All frameworks

NIST AI Risk Management Framework 1.0

NIST AI RMF readiness assessment

Move from AI-governance principles to evidence you can actually defend.

The AI RMF subcategory library (72) across the Govern, Map, Measure, Manage functions.

72 subcategory entries · versioned & change-controlled

Who it’s for

Teams governing AI systems who use the NIST AI Risk Management Framework to structure AI governance.

What readiness means for NIST AI RMF

For the NIST AI RMF, readiness means each applicable subcategory across Govern, Map, Measure and Manage has evidence appropriate to the AI system's risk.

How Netallion handles it

Your NIST AI RMF readiness journey

  1. 1

    Set the AI risk context

    Establish which AI systems are in scope and their risk context, so assessment across the four Functions — Govern, Map, Measure, Manage — reflects the actual systems, not a generic AI programme.

  2. 2

    Map evidence to subcategories

    Attach AI inventories, model documentation, evaluation results and monitoring records to the subcategory outcomes they support, with ownership and review dates.

  3. 3

    Assess outcome sufficiency

    Each subcategory is assessed for whether the evidence demonstrates the described outcome — a bias evaluation actually measured, an impact assessment completed — not merely that AI governance is discussed.

  4. 4

    Surface blockers by function

    Subcategories with thin evidence — documentation without measurement, mapping without management — become explicit blockers grouped by Function.

  5. 5

    Review & finalise

    An authorised assessor reviews the determinations and pins a readiness conclusion; the AI RMF is voluntary, so there is no certification for Netallion to issue.

The control library

What the NIST AI RMF library gives you

The AI RMF subcategory library (72) across the Govern, Map, Measure, Manage functions.

A curated, versioned catalogue of this framework’s 72 subcategory entries — with provenance — to collect, own, organise and track the currency of your evidence against.

From the field

Common NIST AI RMF blockers we find

Where evidence most often falls short — surfaced explicitly, not averaged away.

  • Model documentation exists but there is no evidence of a measured bias evaluation, so a Measure outcome is asserted rather than demonstrated.
  • AI systems are inventoried under Map but never carried through to Manage, so identified risks have no treatment record.
  • Governance policy names AI accountability but no evidence links it to decisions about any specific system.
  • Pre-deployment evaluation exists but there is no ongoing monitoring, so drift after release is invisible.

Evidence

The evidence you'll bring

You upload and own your evidence; Netallion organises it and tracks ownership and expiry. For this framework it typically spans:

Govern

  • AI governance policy & accountability
  • AI risk-management roles
  • third-party/model-supply-chain governance
  • AI incident & decommissioning processes

Map

  • AI system inventory
  • intended-use & context documentation
  • impact assessments
  • stakeholder & affected-party identification

Measure

  • evaluation & test results
  • bias & fairness measurements
  • robustness & security testing
  • performance metrics & thresholds

Manage

  • risk-treatment decisions & prioritisation
  • monitoring & feedback records
  • incident-response for AI
  • change and retirement management

Start now — free

Prepare your NIST AI RMF evidence

Assess your NIST AI RMF evidence with Netallion

There’s no self-serve kit for NIST AI RMF yet. On an assessed engagement, Netallion scopes the requirements, organises your evidence, and determines readiness with explicit blockers.

From evidence to a conclusion

How readiness is reached

The kit helps you prepare. Netallion organises the evidence, assesses whether it's sufficient, and reaches a traceable readiness conclusion.

  1. 1Scope

    The applicable requirement set for your framework and scope.

  2. 2Applicable requirements

    A fixed denominator — every in-scope requirement counts.

  3. 3Evidence

    You attach and own evidence; ownership and expiry are tracked.

  4. 4Evidence assessment

    The evidence is read against each requirement for sufficiency.

  5. 5Determination

    A requirement-level verdict with byte-verified citations.

  6. 6Blocker

    Negative findings surface as explicit blockers, not averages.

  7. 7Remediation

    Track the fix; reassessment — not a checkbox — resolves it.

  8. 8Review (R0–R3)

    Controlled human review with recorded provenance.

  9. 9Finalisation

    A signed, scope-pinned readiness conclusion.

  10. 10Report / export

    Readiness report, evidence index, SoA, audit ZIP + SHA-256.

  11. 11Lifecycle & reassessment

    Evidence expires/changes → affected requirements reopen.

Schematic of the assurance workflow. Evidence collection and management are available today; the assessment, determination, review and finalisation stages are the System-B assurance engine.

What you get out

  • Requirement-level readiness across all 72 AI RMF subcategories
  • results grouped by the Govern, Map, Measure, Manage Functions
  • explicit blocker list with reasons
  • evidence index + audit ZIP with SHA-256 manifest

FAQ

NIST AI RMF readiness — common questions

Is there a NIST AI RMF certification?

No — the AI RMF is a voluntary risk-management framework with no certification programme. Netallion assesses your readiness against its subcategories (72 criteria).

How does this relate to the EU AI Act?

The AI RMF and EU AI Act cover overlapping AI-governance ground; organisations frequently assess both, and the two libraries are linked on the hub.

What AI-governance evidence is assessed?

AI system inventories, model documentation, impact assessments, evaluation results and monitoring records, among others.

Related

Cross-framework leverage

Evidence you assemble for one framework often supports another. Commonly paired with:

Readiness, not certification. Netallion provides evidence assurance and readiness assessment; it does not issue or guarantee any formal outcome. Where a framework has a formal certification, attestation, authorisation or conformity-assessment scheme, that outcome remains with the appropriately authorised third party or authority. NIST offers no AI RMF certification — it is a voluntary risk-management framework. Where the boundary sits.

See what your NIST AI RMF evidence proves

See how Netallion assesses whether your evidence is sufficient — with explicit blockers and a traceable readiness conclusion.