NIST AI Risk Management Framework
Version: AI RMF 1.0 (NIST AI 100-1, January 2023)
A voluntary NIST framework for organizations that design, develop, deploy or use AI systems, organizing AI risk management outcomes into four functions (Govern, Map, Measure, Manage) to promote trustworthy and responsible AI.
Where we stand
Controls
90%
Evidence
13%
Policies
36%
22 of 72 clauses mapped to adopted controls
As of (just now)
Percentages are over clauses mapped to at least one adopted control. Unmapped clauses are listed below and never count as passing. A known gap is a clause that applies to us and that no control covers yet.
Clause-by-clause readiness
| Clause | Title | Controls | Evidence | Policies | Last tested |
|---|---|---|---|---|---|
| GOVERN 1 AI risk policies and processes | |||||
| GOVERN 1.1 | AI legal requirements understood | Unmapped | Unmapped | Unmapped | Not yet |
| GOVERN 1.2 | Trustworthy AI in policy | Unmapped | Unmapped | Unmapped | Not yet |
| GOVERN 1.3 | Risk management level set by tolerance Controls: BIZ-04 | Passing | Not current | Not approved | Not yet |
| GOVERN 1.4 | Transparent risk management controls Controls: BIZ-04 | Passing | Not current | Not approved | Not yet |
| GOVERN 1.5 | Ongoing monitoring and periodic review Controls: BIZ-08 | Passing | Not current | Approved | Not yet |
| GOVERN 1.6 | AI system inventory | Unmapped | Unmapped | Unmapped | Not yet |
| GOVERN 1.7 | Safe decommissioning of AI systems | Unmapped | Unmapped | Unmapped | Not yet |
| GOVERN 2 Accountability structures | |||||
| GOVERN 2.1 | AI risk roles documented Controls: BIZ-15 | Passing | Not current | Not approved | Not yet |
| GOVERN 2.2 | AI risk management training | Unmapped | Unmapped | Unmapped | Not yet |
| GOVERN 2.3 | Executive responsibility for AI risk Controls: BIZ-12 | Passing | Not current | Approved | Not yet |
| GOVERN 3 Workforce diversity and human-AI roles | |||||
| GOVERN 3.1 | Diverse decision-making teams | Unmapped | Unmapped | Unmapped | Not yet |
| GOVERN 3.2 | Human-AI oversight roles defined | Unmapped | Unmapped | Unmapped | Not yet |
| GOVERN 4 Risk-aware culture | |||||
| GOVERN 4.1 | Safety-first mindset | Unmapped | Unmapped | Unmapped | Not yet |
| GOVERN 4.2 | AI risks and impacts documented | Unmapped | Unmapped | Unmapped | Not yet |
| GOVERN 4.3 | Testing, incident and sharing practices | Unmapped | Unmapped | Unmapped | Not yet |
| GOVERN 5 Engagement with AI actors | |||||
| GOVERN 5.1 | External feedback collected Controls: CUST-01 | Passing | Not current | Approved | (4 mo ago) |
| GOVERN 5.2 | Adjudicated feedback incorporated Controls: PDP-01 | Passing | Not current | Approved | (4 mo ago) |
| GOVERN 6 Third-party and supply chain AI risk | |||||
| GOVERN 6.1 | Third-party AI risk policies Controls: VEND-03 | Passing | Not current | Not approved | Not yet |
| GOVERN 6.2 | Third-party failure contingencies Controls: BIZ-01 | Passing | Not current | Not approved | (3 mo ago) |
| MAP 1 Context established | |||||
| MAP 1.1 | Intended purpose and setting documented | Unmapped | Unmapped | Unmapped | Not yet |
| MAP 1.2 | Interdisciplinary context team | Unmapped | Unmapped | Unmapped | Not yet |
| MAP 1.3 | AI mission and goals documented | Unmapped | Unmapped | Unmapped | Not yet |
| MAP 1.4 | Business value defined | Unmapped | Unmapped | Unmapped | Not yet |
| MAP 1.5 | Risk tolerances documented Controls: BIZ-04 | Passing | Not current | Not approved | Not yet |
| MAP 1.6 | System requirements elicited | Unmapped | Unmapped | Unmapped | Not yet |
| MAP 2 AI system categorization | |||||
| MAP 2.1 | Tasks and methods defined | Unmapped | Unmapped | Unmapped | Not yet |
| MAP 2.2 | Knowledge limits and human use documented | Unmapped | Unmapped | Unmapped | Not yet |
| MAP 2.3 | Scientific integrity and TEVV considerations | Unmapped | Unmapped | Unmapped | Not yet |
| MAP 3 Capabilities, benefits and costs | |||||
| MAP 3.1 | Benefits examined | Unmapped | Unmapped | Unmapped | Not yet |
| MAP 3.2 | Costs of errors examined | Unmapped | Unmapped | Unmapped | Not yet |
| MAP 3.3 | Application scope specified | Unmapped | Unmapped | Unmapped | Not yet |
| MAP 3.4 | Operator proficiency processes | Unmapped | Unmapped | Unmapped | Not yet |
| MAP 3.5 | Human oversight processes defined | Unmapped | Unmapped | Unmapped | Not yet |
