GAISSF to NIST AI RMF Crosswalk
Public crosswalk publication mapping GAISSF v1.0 to NIST AI RMF, with scope, method, limitations and traceability.
Document Control
| Field | Controlled value |
|---|---|
| Document ID | CRO-022 |
| Title | GAISSF–NIST AI Risk Management Framework Mapping |
| Version | 1.0 |
| Status | Publication Candidate |
| Classification | Crosswalk — informative |
| Publisher | ODA3 Institute |
| Legal entity | ODA3 Pvt Ltd |
| GAISSF baseline | GAISSF v1.0, 59 controls across D1–D9 |
| NIST baseline | NIST AI 100-1, AI RMF 1.0, January 2023 |
| Verification date | 29 June 2026 |
| Distribution | Public — Website/GitHub |
| Review trigger | Revision of GAISSF, AI RMF, or material mapping evidence |
Executive Summary
CRO-022 provides a bidirectional, outcome-based mapping between the 59 GAISSF v1.0 controls and the 72 NIST AI RMF 1.0 Core subcategories. It supports implementation planning, gap analysis, evidence reuse, profile development, and internal assurance. It does not establish NIST certification, NIST endorsement, regulatory compliance, or automatic satisfaction of NIST outcomes.
Reverse coverage distribution: Indirectly Supported: 5, Not Addressed: 35, Substantially Addressed: 24, Partially Addressed: 8. These counts measure mapping coverage only; they are not a compliance score.
Notably Absent
No NIST certification scheme is created by AI RMF 1.0.
No NIST endorsement or approval of GAISSF was identified.
No automatic legal or regulatory safe harbour is established.
No evidence was identified that GAISSF and NIST AI RMF are fully equivalent.
No universal risk-tolerance threshold is prescribed by AI RMF 1.0.
No mapping result proves operating effectiveness.
1. Purpose and Intended Use
This crosswalk enables practitioners to relate GAISSF controls to NIST AI RMF outcomes, identify supplementary work, reuse verified evidence, and document Current and Target Profile decisions. It is an interpretive mapping, not a substitution mechanism.
2. Scope and Source Baseline
In scope: GAISSF-NOR-001 and GAISSF-NOR-004 corrected final publication editions, version 1.0, dated 29 June 2026; and NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0), January 2023. The NIST AI RMF Playbook and NIST AI 600-1 are supplementary and are not merged into the Core mapping. Future revisions require revalidation.
| Source | Status | Role |
|---|---|---|
| GAISSF-NOR-001 v1.0 | Normative | Framework architecture and conformance baseline |
| GAISSF-NOR-004 v1.0 | Normative | Authoritative 59-control catalogue |
| NIST AI 100-1 | Voluntary framework | Primary NIST Core mapping target |
| NIST AI RMF Playbook | Informative | Optional implementation guidance |
| NIST AI 600-1 | Supplementary profile | Separate GenAI analysis only |
3. Mapping Methodology
Mappings were evaluated at GAISSF control and NIST subcategory level. Relationship strength, reverse coverage status, and confidence are separate fields. Similar terminology alone was not treated as sufficient evidence. One-to-many and composite mappings are retained where an outcome depends on several controls.
| Code | Meaning |
|---|---|
| E | Equivalent or near-equivalent; used only with exceptional evidence |
| SP | Strong partial |
| P | Partial |
| S | Supporting |
| C | Contextual |
| N | No material mapping |
| O | Outside scope |
| U | Unable to determine |
| Confidence | Rule |
|---|---|
| High | Clear, specific support in both primary sources |
| Medium-High | Strong support with modest interpretation |
| Medium | Reasonable but context-dependent |
| Low | Tentative, indirect, or ambiguous |
| Not Rated | No mapping, outside scope, or indeterminate |
4. Function-Level Findings
GOVERN
19 NIST subcategories assessed. Coverage distribution: Indirectly Supported 3, Not Addressed 5, Substantially Addressed 11.
GAISSF provides substantial support through governance, accountability, inventory, supplier, incident, and lifecycle controls. Context-specific legal, workforce, and organizational culture outcomes may require supplementary implementation.
MAP
18 NIST subcategories assessed. Coverage distribution: Partially Addressed 3, Not Addressed 9, Substantially Addressed 4, Indirectly Supported 2.
GAISSF supports context, threat, dependency, human-oversight, and impact analysis. Broader social, mission, benefit, cost, and affected-community mapping may extend beyond security-focused controls.
MEASURE
22 NIST subcategories assessed. Coverage distribution: Partially Addressed 4, Not Addressed 14, Substantially Addressed 4.
GAISSF is comparatively detailed for adversarial testing, monitoring, drift, output integrity, safety, privacy, and assurance evidence. NIST-specific metric selection, independent TEVV, and contextual trustworthiness evaluation remain necessary.
MANAGE
13 NIST subcategories assessed. Coverage distribution: Not Addressed 7, Partially Addressed 1, Substantially Addressed 5.
GAISSF strongly supports treatment, incident response, third-party risk, monitoring, and continuous improvement. Organizations must still determine priorities, resources, acceptance decisions, and residual-risk communication in context.
5. Trustworthiness and Security Analysis
GAISSF controls materially support valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair-with-harmful-bias-managed outcomes. The mapping does not treat these characteristics as independent checkboxes; trade-offs and context remain necessary. GAISSF adds operational detail for adversarial robustness, prompt injection, model extraction, autonomous agents, supply-chain security, runtime monitoring, and incident response.
6. Evidence Reuse Guidance
| Evidence family | Potential reuse | Supplementary NIST context |
|---|---|---|
| AI inventory and scope records | GOVERN inventory, ownership, lifecycle | Mission, risk tolerance, and affected-party context |
| Risk and impact assessments | MAP and MANAGE decisions | Benefits, non-monetary costs, likelihood and magnitude |
| Threat models and security tests | MEASURE security/resilience | Metric appropriateness and independent review |
| Model/data documentation | MAP knowledge limits; MEASURE transparency | Use-context limitations and affected-party communication |
| Monitoring and incident records | MEASURE/MANAGE tracking and response | Risk prioritization, residual risk, and stakeholder reporting |
| Supplier assessments and AI BOMs | GOVERN/MAP/MANAGE third-party outcomes | Contractual responsibilities and downstream use context |
7. Limitations
The AI RMF is voluntary, rights-preserving, non-sector-specific, and use-case agnostic.
Mapping is interpretive and does not prove control implementation or effectiveness.
