Skip to content

Reporting and governance

NIST AI RMF reporting should communicate the selected system’s Profile, evidence position, gaps and decisions without implying NIST certification or universal trustworthiness.

A system report should identify:

  • System and assessed boundary.
  • Framework publication used.
  • Active companion Profiles.
  • Current and Target outcomes.
  • Outcome coverage.
  • Assurance depth.
  • Evidence and testing position.
  • Findings.
  • Material strengths and gaps.
  • Residual risk.
  • Treatment priorities.
  • Owner, review date and reassessment triggers.

Gamut may summarise the proportion of outcomes marked Achieved in:

  • GOVERN.
  • MAP.
  • MEASURE.
  • MANAGE.

This percentage is a Gamut reporting summary. It is:

  • Not a NIST maturity level.
  • Not a compliance percentage.
  • Not evidence quality.
  • Not a certification score.

Read it with assurance depth, evidence, tests and findings.

A portfolio view can show:

  • Systems assessed.
  • Outcome coverage.
  • Common gaps.
  • Recurring evidence needs.
  • High-priority or Enhanced areas.
  • Systems requiring review.
  • Generative-AI exposure.
  • Upcoming review dates.

Portfolio reporting does not replace system-level Profiles. Averaging systems can conceal a severe gap in one consequential system.

NIST outcomes may be cross-referenced with:

  • GTSAF.
  • EU AI Act.
  • MAESTRO.
  • Agentic Trust Framework.
  • ISO/IEC 42001.
  • ISO/IEC 42005.

Mappings support:

  • Evidence discovery.
  • Duplicate-work reduction.
  • Integrated remediation.
  • Common ownership.
  • Multi-framework reporting.

Mappings do not prove equivalence. Validate each framework’s own objective, scope and evidence.

The Profile should support decisions such as:

  • Proceed.
  • Proceed with conditions.
  • Restrict use.
  • Require remediation.
  • Increase monitoring.
  • Obtain independent review.
  • Accept defined residual risk.
  • Pause.
  • Supersede.
  • Disengage or deactivate.

The decision should name:

  • Authority.
  • Conditions.
  • Evidence basis.
  • Residual risk.
  • Review date.
  • Trigger for escalation or reversal.

Do not hide:

  • Unassessed outcomes.
  • Weak assurance.
  • Failed tests.
  • Rejected or stale evidence.
  • Open findings.
  • Incidents and complaints.
  • Supplier limitations.
  • Uncertainty.
  • Deferred Target Profile work.

Prefer:

The organisation has assessed the named system using the NIST AI RMF 1.0 Core and documented system-specific Current and Target Profiles. The report identifies the outcomes reviewed, supporting evidence, assurance limitations, findings and required treatment.

Avoid:

The system is NIST compliant.

  1. Has the system or context changed?
  2. Are material outcomes still achieved?
  3. Is assurance current?
  4. Did tests or monitoring reveal adverse evidence?
  5. Are findings overdue?
  6. Has residual risk changed?
  7. Are Target Profile actions funded and owned?
  8. Are supplier dependencies acceptable?
  9. Is generative-AI risk still appropriately assessed?
  10. Should deployment conditions change?

Review:

  • On the scheduled date.
  • After a material trigger.
  • Before significant expansion.
  • After a serious incident.
  • After a major model or supplier change.
  • When authoritative framework publications change.
  • Scope and Profile basis.
  • Assessment outcomes and rationale.
  • Evidence and test records.
  • Findings and remediation.
  • Risk decisions.
  • Approvals.
  • Monitoring and incidents.
  • Review history.
  • Superseded conclusions.

Retention should follow applicable law, contract and organisational policy.