Reporting and governance
NIST AI RMF reporting should communicate the selected system’s Profile, evidence position, gaps and decisions without implying NIST certification or universal trustworthiness.
System report
Section titled “System report”A system report should identify:
- System and assessed boundary.
- Framework publication used.
- Active companion Profiles.
- Current and Target outcomes.
- Outcome coverage.
- Assurance depth.
- Evidence and testing position.
- Findings.
- Material strengths and gaps.
- Residual risk.
- Treatment priorities.
- Owner, review date and reassessment triggers.
Function summaries
Section titled “Function summaries”Gamut may summarise the proportion of outcomes marked Achieved in:
- GOVERN.
- MAP.
- MEASURE.
- MANAGE.
This percentage is a Gamut reporting summary. It is:
- Not a NIST maturity level.
- Not a compliance percentage.
- Not evidence quality.
- Not a certification score.
Read it with assurance depth, evidence, tests and findings.
Portfolio reporting
Section titled “Portfolio reporting”A portfolio view can show:
- Systems assessed.
- Outcome coverage.
- Common gaps.
- Recurring evidence needs.
- High-priority or Enhanced areas.
- Systems requiring review.
- Generative-AI exposure.
- Upcoming review dates.
Portfolio reporting does not replace system-level Profiles. Averaging systems can conceal a severe gap in one consequential system.
Cross-framework reporting
Section titled “Cross-framework reporting”NIST outcomes may be cross-referenced with:
- GTSAF.
- EU AI Act.
- MAESTRO.
- Agentic Trust Framework.
- ISO/IEC 42001.
- ISO/IEC 42005.
Mappings support:
- Evidence discovery.
- Duplicate-work reduction.
- Integrated remediation.
- Common ownership.
- Multi-framework reporting.
Mappings do not prove equivalence. Validate each framework’s own objective, scope and evidence.
Governance decisions
Section titled “Governance decisions”The Profile should support decisions such as:
- Proceed.
- Proceed with conditions.
- Restrict use.
- Require remediation.
- Increase monitoring.
- Obtain independent review.
- Accept defined residual risk.
- Pause.
- Supersede.
- Disengage or deactivate.
The decision should name:
- Authority.
- Conditions.
- Evidence basis.
- Residual risk.
- Review date.
- Trigger for escalation or reversal.
Reporting adverse information
Section titled “Reporting adverse information”Do not hide:
- Unassessed outcomes.
- Weak assurance.
- Failed tests.
- Rejected or stale evidence.
- Open findings.
- Incidents and complaints.
- Supplier limitations.
- Uncertainty.
- Deferred Target Profile work.
Safe external language
Section titled “Safe external language”Prefer:
The organisation has assessed the named system using the NIST AI RMF 1.0 Core and documented system-specific Current and Target Profiles. The report identifies the outcomes reviewed, supporting evidence, assurance limitations, findings and required treatment.
Avoid:
The system is NIST compliant.
Management review agenda
Section titled “Management review agenda”- Has the system or context changed?
- Are material outcomes still achieved?
- Is assurance current?
- Did tests or monitoring reveal adverse evidence?
- Are findings overdue?
- Has residual risk changed?
- Are Target Profile actions funded and owned?
- Are supplier dependencies acceptable?
- Is generative-AI risk still appropriately assessed?
- Should deployment conditions change?
Reassessment governance
Section titled “Reassessment governance”Review:
- On the scheduled date.
- After a material trigger.
- Before significant expansion.
- After a serious incident.
- After a major model or supplier change.
- When authoritative framework publications change.
Records to retain
Section titled “Records to retain”- Scope and Profile basis.
- Assessment outcomes and rationale.
- Evidence and test records.
- Findings and remediation.
- Risk decisions.
- Approvals.
- Monitoring and incidents.
- Review history.
- Superseded conclusions.
Retention should follow applicable law, contract and organisational policy.