GAISSF conformance does not automatically demonstrate every NIST AI RMF outcome.
NIST Profiles are contextual; Current and Target Profiles require organizational decisions.
The mapping must be revalidated when either baseline changes.
The Playbook is supplementary guidance, not a set of additional mandatory requirements.
8. Conclusions
GAISSF v1.0 supplies a substantial operational and evidence-oriented foundation for many NIST AI RMF outcomes, particularly security, resilience, monitoring, third-party risk, incident response, and lifecycle assurance. Material differences remain in abstraction, organizational context, social impact framing, risk tolerance, benefit/cost analysis, and profile-specific implementation. CRO-022 should therefore be used for planning and traceability—not as a declaration of NIST compliance or equivalence.
Annex A — GAISSF-to-NIST Mapping Register
| Record | GAISSF control | Title | NIST subcategory | Rel. | Confidence | Rationale | Residual gap |
|---|---|---|---|---|---|---|---|
| CRO022-M-001 | D1-CTL-01 | Dataset Provenance & Poisoning Prevention | MEASURE 4.3 | SP | Medium-High | GAISSF D1-CTL-01 addresses dataset provenance & poisoning prevention through Hash verification + source allowlist + poisoning detection.. This supports the NIST outcome concerning measurable performance improvements or de- clines based on consultations with relevant ai actors, in- cluding affected communities, and field data about context- relevant risks and. The mapping does not establish implementation effectiveness or equivalence. | NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context. |
| CRO022-M-002 | D1-CTL-01 | Dataset Provenance & Poisoning Prevention | GOVERN 6.2 | SP | Medium-High | GAISSF D1-CTL-01 addresses dataset provenance & poisoning prevention through Hash verification + source allowlist + poisoning detection.. This supports the NIST outcome concerning contingency processes are in place to handle failures or incidents in third-party data or ai systems deemed to be high-risk. categories subcategories 5.2 map the map function estab. The mapping does not establish implementation effectiveness or equivalence. | NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context. |
| CRO022-M-003 | D1-CTL-01 | Dataset Provenance & Poisoning Prevention | MANAGE 2.4 | SP | Medium-High | GAISSF D1-CTL-01 addresses dataset provenance & poisoning prevention through Hash verification + source allowlist + poisoning detection.. This supports the NIST outcome concerning mechanisms are in place and applied, and respon- sibilities are assigned and understood, to supersede, disengage, or deactivate ai systems that demonstrate performance or outcomes . The mapping does not establish implementation effectiveness or equivalence. | NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context. |
| CRO022-M-004 | D1-CTL-02 | Model Extraction Resistance | MAP 5.2 | SP | Medium-High | GAISSF D1-CTL-02 addresses model extraction resistance through Rate limiting + diversity detection + extraction monitoring.. This supports the NIST outcome concerning practices and personnel for supporting regular en- gagement with relevant ai actors and integrating feedback about positive, negative, and unanticipated impacts are in place and do. The mapping does not establish implementation effectiveness or equivalence. | NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context. |
| CRO022-M-005 | D1-CTL-02 | Model Extraction Resistance | MEASURE 2.6 | SP | Medium-High | GAISSF D1-CTL-02 addresses model extraction resistance through Rate limiting + diversity detection + extraction monitoring.. This supports the NIST outcome concerning the ai system is evaluated regularly for safety risks – as identified in the map function. the ai system to be de- ployed is demonstrated to be safe, its residual negative risk doe. The mapping does not establish implementation effectiveness or equivalence. | NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context. |
| CRO022-M-006 | D1-CTL-02 | Model Extraction Resistance | MANAGE 3.2 | SP | Medium-High | GAISSF D1-CTL-02 addresses model extraction resistance through Rate limiting + diversity detection + extraction monitoring.. This supports the NIST outcome concerning pre-trained models which are used for develop- ment are monitored as part of ai system regular monitoring and maintenance. categories subcategories continued on next page nist ai 1. The mapping does not establish implementation effectiveness or equivalence. | NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context. |
Annex B — NIST-to-GAISSF Reverse Coverage Register
| NIST ID | NIST outcome | GAISSF controls | Coverage | Rel. | Confidence | Gap / further work |
|---|---|---|---|---|---|---|
| GOVERN 1.1 | Legal and regulatory requirements involving AI are understood, managed, and documented. | D8-CTL-03 | Indirectly Supported | C | Low | NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context. |
| GOVERN 1.2 | The characteristics of trustworthy AI are inte- grated into organizational policies, processes, procedures, and practices. | — | Not Addressed | N | Not Rated | No sufficiently direct GAISSF control mapping was identified in this edition. |
| GOVERN 1.3 | Processes, procedures, and practices are in place to determine the needed level of risk management activities based on the organization’s risk tolerance. | — | Not Addressed | N | Not Rated | No sufficiently direct GAISSF control mapping was identified in this edition. |
| GOVERN 1.4 | The risk management process and its outcomes are established through transparent policies, procedures, and other controls based on organizational risk priorities. Categories Subcategories Continued on next page NIST AI 100-1 AI RMF 1.0 Table 1: Categories and subcategories for the GOVERN function. (Continued) | D6-CTL-04, D7-CTL-H03 | Substantially Addressed | SP | Medium-High | NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context. |
| GOVERN 1.5 | Ongoing monitoring and periodic review of the risk management process and its outcomes are planned and or- ganizational roles and responsibilities clearly defined, including determining the frequency of periodic review. | D6-CTL-05, D7-CTL-H03, D8-CTL-04 | Substantially Addressed | SP | Medium-High | NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context. |
| GOVERN 1.6 | Mechanisms are in place to inventory AI systems and are resourced according to organizational risk priorities. | D4-CTL-01, D8-CTL-02 | Substantially Addressed | SP | Medium-High | NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context. |
| GOVERN 1.7 | Processes and procedures are in place for decom- missioning and phasing out AI systems safely and in a man- ner that does not increase risks or decrease the organization’s trustworthiness. GOVERN 2: Accountability structures are in place so that the appropriate teams and individuals are empowered, responsible, and trained for mapping, measuring, and managing AI risks. | D6-CTL-01, D6-CTL-02, D6-CTL-03, D6-CTL-04, D6-CTL-05, D6-CTL-07 | Substantially Addressed | SP | Medium-High | NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context. |
| GOVERN 2.1 | Roles and responsibilities and lines of communi- cation related to mapping, measuring, and managing AI risks are documented and are clear to individuals and teams throughout the organization. | — | Not Addressed | N | Not Rated | No sufficiently direct GAISSF control mapping was identified in this edition. |
