GLACIS·AI security frameworks·NIST AI RMF·Updated August 2026

NIST AI RMF compliance, function by function.

NIST AI RMF compliance means choosing the subcategories that fit a given context, running them, and holding evidence that they ran. This guide maps all four functions — GOVERN, MAP, MEASURE and MANAGE — across AI RMF 1.0 and the NIST AI 600-1 generative AI profile, and covers the profile mechanism, intellectual-property risk, and the SP 800-53 control overlays for AI now tracking through 2026.

By Joe Braidwood, CEO GLACIS·31 min read·Published 20 December 2025·Updated 13 August 2026

Jan 2023
NIST AI RMF 1.0 published — voluntary, sector-agnostic
Jul 2024
NIST AI 600-1 GenAI Profile — 12 risks across GOVERN/MAP/MEASURE/MANAGE
2025
US AISI → CAISI; UK AISI → AI Security Institute
Apr 2026
Critical-Infrastructure Profile concept note (7 Apr 2026)
Joe Braidwood
Joe Braidwood
CEO, GLACIS
28 min read

Executive summary

The NIST AI Risk Management Framework (AI RMF 1.0), released January 2023, has emerged as the de facto standard for AI governance in the United States. The framework provides 72 subcategories across 19 categories and 4 core functions, with the 2024 Generative AI Profile (NIST AI 600-1) adding 200+ actions specific to LLM and generative AI risks.[1]

While voluntary, NIST AI RMF is increasingly referenced across AI governance work. Colorado’s original 2024 AI Act tied a safe harbor to it, but that statute was repealed and replaced by SB 26-189 before it took effect, and the framework safe harbor did not survive — NIST AI RMF remains recommended practice rather than a codified defense.[2] The Federal Artificial Intelligence Risk Management Act of 2024 would make compliance mandatory for federal agencies.[3] Enterprise customers including Workday and Google have publicly adopted the framework.[4]

This guide provides the complete implementation roadmap with evidence requirements, regulatory crosswalks, and practical controls for each function.

72
Subcategories[1]
233
AI Incidents (2024)[5]
$67B
Hallucination Losses[6]
56%
YoY Incident Rise[5]

In this guide

Why NIST AI RMF matters in 2026

Q1 → Q2 2026 update brief

Critical-Infrastructure AI RMF Profile concept note released 7 Apr 2026. Cyber AI Profile finalisation, RMF 1.1 guidance addenda and SP 800-53 Control Overlays for AI are all tracking through 2026.[N1]

NIST AI 600-1 GenAI Profile (26 Jul 2024) remains the canonical operational profile for GenAI risk: 12 risks mapped into GOVERN, MAP, MEASURE and MANAGE subcategories.[N2]

AISI structural changes (mid-2025): the US AI Safety Institute became the Center for AI Standards and Innovation (CAISI); the UK’s AISI was renamed the AI Security Institute. AISIC has ~290 member organisations and is currently closed to new members.[N3][N4]

RMF crosswalks in widespread use: CSA AICM (Aug 2025) publishes the canonical AICM ↔ AI 600-1 mapping; ISO/IEC 42001 ↔ AI 600-1 mapping is in active practitioner use.[N5]

The landscape of AI risk has shifted dramatically. According to the Stanford AI Index, 233 AI-related incidents were reported in 2024—a 56.4% increase over 2023 and a 26-fold increase since 2012.[5] These incidents included deepfake intimate images, chatbots implicated in self-harm, and false identification by anti-theft AI systems — the class of event an AI incident response plan has to be ready for.

The financial stakes are substantial. Global losses attributed to AI hallucinations reached $67.4 billion in 2024, according to AllAboutAI research.[6] In a separate finding, 47% of enterprise AI users admitted to making at least one major business decision based on hallucinated content.[6]

Regulators have taken notice. In 2024 alone, 135 different state AI laws were passed in the United States, with over 800 submitted at the start of the year.[7] The NIST AI RMF has emerged as the common reference point across these regulatory efforts.

Where the law landed: Colorado’s original 2024 AI Act offered a NIST AI RMF / ISO 42001 safe-harbor affirmative defense, but it was repealed and replaced by SB 26-189 (Automated Decision-Making Technology) before taking effect, and that safe harbor was not carried forward. NIST AI RMF stays valuable as the backbone for the documentation, disclosure, and human-review duties that commence January 1, 2027 — even though it is no longer a codified defense.[2]

Under SB 26-189, the Colorado Attorney General enforces violations as deceptive trade practices under the Colorado Consumer Protection Act, with civil penalties up to $20,000 per violation. These obligations are enacted but not operative until January 1, 2027.

