Comply · United States
NIST AI Risk Management Framework
The US voluntary framework for trustworthy AI risk management.
The NIST AI Risk Management Framework is a voluntary, widely-adopted framework from the US National Institute of Standards and Technology for managing risks across the AI lifecycle. It is organized around four functions — Govern, Map, Measure, and Manage — and a set of trustworthy-AI characteristics (valid & reliable, safe, secure & resilient, accountable & transparent, explainable, privacy-enhanced, and fair).
Who it applies to
Any US organization building or deploying AI. Though voluntary, it is frequently referenced in federal contracts, procurement, and as the de-facto baseline for enterprise AI governance programs.
Key obligations
- GOVERN — establish an AI risk management culture, policies, roles, and accountability
- MAP — establish context and identify risks for each AI system
- MEASURE — analyze, assess, and track AI risks with metrics and testing
- MANAGE — prioritize and act on risks, with monitoring and response
- Document trustworthiness characteristics per system
How Maetra maps agents to NIST AI RMF
Maetra operationalizes the four functions per agent: Discover maps the AI inventory, Comply records controls and evidence against GOVERN/MAP/MEASURE/MANAGE, Govern and Secure enforce runtime risk management, and Audit provides the tamper-evident record that measurement and management actually happened.
In practice, Maetra:
- Scans and fingerprints each agent. Discover reads the agent’s code — its tools, data access and sensitivity, actions, model, and environment — into an evidence-backed profile tied to the exact file and commit.
- Decides what applies. That profile determines whether NIST AI RMF is in scope for the agent and which of its requirements apply.
- Auto-detects controls and surfaces gaps. Controls your code already satisfies are detected automatically from the scan; the rest become a clear list of gaps, each tied to the requirement and the evidence it still needs.
- Proves it and keeps it current. Close gaps with linked evidence or generated documents — reused across every framework the same control supports — and Maetra re-checks on each rescan and flags evidence that has gone stale.
Related frameworks
Prove NIST AI RMF compliance with Maetra
Classify your AI agents once and Maetra maps them to NIST AI RMF and every other framework it supports — generating the evidence and documentation, tracking gaps and deadlines, and sealing every decision in an immutable audit trail.