| GOVERN 2.2 | The organization’s personnel and partners receive AI risk management training to enable them to perform their du- ties and responsibilities consistent with related policies, proce- dures, and agreements. | D7-CTL-H01, D7-CTL-H04 | Indirectly Supported | C | Low | NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context. |
| GOVERN 2.3 | Executive leadership of the organization takes re- sponsibility for decisions about risks associated with AI system development and deployment. GOVERN 3: Workforce diversity, equity, inclusion, and accessibility processes are prioritized in the mapping, measuring, and managing of AI risks throughout the lifecycle. | D3-CTL-07, D6-CTL-03 | Substantially Addressed | SP | Medium-High | NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context. |
| GOVERN 3.1 | Decision-making related to mapping, measuring, and managing AI risks throughout the lifecycle is informed by a diverse team (e.g., diversity of demographics, disciplines, expe- rience, expertise, and backgrounds). | — | Not Addressed | N | Not Rated | No sufficiently direct GAISSF control mapping was identified in this edition. |
| GOVERN 3.2 | Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configura- tions and oversight of AI systems. GOVERN 4: Organizational teams are committed to a culture | D6-CTL-01, D6-CTL-03, D6-CTL-07 | Substantially Addressed | SP | Medium-High | NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context. |
| GOVERN 4.1 | Organizational policies and practices are in place to foster a critical thinking and safety-first mindset in the design, development, deployment, and uses of AI systems to minimize potential negative impacts. Categories Subcategories Continued on next page NIST AI 100-1 AI RMF 1.0 Table 1: Categories and subcategories for the GOVERN function. (Continued) that considers and communicates AI risk. | D1-CTL-05, D2-CTL-03, D3-CTL-04, D5-CTL-01, D5-CTL-02, D5-CTL-03 | Substantially Addressed | SP | Medium-High | NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context. |
| GOVERN 4.2 | Organizational teams document the risks and po- tential impacts of the AI technology they design, develop, deploy, evaluate, and use, and they communicate about the impacts more broadly. | — | Not Addressed | N | Not Rated | No sufficiently direct GAISSF control mapping was identified in this edition. |
| GOVERN 4.3 | Organizational practices are in place to enable AI testing, identification of incidents, and information sharing. GOVERN 5: Processes are in place for robust engagement with relevant AI actors. | D2-CTL-01, D2-CTL-06, D5-CTL-04, D6-CTL-02, D7-CTL-H02 | Substantially Addressed | SP | Medium-High | NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context. |
| GOVERN 5.1 | Organizational policies and practices are in place to collect, consider, prioritize, and integrate feedback from those external to the team that developed or deployed the AI system regarding the potential individual and societal impacts related to AI risks. | D7-CTL-H05 | Indirectly Supported | C | Low | NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context. |
| GOVERN 5.2 | Mechanisms are established to enable the team that developed or deployed AI systems to regularly incorporate adjudicated feedback from relevant AI actors into system design and implementation. GOVERN 6: Policies and procedures are in place to address AI risks and benefits arising from third-party software and data and other supply chain issues. | D4-CTL-02, D4-CTL-03, D4-CTL-04, D4-CTL-05, D4-CTL-06, D4-CTL-07 | Substantially Addressed | SP | Medium-High | NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context. |
| GOVERN 6.1 | Policies and procedures are in place that address AI risks associated with third-party entities, including risks of in- fringement of a third-party’s intellectual property or other rights. | D4-CTL-02, D4-CTL-03 | Substantially Addressed | SP | Medium-High | NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context. |
| GOVERN 6.2 | Contingency processes are in place to handle failures or incidents in third-party data or AI systems deemed to be high-risk. Categories Subcategories 5.2 Map The MAP function establishes the context to frame risks related to an AI system. The AI lifecycle consists of many interdependent activities involving a diverse set of actors (See Figure 3). In practice, AI actors in charge of one part of the process often do not have full visibility or control over other parts and their associated contexts. | D1-CTL-01, D4-CTL-01, D4-CTL-02, D4-CTL-03, D4-CTL-04, D7-CTL-H02 | Substantially Addressed | SP | Medium-High | NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context. |
| MAP 1.1 | Intended purposes, potentially beneficial uses, context- specific laws, norms and expectations, and prospective settings in which the AI system will be deployed are understood and docu- mented. Considerations include: the specific set or types of users along with their expectations; potential positive and negative im- pacts of system uses to individuals, communities, organizations, society, and the planet; assumptions and related limitations about AI system purposes, uses, and risks across the development or product AI lifecycle; and related TEVV and system metrics. | D3-CTL-03, D3-CTL-05, D3-CTL-06 | Partially Addressed | P | Medium | NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context. |
| MAP 1.2 | Interdisciplinary AI actors, competencies, skills, and capacities for establishing context reflect demographic diversity and broad domain and user experience expertise, and their par- ticipation is documented. Opportunities for interdisciplinary col- laboration are prioritized. | — | Not Addressed | N | Not Rated | No sufficiently direct GAISSF control mapping was identified in this edition. |
| MAP 1.3 | The organization’s mission and relevant goals for AI technology are understood and documented. | — | Not Addressed | N | Not Rated | No sufficiently direct GAISSF control mapping was identified in this edition. |
| MAP 1.4 | The business value or context of business use has been clearly defined or – in the case of assessing existing AI systems – re-evaluated. | — | Not Addressed | N | Not Rated | No sufficiently direct GAISSF control mapping was identified in this edition. |
| MAP 1.5 | Organizational risk tolerances are determined and documented. | — | Not Addressed | N | Not Rated | No sufficiently direct GAISSF control mapping was identified in this edition. |
| MAP 1.6 | System requirements (e.g., “the system shall respect the privacy of its users”) are elicited from and understood by rel- evant AI actors. Design decisions take socio-technical implica- tions into account to address AI risks. MAP 2: Categorization of the AI system is performed. | D3-CTL-03, D3-CTL-05, D3-CTL-06, D4-CTL-05, D5-CTL-05 | Substantially Addressed | SP | Medium-High | NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context. |
| MAP 2.1 | The specific tasks and methods used to implement the tasks that the AI system will support are defined (e.g., classifiers, generative models, recommenders). | — | Not Addressed | N | Not Rated | No sufficiently direct GAISSF control mapping was identified in this edition. |
