Swipe to see all columns →
| Clause | Requirement | Runback capability | Evidence |
|---|---|---|---|
| GOVERN 1 | Policies, processes, procedures and practices across the organisation related to the mapping, measuring, and managing of AI risks. | Policy library + org-level policy enforcement | A policy rule evaluated on a real tool call See it in the dashboard → |
| MAP 1 | Context is established and understood — categorise AI tasks by risk level. | Agent classification + run tagging | A captured run in the audit trace See it in the dashboard → |
| MEASURE 2 | AI risk or impact concerns are quantified and monitored. | Fleet benchmarks + cost attribution + error tracking | Aggregated from real run data into a compliance report See it in the dashboard → |
| MANAGE 4 | Residual risks, after response actions are in place, are communicated and monitored. | Compliance report + policy block audit trail | A captured run in the audit trace See it in the dashboard → |
Honest limits
What this page does not claim.
- There is nothing to certify against — NIST AI RMF is a framework to structure a risk program around, not a pass/fail standard.
- The subcategories below are a representative slice (one per function), not the full RMF, which runs to dozens of subcategories.
- This is a capability map, not a conformity determination. Whether your deployment satisfies NIST AI RMF is a determination for your own assessor — what's listed above is the evidence that argument draws on.