Enterprise adoption

Major enterprises have publicly embraced NIST AI RMF:

The 2025 AI Governance Survey found that 30% of organizations have at least one AI model in production, with another 40% running pilots.[8] As deployment accelerates, governance frameworks become essential.

Framework structure

The NIST AI RMF is organized around four core functions, 19 categories, and 72 subcategories. The companion Playbook provides suggested actions for each subcategory, while remaining voluntary and adaptable to organizational context.[1]

Function Purpose Categories Subcategories
GOVERN Establish organizational culture and structures 6 ~20
MAP Understand context and identify risks 5 18
MEASURE Assess and analyze identified risks 5 22
MANAGE Prioritize and address risks 3 ~12
TOTAL 19 72
G

GOVERN

Foundational—enables and informs all other functions

Policies, roles, accountability, culture, third-party oversight

M

MAP

Context before deployment—understand operating environment

Use case analysis, stakeholder impact, risk identification

M

MEASURE

Quantify through testing—establish metrics and monitoring

Testing, metrics, bias assessment, continuous monitoring

M

MANAGE

Act on risks—implement controls and response procedures

Risk treatment, mitigation, response planning, documentation

Seven characteristics of trustworthy AI

The framework defines seven characteristics that AI systems should exhibit to be considered trustworthy:[1]

Valid and Reliable
Consistent, accurate performance
Safe
No harm to people or environment
Secure and Resilient
Protected, recoverable from disruptions
Accountable and Transparent
Clear ownership and visibility
Explainable and Interpretable
Decisions can be understood
Privacy-Enhanced
Individual privacy protected
Fair with Harmful Bias Managed
Regular auditing for biases with corrective actions

GOVERN — establishing AI governance

The GOVERN function is foundational—it enables and informs the other three functions. Without effective governance structures, technical controls lack context and accountability. NIST emphasizes that governance should be established first and maintained throughout the AI lifecycle.[1]

Primary ownership typically sits with General Counsel, CISOs, Head of Risk, or Chief Risk Officer—leaders positioned to operationalize AI risk management as part of broader enterprise risk strategy.[9]

GV.1

Organizational Policies

Establish policies that define acceptable AI uses, risk thresholds, and accountability structures.

  • Document AI use policies aligned with organizational values and legal obligations
  • Define risk tolerance thresholds by use case category
  • Establish approval workflows for high-risk AI applications
  • Create incident response procedures specific to AI failures
Evidence Required: Policy documents, approval records, version history
GV.2

Roles and Responsibilities

Define clear accountability for AI risk management across the organization.

  • Assign executive sponsorship for AI governance program
  • Define RACI matrix for AI risk assessment, approval, and monitoring
  • Establish cross-functional AI governance committee
Evidence Required: Org charts, role descriptions, committee charters, meeting minutes
GV.3

Workforce and Culture

Build organizational capability and culture for responsible AI development and deployment.

  • Provide AI risk awareness training for relevant staff
  • Create channels for reporting AI concerns without retaliation
  • Foster culture that values AI safety alongside innovation
Evidence Required: Training records, completion rates, reporting channel documentation
GV.4

Third-Party AI Oversight

Extend governance to AI systems procured from or operated by third parties.

  • Require vendors to complete AI security questionnaires
  • Include AI governance requirements in contracts
  • Audit third-party AI compliance periodically
Evidence Required: Vendor assessments, contract clauses, audit reports

MAP — understanding AI context

The MAP function focuses on understanding the context in which AI systems operate and identifying potential risks before deployment. It comprises 5 categories and 18 subcategories.[10]

Effective mapping requires understanding not just intended uses, but foreseeable misuses. The framework emphasizes considering stakeholders who might be affected by AI decisions, including those who may not directly interact with the system.

MP.1

Context and Use Case Analysis

Document the intended purpose, users, and operating environment for each AI system.

  • Define intended use cases with specific user populations
  • Identify foreseeable misuses and off-label applications
  • Assess deployment environment and integration points
  • Document data sources, quality, and provenance
Evidence Required: Use case documentation, data lineage records, architecture diagrams
MP.2

Stakeholder Impact Assessment

Identify who is affected by AI decisions and how they might be harmed.

