Home/ Frameworks/ NIST AI RMF
Framework · NIST AI RMF

NIST AI RMF: the risk-based framework for trustworthy artificial intelligence.

The NIST Artificial Intelligence Risk Management Framework (AI RMF 1.0), published in January 2023, provides a structured, adaptable approach to managing risks across the full AI lifecycle. Built around four core functions—GOVERN, MAP, MEASURE, MANAGE—it applies to any sector and complements mandatory frameworks such as ISO 42001 and the EU AI Act. Sentrix operationalizes all four AI RMF functions continuously so your AI risk program keeps pace with every new model or system you deploy.

4
Core functions: GOVERN, MAP, MEASURE, MANAGE—interconnected, iterative, and applicable throughout the AI lifecycle
Jan. 2023
Published by NIST—Sentrix AI RMF mappings are aligned to AI RMF 1.0 and updated as NIST releases new playbooks
ISO 42001
Cross-mapped—organizations pursuing both satisfy them from one evidence set; GOVERN aligns to ISO 42001 clauses 5–6
7
Trustworthy AI characteristics tracked: valid, reliable, safe, secure, explainable, privacy-enhanced, fair & accountable
The four AI RMF core functions

GOVERN. MAP. MEASURE. MANAGE.

The AI RMF is outcomes-based and non-prescriptive—it describes what good AI risk management looks like rather than mandating specific controls, making it adaptable to any organization size, sector, or AI maturity level. GOVERN is the foundational function that enables the other three: it establishes culture, strategy, and accountability so that MAP, MEASURE, and MANAGE can operate consistently at scale.

  • GOVERN — Cultivate AI risk culture: policies, accountability, oversight, and supply chain risk governance across the AI lifecycle
  • MAP — Establish context: categorize AI systems, clarify capabilities, identify risks and characterize potential impacts
  • MEASURE — Assess and track: choose metrics, evaluate trustworthiness characteristics, test for bias and fairness, monitor risk over time
  • MANAGE — Prioritize and treat: define risk treatments, plan responses, handle residual risk, monitor third-party AI elements
  • Trustworthy AI: valid & reliable, safe, secure & resilient, explainable & interpretable, privacy-enhanced, fair
  • AI lifecycle coverage: design, development, deployment, operation, decommissioning—all phases tracked in Sentrix

NIST AI RMF · Function coverage

CURRENT PROFILE
GOVERN87%
MAP92%
MEASURE71%
MANAGE84%
Full NIST AI RMF capabilities

From AI inventory to board-ready risk posture—across every system you deploy.

AI system inventory (MAP)

Sentrix automatically discovers and inventories AI systems across your environment—cloud ML platforms, third-party AI APIs, internal models—and classifies them by risk level per the AI RMF MAP function.

Bias & fairness testing (MEASURE)

The MEASURE function requires continuous evaluation of AI trustworthiness characteristics. Sentrix integrates with your model evaluation pipelines to collect bias, fairness, and robustness metrics as ongoing evidence.

AI risk register (MANAGE)

A dedicated AI risk register tracks risk treatments, residual risks, and response plans per AI system. Priority scoring aligns to AI RMF MANAGE categories so teams know what to address first.

ISO 42001 crosswalk

NIST AI RMF and ISO 42001 are complementary. Sentrix maps AI RMF categories to ISO 42001 clauses so organizations pursuing certification under both frameworks satisfy requirements from a single evidence set.

Third-party AI risk (GOVERN)

GOVERN requires supply chain AI risk oversight. Sentrix onboards your AI vendors—LLM providers, AI SaaS tools, model APIs—into your third-party risk program with AI-specific questionnaires and continuous scoring.

Board-ready AI risk reporting

One click generates an AI risk posture summary by RMF function, with trustworthy AI characteristic scores, open risk items, and treatment progress—ready for CISO, board, and regulatory reporting.

See your AI risk posture mapped to NIST AI RMF live.

30-minute demo. We inventory your AI systems live and show you your GOVERN, MAP, MEASURE, MANAGE coverage before the call ends.