CROSSWALKS

GAISSF to NIST AI RMF Crosswalk

Public crosswalk publication mapping GAISSF v1.0 to NIST AI RMF, with scope, method, limitations and traceability.

Document Control

Field Controlled value
Document ID CRO-022
Title GAISSF–NIST AI Risk Management Framework Mapping
Version 1.0
Status Publication Candidate
Classification Crosswalk — informative
Publisher ODA3 Institute
Legal entity ODA3 Pvt Ltd
GAISSF baseline GAISSF v1.0, 59 controls across D1–D9
NIST baseline NIST AI 100-1, AI RMF 1.0, January 2023
Verification date 29 June 2026
Distribution Public — Website/GitHub
Review trigger Revision of GAISSF, AI RMF, or material mapping evidence

Executive Summary

CRO-022 provides a bidirectional, outcome-based mapping between the 59 GAISSF v1.0 controls and the 72 NIST AI RMF 1.0 Core subcategories. It supports implementation planning, gap analysis, evidence reuse, profile development, and internal assurance. It does not establish NIST certification, NIST endorsement, regulatory compliance, or automatic satisfaction of NIST outcomes.

Reverse coverage distribution: Indirectly Supported: 5, Not Addressed: 35, Substantially Addressed: 24, Partially Addressed: 8. These counts measure mapping coverage only; they are not a compliance score.

Notably Absent

  • No NIST certification scheme is created by AI RMF 1.0.

  • No NIST endorsement or approval of GAISSF was identified.

  • No automatic legal or regulatory safe harbour is established.

  • No evidence was identified that GAISSF and NIST AI RMF are fully equivalent.

  • No universal risk-tolerance threshold is prescribed by AI RMF 1.0.

  • No mapping result proves operating effectiveness.

1. Purpose and Intended Use

This crosswalk enables practitioners to relate GAISSF controls to NIST AI RMF outcomes, identify supplementary work, reuse verified evidence, and document Current and Target Profile decisions. It is an interpretive mapping, not a substitution mechanism.

2. Scope and Source Baseline

In scope: GAISSF-NOR-001 and GAISSF-NOR-004 corrected final publication editions, version 1.0, dated 29 June 2026; and NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0), January 2023. The NIST AI RMF Playbook and NIST AI 600-1 are supplementary and are not merged into the Core mapping. Future revisions require revalidation.

Source Status Role
GAISSF-NOR-001 v1.0 Normative Framework architecture and conformance baseline
GAISSF-NOR-004 v1.0 Normative Authoritative 59-control catalogue
NIST AI 100-1 Voluntary framework Primary NIST Core mapping target
NIST AI RMF Playbook Informative Optional implementation guidance
NIST AI 600-1 Supplementary profile Separate GenAI analysis only

3. Mapping Methodology

Mappings were evaluated at GAISSF control and NIST subcategory level. Relationship strength, reverse coverage status, and confidence are separate fields. Similar terminology alone was not treated as sufficient evidence. One-to-many and composite mappings are retained where an outcome depends on several controls.

Code Meaning
E Equivalent or near-equivalent; used only with exceptional evidence
SP Strong partial
P Partial
S Supporting
C Contextual
N No material mapping
O Outside scope
U Unable to determine
Confidence Rule
High Clear, specific support in both primary sources
Medium-High Strong support with modest interpretation
Medium Reasonable but context-dependent
Low Tentative, indirect, or ambiguous
Not Rated No mapping, outside scope, or indeterminate

4. Function-Level Findings

GOVERN

19 NIST subcategories assessed. Coverage distribution: Indirectly Supported 3, Not Addressed 5, Substantially Addressed 11.

GAISSF provides substantial support through governance, accountability, inventory, supplier, incident, and lifecycle controls. Context-specific legal, workforce, and organizational culture outcomes may require supplementary implementation.

MAP

18 NIST subcategories assessed. Coverage distribution: Partially Addressed 3, Not Addressed 9, Substantially Addressed 4, Indirectly Supported 2.

GAISSF supports context, threat, dependency, human-oversight, and impact analysis. Broader social, mission, benefit, cost, and affected-community mapping may extend beyond security-focused controls.

MEASURE

22 NIST subcategories assessed. Coverage distribution: Partially Addressed 4, Not Addressed 14, Substantially Addressed 4.

GAISSF is comparatively detailed for adversarial testing, monitoring, drift, output integrity, safety, privacy, and assurance evidence. NIST-specific metric selection, independent TEVV, and contextual trustworthiness evaluation remain necessary.

MANAGE

13 NIST subcategories assessed. Coverage distribution: Not Addressed 7, Partially Addressed 1, Substantially Addressed 5.

GAISSF strongly supports treatment, incident response, third-party risk, monitoring, and continuous improvement. Organizations must still determine priorities, resources, acceptance decisions, and residual-risk communication in context.

5. Trustworthiness and Security Analysis

GAISSF controls materially support valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair-with-harmful-bias-managed outcomes. The mapping does not treat these characteristics as independent checkboxes; trade-offs and context remain necessary. GAISSF adds operational detail for adversarial robustness, prompt injection, model extraction, autonomous agents, supply-chain security, runtime monitoring, and incident response.

6. Evidence Reuse Guidance

Evidence family Potential reuse Supplementary NIST context
AI inventory and scope records GOVERN inventory, ownership, lifecycle Mission, risk tolerance, and affected-party context
Risk and impact assessments MAP and MANAGE decisions Benefits, non-monetary costs, likelihood and magnitude
Threat models and security tests MEASURE security/resilience Metric appropriateness and independent review
Model/data documentation MAP knowledge limits; MEASURE transparency Use-context limitations and affected-party communication
Monitoring and incident records MEASURE/MANAGE tracking and response Risk prioritization, residual risk, and stakeholder reporting
Supplier assessments and AI BOMs GOVERN/MAP/MANAGE third-party outcomes Contractual responsibilities and downstream use context

7. Limitations

  • The AI RMF is voluntary, rights-preserving, non-sector-specific, and use-case agnostic.

  • Mapping is interpretive and does not prove control implementation or effectiveness.