  • Map all stakeholders affected by AI outputs (direct and indirect)
  • Assess potential harms: physical, psychological, financial, reputational
  • Consider disparate impacts on protected classes
  • Engage affected communities in risk identification
Evidence Required: Impact assessments, stakeholder maps, engagement records
MP.3

Risk Identification

Systematically identify risks across the AI lifecycle and risk categories.

  • Catalog risks to each trustworthy AI characteristic
  • Consider risks from training data, model architecture, deployment
  • Document known limitations and failure modes
Evidence Required: Risk registers, model cards, limitation documentation

MEASURE — assessing AI risks

The MEASURE function involves quantifying and analyzing identified risks through testing, metrics, and ongoing monitoring. It comprises 5 categories and 22 subcategories.[10]

With AI hallucination rates varying from 0.7% (best-in-class) to over 25% in widely deployed enterprise models[6], measurement is critical. The 2024 Stanford AI Index found that standardized evaluations for LLM responsibility are seriously lacking—leading developers test against different benchmarks, complicating cross-model comparison.[5]

MS.1

AI Testing and Evaluation

Establish rigorous testing protocols for AI systems before and after deployment.

  • Conduct performance testing across diverse conditions and edge cases
  • Test for adversarial robustness and prompt injection vulnerabilities
  • Perform red teaming for high-risk applications
  • Measure hallucination rates with domain-specific test sets
Evidence Required: Test plans, results, red team reports, benchmark scores
MS.2

Bias and Fairness Assessment

Measure and document bias across protected categories and use cases.

  • Define fairness metrics appropriate to the use case
  • Test for disparate impact across demographic groups
  • Assess representation in training and evaluation data
Evidence Required: Bias assessment reports, fairness metrics, demographic analysis
MS.3

Continuous Monitoring

Establish ongoing monitoring to detect performance degradation, drift, and emerging risks.

  • Monitor model performance metrics in production
  • Detect data drift and distribution shifts
  • Set up alerting for anomalous outputs or behaviors
Evidence Required: Monitoring dashboards, alert logs, drift reports, incident records

MANAGE — treating AI risks

The MANAGE function covers the prioritization and treatment of identified risks, including mitigation strategies and response planning. It translates measurement into action.

Research shows that 76% of enterprises now include human-in-the-loop processes to catch AI errors before deployment, and 91% of enterprise AI policies include explicit protocols for hallucination mitigation.[6]

MG.1

Risk Prioritization

Prioritize risks based on likelihood, impact, and organizational risk tolerance.

  • Score risks using consistent criteria aligned with enterprise risk
  • Factor in reversibility and remediation difficulty
  • Consider regulatory and reputational implications
Evidence Required: Risk scoring matrices, prioritization decisions, review records
MG.2

Risk Treatment Options

Select and implement appropriate risk treatment strategies.

Avoid
Don’t deploy the AI system or use case
Mitigate
Implement controls to reduce risk to acceptable levels
Transfer
Share risk via contracts, insurance, or partnerships
Accept
Document with appropriate executive approval
Evidence Required: Treatment decisions, control implementation records, acceptance documentation
MG.3

Incident Response

Prepare for and respond to AI failures, incidents, and unintended outcomes.

  • Establish AI-specific incident response procedures
  • Define rollback and human takeover mechanisms
  • Conduct post-incident reviews and update controls
Evidence Required: Incident response plans, runbooks, post-mortem reports

How NIST AI RMF profiles work

The framework is not meant to be applied 72 subcategories at a time, uniformly, to everything an organization builds. The mechanism that makes it tractable is the profile: a selection and prioritization of subcategories for a stated context. Most confusion about NIST AI RMF compliance starts by skipping this step and treating the catalog as a flat checklist.

Three kinds of profile do different jobs, and a working program usually runs more than one at a time.

Profile type What it scopes Worked example What it produces
Use-case One application or deployment setting NIST AI 600-1, the generative AI profile Extra actions against subcategories that already exist
Cross-sectoral A risk that recurs across industries The Critical-Infrastructure profile concept note, 7 April 2026 Shared treatment for a common risk
Temporal — current What the organization does today Baseline assessment of an existing model estate An honest description of present practice
Temporal — target Where the organization intends to be The state a customer contract or a statute requires A gap list, which becomes the work plan

The current-and-target pair is the one auditors and enterprise buyers ask to see, because the gap between them is the part of the framework that describes intent. A current profile identical to the target is either finished or unexamined, and reviewers tend to assume the second.

