FintastIQTrust Center
LoginBook a Consultation
Framework

NIST AI Risk Management Framework

Version: AI RMF 1.0 (NIST AI 100-1, January 2023)

A voluntary NIST framework for organizations that design, develop, deploy or use AI systems, organizing AI risk management outcomes into four functions (Govern, Map, Measure, Manage) to promote trustworthy and responsible AI.

Official source

Summary

Where we stand

Controls
90%
Evidence
13%
Policies
36%

22 of 72 clauses mapped to adopted controls

As of (just now)

Percentages are over clauses mapped to at least one adopted control. Unmapped clauses are listed below and never count as passing. A known gap is a clause that applies to us and that no control covers yet.

Clauses

Clause-by-clause readiness

ClauseTitleControlsEvidencePoliciesLast tested
GOVERN 1 AI risk policies and processes
GOVERN 1.1AI legal requirements understoodUnmappedUnmappedUnmappedNot yet
GOVERN 1.2Trustworthy AI in policyUnmappedUnmappedUnmappedNot yet
GOVERN 1.3Risk management level set by tolerance
Controls: BIZ-04
PassingNot currentNot approvedNot yet
GOVERN 1.4Transparent risk management controls
Controls: BIZ-04
PassingNot currentNot approvedNot yet
GOVERN 1.5Ongoing monitoring and periodic review
Controls: BIZ-08
PassingNot currentApprovedNot yet
GOVERN 1.6AI system inventoryUnmappedUnmappedUnmappedNot yet
GOVERN 1.7Safe decommissioning of AI systemsUnmappedUnmappedUnmappedNot yet
GOVERN 2 Accountability structures
GOVERN 2.1AI risk roles documented
Controls: BIZ-15
PassingNot currentNot approvedNot yet
GOVERN 2.2AI risk management trainingUnmappedUnmappedUnmappedNot yet
GOVERN 2.3Executive responsibility for AI risk
Controls: BIZ-12
PassingNot currentApprovedNot yet
GOVERN 3 Workforce diversity and human-AI roles
GOVERN 3.1Diverse decision-making teamsUnmappedUnmappedUnmappedNot yet
GOVERN 3.2Human-AI oversight roles definedUnmappedUnmappedUnmappedNot yet
GOVERN 4 Risk-aware culture
GOVERN 4.1Safety-first mindsetUnmappedUnmappedUnmappedNot yet
GOVERN 4.2AI risks and impacts documentedUnmappedUnmappedUnmappedNot yet
GOVERN 4.3Testing, incident and sharing practicesUnmappedUnmappedUnmappedNot yet
GOVERN 5 Engagement with AI actors
GOVERN 5.1External feedback collected
Controls: CUST-01
PassingNot currentApproved(4 mo ago)
GOVERN 5.2Adjudicated feedback incorporated
Controls: PDP-01
PassingNot currentApproved(4 mo ago)
GOVERN 6 Third-party and supply chain AI risk
GOVERN 6.1Third-party AI risk policies
Controls: VEND-03
PassingNot currentNot approvedNot yet
GOVERN 6.2Third-party failure contingencies
Controls: BIZ-01
PassingNot currentNot approved(3 mo ago)
MAP 1 Context established
MAP 1.1Intended purpose and setting documentedUnmappedUnmappedUnmappedNot yet
MAP 1.2Interdisciplinary context teamUnmappedUnmappedUnmappedNot yet
MAP 1.3AI mission and goals documentedUnmappedUnmappedUnmappedNot yet
MAP 1.4Business value definedUnmappedUnmappedUnmappedNot yet
MAP 1.5Risk tolerances documented
Controls: BIZ-04
PassingNot currentNot approvedNot yet
MAP 1.6System requirements elicitedUnmappedUnmappedUnmappedNot yet
MAP 2 AI system categorization
MAP 2.1Tasks and methods definedUnmappedUnmappedUnmappedNot yet
MAP 2.2Knowledge limits and human use documentedUnmappedUnmappedUnmappedNot yet
MAP 2.3Scientific integrity and TEVV considerationsUnmappedUnmappedUnmappedNot yet
MAP 3 Capabilities, benefits and costs
MAP 3.1Benefits examinedUnmappedUnmappedUnmappedNot yet
MAP 3.2Costs of errors examinedUnmappedUnmappedUnmappedNot yet
MAP 3.3Application scope specifiedUnmappedUnmappedUnmappedNot yet
MAP 3.4Operator proficiency processesUnmappedUnmappedUnmappedNot yet