  • GAISSF conformance does not automatically demonstrate every NIST AI RMF outcome.

  • NIST Profiles are contextual; Current and Target Profiles require organizational decisions.

  • The mapping must be revalidated when either baseline changes.

  • The Playbook is supplementary guidance, not a set of additional mandatory requirements.

8. Conclusions

GAISSF v1.0 supplies a substantial operational and evidence-oriented foundation for many NIST AI RMF outcomes, particularly security, resilience, monitoring, third-party risk, incident response, and lifecycle assurance. Material differences remain in abstraction, organizational context, social impact framing, risk tolerance, benefit/cost analysis, and profile-specific implementation. CRO-022 should therefore be used for planning and traceability—not as a declaration of NIST compliance or equivalence.

Annex A — GAISSF-to-NIST Mapping Register

Controlled Publication. The table below shows a representative sample (6 of 167 total records). The complete control-by-control mapping register — full requirement-level traceability, evidence guidance and machine-readable export — is a Controlled Publication. Contact ODA3 Institute for access.
Record GAISSF control Title NIST subcategory Rel. Confidence Rationale Residual gap
CRO022-M-001 D1-CTL-01 Dataset Provenance & Poisoning Prevention MEASURE 4.3 SP Medium-High GAISSF D1-CTL-01 addresses dataset provenance & poisoning prevention through Hash verification + source allowlist + poisoning detection.. This supports the NIST outcome concerning measurable performance improvements or de- clines based on consultations with relevant ai actors, in- cluding affected communities, and field data about context- relevant risks and. The mapping does not establish implementation effectiveness or equivalence. NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context.
CRO022-M-002 D1-CTL-01 Dataset Provenance & Poisoning Prevention GOVERN 6.2 SP Medium-High GAISSF D1-CTL-01 addresses dataset provenance & poisoning prevention through Hash verification + source allowlist + poisoning detection.. This supports the NIST outcome concerning contingency processes are in place to handle failures or incidents in third-party data or ai systems deemed to be high-risk. categories subcategories 5.2 map the map function estab. The mapping does not establish implementation effectiveness or equivalence. NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context.
CRO022-M-003 D1-CTL-01 Dataset Provenance & Poisoning Prevention MANAGE 2.4 SP Medium-High GAISSF D1-CTL-01 addresses dataset provenance & poisoning prevention through Hash verification + source allowlist + poisoning detection.. This supports the NIST outcome concerning mechanisms are in place and applied, and respon- sibilities are assigned and understood, to supersede, disengage, or deactivate ai systems that demonstrate performance or outcomes . The mapping does not establish implementation effectiveness or equivalence. NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context.
CRO022-M-004 D1-CTL-02 Model Extraction Resistance MAP 5.2 SP Medium-High GAISSF D1-CTL-02 addresses model extraction resistance through Rate limiting + diversity detection + extraction monitoring.. This supports the NIST outcome concerning practices and personnel for supporting regular en- gagement with relevant ai actors and integrating feedback about positive, negative, and unanticipated impacts are in place and do. The mapping does not establish implementation effectiveness or equivalence. NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context.
CRO022-M-005 D1-CTL-02 Model Extraction Resistance MEASURE 2.6 SP Medium-High GAISSF D1-CTL-02 addresses model extraction resistance through Rate limiting + diversity detection + extraction monitoring.. This supports the NIST outcome concerning the ai system is evaluated regularly for safety risks – as identified in the map function. the ai system to be de- ployed is demonstrated to be safe, its residual negative risk doe. The mapping does not establish implementation effectiveness or equivalence. NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context.
CRO022-M-006 D1-CTL-02 Model Extraction Resistance MANAGE 3.2 SP Medium-High GAISSF D1-CTL-02 addresses model extraction resistance through Rate limiting + diversity detection + extraction monitoring.. This supports the NIST outcome concerning pre-trained models which are used for develop- ment are monitored as part of ai system regular monitoring and maintenance. categories subcategories continued on next page nist ai 1. The mapping does not establish implementation effectiveness or equivalence. NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context.

