Functions and outcome catalogue
This page is a navigation aid for the NIST AI RMF Core as presented in Gamut. The short titles are product-safe summaries. Consult the official AI RMF Core for authoritative wording and context.
Catalogue totals
Section titled “Catalogue totals”| Function | Categories | Outcomes |
|---|---|---|
GOVERN (GV) | 6 | 19 |
MAP (MP) | 5 | 18 |
MEASURE (ME) | 4 | 22 |
MANAGE (MG) | 4 | 13 |
| Total | 19 | 72 |
GOVERN
Section titled “GOVERN”GOVERN establishes the organisation-wide conditions that support risk management throughout the AI lifecycle. It is cross-cutting and should continue as context, expectations and risks change.
GV-1 — Governance policies and practices
Section titled “GV-1 — Governance policies and practices”Focus: transparent policies, controls, risk tolerance, monitoring, inventory and decommissioning.
| ID | Assessment focus |
|---|---|
GV-1.1 | Legal and regulatory requirements |
GV-1.2 | Trustworthy AI characteristics |
GV-1.3 | Risk-management activity level |
GV-1.4 | Risk-management controls |
GV-1.5 | Monitoring and review cadence |
GV-1.6 | AI system inventory |
GV-1.7 | Safe decommissioning |
GV-2 — Accountability structures
Section titled “GV-2 — Accountability structures”Focus: roles, competence, communication and executive responsibility.
| ID | Assessment focus |
|---|---|
GV-2.1 | Roles and communication lines |
GV-2.2 | AI risk-management training |
GV-2.3 | Executive responsibility |
GV-3 — Workforce diversity and human-AI oversight
Section titled “GV-3 — Workforce diversity and human-AI oversight”Focus: diverse decision-making and clear human-AI roles.
| ID | Assessment focus |
|---|---|
GV-3.1 | Diverse AI risk decision-making |
GV-3.2 | Human-AI roles and oversight |
GV-4 — Organisational risk culture
Section titled “GV-4 — Organisational risk culture”Focus: critical thinking, safety-first behaviour, risk communication, testing and incident learning.
| ID | Assessment focus |
|---|---|
GV-4.1 | Critical thinking and safety-first mindset |
GV-4.2 | Risk and impact communication |
GV-4.3 | Testing, incident identification and sharing |
GV-5 — Stakeholder engagement
Section titled “GV-5 — Stakeholder engagement”Focus: obtaining, adjudicating and integrating external and relevant AI-actor feedback.
| ID | Assessment focus |
|---|---|
GV-5.1 | External impact feedback |
GV-5.2 | Adjudicated feedback integration |
GV-6 — Third-party and supply-chain risk
Section titled “GV-6 — Third-party and supply-chain risk”Focus: supplier risks, third-party rights and contingency planning.
| ID | Assessment focus |
|---|---|
GV-6.1 | Third-party AI risk policies |
GV-6.2 | High-risk third-party contingency |
MAP establishes the system’s context and identifies benefits, costs, affected parties, limitations, impacts and risks. Weak MAP work undermines later measurement and treatment.
MP-1 — Context established
Section titled “MP-1 — Context established”Focus: intended purpose, deployment context, mission, risk tolerance and socio-technical requirements.
| ID | Assessment focus |
|---|---|
MP-1.1 | Intended purpose and deployment context |
MP-1.2 | Interdisciplinary context input |
MP-1.3 | Mission and AI goals |
MP-1.4 | Business value or use context |
MP-1.5 | Organisational risk tolerance |
MP-1.6 | System requirements and socio-technical implications |
MP-2 — AI system categorisation
Section titled “MP-2 — AI system categorisation”Focus: tasks, methods, knowledge limits, human oversight and scientific integrity.
| ID | Assessment focus |
|---|---|
MP-2.1 | Tasks and methods |
MP-2.2 | Knowledge limits and human oversight |
MP-2.3 | Scientific integrity and TEVV considerations |
MP-3 — Capabilities, usage, benefits and costs
Section titled “MP-3 — Capabilities, usage, benefits and costs”Focus: benefits, costs, application scope, competence and oversight.
| ID | Assessment focus |
|---|---|
MP-3.1 | Potential benefits |
MP-3.2 | Potential costs |
MP-3.3 | Targeted application scope |
MP-3.4 | Operator and practitioner proficiency |
MP-3.5 | Human oversight processes |
MP-4 — Risk and benefit mapping
Section titled “MP-4 — Risk and benefit mapping”Focus: technology, legal, component and third-party risks and internal controls.
| ID | Assessment focus |
|---|---|
MP-4.1 | Technology and legal risk mapping |
MP-4.2 | Internal risk controls |
MP-5 — Impact characterisation
Section titled “MP-5 — Impact characterisation”Focus: likelihood and magnitude of impacts and continuing engagement with relevant actors.
| ID | Assessment focus |
|---|---|
MP-5.1 | Likelihood and magnitude of impacts |
MP-5.2 | Regular engagement on impacts |
MEASURE
Section titled “MEASURE”MEASURE uses quantitative, qualitative or mixed methods to evaluate risks and trustworthy characteristics, monitor operation and validate whether the measurement approach remains useful.
