Skip to content

NIST AI RMF

Gamut supports system-specific assessment against the NIST Artificial Intelligence Risk Management Framework (AI RMF) 1.0. The module helps an assessor connect the framework’s four Core functions to a named AI system, record a Current Profile, define a Target Profile, collect evidence, test relevant practices, manage findings and document an accountable conclusion.

The central question is:

For this AI system and operating context, which NIST AI RMF outcomes are currently achieved, what target state is required, what evidence supports the assessment, and what actions remain?

If you need to…Read
Explain the difference between the Core, Current Profile, Target Profile and PlaybookCore, Profiles and Playbook
See all 4 functions, 19 categories and 72 outcomesFunctions and outcome catalogue
Explain why every system is available and why some outcomes receive more attentionSystem scope and prioritisation
Complete an assessment from intake to accountable conclusionAssessment workflow
Explain Current outcome, Target outcome, assurance depth and confirmationOutcomes, assurance and conclusions
Know what evidence to request, how to test and when to raise findingsEvidence, testing and findings
Assess a generative AI system using NIST AI 600-1Generative AI Profile
Use AI assistance responsibly and understand what it can considerAI-assisted assessment
Produce and explain system or portfolio reportingReporting and governance
Follow a realistic assessment exampleWorked example
Look up labels, terms and safe explanatory languageReference and glossary
PropertyGamut assessment
Authoritative frameworkNIST AI RMF 1.0, NIST AI 100-1
NatureVoluntary AI risk-management framework
Primary scopeOne selected AI system and its operating context
Core functionsGOVERN, MAP, MEASURE and MANAGE
Categories19
Core subcategories/outcomes72
Assessment structureCurrent Profile plus Target Profile
Current outcome labelsNot assessed, Not achieved, Partially achieved, Achieved
Assurance depthUnverified, Documented, Implemented, Assured
Generative AI companionNIST AI 600-1 when generative-AI characteristics are present
Evidence boundaryEvidence, tests and findings linked to the selected system and outcome
AI supportWhole-system or single-outcome advisory analysis
Human accountabilityThe assessor owns final outcomes, risk decisions and conclusions
FunctionPurposeCategoriesOutcomes
GOVERNEstablish policies, accountability, culture and organisation-wide risk-management conditions.619
MAPEstablish context and identify intended purpose, actors, impacts, benefits, costs and risks.518
MEASUREEvaluate, test, monitor and track AI risks and trustworthy characteristics.422
MANAGEPrioritise and treat risks, make proceed decisions, respond to incidents and improve controls.413

GOVERN is cross-cutting. MAP, MEASURE and MANAGE are iterative rather than a one-time linear sequence. The framework should be revisited as the system, context, evidence, risks and stakeholder expectations change.

Named AI system and context
→ NIST AI RMF Core available
→ context-based assessment priorities
→ Current Profile outcome for each Core subcategory
→ assurance depth, evidence, testing and findings
→ Target Profile outcome
→ treatment, monitoring and reassessment
→ accountable human conclusion

The Current Profile describes the system’s assessed present position. The Target Profile describes the intended risk-management outcome. The gap between them is the improvement plan.

NIST describes trustworthy AI through connected characteristics:

  • Valid and reliable.
  • Safe.
  • Secure and resilient.
  • Accountable and transparent.
  • Explainable and interpretable.
  • Privacy-enhanced.
  • Fair, with harmful bias managed.

These characteristics interact and may involve trade-offs. A system is not trustworthy merely because one metric is strong. For example, high predictive performance does not by itself establish safety, fairness, privacy, transparency or appropriate human oversight.

A well-supported record should include:

  • The correct named system, version, purpose, lifecycle stage and deployment context.
  • Relevant users, affected people, data, suppliers and system boundaries.
  • A Current Profile outcome for every considered Core subcategory.
  • A Target Profile outcome appropriate to risk tolerance and intended use.
  • System-specific rationale rather than generic policy statements.
  • Evidence showing design and operation.
  • Test results and defined pass criteria where effectiveness is claimed.
  • Findings for gaps, failed tests, unsupported assumptions or adverse evidence.
  • Owners, treatment decisions, residual risk and monitoring.
  • A review date and material reassessment triggers.
  • A clear human-authored conclusion.

It does not by itself prove:

  • Legal compliance.
  • Certification.
  • NIST approval or endorsement.
  • That every risk has been eliminated.
  • That a policy operates effectively.
  • That another system inherits the same outcome.
  • That a mapped control automatically satisfies a NIST outcome.
  • That AI-generated advice is correct or approved.
  1. Core, Profiles and Playbook
  2. Functions and outcome catalogue
  3. System scope and prioritisation
  4. Assessment workflow
  5. Outcomes, assurance and conclusions
  6. Evidence, testing and findings
  7. Generative AI Profile
  8. AI-assisted assessment
  9. Reporting and governance
  10. Worked example
  11. Reference and glossary