| MAP 2.2 | Information about the AI system’s knowledge limits and how system output may be utilized and overseen by humans is documented. Documentation provides sufficient information to assist relevant AI actors when making decisions and taking subsequent actions. Categories Subcategories Continued on next page NIST AI 100-1 AI RMF 1.0 Table 2: Categories and subcategories for the MAP function. (Continued) | D8-CTL-01 | Indirectly Supported | S | Medium | NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context. |
| MAP 2.3 | Scientific integrity and TEVV considerations are iden- tified and documented, including those related to experimental design, data collection and selection (e.g., availability, repre- sentativeness, suitability), system trustworthiness, and construct validation. MAP 3: AI capabilities, targeted usage, goals, and expected benefits and costs compared with appropriate benchmarks are understood. | D3-CTL-02, D3-CTL-04, D5-CTL-02, D5-CTL-03, D5-CTL-06 | Partially Addressed | P | Medium | NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context. |
| MAP 3.1 | Potential benefits of intended AI system functionality and performance are examined and documented. | — | Not Addressed | N | Not Rated | No sufficiently direct GAISSF control mapping was identified in this edition. |
| MAP 3.2 | Potential costs, including non-monetary costs, which result from expected or realized AI errors or system functionality and trustworthiness – as connected to organizational risk toler- ance – are examined and documented. | D8-CTL-01 | Indirectly Supported | S | Medium | NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context. |
| MAP 3.3 | Targeted application scope is specified and docu- mented based on the system’s capability, established context, and AI system categorization. | — | Not Addressed | N | Not Rated | No sufficiently direct GAISSF control mapping was identified in this edition. |
| MAP 3.4 | Processes for operator and practitioner proficiency with AI system performance and trustworthiness – and relevant technical standards and certifications – are defined, assessed, and documented. | — | Not Addressed | N | Not Rated | No sufficiently direct GAISSF control mapping was identified in this edition. |
| MAP 3.5 | Processes for human oversight are defined, assessed, and documented in accordance with organizational policies from the GOVERN function. MAP 4: Risks and benefits are mapped for all components of the AI system including third-party software and data. | D3-CTL-01, D3-CTL-07, D4-CTL-06, D4-CTL-07 | Substantially Addressed | SP | Medium-High | NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context. |
| MAP 4.1 | Approaches for mapping AI technology and legal risks of its components – including the use of third-party data or soft- ware – are in place, followed, and documented, as are risks of in- fringement of a third party’s intellectual property or other rights. | D4-CTL-05 | Partially Addressed | P | Medium | NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context. |
| MAP 4.2 | Internal risk controls for components of the AI sys- tem, including third-party AI technologies, are identified and documented. MAP 5: Impacts to individuals, groups, communities, organizations, and society are characterized. | — | Not Addressed | N | Not Rated | No sufficiently direct GAISSF control mapping was identified in this edition. |
| MAP 5.1 | Likelihood and magnitude of each identified impact (both potentially beneficial and harmful) based on expected use, past uses of AI systems in similar contexts, public incident re- ports, feedback from those external to the team that developed or deployed the AI system, or other data are identified and documented. Categories Subcategories Continued on next page NIST AI 100-1 AI RMF 1.0 Table 2: Categories and subcategories for the MAP function. (Continued) | D1-CTL-05, D5-CTL-01, D5-CTL-04 | Substantially Addressed | SP | Medium-High | NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context. |
| MAP 5.2 | Practices and personnel for supporting regular en- gagement with relevant AI actors and integrating feedback about positive, negative, and unanticipated impacts are in place and documented. Categories Subcategories 5.3 Measure The MEASURE function employs quantitative, qualitative, or mixed-method tools, tech- niques, and methodologies to analyze, assess, benchmark, and monitor AI risk and related impacts. It uses knowledge relevant to AI risks identified in the MAP function and informs the MANAGE function. AI systems should be tested before their deployment and regu- larly while in operation. | D1-CTL-02, D1-CTL-03, D1-CTL-09, D2-CTL-02, D2-CTL-03, D2-CTL-04 | Substantially Addressed | SP | Medium-High | NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context. |
| MEASURE 1.1 | Approaches and metrics for measurement of AI risks enumerated during the MAP function are selected for imple- mentation starting with the most significant AI risks. The risks or trustworthiness characteristics that will not – or cannot – be measured are properly documented. | D2-CTL-05 | Partially Addressed | P | Medium | NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context. |
| MEASURE 1.2 | Appropriateness of AI metrics and effectiveness of existing controls are regularly assessed and updated, including reports of errors and potential impacts on affected communities. | D2-CTL-04 | Partially Addressed | P | Medium | NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context. |
| MEASURE 1.3 | Internal experts who did not serve as front-line developers for the system and/or independent assessors are in- volved in regular assessments and updates. Domain experts, users, AI actors external to the team that developed or deployed the AI system, and affected communities are consulted in support of assessments as necessary per organizational risk tolerance. MEASURE 2: AI systems are evaluated for trustworthy characteristics. | D3-CTL-02 | Partially Addressed | P | Medium | NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context. |
| MEASURE 2.1 | Test sets, metrics, and details about the tools used during TEVV are documented. | D1-CTL-04, D1-CTL-06, D1-CTL-08, D2-CTL-06 | Partially Addressed | P | Medium | NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context. |
| MEASURE 2.2 | Evaluations involving human subjects meet ap- plicable requirements (including human subject protection) and are representative of the relevant population. | — | Not Addressed | N | Not Rated | No sufficiently direct GAISSF control mapping was identified in this edition. |
| MEASURE 2.3 | AI system performance or assurance criteria are measured qualitatively or quantitatively and demonstrated for conditions similar to deployment setting(s). Measures are documented. | — | Not Addressed | N | Not Rated | No sufficiently direct GAISSF control mapping was identified in this edition. |
| MEASURE 2.4 | The functionality and behavior of the AI sys- tem and its components – as identified in the MAP function – are monitored when in production. | — | Not Addressed | N | Not Rated | No sufficiently direct GAISSF control mapping was identified in this edition. |
| MEASURE 2.5 | The AI system to be deployed is demonstrated to be valid and reliable. Limitations of the generalizability be- yond the conditions under which the technology was developed are documented. Categories Subcategories Continued on next page NIST AI 100-1 AI RMF 1.0 Table 3: Categories and subcategories for the MEASURE function. (Continued) | — | Not Addressed | N | Not Rated | No sufficiently direct GAISSF control mapping was identified in this edition. |
