NIST AI RMF 1.0
The NIST AI RMF is voluntary. The catalog maps six subcategories to the records, monitoring and oversight statements; statements can serve as evidence toward a subcategory’s outcome, they do not “satisfy” it.
| Registry id | nist-ai-rmf |
| Kind | voluntary |
| Jurisdiction | US |
| Instrument | NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0) |
| Catalog versions | 2026-09 from 2023-01-26 (current) — AI RMF 1.0 (January 2023) |
| Verified against instrument | no — see the banner above |
| Incident deadline rules | none |
| Retention floors | none at classification level |
| Obligations | 6 |
Obligations and their evidence
Section titled “Obligations and their evidence”Each obligation lists the statements it is shown against. The basis is one of recomputed, judged, indicator or declared (what the bases mean); the resolver is from the shared library.
GOVERN 1.1 — legal and regulatory requirements
Section titled “GOVERN 1.1 — legal and regulatory requirements”govern-1-1 · GOVERN 1.1 · applies from 2023-01-26
Can serve as evidence toward understanding and managing legal and regulatory requirements involving AI: a sealed, witnessed record of every governed action. Written from public summaries of the instrument; check the published text before relying on this. Applies to every system for which the framework is active.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| Every governed action produced a sealed record, including refusals. | recomputed | records.every_verdict_sealed |
Integrity is not completeness: covers actions routed through the gateway only; records sealed late by backfill are reported separately. |
| The tenant log’s tree heads covering the window were countersigned by an independent witness. | recomputed | records.witnessed |
A receipt shows inclusion at a tree size, not a witness-observed time; a same-operator witness is self-attested. |
GOVERN 6.1 — third-party risk policies
Section titled “GOVERN 6.1 — third-party risk policies”govern-6-1 · GOVERN 6.1 · applies from 2023-01-26
Can serve as evidence toward policies for AI risks from third-party entities: the operator role and vendor-operated systems are declared. Written from public summaries of the instrument; check the published text before relying on this. Applies to every system for which the framework is active.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| The organisation’s role for this system (builder, operator, vendor) is declared. | declared | profile.field_declared {"path": "core.operator_role"} |
Third-party policies are organisational; they are not evaluated. |
| Grants, capability filters and argument policies are bound and sealed. | declared | authz.least_privilege_declared |
Whether the grants are the least the system needs is the operator’s judgement, not evaluated. |
MEASURE 2.6 — safety evaluated regularly
Section titled “MEASURE 2.6 — safety evaluated regularly”measure-2-6 · MEASURE 2.6 · applies from 2023-01-26
Can serve as evidence toward regular safety evaluation and the ability to fail safely: daily health and the stop controls. Written from public summaries of the instrument; check the published text before relying on this. Applies to every system for which the framework is active.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| Liveness, drift and health were evaluated every day. | recomputed | monitoring.daily_health |
Shows the monitoring ran; what a human did with its findings is shown in the inbox trail. |
| Suspension and run-abort controls are available and every use of them was sealed. | recomputed | monitoring.suspend_available |
Shows the stop controls and their use; not whether they were used when they should have been. |
MEASURE 2.8 — transparency and accountability
Section titled “MEASURE 2.8 — transparency and accountability”measure-2-8 · MEASURE 2.8 · applies from 2023-01-26
Can serve as evidence toward examining transparency and accountability risks: closed record chains and an intact audit trail. Written from public summaries of the instrument; check the published text before relying on this. Applies to every system for which the framework is active.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| Record chains are closed and epoch boundaries match the contract history. | recomputed | records.chain_complete |
Checks the chains the gateway opened; actions that never reached the gateway cannot be counted. |
| The audit row chain over the window recomputes intact, or every gap is a declared prune. | recomputed | records.integrity_verified |
Detects alteration after the fact; it cannot show that a row was accurate when written. |
MANAGE 1.3 — responses to high risks
Section titled “MANAGE 1.3 — responses to high risks”manage-1-3 · MANAGE 1.3 · applies from 2023-01-26
Can serve as evidence toward planned and documented responses to high-priority risks: human override and the record of its use. Written from public summaries of the instrument; check the published text before relying on this. Applies to every system for which the framework is active.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| A human can override or stop the system. | recomputed | oversight.override_available |
Shows the controls exist and are assigned, not that the assigned people are competent. |
| Human approval requests were decided by humans (requested, decided, lapsed). | recomputed | oversight.exercised |
Records the fact of human disposition, not its quality. |
MANAGE 4.1 — post-deployment monitoring
Section titled “MANAGE 4.1 — post-deployment monitoring”manage-4-1 · MANAGE 4.1 · applies from 2023-01-26
Can serve as evidence toward post-deployment monitoring plans, including incident response: daily monitoring and the incident register. Written from public summaries of the instrument; check the published text before relying on this. Applies to every system for which the framework is active.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| Liveness, drift and health were evaluated every day. | recomputed | monitoring.daily_health |
Shows the monitoring ran; what a human did with its findings is shown in the inbox trail. |
| An incident register is kept and no open incident is past its deadline. | recomputed | incidents.register_exists |
Shows incidents someone entered; an incident nobody recorded cannot be counted. |
Related
Section titled “Related”- Framework registry & evidence bases — how catalogs, resolvers and the version in force work
- The Compliance console — the Obligations matrix for this framework
- Incidents, reports & documentation

