Skip to content
AI RMF 1.0NIST AI RMF

Govern, Map,
Measure, Manage.

Run the four functions as live controls over a real estate, with the Generative AI Profile on top.

The four functions
MAPcontext and impactMEASUREanalyse and trackMANAGEprioritise and treatGOVERNcross-cutting
01Requirements

What NIST asks you to demonstrate.

NIST AI RMF is built around four functions — Govern, Map, Measure and Manage. The goal is to show how AI risks are understood, evaluated and addressed across the systems you operate.

GOVERN 1

Policies in operation

Policies, roles and accountability are established for managing AI risk across the organisation.

GOVERN 6

Third-party AI is accounted for

Models, data and AI services supplied by third parties are identified, assessed and governed.

MAP 1

Context is established

The purpose, users, deployment environment and potential impacts of each AI system are understood.

MAP 5

Impacts are assessed

Potential impacts on people, groups and other stakeholders are identified and evaluated.

MEASURE 2

Trustworthiness is evaluated

Systems are evaluated across relevant characteristics such as validity, reliability, safety, security, privacy and fairness.

MANAGE 4

Risk treatments are tracked

Risk responses are assigned, implemented and monitored to ensure identified risks are addressed.

Trustworthy AI characteristics

What a trustworthy AI system should demonstrate.

NIST identifies seven characteristics that help organisations evaluate whether an AI system can be trusted in its intended context.

Valid & reliableSafeSecure & resilientAccountable & transparentExplainable & interpretablePrivacy-enhancedFair — harmful bias managed

Each system can be evaluated against the characteristics relevant to its intended use, with results and supporting evidence retained.

02In practice

From framework to practice.

NIST AI RMF provides the structure for managing AI risk. Effective implementation connects that structure to the systems, decisions, controls and evidence that shape AI in practice.

PolicyCoverage

Policies become effective when it is clear which AI systems they actually govern.

InventoryContext

An inventory becomes useful when each system carries its purpose, owners, risks and dependencies.

AssessmentEvidence

An assessment becomes defensible when the evidence supporting it is retained with it.

GovernanceContinuous oversight

Governance stays effective as systems, models and controls change.

03Strai8 for NIST AI RMF

From NIST outcomes to live AI governance.

Strai8 connects NIST AI RMF outcomes to the systems, controls, assessments and evidence across your AI environment.

Discovery

Find the AI already in use.

Discover AI systems across endpoints, applications, models and third-party services before governance begins.

Outcome mapping

Connect requirements to systems.

Map NIST outcomes to the AI systems, controls and responsibilities they apply to.

Evaluations

Measure the risks that matter.

Evaluate systems across reliability, safety, security, privacy, fairness and other applicable characteristics.

GenAI Profile

Apply additional controls to generative AI.

Capture the additional risks, dependencies and controls associated with generative AI systems.

Monitoring

Keep assessments current.

Detect changes to systems, models and controls that can make previous assessments outdated.

Assurance pack

Turn governance into evidence.

Generate a system-level evidence trail connecting requirements, controls, decisions, assessments and supporting artefacts.

04Questions

Questions teams ask about NIST AI RMF.

NIST AI RMF

Show the four functions on real systems.

Thirty minutes on your own estate: which outcomes carry evidence, and which never ran.