| MEASURE 2.6 | The AI system is evaluated regularly for safety risks – as identified in the MAP function. The AI system to be de- ployed is demonstrated to be safe, its residual negative risk does not exceed the risk tolerance, and it can fail safely, particularly if made to operate beyond its knowledge limits. Safety metrics re- flect system reliability and robustness, real-time monitoring, and response times for AI system failures. | D1-CTL-02, D1-CTL-05, D1-CTL-08, D1-CTL-09, D2-CTL-02, D2-CTL-03 | Substantially Addressed | SP | Medium-High | NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context. |
| MEASURE 2.7 | AI system security and resilience – as identified in the MAP function – are evaluated and documented. | D1-CTL-04, D1-CTL-06, D1-CTL-08, D2-CTL-01, D2-CTL-02, D2-CTL-04 | Substantially Addressed | SP | Medium-High | NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context. |
| MEASURE 2.8 | Risks associated with transparency and account- ability – as identified in the MAP function – are examined and documented. | — | Not Addressed | N | Not Rated | No sufficiently direct GAISSF control mapping was identified in this edition. |
| MEASURE 2.9 | The AI model is explained, validated, and docu- mented, and AI system output is interpreted within its context – as identified in the MAP function – to inform responsible use and governance. | D3-CTL-01, D3-CTL-07 | Substantially Addressed | SP | Medium-High | NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context. |
| MEASURE 2.10 | Privacy risk of the AI system – as identified in the MAP function – is examined and documented. | — | Not Addressed | N | Not Rated | No sufficiently direct GAISSF control mapping was identified in this edition. |
| MEASURE 2.11 | Fairness and bias – as identified in the MAP function – are evaluated and results are documented. | — | Not Addressed | N | Not Rated | No sufficiently direct GAISSF control mapping was identified in this edition. |
| MEASURE 2.12 | Environmental impact and sustainability of AI model training and management activities – as identified in the MAP function – are assessed and documented. | — | Not Addressed | N | Not Rated | No sufficiently direct GAISSF control mapping was identified in this edition. |
| MEASURE 2.13 | Effectiveness of the employed TEVV met- rics and processes in the MEASURE function are evaluated and documented. MEASURE 3: Mechanisms for tracking identified AI risks over time are in place. | — | Not Addressed | N | Not Rated | No sufficiently direct GAISSF control mapping was identified in this edition. |
| MEASURE 3.1 | Approaches, personnel, and documentation are in place to regularly identify and track existing, unanticipated, and emergent AI risks based on factors such as intended and ac- tual performance in deployed contexts. | — | Not Addressed | N | Not Rated | No sufficiently direct GAISSF control mapping was identified in this edition. |
| MEASURE 3.2 | Risk tracking approaches are considered for settings where AI risks are difficult to assess using currently available measurement techniques or where metrics are not yet available. Categories Subcategories Continued on next page NIST AI 100-1 AI RMF 1.0 Table 3: Categories and subcategories for the MEASURE function. (Continued) | — | Not Addressed | N | Not Rated | No sufficiently direct GAISSF control mapping was identified in this edition. |
| MEASURE 3.3 | Feedback processes for end users and impacted communities to report problems and appeal system outcomes are established and integrated into AI system evaluation metrics. MEASURE 4: Feedback about efficacy of measurement is gathered and assessed. | — | Not Addressed | N | Not Rated | No sufficiently direct GAISSF control mapping was identified in this edition. |
| MEASURE 4.1 | Measurement approaches for identifying AI risks are connected to deployment context(s) and informed through consultation with domain experts and other end users. Ap- proaches are documented. | — | Not Addressed | N | Not Rated | No sufficiently direct GAISSF control mapping was identified in this edition. |
| MEASURE 4.2 | Measurement results regarding AI system trust- worthiness in deployment context(s) and across the AI lifecycle are informed by input from domain experts and relevant AI ac- tors to validate whether the system is performing consistently as intended. Results are documented. | — | Not Addressed | N | Not Rated | No sufficiently direct GAISSF control mapping was identified in this edition. |
| MEASURE 4.3 | Measurable performance improvements or de- clines based on consultations with relevant AI actors, in- cluding affected communities, and field data about context- relevant risks and trustworthiness characteristics are identified and documented. Categories Subcategories 5.4 Manage The MANAGE function entails allocating risk resources to mapped and measured risks on a regular basis and as defined by the GOVERN function. Risk treatment comprises plans to respond to, recover from, and communicate about incidents or events. | D1-CTL-01, D1-CTL-04, D1-CTL-06, D1-CTL-07, D2-CTL-01, D3-CTL-01 | Substantially Addressed | SP | Medium-High | NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context. |
| MANAGE 1.1 | A determination is made as to whether the AI system achieves its intended purposes and stated objectives and whether its development or deployment should proceed. | — | Not Addressed | N | Not Rated | No sufficiently direct GAISSF control mapping was identified in this edition. |
| MANAGE 1.2 | Treatment of documented AI risks is prioritized based on impact, likelihood, and available resources or methods. | — | Not Addressed | N | Not Rated | No sufficiently direct GAISSF control mapping was identified in this edition. |
| MANAGE 1.3 | Responses to the AI risks deemed high priority, as identified by the MAP function, are developed, planned, and doc- umented. Risk response options can include mitigating, transfer- ring, avoiding, or accepting. | — | Not Addressed | N | Not Rated | No sufficiently direct GAISSF control mapping was identified in this edition. |
| MANAGE 1.4 | Negative residual risks (defined as the sum of all unmitigated risks) to both downstream acquirers of AI systems and end users are documented. MANAGE 2: Strategies to maximize AI benefits and minimize negative impacts are planned, prepared, implemented, documented, and informed by input from relevant AI actors. | — | Not Addressed | N | Not Rated | No sufficiently direct GAISSF control mapping was identified in this edition. |
| MANAGE 2.1 | Resources required to manage AI risks are taken into account – along with viable non-AI alternative systems, ap- proaches, or methods – to reduce the magnitude or likelihood of potential impacts. | D8-CTL-02 | Partially Addressed | P | Medium | NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context. |
| MANAGE 2.2 | Mechanisms are in place and applied to sustain the value of deployed AI systems. | — | Not Addressed | N | Not Rated | No sufficiently direct GAISSF control mapping was identified in this edition. |
| MANAGE 2.3 | Procedures are followed to respond to and recover from a previously unknown risk when it is identified. | — | Not Addressed | N | Not Rated | No sufficiently direct GAISSF control mapping was identified in this edition. |