Two practical notes. A profile is a scoping decision, not a maturity score: NIST does not certify AI RMF adoption and publishes no conformity grade, so a vendor offering a certified AI RMF level is describing a scheme of its own making. And because AI 600-1 is itself a use-case profile, adopting it adds no subcategories — it tells you which of the 72 carry more weight when a system is generative, and what to do about them.

NIST AI 600-1

Generative AI profile

Released July 26, 2024, per Executive Order 14110, the Generative AI Profile identifies 12 risks unique to or exacerbated by generative AI and provides over 200 suggested actions for risk management.[11]

The 12 GenAI risk categories

1. CBRN Information
Access to chemical, biological, radiological, nuclear weapons information
2. Confabulation
Production of false or misleading content ("hallucinations")
3. Dangerous Content
Creation of violent, hateful, or inciting content
4. Data Privacy
Leakage, unauthorized use, or de-anonymization of personal data
5. Environmental Impacts
High energy consumption and carbon emissions
6. Harmful Bias
Reinforcement of stereotypes and discriminatory outputs
7. Homogenization
Reduction in content diversity and perspective
8. Information Integrity
Mis/disinformation and manipulation of information
9. Information Security
Lowered barrier to cybersecurity attacks
10. Intellectual Property
Training data and output copyright concerns
11. Obscene Content
Generation of sexual, violent, or illegal content
12. Value Chain
Risks from third-party components and integrations

Integration with AI RMF 1.0: The GenAI Profile maps each of the 12 risks to the core GOVERN, MAP, MEASURE, and MANAGE functions, providing specific actions for generative AI contexts. Organizations implementing AI RMF should layer the GenAI Profile for LLM and generative AI deployments.

Intellectual property risk under the generative AI profile

Risk 10 of NIST AI 600-1 gets one line in most summaries and rather more attention in a security review, because it is the generative-AI risk most likely to arrive as a contract question rather than a technical one. It has two halves that are easy to conflate and need separating before either can be managed.

The input half concerns what the model was trained or grounded on: whether training data was licensed, whether retrieval is pulling copyrighted or third-party confidential material into a prompt, and whether an employee pasted something into a general-purpose assistant that the organization had no right to disclose. The output half concerns what the model produces: substantially similar generations, memorized passages reproduced verbatim, and the open question of what rights attach to generated material at all.

The four questions a reviewer actually asks, and the record that answers each:

The first three are documentation questions and most organizations can answer them, slowly, from contracts and data inventories. The fourth is the one that fails in a review. Asserting that a similarity check exists is a policy claim. Showing that it ran on the generation now under dispute, on the date in question, and what it decided, is an evidence claim — and the two are not interchangeable when a rights-holder is asking.

NIST AI 600-1 places the treatment across all four functions rather than in one place. GOVERN carries the policy and the third-party terms. MAP identifies where copyrighted or licensed material can enter. MEASURE covers the similarity and memorization testing. MANAGE covers takedown, retraining, and the response when a claim arrives. A profile that addresses only the GOVERN half is the common failure, and it is visible from outside: the organization can produce the policy and cannot produce a single record of it being applied.

Regulatory signals

NIST AI RMF has transitioned from voluntary guidance to a widely used regulatory reference point. Frameworks and statutes increasingly cite it as a benchmark, though its status as a codified legal defense varies and, in Colorado, no longer applies.

Regulation NIST AI RMF Reference Effective Date Penalties
Colorado SB 26-189 (ADMT) Recommended practice; no codified safe harbor[2] Jan 1, 2027 (compliance) Up to $20,000/violation
Federal AI Risk Mgmt Act (HR6936) Would mandate for federal agencies[3] Proposed Contract eligibility
Executive Order 14110 Incorporates into federal guidelines[12] October 2023 Agency compliance
EU AI Act Compatible risk-based approach August 2025+ Up to 7% revenue

Colorado: from safe harbor to a transparency regime

Colorado’s original 2024 AI Act (SB 24-205) offered an affirmative defense for organizations that could demonstrate compliance with NIST AI RMF or ISO 42001. That law was repealed and replaced by SB 26-189 (Automated Decision-Making Technology), signed May 14, 2026, before it ever took effect — and the framework safe harbor did not survive into the new statute. NIST AI RMF is therefore no longer a codified legal defense in Colorado, though it remains a strong backbone for the documentation and disclosure duties the new law introduces.[2]

SB 26-189 regulates covered automated decision-making technology (ADMT) used to materially influence a consequential decision, rather than the old “high-risk AI system” category. Its core duties — none of which are operative until January 1, 2027 — center on transparency rather than mandatory impact assessments:

The 2024 Act’s reasonable-care duty against algorithmic discrimination, mandatory risk-management programs, and annual impact assessments were eliminated; discrimination is now handled under existing Colorado anti-discrimination law.

