Compliance
NIST AI RMF
The govern, map, measure, manage cycle. Traces, evaluations, and reviews become the measure and manage record.
At a glance
Who this covers, and who enforces it
Any organization designing, developing, deploying, or using AI systems. Voluntary, built around four functions: Govern, Map, Measure, Manage.
- Instrument
- AI RMF 1.0 — voluntary framework
- Issued by
- NIST, US Department of Commerce
- Timeline
- 1.0 Jan 2023; Generative AI Profile Jul 2024
- Penalty
- None — voluntary, but increasingly required in procurement
- Structure
- Govern, Map, Measure, Manage
Requirements
What it asks for
- 1Govern — policy, roles, and accountability for AI risk
- 2Map — context, intended use, and risk identification
- 3Measure — testing, metrics, and tracked performance
- 4Manage — ongoing risk response and resource allocation
Evidence mapping
What PRISM records against each requirement
Every plan records this evidence as your AI runs. Compliance Reports, which turn it into a reviewed, framework-mapped report, are delivered as a service, on request.
- Govern
- Projects & Team plus the Audit Log show who owns and approved each system.
- Map
- Model Inventory records intended use and operating context per system.
- Measure
- Evaluators and Scores & Alerts produce the quantitative record the Measure function asks for.
- Manage
- AI Remediation tracks a finding through root cause, fix, and validation.
Primary source
Read the actual text
Everything on this page is drawn from NIST — AI Risk Management Framework. The capture is live, not a paraphrase — go straight to the source and check us.

Evidence, not certification
This page describes NIST AI RMF’s publicly available requirements and how PRISM’s evidence layer supports them. It is not legal advice, and it does not constitute certification, regulatory approval, or a guarantee of compliance. NIST AI RMF compliance remains your organization’s responsibility, in consultation with qualified counsel.
Keep reading
- All frameworksThe full evidence-layer overview and all twelve frameworks.
- ISO/IEC 42001The auditable AI management system standard. Operational evidence for the clauses an internal auditor asks to see.
- SR 11-7 model riskModel risk management discipline applied to AI and LLMs. Monitoring, validation, and change history in one place.
Ask us about your framework
Tell us how NIST AI RMF applies to your systems and we'll show you the evidence path.