Establish responsibility
Connect registered agents with their named owners and the scope of activity under review.
Connect agent ownership, decision history, and intervention evidence to selected outcomes in the NIST AI Risk Management Framework.
NIST AI RMF organizes risk management around Govern, Map, Measure, and Manage. It is a voluntary framework for evaluating and managing AI risks throughout the lifecycle. Operational records help inform that work, alongside system evaluations and organizational judgment.
Named responsibility, recorded decisions, and intervention history give reviewers concrete material to examine as AI use changes.
Explore agent governanceConnect registered agents with their named owners and the scope of activity under review.
Review recorded actions, policy references, and the basis for each verdict.
Distinguish controls exercised before execution from findings based on observed activity.
Selected NIST references are present in the catalog. A catalog entry does not mean that the review window contains evidence for it.
Product evidenceRegistered-agent attribution and packet records support an inventory review.
Review limitsUnregistered or unobserved systems still need to be identified and assessed.
Product evidenceReceipt history provides a record for transparency and accountability review.
Review limitsRecorded activity does not replace assessment of the relevant AI risks.
Product evidenceVerdicts, rule references, and decision basis provide material for explanation review.
Review limitsA documented decision is not proof that the model itself is interpretable or the explanation is sufficient.
Product evidenceHolds and human-decided gates record interventions in governed activity.
Review limitsObservation-only telemetry cannot demonstrate an in-path intervention.
Product evidenceCatalogued without a mapped incident-reporting artifact.
Review limitsShown as not evidenced. Incident reconstruction does not automatically establish incident communication.
Catalog 2026.09.2. A selected mapping supports evidence review; it does not establish compliance or certification.
The current mappings cover selected records, rather than the whole framework or every risk associated with an AI system.
Context, affected stakeholders, and risk tolerance
System testing, measurement methods, and evaluations
Incident communication and ongoing risk-treatment decisions
No. NIST AI RMF is a voluntary risk-management framework, and the product’s crosswalk is an advisory reference. It is not a NIST certification or endorsement.
It contains selected references within Govern, Measure, and Manage. It is not a complete mapping of the four functions, every subcategory, or the Generative AI Profile.
The catalog includes that reference, but no current evidence primitive maps to an incident-reporting artifact. The gap remains visible even when a packet contains reconstruction or other incident-related records.
Framework requirements and their interpretation should be checked against the authoritative source.
Walk through the scope, available evidence, and remaining requirements with our team.