Annex B — NIST-to-GAISSF Reverse Coverage Register

NIST ID NIST outcome GAISSF controls Coverage Rel. Confidence Gap / further work
GOVERN 1.1 Legal and regulatory requirements involving AI are understood, managed, and documented. D8-CTL-03 Indirectly Supported C Low NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context.
GOVERN 1.2 The characteristics of trustworthy AI are inte- grated into organizational policies, processes, procedures, and practices. Not Addressed N Not Rated No sufficiently direct GAISSF control mapping was identified in this edition.
GOVERN 1.3 Processes, procedures, and practices are in place to determine the needed level of risk management activities based on the organization’s risk tolerance. Not Addressed N Not Rated No sufficiently direct GAISSF control mapping was identified in this edition.
GOVERN 1.4 The risk management process and its outcomes are established through transparent policies, procedures, and other controls based on organizational risk priorities. Categories Subcategories Continued on next page NIST AI 100-1 AI RMF 1.0 Table 1: Categories and subcategories for the GOVERN function. (Continued) D6-CTL-04, D7-CTL-H03 Substantially Addressed SP Medium-High NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context.
GOVERN 1.5 Ongoing monitoring and periodic review of the risk management process and its outcomes are planned and or- ganizational roles and responsibilities clearly defined, including determining the frequency of periodic review. D6-CTL-05, D7-CTL-H03, D8-CTL-04 Substantially Addressed SP Medium-High NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context.
GOVERN 1.6 Mechanisms are in place to inventory AI systems and are resourced according to organizational risk priorities. D4-CTL-01, D8-CTL-02 Substantially Addressed SP Medium-High NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context.
GOVERN 1.7 Processes and procedures are in place for decom- missioning and phasing out AI systems safely and in a man- ner that does not increase risks or decrease the organization’s trustworthiness. GOVERN 2: Accountability structures are in place so that the appropriate teams and individuals are empowered, responsible, and trained for mapping, measuring, and managing AI risks. D6-CTL-01, D6-CTL-02, D6-CTL-03, D6-CTL-04, D6-CTL-05, D6-CTL-07 Substantially Addressed SP Medium-High NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context.
GOVERN 2.1 Roles and responsibilities and lines of communi- cation related to mapping, measuring, and managing AI risks are documented and are clear to individuals and teams throughout the organization. Not Addressed N Not Rated No sufficiently direct GAISSF control mapping was identified in this edition.
GOVERN 2.2 The organization’s personnel and partners receive AI risk management training to enable them to perform their du- ties and responsibilities consistent with related policies, proce- dures, and agreements. D7-CTL-H01, D7-CTL-H04 Indirectly Supported C Low NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context.
GOVERN 2.3 Executive leadership of the organization takes re- sponsibility for decisions about risks associated with AI system development and deployment. GOVERN 3: Workforce diversity, equity, inclusion, and accessibility processes are prioritized in the mapping, measuring, and managing of AI risks throughout the lifecycle. D3-CTL-07, D6-CTL-03 Substantially Addressed SP Medium-High NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context.
GOVERN 3.1 Decision-making related to mapping, measuring, and managing AI risks throughout the lifecycle is informed by a diverse team (e.g., diversity of demographics, disciplines, expe- rience, expertise, and backgrounds). Not Addressed N Not Rated No sufficiently direct GAISSF control mapping was identified in this edition.
GOVERN 3.2 Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configura- tions and oversight of AI systems. GOVERN 4: Organizational teams are committed to a culture D6-CTL-01, D6-CTL-03, D6-CTL-07 Substantially Addressed SP Medium-High NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context.
GOVERN 4.1 Organizational policies and practices are in place to foster a critical thinking and safety-first mindset in the design, development, deployment, and uses of AI systems to minimize potential negative impacts. Categories Subcategories Continued on next page NIST AI 100-1 AI RMF 1.0 Table 1: Categories and subcategories for the GOVERN function. (Continued) that considers and communicates AI risk. D1-CTL-05, D2-CTL-03, D3-CTL-04, D5-CTL-01, D5-CTL-02, D5-CTL-03 Substantially Addressed SP Medium-High NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context.
GOVERN 4.2 Organizational teams document the risks and po- tential impacts of the AI technology they design, develop, deploy, evaluate, and use, and they communicate about the impacts more broadly. Not Addressed N Not Rated No sufficiently direct GAISSF control mapping was identified in this edition.
GOVERN 4.3 Organizational practices are in place to enable AI testing, identification of incidents, and information sharing. GOVERN 5: Processes are in place for robust engagement with relevant AI actors. D2-CTL-01, D2-CTL-06, D5-CTL-04, D6-CTL-02, D7-CTL-H02 Substantially Addressed SP Medium-High NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context.
GOVERN 5.1 Organizational policies and practices are in place to collect, consider, prioritize, and integrate feedback from those external to the team that developed or deployed the AI system regarding the potential individual and societal impacts related to AI risks. D7-CTL-H05 Indirectly Supported C Low NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context.
GOVERN 5.2 Mechanisms are established to enable the team that developed or deployed AI systems to regularly incorporate adjudicated feedback from relevant AI actors into system design and implementation. GOVERN 6: Policies and procedures are in place to address AI risks and benefits arising from third-party software and data and other supply chain issues. D4-CTL-02, D4-CTL-03, D4-CTL-04, D4-CTL-05, D4-CTL-06, D4-CTL-07 Substantially Addressed SP Medium-High NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context.
GOVERN 6.1 Policies and procedures are in place that address AI risks associated with third-party entities, including risks of in- fringement of a third-party’s intellectual property or other rights. D4-CTL-02, D4-CTL-03 Substantially Addressed SP Medium-High NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context.