| MANAGE 2.4 | Mechanisms are in place and applied, and respon- sibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use. MANAGE 3: AI risks and benefits from third-party entities are managed. | D1-CTL-01, D1-CTL-07 | Substantially Addressed | SP | Medium-High | NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context. |
| MANAGE 3.1 | AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented. | D1-CTL-07, D4-CTL-04 | Substantially Addressed | SP | Medium-High | NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context. |
| MANAGE 3.2 | Pre-trained models which are used for develop- ment are monitored as part of AI system regular monitoring and maintenance. Categories Subcategories Continued on next page NIST AI 100-1 AI RMF 1.0 Table 4: Categories and subcategories for the MANAGE function. (Continued) MANAGE 4: Risk treatments, including response and recovery, and communication plans for the identified and measured AI risks are documented and monitored regularly. | D1-CTL-02, D1-CTL-03, D8-CTL-04, D9-CTL-04, D9-CTL-05 | Substantially Addressed | SP | Medium-High | NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context. |
| MANAGE 4.1 | Post-deployment AI system monitoring plans are implemented, including mechanisms for capturing and eval- uating input from users and other relevant AI actors, appeal and override, decommissioning, incident response, recovery, and change management. | D1-CTL-03, D1-CTL-09, D6-CTL-05, D8-CTL-04, D9-CTL-01, D9-CTL-05 | Substantially Addressed | SP | Medium-High | NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context. |
| MANAGE 4.2 | Measurable activities for continual improvements are integrated into AI system updates and include regular engage- ment with interested parties, including relevant AI actors. | — | Not Addressed | N | Not Rated | No sufficiently direct GAISSF control mapping was identified in this edition. |
| MANAGE 4.3 | Incidents and errors are communicated to relevant AI actors, including affected communities. Processes for track- ing, responding to, and recovering from incidents and errors are followed and documented. Categories Subcategories 6. AI RMF Profiles AI RMF use-case profiles are implementations of the AI RMF functions, categories, and subcategories for a specific setting or application based on the requirements, risk tolerance, and resources of the Framework user: for example, an AI RMF hiring profile or an AI RMF fair housing profile. | D4-CTL-07, D6-CTL-06 | Substantially Addressed | SP | Medium-High | NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context. |
Annex C — NIST AI RMF Core Index
| ID | Function | Verified subcategory text |
|---|---|---|
| GOVERN 1.1 | GOVERN | Legal and regulatory requirements involving AI are understood, managed, and documented. |
| GOVERN 1.2 | GOVERN | The characteristics of trustworthy AI are inte- grated into organizational policies, processes, procedures, and practices. |
| GOVERN 1.3 | GOVERN | Processes, procedures, and practices are in place to determine the needed level of risk management activities based on the organization’s risk tolerance. |
| GOVERN 1.4 | GOVERN | The risk management process and its outcomes are established through transparent policies, procedures, and other controls based on organizational risk priorities. Categories Subcategories Continued on next page NIST AI 100-1 AI RMF 1.0 Table 1: Categories and subcategories for the GOVERN function. (Continued) |
| GOVERN 1.5 | GOVERN | Ongoing monitoring and periodic review of the risk management process and its outcomes are planned and or- ganizational roles and responsibilities clearly defined, including determining the frequency of periodic review. |
| GOVERN 1.6 | GOVERN | Mechanisms are in place to inventory AI systems and are resourced according to organizational risk priorities. |
| GOVERN 1.7 | GOVERN | Processes and procedures are in place for decom- missioning and phasing out AI systems safely and in a man- ner that does not increase risks or decrease the organization’s trustworthiness. GOVERN 2: Accountability structures are in place so that the appropriate teams and individuals are empowered, responsible, and trained for mapping, measuring, and managing AI risks. |
| GOVERN 2.1 | GOVERN | Roles and responsibilities and lines of communi- cation related to mapping, measuring, and managing AI risks are documented and are clear to individuals and teams throughout the organization. |
| GOVERN 2.2 | GOVERN | The organization’s personnel and partners receive AI risk management training to enable them to perform their du- ties and responsibilities consistent with related policies, proce- dures, and agreements. |
| GOVERN 2.3 | GOVERN | Executive leadership of the organization takes re- sponsibility for decisions about risks associated with AI system development and deployment. GOVERN 3: Workforce diversity, equity, inclusion, and accessibility processes are prioritized in the mapping, measuring, and managing of AI risks throughout the lifecycle. |
| GOVERN 3.1 | GOVERN | Decision-making related to mapping, measuring, and managing AI risks throughout the lifecycle is informed by a diverse team (e.g., diversity of demographics, disciplines, expe- rience, expertise, and backgrounds). |
| GOVERN 3.2 | GOVERN | Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configura- tions and oversight of AI systems. GOVERN 4: Organizational teams are committed to a culture |
| GOVERN 4.1 | GOVERN | Organizational policies and practices are in place to foster a critical thinking and safety-first mindset in the design, development, deployment, and uses of AI systems to minimize potential negative impacts. Categories Subcategories Continued on next page NIST AI 100-1 AI RMF 1.0 Table 1: Categories and subcategories for the GOVERN function. (Continued) that considers and communicates AI risk. |
| GOVERN 4.2 | GOVERN | Organizational teams document the risks and po- tential impacts of the AI technology they design, develop, deploy, evaluate, and use, and they communicate about the impacts more broadly. |
| GOVERN 4.3 | GOVERN | Organizational practices are in place to enable AI testing, identification of incidents, and information sharing. GOVERN 5: Processes are in place for robust engagement with relevant AI actors. |
| GOVERN 5.1 | GOVERN | Organizational policies and practices are in place to collect, consider, prioritize, and integrate feedback from those external to the team that developed or deployed the AI system regarding the potential individual and societal impacts related to AI risks. |
| GOVERN 5.2 | GOVERN | Mechanisms are established to enable the team that developed or deployed AI systems to regularly incorporate adjudicated feedback from relevant AI actors into system design and implementation. GOVERN 6: Policies and procedures are in place to address AI risks and benefits arising from third-party software and data and other supply chain issues. |
| GOVERN 6.1 | GOVERN | Policies and procedures are in place that address AI risks associated with third-party entities, including risks of in- fringement of a third-party’s intellectual property or other rights. |
