NIST AI RMF 1.0,
subcategory by subcategory.
The NIST AI Risk Management Framework (AI RMF 1.0, NIST AI 100-1) is the U.S. federal standard for managing risks in the design, development, deployment, and use of AI systems. Published by the National Institute of Standards and Technology in January 2023, it defines four core functions, GOVERN, MAP, MEASURE, and MANAGE, with categories and subcategories that organizations can adopt to build trustworthy AI. Below is how Clevername’s agent governance platform maps to each relevant subcategory.
Coverage is self-assessed against the AI RMF subcategory definitions; each card names the control.
- Addressed52 subcategories across all four functions.all
- Covered51 with platform-enforced controls.full
- Org-level1 platform-supported, implemented by your organization.shared
- Partial0 with core controls in place.partial
The four functions are broken down below, then each category and subcategory with its control.
Organizational governance of AI risk
Policies, processes, procedures, and practices across the organization related to the mapping, measuring, and managing of AI risks are in place, transparent, and implemented effectively.
Legal and regulatory requirements involving AI are understood, managed, and documented.
The characteristics of trustworthy AI are integrated into organizational policies, processes, procedures, and practices.
Processes, procedures, and practices are in place to determine the appropriate level of risk management activities based on the organization's risk tolerance.
The risk management process and its outcomes are established through transparent policies, procedures, and other controls.
Ongoing monitoring and periodic review of the risk management process and its outcomes are planned and organizational roles and responsibilities are clearly defined.
Mechanisms are in place to inventory AI systems and are resourced per organizational risk priorities.
Processes and procedures are in place for decommissioning and phasing out AI systems safely and in a manner that does not increase risks or harms.
Accountability structures are in place so that the appropriate teams and individuals are empowered, responsible, and trained for mapping, measuring, and managing AI risks.
Roles and responsibilities and lines of communication related to mapping, measuring, and managing AI risks are documented and are clear to individuals and teams throughout the organization.
The organization's personnel and partners receive AI risk management training.
Executive leadership of the organization takes responsibility for decisions about risks associated with AI system development and deployment.
Workforce diversity, equity, inclusion, and accessibility processes are prioritized in the mapping, measuring, and managing of AI risks throughout the lifecycle.
Policies and procedures define and differentiate the roles and responsibilities for human-AI configurations and oversight of AI systems.
Organizational teams are committed to a culture that considers and communicates AI risk.
Organizational policies and practices are in place to foster a critical thinking and safety-first mindset in the design, development, deployment, and use of AI systems.
Organizational teams document risks and potential impacts of AI technology.
Organizational practices are in place to enable AI testing, identification of incidents, and information sharing.
Processes are in place for robust engagement with relevant AI actors.
Organizational policies and practices are in place to collect, consider, prioritize, and integrate feedback from those external to the team that developed or deployed the AI system.
Mechanisms are established to enable AI actors to regularly incorporate adjudicated feedback into system design and implementation.
Policies and procedures are in place that address AI risks and benefits arising from third-party software and data.
Policies and procedures are in place that address risks associated with third-party entities, including risks of infringement of a third party's intellectual property or other rights.
Contingency processes are in place for handling failures or incidents in third-party data or AI systems.
Context and risk identification
Context is established and understood.
Intended purposes, potentially beneficial uses, context-specific laws, norms and expectations, and prospective settings in which the AI system will be deployed are understood and documented.
Organizational risk tolerances are determined and documented.
System requirements (including those related to relevant AI actors) are elicited from and understood by relevant AI actors. Design decisions take socio-technical implications into account.
Categorization of the AI system is performed.
The specific tasks and methods used to implement the tasks that the AI system will support are defined.
Information about the AI system's knowledge limits and how system output may be utilized is documented.
AI capabilities, targeted usage, goals, and expected benefits and costs compared with appropriate benchmarks are understood.
Potential costs, including non-monetary costs, which result from expected or potential AI errors or system functionality and trustworthiness — as connected to organizational risk tolerance — are examined and documented.
Processes for human oversight are defined, assessed, and documented in accordance with organizational policies from the GOVERN function.
Risks and benefits are mapped for all components of the AI system including third-party software and data.
Approaches for mapping AI technology and legal risks of the component AI systems — including the use of third-party data or software — are in place, followed, and documented, as are risks of infringement of a third party's intellectual property or other rights.
Internal risk controls for components of the AI system are identified and documented.
Impacts to individuals, groups, communities, organizations, and society are characterized.
Likelihood and magnitude of each identified impact (both potentially beneficial and harmful) based on expected use, past uses of similar systems, public incident reports, feedback, or other data are identified and documented.
Risk assessment and analysis
Appropriate methods and metrics are identified and applied.
