TIER 2 · RISK MANAGEMENT FRAMEWORK

NIST AI RMF to AITBM Mapping

Maps GOVERN, MAP, MEASURE, and MANAGE activities to AITBM assessment evidence and decision outputs.

How to use this crosswalk

External requirements, controls, threats, and practices identify evidence to collect or tests to run. Only measured evidence from the assessed deployment determines AITBM rubric placements, IVP, ORP, ACI, MVT findings, and ERS.

Mapping content last verified 2026-08-13. No endorsement by the external framework owner is implied.

NIST AI RMF

Risk management framework

NIST Artificial Intelligence Risk Management Framework (AI RMF 1.0) · National Institute of Standards and Technology (NIST), U.S. Department of Commerce

The NIST AI RMF is a voluntary governance framework that names seven trustworthiness characteristics and a MEASURE function without prescribing one universal scoring method. AITBM is one possible technical measurement companion, using 23 rubrics and IVP/ORP/ACI to produce a system-specific ERS.

RMF Trustworthiness Characteristic Primary AITBM Sub-Metrics Evidence Use / Notes
Valid and ReliableRo-2Ro-3Tr-2Foundational; affects all axes
SafeCn-1Cn-3Cn-2Ro-3High for agentic/user-facing
Secure and ResilientRo-1Ro-4Cn-2Cn-4Cn-5High; spans Robustness + Containment
Accountable and TransparentTr-3Tr-4Moderate; also feeds ORP Rf
Explainable and InterpretableTr-1Tr-2Moderate
Privacy-EnhancedPr-1Pr-3Pr-2Pr-4High for personal-data systems
Fair - with Harmful Bias ManagedFa-1Fa-3Fa-2Fa-4Moderate; full Fairness axis

Key findings

  • MEASURE is the principal integration interface in this crosswalk. The AI RMF does not mandate a score, thresholds, or aggregation method; AITBM offers one compatible implementation by mapping GOVERN to tier/pathway and Tr-3/ORP Rf, MAP to architecture and ORP As/Cp, MEASURE to IVP and ACI Ec, and MANAGE to ERS sensitivity and ACI decay.
  • AI RMF 1.0 does not specifically address agent identity/impersonation; AITBM's Cn-5 (Agent Identity Integrity) covers this frontier gap and should be scored explicitly for Agentic-MCP systems even when the RMF assessment is silent.
  • AITBM's deterministic rubrics narrow inter-assessor variance and make MEASURE outputs comparable across teams/systems/time (it narrows variance, it does not eliminate it), and its ACI temporal decay supplies the decay model the RMF's continuous-monitoring expectation lacks.
  • The NIST AI RMF worked example is retained on its dated 21-sub-metric, pre-GDCP basis. A current assessment must derive Cn-6, Cp, ACI, and ERS under the current specification.

NIST AI RMF reference →