Sentrix

Framework · NIST AI RMF

NIST AI RMF: the risk framework for trustworthy AI

The NIST AI Risk Management Framework, version 1.0 of January 2023: four functions, Govern, Map, Measure, Manage, across the full AI lifecycle in any sector.

The NIST Artificial Intelligence Risk Management Framework (AI RMF 1.0), published in January 2023 by the US National Institute of Standards and Technology, provides a structured, adaptable approach to managing risks across the full AI lifecycle. Built around four core functions, Govern, Map, Measure, and Manage, it applies to any sector and complements ISO 42001 and regulations such as the EU AI Act.

Key facts

  • 4 functions: Govern, Map, Measure, Manage; interconnected, iterative, and applicable throughout the lifecycle.
  • January 2023: version 1.0 published by NIST.
  • 7 characteristics: valid and reliable, safe, secure and resilient, explainable and interpretable, privacy-enhanced, fair, accountable and transparent.
  • Lifecycle: design, development, deployment, operation, and decommissioning.

What the AI RMF covers

The AI RMF is outcomes-based and non-prescriptive. Govern is the foundational function that establishes culture, strategy, and accountability so that the other three can operate consistently at scale.

  1. Govern: cultivate AI risk culture; policies, accountability, oversight, and AI supply chain risk governance
  2. Map: establish context; categorize AI systems, clarify capabilities, identify risks and characterize potential impacts
  3. Measure: assess and track; choose metrics, evaluate trustworthiness characteristics, test for bias and fairness, monitor risk over time
  4. Manage: prioritize and treat; define risk treatments, plan responses, handle residual risk, monitor third-party AI elements
  5. Trustworthy AI: valid and reliable, safe, secure and resilient, explainable and interpretable, privacy-enhanced, fair
  6. AI lifecycle: design, development, deployment, operation, decommissioning

What Sentrix provides for the AI RMF

AI system inventory (Map)

Sentrix discovers and inventories AI systems across your environment, cloud ML platforms, third-party AI APIs, internal models, and classifies them by risk level.

Bias and fairness testing (Measure)

The Measure function requires continuous evaluation of trustworthiness characteristics. Sentrix integrates with your model evaluation pipelines to collect bias, fairness, and robustness metrics as evidence.

AI risk register (Manage)

A dedicated register tracks risk treatments, residual risks, and response plans per AI system. Prioritization aligns to the Manage function categories.

Third-party AI risk (Govern)

Govern requires AI supply chain risk oversight. Sentrix onboards your AI vendors, LLM providers, AI SaaS tools, model APIs, into your third-party risk program with AI-specific questionnaires and continuous scoring.

Board-ready AI risk reporting

Sentrix generates an AI risk posture summary by function, with trustworthiness characteristic scores, open risk items, and treatment progress, for the CISO, the board, and regulatory reporting.

Crosswalks

  • ISO 42001: AI RMF categories are mapped to the ISO 42001 clauses; Govern aligns to clauses 5 and 6.
  • NIST CSF 2.0: same outcomes-based approach; supply chain governance meets across both.

Further reading

Third-party risk for AI vendor oversight.

See your AI risk posture mapped to the AI RMF.

Contact us

Frequently asked questions

Is the NIST AI RMF mandatory?
No. The NIST AI Risk Management Framework is voluntary, outcomes-based and non-prescriptive: it describes what good AI risk management looks like rather than mandating controls, which makes it adaptable to any organization size, sector or AI maturity level. It complements ISO 42001 and regulations such as the EU AI Act.
What are the four AI RMF functions?
Govern establishes culture, strategy and accountability, and enables the other three to operate at scale. Map establishes context: categorize AI systems, identify risks and characterize impacts. Measure assesses and tracks: metrics, trustworthiness characteristics, bias and fairness testing. Manage prioritizes and treats: risk treatments, residual risk, monitoring of third-party AI elements.
What are the characteristics of trustworthy AI according to NIST?
The AI RMF tracks seven characteristics: valid and reliable, safe, secure and resilient, explainable and interpretable, privacy-enhanced, fair with harmful bias managed, and accountable and transparent. The Measure function requires their continuous evaluation; Sentrix integrates with your model evaluation pipelines to collect these metrics as evidence.

Let's talk about your compliance program.

Last updated: 2026-09-17