| GOVERN 6.2 | GOVERN | Contingency processes are in place to handle failures or incidents in third-party data or AI systems deemed to be high-risk. Categories Subcategories 5.2 Map The MAP function establishes the context to frame risks related to an AI system. The AI lifecycle consists of many interdependent activities involving a diverse set of actors (See Figure 3). In practice, AI actors in charge of one part of the process often do not have full visibility or control over other parts and their associated contexts. |
| MAP 1.1 | MAP | Intended purposes, potentially beneficial uses, context- specific laws, norms and expectations, and prospective settings in which the AI system will be deployed are understood and docu- mented. Considerations include: the specific set or types of users along with their expectations; potential positive and negative im- pacts of system uses to individuals, communities, organizations, society, and the planet; assumptions and related limitations about AI system purposes, uses, and risks across the development or product AI lifecycle; and related TEVV and system metrics. |
| MAP 1.2 | MAP | Interdisciplinary AI actors, competencies, skills, and capacities for establishing context reflect demographic diversity and broad domain and user experience expertise, and their par- ticipation is documented. Opportunities for interdisciplinary col- laboration are prioritized. |
| MAP 1.3 | MAP | The organization’s mission and relevant goals for AI technology are understood and documented. |
| MAP 1.4 | MAP | The business value or context of business use has been clearly defined or – in the case of assessing existing AI systems – re-evaluated. |
| MAP 1.5 | MAP | Organizational risk tolerances are determined and documented. |
| MAP 1.6 | MAP | System requirements (e.g., “the system shall respect the privacy of its users”) are elicited from and understood by rel- evant AI actors. Design decisions take socio-technical implica- tions into account to address AI risks. MAP 2: Categorization of the AI system is performed. |
| MAP 2.1 | MAP | The specific tasks and methods used to implement the tasks that the AI system will support are defined (e.g., classifiers, generative models, recommenders). |
| MAP 2.2 | MAP | Information about the AI system’s knowledge limits and how system output may be utilized and overseen by humans is documented. Documentation provides sufficient information to assist relevant AI actors when making decisions and taking subsequent actions. Categories Subcategories Continued on next page NIST AI 100-1 AI RMF 1.0 Table 2: Categories and subcategories for the MAP function. (Continued) |
| MAP 2.3 | MAP | Scientific integrity and TEVV considerations are iden- tified and documented, including those related to experimental design, data collection and selection (e.g., availability, repre- sentativeness, suitability), system trustworthiness, and construct validation. MAP 3: AI capabilities, targeted usage, goals, and expected benefits and costs compared with appropriate benchmarks are understood. |
| MAP 3.1 | MAP | Potential benefits of intended AI system functionality and performance are examined and documented. |
| MAP 3.2 | MAP | Potential costs, including non-monetary costs, which result from expected or realized AI errors or system functionality and trustworthiness – as connected to organizational risk toler- ance – are examined and documented. |
| MAP 3.3 | MAP | Targeted application scope is specified and docu- mented based on the system’s capability, established context, and AI system categorization. |
| MAP 3.4 | MAP | Processes for operator and practitioner proficiency with AI system performance and trustworthiness – and relevant technical standards and certifications – are defined, assessed, and documented. |
| MAP 3.5 | MAP | Processes for human oversight are defined, assessed, and documented in accordance with organizational policies from the GOVERN function. MAP 4: Risks and benefits are mapped for all components of the AI system including third-party software and data. |
| MAP 4.1 | MAP | Approaches for mapping AI technology and legal risks of its components – including the use of third-party data or soft- ware – are in place, followed, and documented, as are risks of in- fringement of a third party’s intellectual property or other rights. |
| MAP 4.2 | MAP | Internal risk controls for components of the AI sys- tem, including third-party AI technologies, are identified and documented. MAP 5: Impacts to individuals, groups, communities, organizations, and society are characterized. |
| MAP 5.1 | MAP | Likelihood and magnitude of each identified impact (both potentially beneficial and harmful) based on expected use, past uses of AI systems in similar contexts, public incident re- ports, feedback from those external to the team that developed or deployed the AI system, or other data are identified and documented. Categories Subcategories Continued on next page NIST AI 100-1 AI RMF 1.0 Table 2: Categories and subcategories for the MAP function. (Continued) |
| MAP 5.2 | MAP | Practices and personnel for supporting regular en- gagement with relevant AI actors and integrating feedback about positive, negative, and unanticipated impacts are in place and documented. Categories Subcategories 5.3 Measure The MEASURE function employs quantitative, qualitative, or mixed-method tools, tech- niques, and methodologies to analyze, assess, benchmark, and monitor AI risk and related impacts. It uses knowledge relevant to AI risks identified in the MAP function and informs the MANAGE function. AI systems should be tested before their deployment and regu- larly while in operation. |
| MEASURE 1.1 | MEASURE | Approaches and metrics for measurement of AI risks enumerated during the MAP function are selected for imple- mentation starting with the most significant AI risks. The risks or trustworthiness characteristics that will not – or cannot – be measured are properly documented. |
| MEASURE 1.2 | MEASURE | Appropriateness of AI metrics and effectiveness of existing controls are regularly assessed and updated, including reports of errors and potential impacts on affected communities. |
| MEASURE 1.3 | MEASURE | Internal experts who did not serve as front-line developers for the system and/or independent assessors are in- volved in regular assessments and updates. Domain experts, users, AI actors external to the team that developed or deployed the AI system, and affected communities are consulted in support of assessments as necessary per organizational risk tolerance. MEASURE 2: AI systems are evaluated for trustworthy characteristics. |
| MEASURE 2.1 | MEASURE | Test sets, metrics, and details about the tools used during TEVV are documented. |
| MEASURE 2.2 | MEASURE | Evaluations involving human subjects meet ap- plicable requirements (including human subject protection) and are representative of the relevant population. |
| MEASURE 2.3 | MEASURE | AI system performance or assurance criteria are measured qualitatively or quantitatively and demonstrated for conditions similar to deployment setting(s). Measures are documented. |
| MEASURE 2.4 | MEASURE | The functionality and behavior of the AI sys- tem and its components – as identified in the MAP function – are monitored when in production. |
| MEASURE 2.5 | MEASURE | The AI system to be deployed is demonstrated to be valid and reliable. Limitations of the generalizability be- yond the conditions under which the technology was developed are documented. Categories Subcategories Continued on next page NIST AI 100-1 AI RMF 1.0 Table 3: Categories and subcategories for the MEASURE function. (Continued) |