| MAP 4 Component and third-party risks mapped | |||||
| MAP 4.1 | Component legal and technology risks mapped | Unmapped | Unmapped | Unmapped | Not yet |
| MAP 4.2 | Component risk controls documented | Unmapped | Unmapped | Unmapped | Not yet |
| MAP 5 Impacts characterized | |||||
| MAP 5.1 | Impact likelihood and magnitude documented | Unmapped | Unmapped | Unmapped | Not yet |
| MAP 5.2 | Impact feedback engagement | Unmapped | Unmapped | Unmapped | Not yet |
| MEASURE 1 Methods and metrics | |||||
| MEASURE 1.1 | Metrics selected for top risks | Unmapped | Unmapped | Unmapped | Not yet |
| MEASURE 1.2 | Metrics and controls reassessed Controls: BIZ-08 | Passing | Not current | Approved | Not yet |
| MEASURE 1.3 | Independent assessors involved | Unmapped | Unmapped | Unmapped | Not yet |
| MEASURE 2 Trustworthiness evaluation | |||||
| MEASURE 2.1 | TEVV artifacts documented | Unmapped | Unmapped | Unmapped | Not yet |
| MEASURE 2.2 | Human subject evaluations | Unmapped | Unmapped | Unmapped | Not yet |
| MEASURE 2.3 | Performance measured in deployment conditions | Unmapped | Unmapped | Unmapped | Not yet |
| MEASURE 2.4 | Production behavior monitored | Unmapped | Unmapped | Unmapped | Not yet |
| MEASURE 2.5 | Validity and reliability demonstrated | Unmapped | Unmapped | Unmapped | Not yet |
| MEASURE 2.6 | Safety evaluated | Unmapped | Unmapped | Unmapped | Not yet |
| MEASURE 2.7 | Security and resilience evaluated Controls: MON-04 | Not passing | Current | Not approved | (8 h ago) |
| MEASURE 2.8 | Transparency and accountability risks examined | Unmapped | Unmapped | Unmapped | Not yet |
| MEASURE 2.9 | Model explained and validated | Unmapped | Unmapped | Unmapped | Not yet |
| MEASURE 2.10 | Privacy risk examined | Unmapped | Unmapped | Unmapped | Not yet |
| MEASURE 2.11 | Fairness and bias evaluated | Unmapped | Unmapped | Unmapped | Not yet |
| MEASURE 2.12 | Environmental impact assessed | Unmapped | Unmapped | Unmapped | Not yet |
| MEASURE 2.13 | TEVV effectiveness evaluated Controls: BIZ-08 | Passing | Not current | Approved | Not yet |
| MEASURE 3 Risk tracking over time | |||||
| MEASURE 3.1 | Emergent risks tracked Controls: BIZ-05 | Passing | Not current | Not approved | (4 mo ago) |
| MEASURE 3.2 | Hard-to-measure risks tracked Controls: BIZ-05 | Passing | Not current | Not approved | (4 mo ago) |
| MEASURE 3.3 | User problem reporting and appeals Controls: CUST-01 | Passing | Not current | Approved | (4 mo ago) |
| MEASURE 4 Measurement efficacy feedback | |||||
| MEASURE 4.1 | Measurement tied to deployment context | Unmapped | Unmapped | Unmapped | Not yet |
| MEASURE 4.2 | Trustworthiness results validated | Unmapped | Unmapped | Unmapped | Not yet |
| MEASURE 4.3 | Performance changes documented | Unmapped | Unmapped | Unmapped | Not yet |
| MANAGE 1 Risk prioritization and response | |||||
| MANAGE 1.1 | Go or no-go determination | Unmapped | Unmapped | Unmapped | Not yet |
| MANAGE 1.2 | Risk treatment prioritized Controls: BIZ-05 | Passing | Not current | Not approved | (4 mo ago) |
| MANAGE 1.3 | High-priority risk responses planned Controls: BIZ-04 | Passing | Not current | Not approved | Not yet |
| MANAGE 1.4 | Residual risk documented | Unmapped | Unmapped | Unmapped | Not yet |
| MANAGE 2 Maximizing benefits and minimizing harm | |||||
| MANAGE 2.1 | Resources and non-AI alternatives considered | Unmapped | Unmapped | Unmapped | Not yet |
| MANAGE 2.2 | Value of deployed systems sustained | Unmapped | Unmapped | Unmapped | Not yet |
| MANAGE 2.3 | Response to unknown risks Controls: BIZ-02 | Passing | Not current | Not approved | (3 mo ago) |
| MANAGE 2.4 | Ability to disengage AI systems | Unmapped | Unmapped | Unmapped | Not yet |
| MANAGE 3 Third-party AI risk management | |||||
| MANAGE 3.1 | Third-party AI risks monitored Controls: VEND-04 | Not passing | Current | Not approved | (8 h ago) |
| MANAGE 3.2 | Pre-trained models monitored | Unmapped | Unmapped | Unmapped | Not yet |
| MANAGE 4 Risk treatment, response and communication | |||||
| MANAGE 4.1 | Post-deployment monitoring plans | Unmapped | Unmapped | Unmapped | Not yet |
| MANAGE 4.2 | Continual improvement in updates Controls: PDP-01 | Passing | Not current | Approved | (4 mo ago) |
| MANAGE 4.3 | Incidents communicated and tracked Controls: BIZ-03 | Passing | Current | Not approved | (8 h ago) |
