Other frameworks
NIST AI RMF: Govern, Map, Measure, Manage
The NIST AI Risk Management Framework is a voluntary US framework, widely referenced even outside the US as a common vocabulary for AI risk. It organises the work into four functions (Govern, Map, Measure and Manage) comprising 72 real subcategories in total (there is no fifth 'Track' function; that was an error in an earlier version of this guide). EuroCompliant covers all 72.
Transcript
The NIST AI Risk Management Framework organises AI governance into four functions: Govern, Map, Measure, and Manage. It is voluntary, but it is the framework most enterprises adopt first because it is practical.
Govern is accountability: roles and responsibilities. Map is context: a system's intended use. Measure is testing and evaluation. Manage is deciding what to do about the risk you found.
Open Settings and go to Compliance Frameworks. Like every voluntary framework here, NIST AI RMF is switched on with a single toggle.
Enabling the framework adds all 72 real subcategories to your list at once, across the four functions. Each one is drawn from NIST's own Playbook, not a paraphrased summary.
My Obligations now shows the NIST subcategories alongside the AI Act and GDPR. Filter by framework to focus on what NIST expects, or work them together where obligations overlap.
Open a registered system's checklist. Each NIST subcategory carries its own action guidance drawn from the Playbook text, not just a clause title, so you know what evidence to gather.
Compliance posture updates across the board: the dashboard now scores you against NIST as well as the EU frameworks, so your voluntary controls are visible in the same place as your statutory ones.
Why this is required
Govern is about accountability: legal and regulatory requirements, integrating risk management into organisational practice, and clear roles and responsibilities (19 subcategories). Map is about context: understanding a system's intended purpose and its potential impact on individuals and groups (18 subcategories). Measure is about evidence: methods for assessing risk, tracking performance and reliability, and prioritising what to fix (22 subcategories). Manage is about response: planning, implementing risk-response practices, and monitoring after deployment (13 subcategories).
NIST AI RMF doesn't set legal obligations the way the EU AI Act does. Its value is as a shared structure: a way to organise AI governance work that a US customer, insurer or auditor will recognise, even where no law requires it.
What EuroCompliant does
Enabling NIST AI RMF adds all 72 real subcategories across Govern, Map, Measure and Manage to your Obligations page, each with its own action guidance drawn from NIST's own Playbook text, not a bare restatement of the subcategory title. Ten subcategories are automatically evidenced from platform data: systems inventory (Govern 1.6), roles and responsibilities (Govern 2.1), incident-identification practices (Govern 4.3), impact assessment (Map 5.1), production monitoring (Measure 2.4), security/resilience review (Measure 2.7), privacy risk (Measure 2.10), ongoing monitoring data (Measure 4.3), post-deployment monitoring (Manage 4.1), and incident tracking (Manage 4.3). The remaining 62 are honest manual checklist items with a specific action to complete.
Four document types exist in the platform's document engine for this framework, each built from your registered AI systems: an AI Risk Assessment Report (Govern), a Governance Framework, an Accountability Framework (Measure), and an Impact Assessment (Map).
Walking through it
Enable NIST AI RMF
Adds all 72 real Govern/Map/Measure/Manage subcategories to your Obligations page.
Open /settings/profile?tab=frameworks →Work through function by function
Govern first (accountability and roles), then Map (purpose and impact), then Measure (evidence), then Manage (response). The order mirrors how the functions build on each other.
Open /obligations →Lean on your system inventory for Map and Measure
A complete, accurate AI Systems record does most of the work the Map function asks for.
Open /systems →The law
Accountability structures
Roles and responsibilities and lines of communication related to mapping, measuring, and managing AI risks are documented and clear to individuals and teams throughout the organization.
Context and purpose
Intended purpose, potentially beneficial uses, context-specific laws, norms and expectations, and prospective settings in which the AI system will be deployed are understood and documented.
Performance monitoring
The functionality and behavior of the AI system and its components are monitored when in production.
Post-deployment monitoring
Post-deployment AI system monitoring plans are implemented, including mechanisms for capturing input from users, appeal and override, decommissioning, incident response, recovery, and change management.
Frequently asked
Do we need this if we already track the EU AI Act?
Only if you have a reason to: a US customer's due-diligence questionnaire, an insurer's requirements, or your own governance preference. It's not a legal requirement in the way the AI Act or GDPR are.
Is this the real 72-subcategory structure, or a simplified version?
The real structure: all 72 subcategories across the framework's actual four functions (Govern, Map, Measure, Manage), sourced from the official NIST AI RMF Playbook. An earlier version of this platform modelled only 13 function-level placeholders and an invented fifth 'Track' function that doesn't exist in the real framework; that has been corrected.
Related guides
ISO 42001: AI management systems
The AI-specific counterpart to ISO 27001: how EuroCompliant currently supports it, and what's still coming.
Risk classification
The Article 6 assessment that decides which obligations a system carries, and why the reasoning matters as much as the result.
Post-market monitoring
The Article 72 duty to actively watch a high-risk system for its whole life, and why AI systems degrade without anyone changing the code.
Try it on your own systems
Everything in this guide runs in the live product. Start a free trial and follow along with your own data.
Start free trial