Skip to content
Compliance frameworks / NIST AI RMF

Give AI risk management a record to work from.

Connect agent ownership, decision history, and intervention evidence to selected outcomes in the NIST AI Risk Management Framework.

Voluntary AI risk framework
Selected catalog mappingsCatalog 2026.09.2

Risk management continues after deployment.

NIST AI RMF organizes risk management around Govern, Map, Measure, and Manage. It is a voluntary framework for evaluating and managing AI risks throughout the lifecycle. Operational records help inform that work, alongside system evaluations and organizational judgment.

Bring operating evidence into the risk conversation.

Named responsibility, recorded decisions, and intervention history give reviewers concrete material to examine as AI use changes.

Explore agent governance
01

Establish responsibility

Connect registered agents with their named owners and the scope of activity under review.

02

Examine decisions

Review recorded actions, policy references, and the basis for each verdict.

03

Assess intervention

Distinguish controls exercised before execution from findings based on observed activity.

See the crosswalk and the open gap.

Selected NIST references are present in the catalog. A catalog entry does not mean that the review window contains evidence for it.

Catalog referenceProduct evidenceReview limits

GOVERN 1.6

Product evidenceRegistered-agent attribution and packet records support an inventory review.

Review limitsUnregistered or unobserved systems still need to be identified and assessed.

MEASURE 2.8

Product evidenceReceipt history provides a record for transparency and accountability review.

Review limitsRecorded activity does not replace assessment of the relevant AI risks.

MEASURE 2.9

Product evidenceVerdicts, rule references, and decision basis provide material for explanation review.

Review limitsA documented decision is not proof that the model itself is interpretable or the explanation is sufficient.

MANAGE 4.1

Product evidenceHolds and human-decided gates record interventions in governed activity.

Review limitsObservation-only telemetry cannot demonstrate an in-path intervention.

MANAGE 4.3

Not evidenced

Product evidenceCatalogued without a mapped incident-reporting artifact.

Review limitsShown as not evidenced. Incident reconstruction does not automatically establish incident communication.

Catalog 2026.09.2. A selected mapping supports evidence review; it does not establish compliance or certification.

Use the crosswalk within a broader risk program.

The current mappings cover selected records, rather than the whole framework or every risk associated with an AI system.

  • 01

    Context, affected stakeholders, and risk tolerance

  • 02

    System testing, measurement methods, and evaluations

  • 03

    Incident communication and ongoing risk-treatment decisions

Questions about NIST AI RMF?

Is this a NIST certification?

No. NIST AI RMF is a voluntary risk-management framework, and the product’s crosswalk is an advisory reference. It is not a NIST certification or endorsement.

Does the catalog cover all four core functions?

It contains selected references within Govern, Measure, and Manage. It is not a complete mapping of the four functions, every subcategory, or the Generative AI Profile.

Why is MANAGE 4.3 marked not evidenced?

The catalog includes that reference, but no current evidence primitive maps to an incident-reporting artifact. The gap remains visible even when a packet contains reconstruction or other incident-related records.

Read the primary references.

Framework requirements and their interpretation should be checked against the authoritative source.

Make your next AI risk review more concrete.

Walk through the scope, available evidence, and remaining requirements with our team.

We do not currently use analytics or advertising cookies. Cookie policy · Privacy policy