AIXYRA
All Frameworks
AI standards & riskVoluntary framework, published January 2023. Widely referenced by US enterprises and regulators.

NIST AI RMF

NIST AI Risk Management Framework (AI RMF 1.0)

The US reference framework for trustworthy AI: four functions — Govern, Map, Measure, Manage — for identifying and managing AI risk across the lifecycle.

72 individual requirements seeded and assessable in AIXYRA.

The NIST AI Risk Management Framework is the de facto reference for AI risk programs in the United States. It is voluntary, but boards, insurers, customers, and regulators increasingly ask organizations to show alignment. The framework organizes AI risk work into four functions: Govern (culture, accountability, policy), Map (context and risk identification), Measure (assessment and tracking), and Manage (prioritization and response).

Because the AI RMF is outcome-oriented rather than prescriptive, the practical challenge is evidencing it: showing that every AI system is inventoried, that risks are actually measured, and that governance decisions are recorded — not just that a policy document exists.

Who it applies to

Any organization designing, developing, deploying, or using AI systems — especially US enterprises and government suppliers asked to demonstrate AI risk management maturity.

Key requirement themes

Govern

Accountability structures, policies, and a risk-aware culture — who owns each AI system and who approves it for use.

Map

Establish context: what AI systems exist, what they depend on, who they affect, and what could go wrong.

Measure

Assess and track AI risks with defined metrics — including performance drift after deployment.

Manage

Prioritize and respond to measured risks, with documented treatment decisions and continuous review.

Orientation for evaluators — not legal advice. Consult counsel for obligations specific to your organization.

How AIXYRA helps

  • The registry, ownership model, and approval workflows give Govern and Map concrete, auditable form
  • Six-dimension risk scoring with dependency propagation operationalizes Measure across interconnected systems
  • Monitoring integrations trigger governance re-review when runtime behavior drifts — Manage as a living process
  • Assessments map to seeded NIST AI RMF articles with evidence, coverage tracking, and audit-ready reporting

NIST AI RMF FAQ

Is the NIST AI RMF mandatory?

No — it is a voluntary framework. But it has become the common language for AI risk in the US: customers, auditors, and regulators use it as a benchmark, and demonstrating alignment is increasingly a procurement requirement.

How does AIXYRA map to the four AI RMF functions?

Govern maps to ownership, roles, and approval workflows; Map to the entity registry and architecture dependency graphs; Measure to risk scoring and monitoring; Manage to governance checkgates, triggers, and the audit trail. Assessments against seeded AI RMF articles tie the evidence together.

Assess your AI systems against NIST AI RMF

NIST AI RMF ships built into AIXYRA — and the same assessment maps to every other enabled framework at once.