NIST AI RMF

Two of the four functions only exist at runtime.

Govern and Map can be satisfied on paper, and a great deal of governance tooling stops exactly there. Measure and Manage ask what actually happened — which is a question only something watching the calls can answer.

The pattern worth noticing

Documentation answers half the framework.

Policy templates and risk registers produce a defensible Govern story and a reasonable Map story. Then Measure asks how risk is analyzed and tracked, and Manage asks for traceable evidence that controls are working — and a document cannot supply either.

Both halves matter. The point is not that documentation is worthless; it is that the second half is only produced by enforcement, and enforcement has to happen where the calls are.

Function by function

What each one asks, and what is produced.

Govern

Accountability and policy lifecycle

Policies, roles and accountability for AI risk are established, assigned and maintained.

Policy authored in plain language with version history and a recorded approval before anything enforces. Roles federated from the identity provider already in use and bound directly to rules. A registry of AI systems carrying named owners and enforcement mode.

Evidence artifactPolicy definitions, approval and version history, role-binding records, registry export.

Map

Discover, contextualize, categorize

AI systems, their context and their data provenance are identified and documented.

Scheduled discovery of every registered server and what it exposes, introspection of the data behind it down to the column, sensitivity labeling applied as it is found, and a navigable graph of which roles and actors can reach which data.

Evidence artifactRegistry export, catalog to column level, timestamped topology of access paths.

Measure

Simulate, assess, track

Risks are analyzed and tracked with methods appropriate to the context.

A proposed rule evaluated against activity that already happened, and a live rule run without blocking while recording what it would have denied. Policy-activity views show which rules carry the load and which have never fired at all.

Evidence artifactSimulation results, observe-mode access records, rule-firing and coverage-gap reports.

Manage

Enforce, respond, document

Risks are prioritized, responded to and documented with traceable evidence.

Enforcement down to the individual column before the call proceeds, staged per server through observe, simulate and enforce, and an operator stop for a misbehaving actor that fires without any rule being authored.

Evidence artifactDecision record export, policy change history, replay of a past decision against current rules.

Boundaries

Where a runtime control is not the answer.

The framework is broader than any single control, and several of its concerns sit outside what governing tool calls can address.

  • Model performance, accuracy and validity measurementOwned by your evaluation practice. It checks whether the answer was good; we govern what the system was permitted to use to produce it.
  • Bias, fairness and representativeness testing of training dataOwned by your MLOps and data science teams. Upstream of anything a runtime control can observe.
  • Risk appetite, tolerance setting and workforce practice under GovernOwned by your risk function. We enforce the decisions that come out of it and record that they were enforced.
  • Third-party model provenance and supply-chain assuranceOwned by your vendor risk process, beyond the provenance a caller declares on the call itself.
  • Incident severity scoring and response workflowOwned by your detection and response tooling. Decision records are exportable so they can feed it.

Every line above is a reason we integrate rather than replace. We are glad to work alongside the tools already covering those functions — the framework is bigger than any one control, and a vendor claiming otherwise would not be much help to you.

Talk to us

Map this against your own estate.

The mapping is more useful with your systems in it — which functions you already cover, and which evidence you currently cannot produce.