NIST AI Risk Management Framework 1.0
NIST AI RMF readiness assessment
Move from AI-governance principles to evidence you can actually defend.
The AI RMF subcategory library (72) across the Govern, Map, Measure, Manage functions.
72 subcategory entries · versioned & change-controlled
Who it’s for
Teams governing AI systems who use the NIST AI Risk Management Framework to structure AI governance.
What readiness means for NIST AI RMF
For the NIST AI RMF, readiness means each applicable subcategory across Govern, Map, Measure and Manage has evidence appropriate to the AI system's risk.
How Netallion handles it
Your NIST AI RMF readiness journey
- 1
Set the AI risk context
Establish which AI systems are in scope and their risk context, so assessment across the four Functions — Govern, Map, Measure, Manage — reflects the actual systems, not a generic AI programme.
- 2
Map evidence to subcategories
Attach AI inventories, model documentation, evaluation results and monitoring records to the subcategory outcomes they support, with ownership and review dates.
- 3
Assess outcome sufficiency
Each subcategory is assessed for whether the evidence demonstrates the described outcome — a bias evaluation actually measured, an impact assessment completed — not merely that AI governance is discussed.
- 4
Surface blockers by function
Subcategories with thin evidence — documentation without measurement, mapping without management — become explicit blockers grouped by Function.
- 5
Review & finalise
An authorised assessor reviews the determinations and pins a readiness conclusion; the AI RMF is voluntary, so there is no certification for Netallion to issue.
The control library
What the NIST AI RMF library gives you
The AI RMF subcategory library (72) across the Govern, Map, Measure, Manage functions.
A curated, versioned catalogue of this framework’s 72 subcategory entries — with provenance — to collect, own, organise and track the currency of your evidence against.
From the field
Common NIST AI RMF blockers we find
Where evidence most often falls short — surfaced explicitly, not averaged away.
- Model documentation exists but there is no evidence of a measured bias evaluation, so a Measure outcome is asserted rather than demonstrated.
- AI systems are inventoried under Map but never carried through to Manage, so identified risks have no treatment record.
- Governance policy names AI accountability but no evidence links it to decisions about any specific system.
- Pre-deployment evaluation exists but there is no ongoing monitoring, so drift after release is invisible.
Evidence
The evidence you'll bring
You upload and own your evidence; Netallion organises it and tracks ownership and expiry. For this framework it typically spans:
Govern
- AI governance policy & accountability
- AI risk-management roles
- third-party/model-supply-chain governance
- AI incident & decommissioning processes
Map
- AI system inventory
- intended-use & context documentation
- impact assessments
- stakeholder & affected-party identification
Measure
- evaluation & test results
- bias & fairness measurements
- robustness & security testing
- performance metrics & thresholds
Manage
- risk-treatment decisions & prioritisation
- monitoring & feedback records
- incident-response for AI
- change and retirement management
Start now — free
Prepare your NIST AI RMF evidence
Assess your NIST AI RMF evidence with Netallion
There’s no self-serve kit for NIST AI RMF yet. On an assessed engagement, Netallion scopes the requirements, organises your evidence, and determines readiness with explicit blockers.
From evidence to a conclusion
How readiness is reached
The kit helps you prepare. Netallion organises the evidence, assesses whether it's sufficient, and reaches a traceable readiness conclusion.
- 1Scope
The applicable requirement set for your framework and scope.
- 2Applicable requirements
A fixed denominator — every in-scope requirement counts.
- 3Evidence
You attach and own evidence; ownership and expiry are tracked.
- 4Evidence assessment
The evidence is read against each requirement for sufficiency.
- 5Determination
A requirement-level verdict with byte-verified citations.
- 6Blocker
Negative findings surface as explicit blockers, not averages.
- 7Remediation
Track the fix; reassessment — not a checkbox — resolves it.
- 8Review (R0–R3)
Controlled human review with recorded provenance.
- 9Finalisation
A signed, scope-pinned readiness conclusion.
- 10Report / export
Readiness report, evidence index, SoA, audit ZIP + SHA-256.
- 11Lifecycle & reassessment
Evidence expires/changes → affected requirements reopen.
Schematic of the assurance workflow. Evidence collection and management are available today; the assessment, determination, review and finalisation stages are the System-B assurance engine.
What you get out
- Requirement-level readiness across all 72 AI RMF subcategories
- results grouped by the Govern, Map, Measure, Manage Functions
- explicit blocker list with reasons
- evidence index + audit ZIP with SHA-256 manifest
FAQ
NIST AI RMF readiness — common questions
Is there a NIST AI RMF certification?
No — the AI RMF is a voluntary risk-management framework with no certification programme. Netallion assesses your readiness against its subcategories (72 criteria).
How does this relate to the EU AI Act?
The AI RMF and EU AI Act cover overlapping AI-governance ground; organisations frequently assess both, and the two libraries are linked on the hub.
What AI-governance evidence is assessed?
AI system inventories, model documentation, impact assessments, evaluation results and monitoring records, among others.
Related
Cross-framework leverage
Evidence you assemble for one framework often supports another. Commonly paired with:
Readiness, not certification. Netallion provides evidence assurance and readiness assessment; it does not issue or guarantee any formal outcome. Where a framework has a formal certification, attestation, authorisation or conformity-assessment scheme, that outcome remains with the appropriately authorised third party or authority. NIST offers no AI RMF certification — it is a voluntary risk-management framework. Where the boundary sits.
See what your NIST AI RMF evidence proves
See how Netallion assesses whether your evidence is sufficient — with explicit blockers and a traceable readiness conclusion.