Skip to content
Sovrinty
All posts

AI Governance & Compliance

NIST AI Risk Management Framework for Regulated AI

By Sovrinty Team
Glowing shield and circuit motif above institutional pillars representing AI risk management

The NIST AI Risk Management Framework (AI RMF) is a voluntary, sector-agnostic framework from the U.S. National Institute of Standards and Technology that helps organizations identify, measure, and manage risk across the AI lifecycle. It organizes trustworthy-AI practices into four functions, Govern, Map, Measure, and Manage, so teams can make AI systems more accountable.

NIST AI RMF FUNCTIONWHAT IT ASKS OF YOUR TEAMWHAT PROOF LOOKS LIKE IN PRODUCTION
GovernSet policies, roles, and accountability for AI riskControls enforced in the system, not written in a PDF
MapIdentify context, data sources, and where risk livesEvery source cataloged, permissioned, and traceable
MeasureAssess performance, reliability, and biasConfidence tied to real evidence, drift detected
ManagePrioritize, respond to, and monitor risk over timeStale knowledge expires, answers stay current and cited

What is the NIST AI Risk Management Framework?

NIST released the AI RMF in 2023 and added a companion Generative AI Profile in 2024, giving organizations a common vocabulary for trustworthy AI. It is voluntary, but in regulated sectors it has become a de facto baseline: auditors cite it, procurement teams ask for it, and it maps cleanly onto binding regimes like the EU AI Act. The NIST AI RMF does not tell you which tools to buy. It tells you what good looks like, then leaves the enforcement to you.

Diagram of the four NIST AI RMF functions Govern, Map, Measure and Manage around a hub

The four core functions of the AI RMF

The framework groups its guidance into four functions that run continuously rather than once at launch.

Govern

Govern is the backbone. It sets the policies, roles, and accountability that make risk decisions repeatable instead of ad hoc. In practice, governance fails when it lives only in a policy document that no running system references.

Map

Map establishes context: which data feeds the system, who can see it, and where harm could occur. For an AI knowledge tool, this means cataloging every source and its permissions, so no answer can draw on data a user is not cleared to see.

Measure

Measure assesses performance, reliability, and bias with repeatable methods. The hard part is tying scores to real evidence rather than impressions, so a confidence number reflects the strength of the underlying sources.

Manage

Manage prioritizes and responds to risks over time, including the slow risk of knowledge going stale. A control that was accurate at launch becomes a liability once the underlying policy changes and nobody updates the answer.

Why the NIST AI risk management framework is hard to operationalize

Most teams can write an AI RMF-aligned policy in a week. The gap opens when that policy has to be enforced inside a live system that answers thousands of questions a day. Gartner forecasts that 60% of enterprise AI projects will be abandoned through 2026 for lack of AI-ready data, and unenforced governance is a direct contributor. A framework on paper cannot stop an AI from citing a retired SOP or surfacing a document the reader was never cleared to open.

The fix is to move the controls out of the policy binder and into the architecture, so the AI RMF functions are enforced by the system rather than by human diligence. That is the difference between governance you describe and governance you can prove.

Layered governed AI knowledge stack linking cited, timestamped sources to one verified answer

From framework to enforcement: governing the AI knowledge layer

Sovrinty is built on the principle that governance should live in the architecture, not a settings page. Each AI RMF function maps to a control the system enforces on every answer.

For Map and Govern, answers are drawn only from approved sources, and any sentence that cannot be traced to one is removed before the answer reaches the reader. Access is enforced with attribute-based access control at the AI layer, so sovereignty and zero-exfiltration are handled as table stakes rather than afterthoughts.

For Measure, confidence reflects the underlying semantic evidence rather than being inflated by ranking, which gives reviewers an honest signal instead of false reassurance. For Manage, knowledge that passes its review-by date expires and is pulled from circulation automatically, and every source is versioned and never overwritten, with content hashes that flag drift. The result is an answer a regulated team can defend: cited, current, and traceable to its source.

How the AI RMF connects to the EU AI Act and ISO 42001

The AI RMF is not the only game in town, and these regimes reinforce each other. The EU AI Act carries penalties of up to EUR 35 million or 7% of global turnover, and its documentation and risk-management duties align closely with the AI RMF's Map and Manage functions. ISO/IEC 42001 adds a certifiable management-system layer on top. A team that operationalizes the AI RMF well is already most of the way to both.

This matters most in sectors where an unprovable answer is a finding. Financial services teams working under model risk expectations, for example, need every AI output to carry its lineage.

Governance that only lives on paper is the risk the NIST AI RMF is trying to retire. See how Sovrinty enforces each of its functions on every answer: request a demo.

NIST AI RMFAI risk managementAI governanceregulated industriesAI compliancetrustworthy AI

FAQ

Common questions

What is the NIST AI Risk Management Framework?

It is a voluntary framework from NIST that helps organizations identify, measure, and manage risk across the AI lifecycle, organized into four functions: Govern, Map, Measure, and Manage.

Is the NIST AI Risk Management Framework mandatory?

No, the AI RMF is voluntary, but in regulated industries it has become a de facto baseline that auditors, procurement teams, and regulators reference, and it aligns closely with binding rules like the EU AI Act.

What are the four functions of the NIST AI RMF?

Govern, Map, Measure, and Manage. Govern sets policy and accountability, Map identifies context and data, Measure assesses performance and reliability, and Manage prioritizes and monitors risk over time.

How is the NIST AI RMF different from the EU AI Act?

The NIST AI RMF is voluntary guidance for managing AI risk, while the EU AI Act is binding law with penalties up to EUR 35 million or 7% of global turnover. Their risk and documentation practices overlap heavily.

How do you operationalize the NIST AI risk management framework?

Move its controls out of policy documents and into the system architecture, so approved-only sourcing, access control, evidence-based confidence, and automatic expiry are enforced on every answer rather than left to human diligence.

Answers your business can prove.

See it on your content, in your environment.