NIST AI Risk Management Framework
The NIST AI RMF (1.0) organizes AI risk management around four functions: Govern, Map, Measure, Manage. Gadriel Code contributes evidence primarily to Measure and Manage, plus the technical subcategories of Govern.
Related: Compliance overview · EU AI Act.
At a glance
| Property | Value |
|---|---|
| Slug | nist-ai-rmf |
| Aliases | nist, ai-rmf |
| Controls | 12 |
| Manual-only | 4 |
| Machine-assessable | 8 |
| Direct mapping key | nist_ai_rmf |
Generating the report
bashgadriel code report --compliance nist-ai-rmf
Outputs: .security/compliance/nist-ai-rmf.{md,typ,pdf}.
What Gadriel evaluates
GVL rules carry mappings like nist_ai_rmf: GOVERN-1.1, MEASURE-2.7,
MANAGE-4.1. The report groups results by function and subcategory.
- Govern (partial) — technical policy signals (secrets management, access boundaries, logging).
- Map (mostly manual) — context, intended use, and stakeholder framing are manual by design.
- Measure (strong) — robustness, bias, prompt-injection, and cybersecurity findings feed here directly.
- Manage (strong) — remediation actions, incident-handling artifacts, and guardrail configuration.
Four subcategories are manual-only and always render as NOT ASSESSABLE. They are neutral in the rollup — a framework whose only non-PASS controls are manual will still roll up to PASS.
Pairing with other AI-governance reports
Run alongside the EU AI Act and ISO/IEC 42001 reports to get complementary technical, regulatory, and management-system views.