Approaches and metrics for measurement of AI risks enumerated during the MAP function are selected for implementation starting with the most significant AI risks.
Appropriateness of AI metrics and effectiveness of existing measures are regularly assessed and updated, including reports of errors and impacts on affected communities.
AI systems are evaluated for trustworthy characteristics.
AI system performance or assurance criteria are measured qualitatively or quantitatively and demonstrated for conditions similar to deployment conditions.
The functionality and behavior of the AI system and its components — as identified in the MAP function — are monitored when the system is deployed.
The AI system is evaluated regularly for safety risks — as identified in the MAP function. The AI system is demonstrated to be safe, its residual negative risk does not exceed the risk tolerance, and it can fail safely.
AI system security and resilience — as identified in the MAP function — are evaluated and documented.
Risks associated with transparency and accountability — as identified in the MAP function — are examined and documented.
Privacy risk of the AI system — as identified in the MAP function — is examined and documented.
Mechanisms for tracking identified AI risks over time are in place.
Approaches, personnel, and the frequency of periodic risk tracking are in place to regularly identify and track existing, unanticipated, and emergent AI risks based on factors such as intended and actual performance.
Risk tracking approaches are considered for settings where AI risks are difficult to assess using currently available measurement techniques or where metrics are not yet available.
Feedback processes for end users and impacted communities to report problems and appeal outcomes are established.
Feedback about efficacy of measurement is collected and assessed.
Measurement approaches for identifying AI risks are connected to deployment context(s) and informed through consultation with domain experts and relevant AI actors.
Risk treatment and monitoring
AI risks based on the outcomes of the MAP and MEASURE functions are prioritized, responded to, and managed.
A determination is made as to whether the AI system achieves its intended purposes and whether its development or deployment should proceed.
Treatment of documented AI risks is prioritized based on impact, likelihood, and available resources or methods.
Responses to the AI risks deemed high priority are developed, planned, and documented. Risk response options can include mitigating, transferring, avoiding, or accepting.
Negative residual risks (defined as the risks remaining after risk treatment) for each AI system are documented.
Strategies to maximize AI benefits and minimize negative impacts are planned, prepared, implemented, documented, and informed by input from relevant AI actors.
Mechanisms are in place and applied, and continue to be effective, to sustain the value of deployed AI systems.
Procedures are followed to respond to and recover from a previously unknown risk when it is identified.
Mechanisms are in place and applied, and continue to be effective, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use.
AI risks and benefits from third-party entities are managed.
AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented.
Pre-trained models used for deployment are monitored as part of AI system regular monitoring and maintenance.
Risk treatments, including response and recovery, and communication plans for the identified and measured AI risks are documented and monitored regularly.
Post-deployment AI system monitoring plans are implemented, including mechanisms for capturing and evaluating input from users and other relevant AI actors, appeal and override mechanisms, and decommissioning.
Measurable activities for continual improvements are integrated into AI system updates and include regular engagement with interested parties.
Responses to the AI risk management are documented and monitored regularly, and AI risk management plans are updated including when events, incidents, or errors are identified.
How Clevername maps to the four AI RMF functions
The NIST AI RMF is designed for the full AI lifecycle. Clevername provides platform-level enforcement for each function, from organizational governance policies to runtime risk treatment, so that compliance is continuous rather than a point-in-time audit.
GOVERN: Organizational oversight
Agent Review provides structured human oversight with quorum-based governance, role-based accountability, and organization-level policy configuration. Every agent passes a 27-question security intake before activation.
MAP: Risk identification
Review questionnaire systematically identifies risks across scope, security, data handling, autonomy, integration, and compliance. Guardrail profiles document all identified risks and their treatment.
MEASURE: Risk assessment
CleverGuard 4-tier scanner provides quantitative risk measurement. The full governed pipeline (including the beta Tier-3 deep scan, which runs on every request for governed agents and escalates on ambiguity/disagreement for ungoverned traffic) reaches 94.8% detection / 14.75% FP across an in-distribution 310-attack corpus (internal test set); the always-on Tiers 0–2 baseline against live traffic is 94.7% / 2.66% FP on in-distribution attacks (see /cleverguard). Generalization to novel attack styles is lower and actively being improved. Continuous drift detection tracks risks over time. FP dispute system ensures measurement accuracy through feedback loops.
MANAGE: Risk treatment
Gateway enforces risk treatments inline: scoped tokens, budget caps, tool allowlists, and auto-restrict. Key Interception prevents credential exposure. BYOK isolates third-party risk. Every action is audited.
Ready to govern your AI agents?
Start with a free account, or explore the Gateway to add NIST-aligned governance to your existing agent stack in minutes.