AccuroAI
Products
What We Do
Solutions
Company
Resources
Book demo
NIST AI RMF 1.0 · Generative AI Profile (AI 600-1)

Govern, Map, Measure, Manage — with the telemetry to back each one.

The NIST AI Risk Management Framework is voluntary, but it is the lingua franca US regulators, boards and insurers use to judge an AI programme. AccuroAI turns its four functions into running controls and the Generative AI Profile's risk categories into measurable events.
Jan 2023
AI RMF 1.0 released
Jul 2024
Generative AI Profile (NIST AI 600-1)
4 · 12
Four core functions, twelve GenAI risk categories
ConsoleCompliance · NIST AI RMFEvidence live
Requirement · referenceEvidence
Know what you governMAP 1.1 · MAP 3.1 · AI system register with context, purpose and ownerGenerated
Turn policy into enforcementGOVERN 1.2 · GOVERN 1.4 · Policy decisions and exceptions, versionedGenerated
Measure the risks that matterMEASURE 2.6 · 2.7 · 2.10 · Risk metrics by category, team and system, trended over timeGenerated
Respond and recoverMANAGE 2.3 · MANAGE 4.1 · Incident records with response actions and timingsGenerated
Manage third-party and component riskGOVERN 6.1 · MANAGE 3.1 · AI 600-1 2.12 · AI bill of materials with provenance and capability statusGenerated
Report to the boardGOVERN 4 · MEASURE 4 · Board-ready risk report, refreshed continuouslyGenerated
6 requirements mapped · evidence refreshed continuously8 frameworks
Why it matters

The framework boards and regulators reach for first.

The AI RMF organises trustworthy-AI work into four functions — GOVERN sets policy and accountability, MAP establishes context and inventory, MEASURE tests and tracks risk, MANAGE prioritises and responds. The Generative AI Profile adds twelve risk categories specific to GenAI, including data privacy, information security, intellectual property and value-chain integration. Security teams usually find the gap is not in intent but in instrumentation: MEASURE and MANAGE assume you can observe every AI interaction, and most organisations cannot.

What NIST AI RMF asks for

The obligations that touch security and IT.

01GOVERN 1 – 6

Policies, accountability and culture

Legal and regulatory requirements understood; policies in place; roles assigned; risk tolerance set; third-party risks addressed (GOVERN 6).

02MAP 1 – 5

Context and inventory

Intended purposes, users and impacts documented; AI systems categorised; risks and benefits of components including third-party software mapped.

03MEASURE 1 – 4

Metrics and monitoring

Appropriate methods chosen; trustworthy characteristics evaluated; mechanisms for tracking risks over time; feedback gathered.

04MANAGE 1 – 4

Prioritise, respond, recover

Risks prioritised and treated; strategies to maximise benefit and minimise harm; third-party risks managed; incident response and post-deployment monitoring.

05AI 600-1 · 2.4 · 2.9

Data privacy & information security

Leakage of personal or confidential data through prompts and outputs; prompt injection, data poisoning and exfiltration through GenAI systems.

06AI 600-1 · 2.10 · 2.12

Intellectual property & value chain

Source code and IP exposure to external models; risks inherited from upstream models, plugins, tools and components.

How AccuroAI maps

Each requirement, one control, one piece of evidence.

RequirementReferenceAccuroAI controlEvidence produced
Know what you governMAP 1.1 · MAP 3.1Continuous AI inventory across 1,400+ apps, agents, IDEs and MCP servers with user and agent attributionAI system register with context, purpose and owner
Turn policy into enforcementGOVERN 1.2 · GOVERN 1.4Policy engine applying acceptable use, data rules and agent permissions everywhere AI runsPolicy decisions and exceptions, versioned
Measure the risks that matterMEASURE 2.6 · 2.7 · 2.10Inline inspection of 14M+ prompts daily: PII, secrets, IP, injection — at <38ms p99Risk metrics by category, team and system, trended over time
Respond and recoverMANAGE 2.3 · MANAGE 4.1Redact, warn or block in real time; approval gates and kill switch for agents; alerting into your SIEMIncident records with response actions and timings
Manage third-party and component riskGOVERN 6.1 · MANAGE 3.1 · AI 600-1 2.12AI supply-chain vetting of models, MCP servers, skills and packagesAI bill of materials with provenance and capability status
Report to the boardGOVERN 4 · MEASURE 4Executive reporting mapped to the four functions and to 8 frameworksBoard-ready risk report, refreshed continuously

General information about the public text of the framework, not legal advice. Mappings describe how AccuroAI controls support each obligation; scope and conformity decisions remain with your legal, compliance and certification partners.

Where it runs

The products behind the evidence.

Further reading
FAQ

What teams ask about NIST AI RMF.

The AI RMF is voluntary — why build to it?

Because it is the reference point everyone else uses: US federal guidance, state laws such as Colorado's, cyber-insurance questionnaires, and auditors reading NIST CSF 2.0 alongside it. Showing your controls in the four-function vocabulary shortens every one of those conversations.

How does the Generative AI Profile change things?

NIST AI 600-1 (July 2024) names twelve GenAI-specific risks and suggested actions for each. The ones security teams own — data privacy, information security, intellectual property, value-chain integration — are exactly the categories inline inspection and supply-chain vetting make measurable.

Which functions does AccuroAI cover?

MAP and MEASURE almost entirely through discovery, attribution and inline inspection; MANAGE through real-time response, agent gating and incident records; GOVERN through policy enforcement and reporting. Setting risk tolerance and assigning accountability remain organisational decisions.

Can the same evidence serve the EU AI Act and ISO 42001?

Yes. AccuroAI maps each artefact to 8 frameworks, so the inventory, logs and oversight records you generate for the AI RMF are reused for the EU AI Act's deployer obligations and ISO 42001's Annex A.

Is this legal advice?

No. This page summarises the public NIST AI RMF 1.0 and AI 600-1 documents and describes how AccuroAI controls support them.

See your NIST AI RMF evidence, live.

Book a 30-minute demo and we'll show the inventory, the logs and the oversight controls behind every mapping on this page — on your own AI estate within 72 hours.

Book a demoTalk to security