GOVERN 6.2 Contingency processes are in place to handle failures or incidents in third-party data or AI systems deemed to be high-risk. Categories Subcategories 5.2 Map The MAP function establishes the context to frame risks related to an AI system. The AI lifecycle consists of many interdependent activities involving a diverse set of actors (See Figure 3). In practice, AI actors in charge of one part of the process often do not have full visibility or control over other parts and their associated contexts. D1-CTL-01, D4-CTL-01, D4-CTL-02, D4-CTL-03, D4-CTL-04, D7-CTL-H02 Substantially Addressed SP Medium-High NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context.
MAP 1.1 Intended purposes, potentially beneficial uses, context- specific laws, norms and expectations, and prospective settings in which the AI system will be deployed are understood and docu- mented. Considerations include: the specific set or types of users along with their expectations; potential positive and negative im- pacts of system uses to individuals, communities, organizations, society, and the planet; assumptions and related limitations about AI system purposes, uses, and risks across the development or product AI lifecycle; and related TEVV and system metrics. D3-CTL-03, D3-CTL-05, D3-CTL-06 Partially Addressed P Medium NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context.
MAP 1.2 Interdisciplinary AI actors, competencies, skills, and capacities for establishing context reflect demographic diversity and broad domain and user experience expertise, and their par- ticipation is documented. Opportunities for interdisciplinary col- laboration are prioritized. Not Addressed N Not Rated No sufficiently direct GAISSF control mapping was identified in this edition.
MAP 1.3 The organization’s mission and relevant goals for AI technology are understood and documented. Not Addressed N Not Rated No sufficiently direct GAISSF control mapping was identified in this edition.
MAP 1.4 The business value or context of business use has been clearly defined or – in the case of assessing existing AI systems – re-evaluated. Not Addressed N Not Rated No sufficiently direct GAISSF control mapping was identified in this edition.
MAP 1.5 Organizational risk tolerances are determined and documented. Not Addressed N Not Rated No sufficiently direct GAISSF control mapping was identified in this edition.
MAP 1.6 System requirements (e.g., “the system shall respect the privacy of its users”) are elicited from and understood by rel- evant AI actors. Design decisions take socio-technical implica- tions into account to address AI risks. MAP 2: Categorization of the AI system is performed. D3-CTL-03, D3-CTL-05, D3-CTL-06, D4-CTL-05, D5-CTL-05 Substantially Addressed SP Medium-High NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context.
MAP 2.1 The specific tasks and methods used to implement the tasks that the AI system will support are defined (e.g., classifiers, generative models, recommenders). Not Addressed N Not Rated No sufficiently direct GAISSF control mapping was identified in this edition.
MAP 2.2 Information about the AI system’s knowledge limits and how system output may be utilized and overseen by humans is documented. Documentation provides sufficient information to assist relevant AI actors when making decisions and taking subsequent actions. Categories Subcategories Continued on next page NIST AI 100-1 AI RMF 1.0 Table 2: Categories and subcategories for the MAP function. (Continued) D8-CTL-01 Indirectly Supported S Medium NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context.
MAP 2.3 Scientific integrity and TEVV considerations are iden- tified and documented, including those related to experimental design, data collection and selection (e.g., availability, repre- sentativeness, suitability), system trustworthiness, and construct validation. MAP 3: AI capabilities, targeted usage, goals, and expected benefits and costs compared with appropriate benchmarks are understood. D3-CTL-02, D3-CTL-04, D5-CTL-02, D5-CTL-03, D5-CTL-06 Partially Addressed P Medium NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context.
MAP 3.1 Potential benefits of intended AI system functionality and performance are examined and documented. Not Addressed N Not Rated No sufficiently direct GAISSF control mapping was identified in this edition.
MAP 3.2 Potential costs, including non-monetary costs, which result from expected or realized AI errors or system functionality and trustworthiness – as connected to organizational risk toler- ance – are examined and documented. D8-CTL-01 Indirectly Supported S Medium NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context.
MAP 3.3 Targeted application scope is specified and docu- mented based on the system’s capability, established context, and AI system categorization. Not Addressed N Not Rated No sufficiently direct GAISSF control mapping was identified in this edition.
MAP 3.4 Processes for operator and practitioner proficiency with AI system performance and trustworthiness – and relevant technical standards and certifications – are defined, assessed, and documented. Not Addressed N Not Rated No sufficiently direct GAISSF control mapping was identified in this edition.
MAP 3.5 Processes for human oversight are defined, assessed, and documented in accordance with organizational policies from the GOVERN function. MAP 4: Risks and benefits are mapped for all components of the AI system including third-party software and data. D3-CTL-01, D3-CTL-07, D4-CTL-06, D4-CTL-07 Substantially Addressed SP Medium-High NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context.
MAP 4.1 Approaches for mapping AI technology and legal risks of its components – including the use of third-party data or soft- ware – are in place, followed, and documented, as are risks of in- fringement of a third party’s intellectual property or other rights. D4-CTL-05 Partially Addressed P Medium NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context.
MAP 4.2 Internal risk controls for components of the AI sys- tem, including third-party AI technologies, are identified and documented. MAP 5: Impacts to individuals, groups, communities, organizations, and society are characterized. Not Addressed N Not Rated No sufficiently direct GAISSF control mapping was identified in this edition.
MAP 5.1 Likelihood and magnitude of each identified impact (both potentially beneficial and harmful) based on expected use, past uses of AI systems in similar contexts, public incident re- ports, feedback from those external to the team that developed or deployed the AI system, or other data are identified and documented. Categories Subcategories Continued on next page NIST AI 100-1 AI RMF 1.0 Table 2: Categories and subcategories for the MAP function. (Continued) D1-CTL-05, D5-CTL-01, D5-CTL-04 Substantially Addressed SP Medium-High NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context.