| MEASURE 2.6 | MEASURE | The AI system is evaluated regularly for safety risks – as identified in the MAP function. The AI system to be de- ployed is demonstrated to be safe, its residual negative risk does not exceed the risk tolerance, and it can fail safely, particularly if made to operate beyond its knowledge limits. Safety metrics re- flect system reliability and robustness, real-time monitoring, and response times for AI system failures. |
| MEASURE 2.7 | MEASURE | AI system security and resilience – as identified in the MAP function – are evaluated and documented. |
| MEASURE 2.8 | MEASURE | Risks associated with transparency and account- ability – as identified in the MAP function – are examined and documented. |
| MEASURE 2.9 | MEASURE | The AI model is explained, validated, and docu- mented, and AI system output is interpreted within its context – as identified in the MAP function – to inform responsible use and governance. |
| MEASURE 2.10 | MEASURE | Privacy risk of the AI system – as identified in the MAP function – is examined and documented. |
| MEASURE 2.11 | MEASURE | Fairness and bias – as identified in the MAP function – are evaluated and results are documented. |
| MEASURE 2.12 | MEASURE | Environmental impact and sustainability of AI model training and management activities – as identified in the MAP function – are assessed and documented. |
| MEASURE 2.13 | MEASURE | Effectiveness of the employed TEVV met- rics and processes in the MEASURE function are evaluated and documented. MEASURE 3: Mechanisms for tracking identified AI risks over time are in place. |
| MEASURE 3.1 | MEASURE | Approaches, personnel, and documentation are in place to regularly identify and track existing, unanticipated, and emergent AI risks based on factors such as intended and ac- tual performance in deployed contexts. |
| MEASURE 3.2 | MEASURE | Risk tracking approaches are considered for settings where AI risks are difficult to assess using currently available measurement techniques or where metrics are not yet available. Categories Subcategories Continued on next page NIST AI 100-1 AI RMF 1.0 Table 3: Categories and subcategories for the MEASURE function. (Continued) |
| MEASURE 3.3 | MEASURE | Feedback processes for end users and impacted communities to report problems and appeal system outcomes are established and integrated into AI system evaluation metrics. MEASURE 4: Feedback about efficacy of measurement is gathered and assessed. |
| MEASURE 4.1 | MEASURE | Measurement approaches for identifying AI risks are connected to deployment context(s) and informed through consultation with domain experts and other end users. Ap- proaches are documented. |
| MEASURE 4.2 | MEASURE | Measurement results regarding AI system trust- worthiness in deployment context(s) and across the AI lifecycle are informed by input from domain experts and relevant AI ac- tors to validate whether the system is performing consistently as intended. Results are documented. |
| MEASURE 4.3 | MEASURE | Measurable performance improvements or de- clines based on consultations with relevant AI actors, in- cluding affected communities, and field data about context- relevant risks and trustworthiness characteristics are identified and documented. Categories Subcategories 5.4 Manage The MANAGE function entails allocating risk resources to mapped and measured risks on a regular basis and as defined by the GOVERN function. Risk treatment comprises plans to respond to, recover from, and communicate about incidents or events. |
| MANAGE 1.1 | MANAGE | A determination is made as to whether the AI system achieves its intended purposes and stated objectives and whether its development or deployment should proceed. |
| MANAGE 1.2 | MANAGE | Treatment of documented AI risks is prioritized based on impact, likelihood, and available resources or methods. |
| MANAGE 1.3 | MANAGE | Responses to the AI risks deemed high priority, as identified by the MAP function, are developed, planned, and doc- umented. Risk response options can include mitigating, transfer- ring, avoiding, or accepting. |
| MANAGE 1.4 | MANAGE | Negative residual risks (defined as the sum of all unmitigated risks) to both downstream acquirers of AI systems and end users are documented. MANAGE 2: Strategies to maximize AI benefits and minimize negative impacts are planned, prepared, implemented, documented, and informed by input from relevant AI actors. |
| MANAGE 2.1 | MANAGE | Resources required to manage AI risks are taken into account – along with viable non-AI alternative systems, ap- proaches, or methods – to reduce the magnitude or likelihood of potential impacts. |
| MANAGE 2.2 | MANAGE | Mechanisms are in place and applied to sustain the value of deployed AI systems. |
| MANAGE 2.3 | MANAGE | Procedures are followed to respond to and recover from a previously unknown risk when it is identified. |
| MANAGE 2.4 | MANAGE | Mechanisms are in place and applied, and respon- sibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use. MANAGE 3: AI risks and benefits from third-party entities are managed. |
| MANAGE 3.1 | MANAGE | AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented. |
| MANAGE 3.2 | MANAGE | Pre-trained models which are used for develop- ment are monitored as part of AI system regular monitoring and maintenance. Categories Subcategories Continued on next page NIST AI 100-1 AI RMF 1.0 Table 4: Categories and subcategories for the MANAGE function. (Continued) MANAGE 4: Risk treatments, including response and recovery, and communication plans for the identified and measured AI risks are documented and monitored regularly. |
| MANAGE 4.1 | MANAGE | Post-deployment AI system monitoring plans are implemented, including mechanisms for capturing and eval- uating input from users and other relevant AI actors, appeal and override, decommissioning, incident response, recovery, and change management. |
| MANAGE 4.2 | MANAGE | Measurable activities for continual improvements are integrated into AI system updates and include regular engage- ment with interested parties, including relevant AI actors. |
| MANAGE 4.3 | MANAGE | Incidents and errors are communicated to relevant AI actors, including affected communities. Processes for track- ing, responding to, and recovering from incidents and errors are followed and documented. Categories Subcategories 6. AI RMF Profiles AI RMF use-case profiles are implementations of the AI RMF functions, categories, and subcategories for a specific setting or application based on the requirements, risk tolerance, and resources of the Framework user: for example, an AI RMF hiring profile or an AI RMF fair housing profile. |
Annex D — Quality-Assurance Record
| Check | Result |
|---|---|
| GAISSF control inventory | 59 controls extracted from GAISSF-NOR-004 v1.0 |
| NIST subcategory inventory | 72 unique Core subcategories extracted from NIST AI 100-1 |
| Bidirectional register | Completed |
| Unsupported equivalence claims | Removed |
| Playbook/Core distinction | Preserved |
| GenAI Profile separation | Preserved |
| Future revision caveat | Included |
| Notably Absent discipline | Included |
Change Log
| Version | Date | Change |
|---|---|---|
| 1.0 | 29 June 2026 | Initial publication candidate; complete bidirectional mapping and evidence-reuse guidance. |