Govern, Map,
Measure, Manage.
Run the four functions as live controls over a real estate, with the Generative AI Profile on top.
What NIST asks you to demonstrate.
NIST AI RMF is built around four functions — Govern, Map, Measure and Manage. The goal is to show how AI risks are understood, evaluated and addressed across the systems you operate.
Policies in operation
Policies, roles and accountability are established for managing AI risk across the organisation.
Third-party AI is accounted for
Models, data and AI services supplied by third parties are identified, assessed and governed.
Context is established
The purpose, users, deployment environment and potential impacts of each AI system are understood.
Impacts are assessed
Potential impacts on people, groups and other stakeholders are identified and evaluated.
Trustworthiness is evaluated
Systems are evaluated across relevant characteristics such as validity, reliability, safety, security, privacy and fairness.
Risk treatments are tracked
Risk responses are assigned, implemented and monitored to ensure identified risks are addressed.
Trustworthy AI characteristics
What a trustworthy AI system should demonstrate.
NIST identifies seven characteristics that help organisations evaluate whether an AI system can be trusted in its intended context.
Each system can be evaluated against the characteristics relevant to its intended use, with results and supporting evidence retained.
From framework to practice.
NIST AI RMF provides the structure for managing AI risk. Effective implementation connects that structure to the systems, decisions, controls and evidence that shape AI in practice.
Policies become effective when it is clear which AI systems they actually govern.
An inventory becomes useful when each system carries its purpose, owners, risks and dependencies.
An assessment becomes defensible when the evidence supporting it is retained with it.
Governance stays effective as systems, models and controls change.
From NIST outcomes to live AI governance.
Strai8 connects NIST AI RMF outcomes to the systems, controls, assessments and evidence across your AI environment.
Discovery
Find the AI already in use.
Discover AI systems across endpoints, applications, models and third-party services before governance begins.
Outcome mapping
Connect requirements to systems.
Map NIST outcomes to the AI systems, controls and responsibilities they apply to.
Evaluations
Measure the risks that matter.
Evaluate systems across reliability, safety, security, privacy, fairness and other applicable characteristics.
GenAI Profile
Apply additional controls to generative AI.
Capture the additional risks, dependencies and controls associated with generative AI systems.
Monitoring
Keep assessments current.
Detect changes to systems, models and controls that can make previous assessments outdated.
Assurance pack
Turn governance into evidence.
Generate a system-level evidence trail connecting requirements, controls, decisions, assessments and supporting artefacts.
Questions teams ask about NIST AI RMF.
Show the four functions on real systems.
Thirty minutes on your own estate: which outcomes carry evidence, and which never ran.