New signups are temporarily closed.Existing customers can still sign in. Contact us to be notified when we reopen.
Skip to main content
Documentation

Other frameworks

NIST AI RMF: Govern, Map, Measure, Manage

The NIST AI Risk Management Framework is a voluntary US framework, widely referenced even outside the US as a common vocabulary for AI risk. It organises the work into four functions (Govern, Map, Measure and Manage) comprising 72 real subcategories in total (there is no fifth 'Track' function; that was an error in an earlier version of this guide). EuroCompliant covers all 72.

Transcript

The NIST AI Risk Management Framework organises AI governance into four functions: Govern, Map, Measure, and Manage. It is voluntary, but it is the framework most enterprises adopt first because it is practical.

Govern is accountability: roles and responsibilities. Map is context: a system's intended use. Measure is testing and evaluation. Manage is deciding what to do about the risk you found.

Open Settings and go to Compliance Frameworks. Like every voluntary framework here, NIST AI RMF is switched on with a single toggle.

Enabling the framework adds all 72 real subcategories to your list at once, across the four functions. Each one is drawn from NIST's own Playbook, not a paraphrased summary.

My Obligations now shows the NIST subcategories alongside the AI Act and GDPR. Filter by framework to focus on what NIST expects, or work them together where obligations overlap.

Open a registered system's checklist. Each NIST subcategory carries its own action guidance drawn from the Playbook text, not just a clause title, so you know what evidence to gather.

Compliance posture updates across the board: the dashboard now scores you against NIST as well as the EU frameworks, so your voluntary controls are visible in the same place as your statutory ones.

Why this is required

Govern is about accountability: legal and regulatory requirements, integrating risk management into organisational practice, and clear roles and responsibilities (19 subcategories). Map is about context: understanding a system's intended purpose and its potential impact on individuals and groups (18 subcategories). Measure is about evidence: methods for assessing risk, tracking performance and reliability, and prioritising what to fix (22 subcategories). Manage is about response: planning, implementing risk-response practices, and monitoring after deployment (13 subcategories).

NIST AI RMF doesn't set legal obligations the way the EU AI Act does. Its value is as a shared structure: a way to organise AI governance work that a US customer, insurer or auditor will recognise, even where no law requires it.

What EuroCompliant does

Enabling NIST AI RMF adds all 72 real subcategories across Govern, Map, Measure and Manage to your Obligations page, each with its own action guidance drawn from NIST's own Playbook text, not a bare restatement of the subcategory title. Ten subcategories are automatically evidenced from platform data: systems inventory (Govern 1.6), roles and responsibilities (Govern 2.1), incident-identification practices (Govern 4.3), impact assessment (Map 5.1), production monitoring (Measure 2.4), security/resilience review (Measure 2.7), privacy risk (Measure 2.10), ongoing monitoring data (Measure 4.3), post-deployment monitoring (Manage 4.1), and incident tracking (Manage 4.3). The remaining 62 are honest manual checklist items with a specific action to complete.

Four document types exist in the platform's document engine for this framework, each built from your registered AI systems: an AI Risk Assessment Report (Govern), a Governance Framework, an Accountability Framework (Measure), and an Impact Assessment (Map).

Walking through it

1

Enable NIST AI RMF

Adds all 72 real Govern/Map/Measure/Manage subcategories to your Obligations page.

Open /settings/profile?tab=frameworks →
2

Work through function by function

Govern first (accountability and roles), then Map (purpose and impact), then Measure (evidence), then Manage (response). The order mirrors how the functions build on each other.

Open /obligations →
3

Lean on your system inventory for Map and Measure

A complete, accurate AI Systems record does most of the work the Map function asks for.

Open /systems →

The law

Frequently asked

Do we need this if we already track the EU AI Act?

Only if you have a reason to: a US customer's due-diligence questionnaire, an insurer's requirements, or your own governance preference. It's not a legal requirement in the way the AI Act or GDPR are.

Is this the real 72-subcategory structure, or a simplified version?

The real structure: all 72 subcategories across the framework's actual four functions (Govern, Map, Measure, Manage), sourced from the official NIST AI RMF Playbook. An earlier version of this platform modelled only 13 function-level placeholders and an invented fifth 'Track' function that doesn't exist in the real framework; that has been corrected.

Related guides

Try it on your own systems

Everything in this guide runs in the live product. Start a free trial and follow along with your own data.

Start free trial