Skip to content

Keep AI risk connected to the work.

The business records who is responsible, what people and agents decided, and where an action was held. Those records support selected NIST AI RMF references without pretending to measure every risk.

Risk management continues after deployment.

NIST AI RMF organizes risk management around Govern, Map, Measure, and Manage. It is a voluntary framework for evaluating and managing AI risks throughout the lifecycle. Operational records help inform that work, alongside system evaluations and organizational judgment.

Four functions. A wider review.

Selected records contribute to the framework. They do not replace the risk program.

Govern

Who is responsible?

Agent ownership and decision records

Selected references mapped

Map

What could this affect?

Business context and risk assessment

No current catalog mapping

Measure

What does the evidence support?

Decision history and recorded reasons

Selected references mapped

Manage

What was done about it?

Holds, approvals and incident communications

Selected references mapped

See the references and the evidence they need.

Selected NIST references are present in the catalog. A catalog entry does not mean that the review window contains evidence for it.

ReferenceWhat the record contributesWhat still needs review

GOVERN 1.6

What the record contributesEach registered agent has a named responsible person, and its packet shows what it did. Together they support an inventory review.

What still needs reviewUnregistered or unobserved systems still need to be identified and assessed.

MEASURE 2.8

What the record contributesThe receipts show who acted, who approved and which rule applied, which is the record a transparency and accountability review needs.

What still needs reviewRecorded activity does not replace assessment of the relevant AI risks.

MEASURE 2.9

What the record contributesEach held or permitted action carries the rule that applied and the reason for the decision, so a reviewer can examine how it was explained.

What still needs reviewA documented decision is not proof that the model itself is interpretable or the explanation is sufficient.

MANAGE 4.1

What the record contributesHolds and recorded human approvals show where the company intervened.

What still needs reviewActivity learned about afterward does not demonstrate that an action was held.

MANAGE 4.3

What the record contributesRecorded communications to affected customers about a service incident support incident-communication review.

What still needs reviewA review window without a qualifying communication remains not evidenced. Reconstructing an incident does not establish that anyone was told.

Mapping version 2026.09.3. Selected references support a review; they do not establish compliance or certification. Packet availability is confirmed for your deployment.

Keep the review bigger than the selected records.

The selected mappings connect the review to recorded work. The company still needs to assess risks beyond that record.

Receipts & verification
  • 01

    Context, affected stakeholders, and risk tolerance

  • 02

    System testing, measurement methods, and evaluations

  • 03

    Incident communication and ongoing risk-treatment decisions

Questions about NIST AI RMF?

Is this a NIST certification?

No. NIST AI RMF is a voluntary risk-management framework, and the selected mapping is a reference for review. It is not a NIST certification or endorsement.

Does the catalog cover all four core functions?

It contains selected references within Govern, Measure, and Manage. It is not a complete mapping of the four functions, every subcategory, or the Generative AI Profile.

When is MANAGE 4.3 marked not evidenced?

When the review window has no qualifying record of a service-incident communication to an affected customer. The catalog links that kind of record to MANAGE 4.3; a reconstruction alone does not establish that the communication happened.

Go back to the source.

The authoritative framework and the scope of your review remain the reference points.

Start with the risk your team needs to understand.

Discuss your requirements