MAP 5.2 Practices and personnel for supporting regular en- gagement with relevant AI actors and integrating feedback about positive, negative, and unanticipated impacts are in place and documented. Categories Subcategories 5.3 Measure The MEASURE function employs quantitative, qualitative, or mixed-method tools, tech- niques, and methodologies to analyze, assess, benchmark, and monitor AI risk and related impacts. It uses knowledge relevant to AI risks identified in the MAP function and informs the MANAGE function. AI systems should be tested before their deployment and regu- larly while in operation. D1-CTL-02, D1-CTL-03, D1-CTL-09, D2-CTL-02, D2-CTL-03, D2-CTL-04 Substantially Addressed SP Medium-High NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context.
MEASURE 1.1 Approaches and metrics for measurement of AI risks enumerated during the MAP function are selected for imple- mentation starting with the most significant AI risks. The risks or trustworthiness characteristics that will not – or cannot – be measured are properly documented. D2-CTL-05 Partially Addressed P Medium NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context.
MEASURE 1.2 Appropriateness of AI metrics and effectiveness of existing controls are regularly assessed and updated, including reports of errors and potential impacts on affected communities. D2-CTL-04 Partially Addressed P Medium NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context.
MEASURE 1.3 Internal experts who did not serve as front-line developers for the system and/or independent assessors are in- volved in regular assessments and updates. Domain experts, users, AI actors external to the team that developed or deployed the AI system, and affected communities are consulted in support of assessments as necessary per organizational risk tolerance. MEASURE 2: AI systems are evaluated for trustworthy characteristics. D3-CTL-02 Partially Addressed P Medium NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context.
MEASURE 2.1 Test sets, metrics, and details about the tools used during TEVV are documented. D1-CTL-04, D1-CTL-06, D1-CTL-08, D2-CTL-06 Partially Addressed P Medium NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context.
MEASURE 2.2 Evaluations involving human subjects meet ap- plicable requirements (including human subject protection) and are representative of the relevant population. Not Addressed N Not Rated No sufficiently direct GAISSF control mapping was identified in this edition.
MEASURE 2.3 AI system performance or assurance criteria are measured qualitatively or quantitatively and demonstrated for conditions similar to deployment setting(s). Measures are documented. Not Addressed N Not Rated No sufficiently direct GAISSF control mapping was identified in this edition.
MEASURE 2.4 The functionality and behavior of the AI sys- tem and its components – as identified in the MAP function – are monitored when in production. Not Addressed N Not Rated No sufficiently direct GAISSF control mapping was identified in this edition.
MEASURE 2.5 The AI system to be deployed is demonstrated to be valid and reliable. Limitations of the generalizability be- yond the conditions under which the technology was developed are documented. Categories Subcategories Continued on next page NIST AI 100-1 AI RMF 1.0 Table 3: Categories and subcategories for the MEASURE function. (Continued) Not Addressed N Not Rated No sufficiently direct GAISSF control mapping was identified in this edition.
MEASURE 2.6 The AI system is evaluated regularly for safety risks – as identified in the MAP function. The AI system to be de- ployed is demonstrated to be safe, its residual negative risk does not exceed the risk tolerance, and it can fail safely, particularly if made to operate beyond its knowledge limits. Safety metrics re- flect system reliability and robustness, real-time monitoring, and response times for AI system failures. D1-CTL-02, D1-CTL-05, D1-CTL-08, D1-CTL-09, D2-CTL-02, D2-CTL-03 Substantially Addressed SP Medium-High NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context.
MEASURE 2.7 AI system security and resilience – as identified in the MAP function – are evaluated and documented. D1-CTL-04, D1-CTL-06, D1-CTL-08, D2-CTL-01, D2-CTL-02, D2-CTL-04 Substantially Addressed SP Medium-High NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context.
MEASURE 2.8 Risks associated with transparency and account- ability – as identified in the MAP function – are examined and documented. Not Addressed N Not Rated No sufficiently direct GAISSF control mapping was identified in this edition.
MEASURE 2.9 The AI model is explained, validated, and docu- mented, and AI system output is interpreted within its context – as identified in the MAP function – to inform responsible use and governance. D3-CTL-01, D3-CTL-07 Substantially Addressed SP Medium-High NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context.
MEASURE 2.10 Privacy risk of the AI system – as identified in the MAP function – is examined and documented. Not Addressed N Not Rated No sufficiently direct GAISSF control mapping was identified in this edition.
MEASURE 2.11 Fairness and bias – as identified in the MAP function – are evaluated and results are documented. Not Addressed N Not Rated No sufficiently direct GAISSF control mapping was identified in this edition.
MEASURE 2.12 Environmental impact and sustainability of AI model training and management activities – as identified in the MAP function – are assessed and documented. Not Addressed N Not Rated No sufficiently direct GAISSF control mapping was identified in this edition.
MEASURE 2.13 Effectiveness of the employed TEVV met- rics and processes in the MEASURE function are evaluated and documented. MEASURE 3: Mechanisms for tracking identified AI risks over time are in place. Not Addressed N Not Rated No sufficiently direct GAISSF control mapping was identified in this edition.
MEASURE 3.1 Approaches, personnel, and documentation are in place to regularly identify and track existing, unanticipated, and emergent AI risks based on factors such as intended and ac- tual performance in deployed contexts. Not Addressed N Not Rated No sufficiently direct GAISSF control mapping was identified in this edition.
