 Generative AI Profile with ISO/IEC 23894:2023 and ISO/IEC 42001:2023 to produce a concise, citable one-page checklist mapped to auditable clauses. The artifact was developed under a design-science method using a structured, rulegoverned mapping protocol applied to the two standards and to the official National Institute of Standards and Technology - NIST crosswalks. Organized by the RMF functions (Govern, Map, Measure, Manage), the result is a set of sixteen minimum-viable controls, each mapped to specific ISO/IEC clauses, together with a gap analysis contrasting typical SME practice with framework expectations, a framework crosswalk matrix, and a risk-lifecycle role allocation. The artifact further contributes a worked example of release-gate thresholds, a procedure for deriving local gate values from a measured baseline, and a lightweight eight-to-twelve-week validation plan suited to resource-constrained organizations. The example threshold values are illustrative and have not been empirically validated. We conclude that the distance between voluntary framework guidance and auditable management-system requirements can be closed for SMEs by a small, clause-mapped control set with explicit evidence requirements, and that the principal remaining barrier is threshold calibration rather than control selection. The significance is practical: SMEs obtain a short and defensible route from RMF guidance toward ISO/IEC 42001 certification practices. Empirical validation across multiple SMEs is planned as future work.

Read PDF

Similar papers

Preprint Aug 2026

Operationalizing Regulations into Code: A Model to Enhance Governance and Compliance in LLM Selection for Software Engineering

The results provide preliminary evidence that regulatory disqualification logic, particularly K.O. criteria, can prevent the selection of technically competitive models that nonetheless pose unacceptable compliance risks, demonstrating the feasibility of governance-oriented LLM selection in software engineering project...

J. Quintino, H. Moura, Filipe Calegario · 0 citations
Conference Open access Aug 2026

CORRELATION ANALYSIS, CONFORMITY MATRIX, AND TRANSITION STRATEGY FROM ISO 9001:2015 TO ISO 9001:2026 IN THE IMPLEMENTATION OF A MODERN QUALITY MANAGEMENT SYSTEM

ISO 9001 is the most widely used international standard for implementing Quality Management Systems (QMS) across various industrial and service sectors. Since the publication of ISO 9001:2015, organizations worldwide have adopted a risk-based approach, a process approach, and the Plan-Do-Check-Act (PDCA) cycle as the f...

Wiwiet Prihatmadji, Faridah, Herry Syafrial · 0 citations
Review Open access Sep 2026

Modernizing Legacy ABAP to Clean-Core SAP: A Measurable Framework for Secure and Human-Centered ERP Transformation in U.S. Small and Mid-Sized Manufacturing

Small and mid-sized manufacturers that have operated SAP environments for many years often carry a substantial layer of custom ABAP code, interfaces, enhancements, and process-specific modifications. Those assets may encode valuable business knowledge, but they can also increase technical debt, complicate upgrades, wea...

Azlan Ahmed, Syeda Areeba Hasan · 0 citations
Open access Aug 2026

A Conceptual Framework for OT/ICS Cybersecurity Governance in Malaysian Manufacturing Environments Under Industry 4.0

The convergence of Information Technology (IT) and Operational Technology (OT) in Malaysian manufacturing environments has created a cybersecurity governance problem that existing frameworks were not designed to solve. Malaysia's manufacturing sector contributes 24.5% of national GDP (EPU, 2022) and is overwhelmingly m...

Navenesh Kumar · 0 citations
Open access Sep 2026

From legal to organizational formalization: A pyramid of organizational development approach to SME maturity a multiple case study of an Indonesian machining and MRO workshop

Small and medium-sized enterprises (SMEs) in Indonesia are increasingly converting into limited liability companies, but such conversion changes a firm’s legal status without necessarily transforming how it operates. This study examines that gap in a family-owned machining and maintenance, repair, and operations (MRO)...

Rivaldo Ciady, Sahat · 0 citations

Related blog posts

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.