The AI RMF organises trustworthy-AI work into four functions — GOVERN sets policy and accountability, MAP establishes context and inventory, MEASURE tests and tracks risk, MANAGE prioritises and responds. The Generative AI Profile adds twelve risk categories specific to GenAI, including data privacy, information security, intellectual property and value-chain integration. Security teams usually find the gap is not in intent but in instrumentation: MEASURE and MANAGE assume you can observe every AI interaction, and most organisations cannot.
Legal and regulatory requirements understood; policies in place; roles assigned; risk tolerance set; third-party risks addressed (GOVERN 6).
Intended purposes, users and impacts documented; AI systems categorised; risks and benefits of components including third-party software mapped.
Appropriate methods chosen; trustworthy characteristics evaluated; mechanisms for tracking risks over time; feedback gathered.
Risks prioritised and treated; strategies to maximise benefit and minimise harm; third-party risks managed; incident response and post-deployment monitoring.
Leakage of personal or confidential data through prompts and outputs; prompt injection, data poisoning and exfiltration through GenAI systems.
Source code and IP exposure to external models; risks inherited from upstream models, plugins, tools and components.
General information about the public text of the framework, not legal advice. Mappings describe how AccuroAI controls support each obligation; scope and conformity decisions remain with your legal, compliance and certification partners.
Because it is the reference point everyone else uses: US federal guidance, state laws such as Colorado's, cyber-insurance questionnaires, and auditors reading NIST CSF 2.0 alongside it. Showing your controls in the four-function vocabulary shortens every one of those conversations.
NIST AI 600-1 (July 2024) names twelve GenAI-specific risks and suggested actions for each. The ones security teams own — data privacy, information security, intellectual property, value-chain integration — are exactly the categories inline inspection and supply-chain vetting make measurable.
MAP and MEASURE almost entirely through discovery, attribution and inline inspection; MANAGE through real-time response, agent gating and incident records; GOVERN through policy enforcement and reporting. Setting risk tolerance and assigning accountability remain organisational decisions.
Yes. AccuroAI maps each artefact to 8 frameworks, so the inventory, logs and oversight records you generate for the AI RMF are reused for the EU AI Act's deployer obligations and ISO 42001's Annex A.
No. This page summarises the public NIST AI RMF 1.0 and AI 600-1 documents and describes how AccuroAI controls support them.