MEASURE 3.2 Risk tracking approaches are considered for settings where AI risks are difficult to assess using currently available measurement techniques or where metrics are not yet available. Categories Subcategories Continued on next page NIST AI 100-1 AI RMF 1.0 Table 3: Categories and subcategories for the MEASURE function. (Continued) Not Addressed N Not Rated No sufficiently direct GAISSF control mapping was identified in this edition.
MEASURE 3.3 Feedback processes for end users and impacted communities to report problems and appeal system outcomes are established and integrated into AI system evaluation metrics. MEASURE 4: Feedback about efficacy of measurement is gathered and assessed. Not Addressed N Not Rated No sufficiently direct GAISSF control mapping was identified in this edition.
MEASURE 4.1 Measurement approaches for identifying AI risks are connected to deployment context(s) and informed through consultation with domain experts and other end users. Ap- proaches are documented. Not Addressed N Not Rated No sufficiently direct GAISSF control mapping was identified in this edition.
MEASURE 4.2 Measurement results regarding AI system trust- worthiness in deployment context(s) and across the AI lifecycle are informed by input from domain experts and relevant AI ac- tors to validate whether the system is performing consistently as intended. Results are documented. Not Addressed N Not Rated No sufficiently direct GAISSF control mapping was identified in this edition.
MEASURE 4.3 Measurable performance improvements or de- clines based on consultations with relevant AI actors, in- cluding affected communities, and field data about context- relevant risks and trustworthiness characteristics are identified and documented. Categories Subcategories 5.4 Manage The MANAGE function entails allocating risk resources to mapped and measured risks on a regular basis and as defined by the GOVERN function. Risk treatment comprises plans to respond to, recover from, and communicate about incidents or events. D1-CTL-01, D1-CTL-04, D1-CTL-06, D1-CTL-07, D2-CTL-01, D3-CTL-01 Substantially Addressed SP Medium-High NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context.
MANAGE 1.1 A determination is made as to whether the AI system achieves its intended purposes and stated objectives and whether its development or deployment should proceed. Not Addressed N Not Rated No sufficiently direct GAISSF control mapping was identified in this edition.
MANAGE 1.2 Treatment of documented AI risks is prioritized based on impact, likelihood, and available resources or methods. Not Addressed N Not Rated No sufficiently direct GAISSF control mapping was identified in this edition.
MANAGE 1.3 Responses to the AI risks deemed high priority, as identified by the MAP function, are developed, planned, and doc- umented. Risk response options can include mitigating, transfer- ring, avoiding, or accepting. Not Addressed N Not Rated No sufficiently direct GAISSF control mapping was identified in this edition.
MANAGE 1.4 Negative residual risks (defined as the sum of all unmitigated risks) to both downstream acquirers of AI systems and end users are documented. MANAGE 2: Strategies to maximize AI benefits and minimize negative impacts are planned, prepared, implemented, documented, and informed by input from relevant AI actors. Not Addressed N Not Rated No sufficiently direct GAISSF control mapping was identified in this edition.
MANAGE 2.1 Resources required to manage AI risks are taken into account – along with viable non-AI alternative systems, ap- proaches, or methods – to reduce the magnitude or likelihood of potential impacts. D8-CTL-02 Partially Addressed P Medium NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context.
MANAGE 2.2 Mechanisms are in place and applied to sustain the value of deployed AI systems. Not Addressed N Not Rated No sufficiently direct GAISSF control mapping was identified in this edition.
MANAGE 2.3 Procedures are followed to respond to and recover from a previously unknown risk when it is identified. Not Addressed N Not Rated No sufficiently direct GAISSF control mapping was identified in this edition.
MANAGE 2.4 Mechanisms are in place and applied, and respon- sibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use. MANAGE 3: AI risks and benefits from third-party entities are managed. D1-CTL-01, D1-CTL-07 Substantially Addressed SP Medium-High NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context.
MANAGE 3.1 AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented. D1-CTL-07, D4-CTL-04 Substantially Addressed SP Medium-High NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context.
MANAGE 3.2 Pre-trained models which are used for develop- ment are monitored as part of AI system regular monitoring and maintenance. Categories Subcategories Continued on next page NIST AI 100-1 AI RMF 1.0 Table 4: Categories and subcategories for the MANAGE function. (Continued) MANAGE 4: Risk treatments, including response and recovery, and communication plans for the identified and measured AI risks are documented and monitored regularly. D1-CTL-02, D1-CTL-03, D8-CTL-04, D9-CTL-04, D9-CTL-05 Substantially Addressed SP Medium-High NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context.
MANAGE 4.1 Post-deployment AI system monitoring plans are implemented, including mechanisms for capturing and eval- uating input from users and other relevant AI actors, appeal and override, decommissioning, incident response, recovery, and change management. D1-CTL-03, D1-CTL-09, D6-CTL-05, D8-CTL-04, D9-CTL-01, D9-CTL-05 Substantially Addressed SP Medium-High NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context.
MANAGE 4.2 Measurable activities for continual improvements are integrated into AI system updates and include regular engage- ment with interested parties, including relevant AI actors. Not Addressed N Not Rated No sufficiently direct GAISSF control mapping was identified in this edition.
MANAGE 4.3 Incidents and errors are communicated to relevant AI actors, including affected communities. Processes for track- ing, responding to, and recovering from incidents and errors are followed and documented. Categories Subcategories 6. AI RMF Profiles AI RMF use-case profiles are implementations of the AI RMF functions, categories, and subcategories for a specific setting or application based on the requirements, risk tolerance, and resources of the Framework user: for example, an AI RMF hiring profile or an AI RMF fair housing profile. D4-CTL-07, D6-CTL-06 Substantially Addressed SP Medium-High NIST requires organization- and context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context.

