← Article 50 readiness

NIST AI RMF evidence map

NIST describes the AI RMF as voluntary. The useful operating question is not “did we adopt a framework?” but “what evidence shows the risk practice exists and is owned?”

Practice areaPractical evidence to retain
GovernAI inventory, accountable owner, policy, approval authority, exception log, review cadence.
MapUse-case purpose, affected people, data sources, vendor dependencies, expected benefit, foreseeable harms.
MeasureTest plan, accuracy/quality measures, security/privacy tests, failure cases, monitoring thresholds.
ManageRisk treatment, residual-risk decision, launch gate, incident response, stop criteria, next review date.
GenAI-specificPrompt/data exposure review, hallucination controls, content provenance, misuse testing, human oversight, vendor/model-change tracking.

Use the control workbook

Reference: NIST AI RMF 1.0 and NIST AI 600-1 Generative AI Profile. These are risk-management resources, not legal compliance certifications.