Crosswalk to other frameworks

Organizations implementing NIST AI RMF build a strong foundation for compliance with multiple regulatory frameworks:

NIST AI RMF Function EU AI Act ISO 42001 Colorado SB 26-189 (ADMT)
GOVERN Quality Management (Art. 17) Clauses 5-7 (Leadership, Planning) Governance Policy
MAP Risk Classification (Art. 6) Clause 6.1 (Risk Assessment) Covered-ADMT scoping
MEASURE Testing & Monitoring (Art. 9) Clauses 9-10 (Evaluation) Ongoing Assessment
MANAGE Risk Management (Art. 9) Clause 8 (Operation) Risk Mitigation

SP 800-53 control overlays for AI, and what to do before they land

AI RMF is a risk framework, not a control catalog. It tells an organization what to reason about and leaves the specific controls open, which is why two teams can both claim NIST AI RMF alignment and have almost nothing in common. The work now tracking through 2026 to produce control overlays for AI against NIST SP 800-53 is aimed squarely at that gap: overlays express AI-specific controls in the vocabulary federal systems already use for everything else.

For anyone already inside a federal or FedRAMP boundary this matters more than the framework itself, because 800-53 is the language of the authorization package. An overlay turns AI RMF from a parallel exercise into a set of controls that sit in the same baseline, get assessed by the same assessor, and appear in the same system security plan.

The overlays are not final, and building a program around unpublished control identifiers would be a mistake. Three things are safe to do now because they hold regardless of the final numbering:

The order matters. Organizations that wait for the overlays and then start recording have no history to assess against them on day one. Organizations that record control outcomes now arrive with a back catalog that can be relabeled in an afternoon.

See our detailed guides on ISO 42001, EU AI Act for Healthcare, and Colorado AI Act.

GLACIS logoGLACIS
Evidence Requirements

The GLACIS evidence hierarchy

NIST AI RMF describes what to do, but regulators and auditors increasingly demand proof you did it. The difference determines whether you can demonstrate diligence and meet documentation and disclosure duties when they take effect.

Knowledge workers spend an average of 4.3 hours per week verifying AI outputs.[6] Each enterprise employee costs approximately $14,200 per year in hallucination mitigation efforts.[6] The evidence you collect determines whether that investment is defensible to regulators, auditors, and customers.

1
Policy Documentation
Written AI policies and procedures
Weak
2
Process Records
Risk assessments, impact documentation
Moderate
3
Execution Logs
Automated monitoring, test results, audit trails
Good
4
Cryptographic Attestation
Signed, timestamped proof of control execution
Strong

Most organizations operate at Levels 1-2. Regulators and sophisticated customers increasingly demand Level 3-4 evidence. Read more about the Proof Gap.

Frequently asked questions

What is the NIST AI RMF?

The NIST AI Risk Management Framework (AI RMF 1.0) is a voluntary framework published by the National Institute of Standards and Technology in January 2023. It provides 72 subcategories across 19 categories and 4 core functions — GOVERN, MAP, MEASURE and MANAGE — to help organizations design, develop, deploy and use AI systems responsibly.[1]

Is NIST AI RMF mandatory?

Currently voluntary for private sector organizations. The Federal Artificial Intelligence Risk Management Act of 2024 (HR6936) would make compliance mandatory for federal agencies and their contractors.[3] Colorado’s original 2024 AI Act tied a safe harbor to it, but that statute was repealed and replaced by SB 26-189 before taking effect and the safe harbor did not survive; NIST AI RMF nonetheless remains widely required in enterprise procurement and recommended practice as state AI rules evolve.[2]

What is NIST AI 600-1?

NIST AI 600-1 is the Generative AI Profile released in July 2024, mandated by Executive Order 14110. It identifies 12 risks unique to or exacerbated by generative AI and provides over 200 suggested actions for risk management, covering confabulation, CBRN information risks, harmful content, data privacy, information security and intellectual property.[11]

How does NIST AI RMF relate to the Colorado AI Act?

