FRAMEWORK

NIST AI RMF

NIST AI Risk Management Framework (AI 100-1). A voluntary framework for managing risks to individuals, organisations, and society associated with AI. Vigilens maps the four core functions to your pipeline and maintains continuous evidence of trustworthy AI practices.

Type Framework
Body NIST (US)
Published January 2023
Vigilens coverage Core functions

What it requires

The NIST AI RMF provides a structured approach to managing AI risks. While voluntary, it is increasingly referenced by US federal agencies, procurement requirements, and international standards bodies. The framework is organised around four core functions, each with categories and subcategories.

Core functions

  • Govern: Cultivate a culture of risk management. Establish policies, processes, procedures, and practices for AI risk management across the organisation
  • Map: Contextualise risks. Identify and understand the AI system's context, capabilities, limitations, and potential impacts
  • Measure: Analyse and assess risks. Use quantitative and qualitative methods to assess identified risks
  • Manage: Prioritise and act on risks. Allocate resources and implement plans to respond to, recover from, and communicate about AI risks

Trustworthy AI characteristics

  • Valid and reliable: the system performs as intended
  • Safe: the system does not endanger human life, health, property, or the environment
  • Secure and resilient: the system withstands adversarial conditions
  • Accountable and transparent: appropriate mechanisms are in place for oversight
  • Explainable and interpretable: outputs can be understood by stakeholders
  • Privacy-enhanced: the system protects personal information
  • Fair with harmful bias managed: the system avoids systematic discrimination

How Vigilens automates it

Vigilens maps NIST AI RMF subcategories to controls that can be evidenced from your engineering pipeline. The four core functions translate to concrete, measurable activities within the CI/CD workflow.

  • Govern subcategories mapped to organisational policy evidence and role assignments
  • Map subcategories linked to classification results and system context documentation
  • Measure subcategories tied to model evaluation metrics, bias testing, and security assessments
  • Manage subcategories evidenced by risk treatment plans, incident response, and monitoring
  • Cross-mapped to EU AI Act and ISO 42001 for organisations with both US and EU exposure

NIST AI RMF and EU frameworks

Many organisations operating in both the US and EU need to satisfy NIST AI RMF expectations alongside EU AI Act obligations. Vigilens maps the overlaps: NIST Govern aligns with EU AI Act Article 17 (quality management), NIST Map aligns with risk classification, and NIST Measure aligns with Articles 9 and 15 (risk management and accuracy). A single governance record satisfies both.

LIVE IN VIGILENS

Coverage

Core functions (Govern, Map, Measure, Manage) with key subcategories. Cross-mapped to EU AI Act and ISO 42001.

Start automating NIST AI RMF compliance.

Govern, Map, Measure, Manage in your pipeline. Continuous evidence for trustworthy AI.

Classify your AI → Start free