ME-1 — Measurement methods
Section titled “ME-1 — Measurement methods”Focus: risk metrics, control effectiveness and appropriate assessment participation.
| ID | Assessment focus |
|---|---|
ME-1.1 | Risk-measurement approaches |
ME-1.2 | Metric and control effectiveness |
ME-1.3 | Independent and stakeholder-supported assessment |
ME-2 — Trustworthy AI evaluation
Section titled “ME-2 — Trustworthy AI evaluation”Focus: TEVV, performance, monitoring, safety, security, transparency, explainability, privacy, fairness and environmental impact.
| ID | Assessment focus |
|---|---|
ME-2.1 | TEVV artefact documentation |
ME-2.2 | Human-subject evaluation requirements |
ME-2.3 | Deployment-like performance criteria |
ME-2.4 | Production monitoring |
ME-2.5 | Valid and reliable demonstration |
ME-2.6 | Safety evaluation |
ME-2.7 | Security and resilience evaluation |
ME-2.8 | Transparency and accountability risks |
ME-2.9 | Explainability and interpretability |
ME-2.10 | Privacy risk examination |
ME-2.11 | Fairness and bias evaluation |
ME-2.12 | Environmental impact and sustainability |
ME-2.13 | TEVV effectiveness |
ME-3 — Risk tracking
Section titled “ME-3 — Risk tracking”Focus: existing, unknown and emergent risks, including feedback and appeal.
| ID | Assessment focus |
|---|---|
ME-3.1 | Existing and emergent risk tracking |
ME-3.2 | Tracking where metrics are immature |
ME-3.3 | End-user and impacted-community feedback |
ME-4 — Measurement feedback
Section titled “ME-4 — Measurement feedback”Focus: connecting measurement to context and validating whether results and trends remain useful.
| ID | Assessment focus |
|---|---|
ME-4.1 | Context-connected measurement approaches |
ME-4.2 | Trustworthiness-results validation |
ME-4.3 | Performance-change tracking |
MANAGE
Section titled “MANAGE”MANAGE turns mapped and measured risk into decisions, treatment, resource allocation, response, recovery, communication and continual improvement.
MG-1 — Risk response
Section titled “MG-1 — Risk response”Focus: proceed decisions, prioritisation, treatment and residual-risk communication.
| ID | Assessment focus |
|---|---|
MG-1.1 | Proceed decision |
MG-1.2 | Risk-treatment prioritisation |
MG-1.3 | High-priority risk responses |
MG-1.4 | Residual-risk documentation |
MG-2 — Benefit maximisation and impact reduction
Section titled “MG-2 — Benefit maximisation and impact reduction”Focus: resources, non-AI alternatives, sustained value, unknown risks and deactivation.
| ID | Assessment focus |
|---|---|
MG-2.1 | Risk resources and non-AI alternatives |
MG-2.2 | Sustaining deployed AI value |
MG-2.3 | Previously unknown risk response |
MG-2.4 | Supersede, disengage or deactivate |
MG-3 — Third-party risk management
Section titled “MG-3 — Third-party risk management”Focus: ongoing monitoring and control of third-party resources and pre-trained models.
| ID | Assessment focus |
|---|---|
MG-3.1 | Third-party monitoring and controls |
MG-3.2 | Pre-trained model monitoring |
MG-4 — Treatment monitoring and incident communication
Section titled “MG-4 — Treatment monitoring and incident communication”Focus: post-deployment monitoring, appeal, override, incident response, recovery, change and continual improvement.
| ID | Assessment focus |
|---|---|
MG-4.1 | Post-deployment monitoring plans |
MG-4.2 | Continual improvement in updates |
MG-4.3 | Incident and error communication |
How to use the catalogue
Section titled “How to use the catalogue”For each outcome:
- Read the official Core wording.
- Confirm the selected system and context.
- Use the Gamut advisory to plan questions, evidence and testing.
- Record Current and Target Profile outcomes.
- Record assurance depth separately.
- Link evidence, tests and findings.
- Define monitoring and reassessment.