Annex C — NIST AI RMF Core Index

ID Function Verified subcategory text
GOVERN 1.1 GOVERN Legal and regulatory requirements involving AI are understood, managed, and documented.
GOVERN 1.2 GOVERN The characteristics of trustworthy AI are inte- grated into organizational policies, processes, procedures, and practices.
GOVERN 1.3 GOVERN Processes, procedures, and practices are in place to determine the needed level of risk management activities based on the organization’s risk tolerance.
GOVERN 1.4 GOVERN The risk management process and its outcomes are established through transparent policies, procedures, and other controls based on organizational risk priorities. Categories Subcategories Continued on next page NIST AI 100-1 AI RMF 1.0 Table 1: Categories and subcategories for the GOVERN function. (Continued)
GOVERN 1.5 GOVERN Ongoing monitoring and periodic review of the risk management process and its outcomes are planned and or- ganizational roles and responsibilities clearly defined, including determining the frequency of periodic review.
GOVERN 1.6 GOVERN Mechanisms are in place to inventory AI systems and are resourced according to organizational risk priorities.
GOVERN 1.7 GOVERN Processes and procedures are in place for decom- missioning and phasing out AI systems safely and in a man- ner that does not increase risks or decrease the organization’s trustworthiness. GOVERN 2: Accountability structures are in place so that the appropriate teams and individuals are empowered, responsible, and trained for mapping, measuring, and managing AI risks.
GOVERN 2.1 GOVERN Roles and responsibilities and lines of communi- cation related to mapping, measuring, and managing AI risks are documented and are clear to individuals and teams throughout the organization.
GOVERN 2.2 GOVERN The organization’s personnel and partners receive AI risk management training to enable them to perform their du- ties and responsibilities consistent with related policies, proce- dures, and agreements.
GOVERN 2.3 GOVERN Executive leadership of the organization takes re- sponsibility for decisions about risks associated with AI system development and deployment. GOVERN 3: Workforce diversity, equity, inclusion, and accessibility processes are prioritized in the mapping, measuring, and managing of AI risks throughout the lifecycle.
GOVERN 3.1 GOVERN Decision-making related to mapping, measuring, and managing AI risks throughout the lifecycle is informed by a diverse team (e.g., diversity of demographics, disciplines, expe- rience, expertise, and backgrounds).
GOVERN 3.2 GOVERN Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configura- tions and oversight of AI systems. GOVERN 4: Organizational teams are committed to a culture
GOVERN 4.1 GOVERN Organizational policies and practices are in place to foster a critical thinking and safety-first mindset in the design, development, deployment, and uses of AI systems to minimize potential negative impacts. Categories Subcategories Continued on next page NIST AI 100-1 AI RMF 1.0 Table 1: Categories and subcategories for the GOVERN function. (Continued) that considers and communicates AI risk.
GOVERN 4.2 GOVERN Organizational teams document the risks and po- tential impacts of the AI technology they design, develop, deploy, evaluate, and use, and they communicate about the impacts more broadly.
GOVERN 4.3 GOVERN Organizational practices are in place to enable AI testing, identification of incidents, and information sharing. GOVERN 5: Processes are in place for robust engagement with relevant AI actors.
GOVERN 5.1 GOVERN Organizational policies and practices are in place to collect, consider, prioritize, and integrate feedback from those external to the team that developed or deployed the AI system regarding the potential individual and societal impacts related to AI risks.
GOVERN 5.2 GOVERN Mechanisms are established to enable the team that developed or deployed AI systems to regularly incorporate adjudicated feedback from relevant AI actors into system design and implementation. GOVERN 6: Policies and procedures are in place to address AI risks and benefits arising from third-party software and data and other supply chain issues.
GOVERN 6.1 GOVERN Policies and procedures are in place that address AI risks associated with third-party entities, including risks of in- fringement of a third-party’s intellectual property or other rights.
GOVERN 6.2 GOVERN Contingency processes are in place to handle failures or incidents in third-party data or AI systems deemed to be high-risk. Categories Subcategories 5.2 Map The MAP function establishes the context to frame risks related to an AI system. The AI lifecycle consists of many interdependent activities involving a diverse set of actors (See Figure 3). In practice, AI actors in charge of one part of the process often do not have full visibility or control over other parts and their associated contexts.
MAP 1.1 MAP Intended purposes, potentially beneficial uses, context- specific laws, norms and expectations, and prospective settings in which the AI system will be deployed are understood and docu- mented. Considerations include: the specific set or types of users along with their expectations; potential positive and negative im- pacts of system uses to individuals, communities, organizations, society, and the planet; assumptions and related limitations about AI system purposes, uses, and risks across the development or product AI lifecycle; and related TEVV and system metrics.
MAP 1.2 MAP Interdisciplinary AI actors, competencies, skills, and capacities for establishing context reflect demographic diversity and broad domain and user experience expertise, and their par- ticipation is documented. Opportunities for interdisciplinary col- laboration are prioritized.
MAP 1.3 MAP The organization’s mission and relevant goals for AI technology are understood and documented.
MAP 1.4 MAP The business value or context of business use has been clearly defined or – in the case of assessing existing AI systems – re-evaluated.
MAP 1.5 MAP Organizational risk tolerances are determined and documented.
MAP 1.6 MAP System requirements (e.g., “the system shall respect the privacy of its users”) are elicited from and understood by rel- evant AI actors. Design decisions take socio-technical implica- tions into account to address AI risks. MAP 2: Categorization of the AI system is performed.
MAP 2.1 MAP The specific tasks and methods used to implement the tasks that the AI system will support are defined (e.g., classifiers, generative models, recommenders).
MAP 2.2 MAP Information about the AI system’s knowledge limits and how system output may be utilized and overseen by humans is documented. Documentation provides sufficient information to assist relevant AI actors when making decisions and taking subsequent actions. Categories Subcategories Continued on next page NIST AI 100-1 AI RMF 1.0 Table 2: Categories and subcategories for the MAP function. (Continued)
MAP 2.3 MAP Scientific integrity and TEVV considerations are iden- tified and documented, including those related to experimental design, data collection and selection (e.g., availability, repre- sentativeness, suitability), system trustworthiness, and construct validation. MAP 3: AI capabilities, targeted usage, goals, and expected benefits and costs compared with appropriate benchmarks are understood.
MAP 3.1 MAP Potential benefits of intended AI system functionality and performance are examined and documented.
MAP 3.2 MAP Potential costs, including non-monetary costs, which result from expected or realized AI errors or system functionality and trustworthiness – as connected to organizational risk toler- ance – are examined and documented.
MAP 3.3 MAP Targeted application scope is specified and docu- mented based on the system’s capability, established context, and AI system categorization.
MAP 3.4 MAP Processes for operator and practitioner proficiency with AI system performance and trustworthiness – and relevant technical standards and certifications – are defined, assessed, and documented.
MAP 3.5 MAP Processes for human oversight are defined, assessed, and documented in accordance with organizational policies from the GOVERN function. MAP 4: Risks and benefits are mapped for all components of the AI system including third-party software and data.
MAP 4.1 MAP Approaches for mapping AI technology and legal risks of its components – including the use of third-party data or soft- ware – are in place, followed, and documented, as are risks of in- fringement of a third party’s intellectual property or other rights.
MAP 4.2 MAP Internal risk controls for components of the AI sys- tem, including third-party AI technologies, are identified and documented. MAP 5: Impacts to individuals, groups, communities, organizations, and society are characterized.
MAP 5.1 MAP Likelihood and magnitude of each identified impact (both potentially beneficial and harmful) based on expected use, past uses of AI systems in similar contexts, public incident re- ports, feedback from those external to the team that developed or deployed the AI system, or other data are identified and documented. Categories Subcategories Continued on next page NIST AI 100-1 AI RMF 1.0 Table 2: Categories and subcategories for the MAP function. (Continued)