MAP 3.5Human oversight processes definedUnmappedUnmappedUnmappedNot yet
MAP 4 Component and third-party risks mapped
MAP 4.1Component legal and technology risks mappedUnmappedUnmappedUnmappedNot yet
MAP 4.2Component risk controls documentedUnmappedUnmappedUnmappedNot yet
MAP 5 Impacts characterized
MAP 5.1Impact likelihood and magnitude documentedUnmappedUnmappedUnmappedNot yet
MAP 5.2Impact feedback engagementUnmappedUnmappedUnmappedNot yet
MEASURE 1 Methods and metrics
MEASURE 1.1Metrics selected for top risksUnmappedUnmappedUnmappedNot yet
MEASURE 1.2Metrics and controls reassessed
Controls: BIZ-08
PassingNot currentApprovedNot yet
MEASURE 1.3Independent assessors involvedUnmappedUnmappedUnmappedNot yet
MEASURE 2 Trustworthiness evaluation
MEASURE 2.1TEVV artifacts documentedUnmappedUnmappedUnmappedNot yet
MEASURE 2.2Human subject evaluationsUnmappedUnmappedUnmappedNot yet
MEASURE 2.3Performance measured in deployment conditionsUnmappedUnmappedUnmappedNot yet
MEASURE 2.4Production behavior monitoredUnmappedUnmappedUnmappedNot yet
MEASURE 2.5Validity and reliability demonstratedUnmappedUnmappedUnmappedNot yet
MEASURE 2.6Safety evaluatedUnmappedUnmappedUnmappedNot yet
MEASURE 2.7Security and resilience evaluated
Controls: MON-04
Not passingCurrentNot approved(8 h ago)
MEASURE 2.8Transparency and accountability risks examinedUnmappedUnmappedUnmappedNot yet
MEASURE 2.9Model explained and validatedUnmappedUnmappedUnmappedNot yet
MEASURE 2.10Privacy risk examinedUnmappedUnmappedUnmappedNot yet
MEASURE 2.11Fairness and bias evaluatedUnmappedUnmappedUnmappedNot yet
MEASURE 2.12Environmental impact assessedUnmappedUnmappedUnmappedNot yet
MEASURE 2.13TEVV effectiveness evaluated
Controls: BIZ-08
PassingNot currentApprovedNot yet
MEASURE 3 Risk tracking over time
MEASURE 3.1Emergent risks tracked
Controls: BIZ-05
PassingNot currentNot approved(4 mo ago)
MEASURE 3.2Hard-to-measure risks tracked
Controls: BIZ-05
PassingNot currentNot approved(4 mo ago)
MEASURE 3.3User problem reporting and appeals
Controls: CUST-01
PassingNot currentApproved(4 mo ago)
MEASURE 4 Measurement efficacy feedback
MEASURE 4.1Measurement tied to deployment contextUnmappedUnmappedUnmappedNot yet
MEASURE 4.2Trustworthiness results validatedUnmappedUnmappedUnmappedNot yet
MEASURE 4.3Performance changes documentedUnmappedUnmappedUnmappedNot yet
MANAGE 1 Risk prioritization and response
MANAGE 1.1Go or no-go determinationUnmappedUnmappedUnmappedNot yet
MANAGE 1.2Risk treatment prioritized
Controls: BIZ-05
PassingNot currentNot approved(4 mo ago)
MANAGE 1.3High-priority risk responses planned
Controls: BIZ-04
PassingNot currentNot approvedNot yet
MANAGE 1.4Residual risk documentedUnmappedUnmappedUnmappedNot yet
MANAGE 2 Maximizing benefits and minimizing harm
MANAGE 2.1Resources and non-AI alternatives consideredUnmappedUnmappedUnmappedNot yet
MANAGE 2.2Value of deployed systems sustainedUnmappedUnmappedUnmappedNot yet
MANAGE 2.3Response to unknown risks
Controls: BIZ-02
PassingNot currentNot approved(3 mo ago)
MANAGE 2.4Ability to disengage AI systemsUnmappedUnmappedUnmappedNot yet
MANAGE 3 Third-party AI risk management
MANAGE 3.1Third-party AI risks monitored
Controls: VEND-04
Not passingCurrentNot approved(8 h ago)
MANAGE 3.2Pre-trained models monitoredUnmappedUnmappedUnmappedNot yet
MANAGE 4 Risk treatment, response and communication
MANAGE 4.1Post-deployment monitoring plansUnmappedUnmappedUnmappedNot yet
MANAGE 4.2Continual improvement in updates
Controls: PDP-01
PassingNot currentApproved(4 mo ago)
MANAGE 4.3Incidents communicated and tracked
Controls: BIZ-03
PassingCurrentNot approved(8 h ago)