GCA · COMPLIANCE

    NIST AI RMF

    Govern / Map / Measure / Manage — 12 controls, 8 machine-assessable.

    NIST AI Risk Management Framework

    The NIST AI RMF (1.0) organizes AI risk management around four functions: Govern, Map, Measure, Manage. Gadriel Code contributes evidence primarily to Measure and Manage, plus the technical subcategories of Govern.

    Related: Compliance overview · EU AI Act.


    At a glance

    PropertyValue
    Slugnist-ai-rmf
    Aliasesnist, ai-rmf
    Controls12
    Manual-only4
    Machine-assessable8
    Direct mapping keynist_ai_rmf

    Generating the report

    gadriel code report --compliance nist-ai-rmf

    Outputs: .security/compliance/nist-ai-rmf.{md,typ,pdf}.


    What Gadriel evaluates

    GVL rules carry mappings like nist_ai_rmf: GOVERN-1.1, MEASURE-2.7, MANAGE-4.1. The report groups results by function and subcategory.

    • Govern (partial) — technical policy signals (secrets management, access boundaries, logging).
    • Map (mostly manual) — context, intended use, and stakeholder framing are manual by design.
    • Measure (strong) — robustness, bias, prompt-injection, and cybersecurity findings feed here directly.
    • Manage (strong) — remediation actions, incident-handling artifacts, and guardrail configuration.
    IMPORTANT

    Four subcategories are manual-only and always render as NOT ASSESSABLE. They are neutral in the rollup — a framework whose only non-PASS controls are manual will still roll up to PASS.


    Pairing with other AI-governance reports

    Run alongside the EU AI Act and ISO/IEC 42001 reports to get complementary technical, regulatory, and management-system views.