MAP 5.2 MAP Practices and personnel for supporting regular en- gagement with relevant AI actors and integrating feedback about positive, negative, and unanticipated impacts are in place and documented. Categories Subcategories 5.3 Measure The MEASURE function employs quantitative, qualitative, or mixed-method tools, tech- niques, and methodologies to analyze, assess, benchmark, and monitor AI risk and related impacts. It uses knowledge relevant to AI risks identified in the MAP function and informs the MANAGE function. AI systems should be tested before their deployment and regu- larly while in operation.
MEASURE 1.1 MEASURE Approaches and metrics for measurement of AI risks enumerated during the MAP function are selected for imple- mentation starting with the most significant AI risks. The risks or trustworthiness characteristics that will not – or cannot – be measured are properly documented.
MEASURE 1.2 MEASURE Appropriateness of AI metrics and effectiveness of existing controls are regularly assessed and updated, including reports of errors and potential impacts on affected communities.
MEASURE 1.3 MEASURE Internal experts who did not serve as front-line developers for the system and/or independent assessors are in- volved in regular assessments and updates. Domain experts, users, AI actors external to the team that developed or deployed the AI system, and affected communities are consulted in support of assessments as necessary per organizational risk tolerance. MEASURE 2: AI systems are evaluated for trustworthy characteristics.
MEASURE 2.1 MEASURE Test sets, metrics, and details about the tools used during TEVV are documented.
MEASURE 2.2 MEASURE Evaluations involving human subjects meet ap- plicable requirements (including human subject protection) and are representative of the relevant population.
MEASURE 2.3 MEASURE AI system performance or assurance criteria are measured qualitatively or quantitatively and demonstrated for conditions similar to deployment setting(s). Measures are documented.
MEASURE 2.4 MEASURE The functionality and behavior of the AI sys- tem and its components – as identified in the MAP function – are monitored when in production.
MEASURE 2.5 MEASURE The AI system to be deployed is demonstrated to be valid and reliable. Limitations of the generalizability be- yond the conditions under which the technology was developed are documented. Categories Subcategories Continued on next page NIST AI 100-1 AI RMF 1.0 Table 3: Categories and subcategories for the MEASURE function. (Continued)
MEASURE 2.6 MEASURE The AI system is evaluated regularly for safety risks – as identified in the MAP function. The AI system to be de- ployed is demonstrated to be safe, its residual negative risk does not exceed the risk tolerance, and it can fail safely, particularly if made to operate beyond its knowledge limits. Safety metrics re- flect system reliability and robustness, real-time monitoring, and response times for AI system failures.
MEASURE 2.7 MEASURE AI system security and resilience – as identified in the MAP function – are evaluated and documented.
MEASURE 2.8 MEASURE Risks associated with transparency and account- ability – as identified in the MAP function – are examined and documented.
MEASURE 2.9 MEASURE The AI model is explained, validated, and docu- mented, and AI system output is interpreted within its context – as identified in the MAP function – to inform responsible use and governance.
MEASURE 2.10 MEASURE Privacy risk of the AI system – as identified in the MAP function – is examined and documented.
MEASURE 2.11 MEASURE Fairness and bias – as identified in the MAP function – are evaluated and results are documented.
MEASURE 2.12 MEASURE Environmental impact and sustainability of AI model training and management activities – as identified in the MAP function – are assessed and documented.
MEASURE 2.13 MEASURE Effectiveness of the employed TEVV met- rics and processes in the MEASURE function are evaluated and documented. MEASURE 3: Mechanisms for tracking identified AI risks over time are in place.
MEASURE 3.1 MEASURE Approaches, personnel, and documentation are in place to regularly identify and track existing, unanticipated, and emergent AI risks based on factors such as intended and ac- tual performance in deployed contexts.
MEASURE 3.2 MEASURE Risk tracking approaches are considered for settings where AI risks are difficult to assess using currently available measurement techniques or where metrics are not yet available. Categories Subcategories Continued on next page NIST AI 100-1 AI RMF 1.0 Table 3: Categories and subcategories for the MEASURE function. (Continued)
MEASURE 3.3 MEASURE Feedback processes for end users and impacted communities to report problems and appeal system outcomes are established and integrated into AI system evaluation metrics. MEASURE 4: Feedback about efficacy of measurement is gathered and assessed.
MEASURE 4.1 MEASURE Measurement approaches for identifying AI risks are connected to deployment context(s) and informed through consultation with domain experts and other end users. Ap- proaches are documented.
MEASURE 4.2 MEASURE Measurement results regarding AI system trust- worthiness in deployment context(s) and across the AI lifecycle are informed by input from domain experts and relevant AI ac- tors to validate whether the system is performing consistently as intended. Results are documented.
MEASURE 4.3 MEASURE Measurable performance improvements or de- clines based on consultations with relevant AI actors, in- cluding affected communities, and field data about context- relevant risks and trustworthiness characteristics are identified and documented. Categories Subcategories 5.4 Manage The MANAGE function entails allocating risk resources to mapped and measured risks on a regular basis and as defined by the GOVERN function. Risk treatment comprises plans to respond to, recover from, and communicate about incidents or events.
MANAGE 1.1 MANAGE A determination is made as to whether the AI system achieves its intended purposes and stated objectives and whether its development or deployment should proceed.
MANAGE 1.2 MANAGE Treatment of documented AI risks is prioritized based on impact, likelihood, and available resources or methods.
MANAGE 1.3 MANAGE Responses to the AI risks deemed high priority, as identified by the MAP function, are developed, planned, and doc- umented. Risk response options can include mitigating, transfer- ring, avoiding, or accepting.
MANAGE 1.4 MANAGE Negative residual risks (defined as the sum of all unmitigated risks) to both downstream acquirers of AI systems and end users are documented. MANAGE 2: Strategies to maximize AI benefits and minimize negative impacts are planned, prepared, implemented, documented, and informed by input from relevant AI actors.
MANAGE 2.1 MANAGE Resources required to manage AI risks are taken into account – along with viable non-AI alternative systems, ap- proaches, or methods – to reduce the magnitude or likelihood of potential impacts.
MANAGE 2.2 MANAGE Mechanisms are in place and applied to sustain the value of deployed AI systems.
MANAGE 2.3 MANAGE Procedures are followed to respond to and recover from a previously unknown risk when it is identified.
MANAGE 2.4 MANAGE Mechanisms are in place and applied, and respon- sibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use. MANAGE 3: AI risks and benefits from third-party entities are managed.
MANAGE 3.1 MANAGE AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented.
MANAGE 3.2 MANAGE Pre-trained models which are used for develop- ment are monitored as part of AI system regular monitoring and maintenance. Categories Subcategories Continued on next page NIST AI 100-1 AI RMF 1.0 Table 4: Categories and subcategories for the MANAGE function. (Continued) MANAGE 4: Risk treatments, including response and recovery, and communication plans for the identified and measured AI risks are documented and monitored regularly.
MANAGE 4.1 MANAGE Post-deployment AI system monitoring plans are implemented, including mechanisms for capturing and eval- uating input from users and other relevant AI actors, appeal and override, decommissioning, incident response, recovery, and change management.
MANAGE 4.2 MANAGE Measurable activities for continual improvements are integrated into AI system updates and include regular engage- ment with interested parties, including relevant AI actors.
MANAGE 4.3 MANAGE Incidents and errors are communicated to relevant AI actors, including affected communities. Processes for track- ing, responding to, and recovering from incidents and errors are followed and documented. Categories Subcategories 6. AI RMF Profiles AI RMF use-case profiles are implementations of the AI RMF functions, categories, and subcategories for a specific setting or application based on the requirements, risk tolerance, and resources of the Framework user: for example, an AI RMF hiring profile or an AI RMF fair housing profile.

Annex D — Quality-Assurance Record

Check Result
GAISSF control inventory 59 controls extracted from GAISSF-NOR-004 v1.0
NIST subcategory inventory 72 unique Core subcategories extracted from NIST AI 100-1
Bidirectional register Completed
Unsupported equivalence claims Removed
Playbook/Core distinction Preserved
GenAI Profile separation Preserved
Future revision caveat Included
Notably Absent discipline Included

Change Log

Version Date Change
1.0 29 June 2026 Initial publication candidate; complete bidirectional mapping and evidence-reuse guidance.