NIST AI RMF evidence map
NIST describes the AI RMF as voluntary. The useful operating question is not “did we adopt a framework?” but “what evidence shows the risk practice exists and is owned?”
| Practice area | Practical evidence to retain |
|---|---|
| Govern | AI inventory, accountable owner, policy, approval authority, exception log, review cadence. |
| Map | Use-case purpose, affected people, data sources, vendor dependencies, expected benefit, foreseeable harms. |
| Measure | Test plan, accuracy/quality measures, security/privacy tests, failure cases, monitoring thresholds. |
| Manage | Risk treatment, residual-risk decision, launch gate, incident response, stop criteria, next review date. |
| GenAI-specific | Prompt/data exposure review, hallucination controls, content provenance, misuse testing, human oversight, vendor/model-change tracking. |
Reference: NIST AI RMF 1.0 and NIST AI 600-1 Generative AI Profile. These are risk-management resources, not legal compliance certifications.