Colorado’s original 2024 AI Act (SB 24-205) cited NIST AI RMF and ISO 42001 as the basis for a safe-harbor affirmative defense, but that law was repealed and replaced before it ever took effect. The successor statute, SB 26-189 (Automated Decision-Making Technology), signed May 14, 2026 with substantive obligations commencing January 1, 2027, does not carry over the NIST/ISO safe harbor. Aligning with NIST AI RMF remains strong recommended practice and supports documentation and disclosure duties, but it is no longer a codified legal defense in Colorado.[2]

What is a NIST AI RMF profile?

A profile is the AI RMF’s tailoring mechanism. Rather than applying all 72 subcategories uniformly, an organization selects and prioritizes them for a specific context. A use-case profile scopes the framework to one application, such as generative AI or a hiring system. A cross-sectoral profile addresses a risk that cuts across industries. A temporal profile is the pair you actually manage against: a current profile describing what you do today and a target profile describing where you intend to be, with the gap between them forming the work plan. NIST AI 600-1 is itself a use-case profile, which is why it adds actions rather than new subcategories.

How does NIST AI RMF differ from NIST CSF?

The NIST Cybersecurity Framework addresses cybersecurity risks broadly. NIST AI RMF specifically addresses AI-related risks such as bias, explainability, confabulation, and AI-specific security concerns such as prompt injection. Organizations typically need both frameworks for comprehensive risk coverage.

What is the difference between NIST AI RMF and ISO 42001?

NIST AI RMF is a risk management framework focused on AI-specific risks — it tells you what to address. ISO 42001 is a certifiable management system standard that provides the how of organizational implementation. They are complementary: use NIST AI RMF for risk identification and ISO 42001 for management system certification.

Can small organizations implement NIST AI RMF?

Yes. The framework is designed to be scalable and risk-proportionate. Small organizations can implement a simplified version focused on their highest-priority AI systems. Start with governance foundations (GOVERN), identify the critical use cases (MAP), and expand measurement and management based on risk levels.

Who should own NIST AI RMF implementation?

Primary ownership typically sits with General Counsel, the CISO, the Head of Risk, or the Chief Risk Officer — leaders positioned to operationalize AI risk management as part of broader enterprise risk strategy.[9] Implementation requires a cross-functional team including legal, compliance, engineering, and business stakeholders.

References

  1. [1] NIST. "AI Risk Management Framework 1.0." NIST AI 100-1, January 2023. nvlpubs.nist.gov
  2. [2] Colorado General Assembly. SB 24-205 (Colorado AI Act, signed May 17, 2024) was repealed and replaced by SB 26-189 ("Automated Decision-Making Technology"), signed May 14, 2026, with substantive compliance commencing Jan 1, 2027. leg.colorado.gov/bills/sb26-189
  3. [3] U.S. Congress. "Federal Artificial Intelligence Risk Management Act of 2024 (HR6936)." Introduced January 10, 2024. holisticai.com
  4. [4] NIST. "Perspectives about the NIST AI Risk Management Framework." 2023. nist.gov
  5. [5] Stanford HAI. "AI Index 2025: State of AI in 10 Charts." April 2025. hai.stanford.edu
  6. [6] AllAboutAI. "The Hidden Cost Crisis: Economic Impact of AI Content Reliability Issues." 2025. Analysis: Korra
  7. [7] The Data Exchange. "2025 AI Governance Survey." 2025. thedataexchange.media
  8. [8] The Data Exchange. "2025 AI Governance Survey - Deployment Statistics." 2025.
  9. [9] Net Solutions. "How to Implement NIST AI RMF for Enterprises." 2024. netsolutions.com
  10. [10] Ankura. "Implementing the NIST AI Risk Management Framework." 2024. ankura.com
  11. [11] NIST. "Generative Artificial Intelligence Profile (NIST AI 600-1)." July 2024. nvlpubs.nist.gov
  12. [12] White House. "Executive Order 14110 on Safe, Secure, and Trustworthy AI." October 2023. federalregister.gov
  13. [13] Forrester. "AI Governance Software Spend Will See 30% CAGR From 2024 To 2030." 2024. forrester.com
  14. [14] NIST. "AI RMF Playbook." 2023. nist.gov

GLACIS·NIST AI RMF evidence

Move from RMF policy to RMF receipts.

Board-ready compliance evidence mapped to the AI RMF and the GenAI Profile (NIST AI 600-1) — proof that GOVERN, MAP, MEASURE and MANAGE controls actually execute, with crosswalks to ISO/IEC 42001 and the EU AI Act.

See an evidence pack    Run an RMF readiness scan

Related guides