Govern
Who is responsible?Agent ownership and decision records
Selected references mappedThe business records who is responsible, what people and agents decided, and where an action was held. Those records support selected NIST AI RMF references without pretending to measure every risk.
NIST AI RMF organizes risk management around Govern, Map, Measure, and Manage. It is a voluntary framework for evaluating and managing AI risks throughout the lifecycle. Operational records help inform that work, alongside system evaluations and organizational judgment.
Selected records contribute to the framework. They do not replace the risk program.
Agent ownership and decision records
Selected references mappedBusiness context and risk assessment
No current catalog mappingDecision history and recorded reasons
Selected references mappedHolds, approvals and incident communications
Selected references mappedSelected NIST references are present in the catalog. A catalog entry does not mean that the review window contains evidence for it.
What the record contributesEach registered agent has a named responsible person, and its packet shows what it did. Together they support an inventory review.
What still needs reviewUnregistered or unobserved systems still need to be identified and assessed.
What the record contributesThe receipts show who acted, who approved and which rule applied, which is the record a transparency and accountability review needs.
What still needs reviewRecorded activity does not replace assessment of the relevant AI risks.
What the record contributesEach held or permitted action carries the rule that applied and the reason for the decision, so a reviewer can examine how it was explained.
What still needs reviewA documented decision is not proof that the model itself is interpretable or the explanation is sufficient.
What the record contributesHolds and recorded human approvals show where the company intervened.
What still needs reviewActivity learned about afterward does not demonstrate that an action was held.
What the record contributesRecorded communications to affected customers about a service incident support incident-communication review.
What still needs reviewA review window without a qualifying communication remains not evidenced. Reconstructing an incident does not establish that anyone was told.
Mapping version 2026.09.3. Selected references support a review; they do not establish compliance or certification. Packet availability is confirmed for your deployment.
The selected mappings connect the review to recorded work. The company still needs to assess risks beyond that record.
Receipts & verificationContext, affected stakeholders, and risk tolerance
System testing, measurement methods, and evaluations
Incident communication and ongoing risk-treatment decisions
No. NIST AI RMF is a voluntary risk-management framework, and the selected mapping is a reference for review. It is not a NIST certification or endorsement.
It contains selected references within Govern, Measure, and Manage. It is not a complete mapping of the four functions, every subcategory, or the Generative AI Profile.
When the review window has no qualifying record of a service-incident communication to an affected customer. The catalog links that kind of record to MANAGE 4.3; a reconstruction alone does not establish that the communication happened.
The authoritative framework and the scope of your review remain the reference points.