Skip to content

NIST AI RMF 1.0

The NIST AI RMF is voluntary. The catalog maps six subcategories to the records, monitoring and oversight statements; statements can serve as evidence toward a subcategory’s outcome, they do not “satisfy” it.

Registry id nist-ai-rmf
Kind voluntary
Jurisdiction US
Instrument NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0)
Catalog versions 2026-09 from 2023-01-26 (current) — AI RMF 1.0 (January 2023)
Verified against instrument no — see the banner above
Incident deadline rules none
Retention floors none at classification level
Obligations 6

Each obligation lists the statements it is shown against. The basis is one of recomputed, judged, indicator or declared (what the bases mean); the resolver is from the shared library.

Section titled “GOVERN 1.1 — legal and regulatory requirements”

govern-1-1 · GOVERN 1.1 · applies from 2023-01-26

Can serve as evidence toward understanding and managing legal and regulatory requirements involving AI: a sealed, witnessed record of every governed action. Written from public summaries of the instrument; check the published text before relying on this. Applies to every system for which the framework is active.

Statement Basis Resolver Does not show
Every governed action produced a sealed record, including refusals. recomputed records.every_verdict_sealed Integrity is not completeness: covers actions routed through the gateway only; records sealed late by backfill are reported separately.
The tenant log’s tree heads covering the window were countersigned by an independent witness. recomputed records.witnessed A receipt shows inclusion at a tree size, not a witness-observed time; a same-operator witness is self-attested.

govern-6-1 · GOVERN 6.1 · applies from 2023-01-26

Can serve as evidence toward policies for AI risks from third-party entities: the operator role and vendor-operated systems are declared. Written from public summaries of the instrument; check the published text before relying on this. Applies to every system for which the framework is active.

Statement Basis Resolver Does not show
The organisation’s role for this system (builder, operator, vendor) is declared. declared profile.field_declared {"path": "core.operator_role"} Third-party policies are organisational; they are not evaluated.
Grants, capability filters and argument policies are bound and sealed. declared authz.least_privilege_declared Whether the grants are the least the system needs is the operator’s judgement, not evaluated.

MEASURE 2.6 — safety evaluated regularly

Section titled “MEASURE 2.6 — safety evaluated regularly”

measure-2-6 · MEASURE 2.6 · applies from 2023-01-26

Can serve as evidence toward regular safety evaluation and the ability to fail safely: daily health and the stop controls. Written from public summaries of the instrument; check the published text before relying on this. Applies to every system for which the framework is active.

Statement Basis Resolver Does not show
Liveness, drift and health were evaluated every day. recomputed monitoring.daily_health Shows the monitoring ran; what a human did with its findings is shown in the inbox trail.
Suspension and run-abort controls are available and every use of them was sealed. recomputed monitoring.suspend_available Shows the stop controls and their use; not whether they were used when they should have been.

MEASURE 2.8 — transparency and accountability

Section titled “MEASURE 2.8 — transparency and accountability”

measure-2-8 · MEASURE 2.8 · applies from 2023-01-26

Can serve as evidence toward examining transparency and accountability risks: closed record chains and an intact audit trail. Written from public summaries of the instrument; check the published text before relying on this. Applies to every system for which the framework is active.

Statement Basis Resolver Does not show
Record chains are closed and epoch boundaries match the contract history. recomputed records.chain_complete Checks the chains the gateway opened; actions that never reached the gateway cannot be counted.
The audit row chain over the window recomputes intact, or every gap is a declared prune. recomputed records.integrity_verified Detects alteration after the fact; it cannot show that a row was accurate when written.

manage-1-3 · MANAGE 1.3 · applies from 2023-01-26

Can serve as evidence toward planned and documented responses to high-priority risks: human override and the record of its use. Written from public summaries of the instrument; check the published text before relying on this. Applies to every system for which the framework is active.

Statement Basis Resolver Does not show
A human can override or stop the system. recomputed oversight.override_available Shows the controls exist and are assigned, not that the assigned people are competent.
Human approval requests were decided by humans (requested, decided, lapsed). recomputed oversight.exercised Records the fact of human disposition, not its quality.

manage-4-1 · MANAGE 4.1 · applies from 2023-01-26

Can serve as evidence toward post-deployment monitoring plans, including incident response: daily monitoring and the incident register. Written from public summaries of the instrument; check the published text before relying on this. Applies to every system for which the framework is active.

Statement Basis Resolver Does not show
Liveness, drift and health were evaluated every day. recomputed monitoring.daily_health Shows the monitoring ran; what a human did with its findings is shown in the inbox trail.
An incident register is kept and no open incident is past its deadline. recomputed incidents.register_exists Shows incidents someone entered; an incident nobody recorded cannot be counted.