Frameworks / NIST_AI_RMF
AI Risk Management Framework 1.0
NIST · US · effective 2023-01-26 · NIST_AI_RMF
Voluntary. Four functions: Govern, Map, Measure, Manage. Widely used as the scaffolding US examiners expect to see.
5 controls, mapped to the evidence that satisfies each
Every control links to the dimension whose evidence would satisfy it. That mapping is the working link between an obligation written in law or a standard and a document somebody has to produce. Each row has its own address: link to a single control.
| Control | Title | Requirement | Satisfied by |
|---|---|---|---|
| MAP-2.3 | Scientific integrity and TEVV | Test, evaluation, verification and validation defined and documented. | D2 |
| MEASURE-2.7 | Security and resilience evaluated | Red-team and adversarial results recorded. | D3 |
| MEASURE-2.11 | Fairness and bias evaluated | Bias measured across relevant demographic groups. | D4 |
| MANAGE-4.1 | Post-deployment monitoring | Performance monitored in production with defined thresholds. | D6 |
| GOVERN-1.1 | Legal and regulatory requirements understood | Requirements applying to the system are inventoried and tracked. | D7 |
What this mapping is, and what it is not
It is a reading of a published instrument, with each control cited to its source, mapped to the kind of evidence that would satisfy it. It is not legal advice, not a certification, and not a statement that any organisation complies with anything. Where an instrument is not yet in force, this page says so rather than selling urgency.
Talk to the person who built this
If you assess clients against this instrument, the mapping is the part you can check line by line. There is no sales team: this is founder-led, so it reaches the founder directly. Tenant access is $500 a month, and free early access to the method, the corpus and the router is on offer first if that is useful. If it is not a fit, saying so costs you one reply.