Skip to main content
Compliance

NIST AI Risk Management Framework (AI RMF 1.0)

The NIST AI Risk Management Framework (AI RMF 1.0, NIST AI 100-1) is the U.S. federal standard for managing risks in the design, development, deployment, and use of AI systems. Published by the National Institute of Standards and Technology in January 2023, it defines four core functions — GOVERN, MAP, MEASURE, and MANAGE — with categories and subcategories that organizations can adopt to build trustworthy AI.

Below is how Clevername’s agent governance platform maps to each relevant AI RMF subcategory — with specific controls, enforcement mechanisms, and the features that address them.

Subcategories addressed52Across all four functions
Fully covered51Platform-enforced controls
Organizational1Platform-supported, org-implemented
Partially covered0Core controls in place
GOVERN18subcategories addressed
MAP10subcategories addressed
MEASURE12subcategories addressed
MANAGE12subcategories addressed
GOVERN Function

Organizational governance of AI risk

GOVERN 1

Policies, processes, procedures, and practices across the organization related to the mapping, measuring, and managing of AI risks are in place, transparent, and implemented effectively.

GOVERN 1.1

Legal and regulatory requirements involving AI are understood, managed, and documented.

Covered
How Clevername addresses this
Agent Review 27-question security intake explicitly addresses regulatory scope, data classification, and compliance requirements per agent
Guardrail profiles compiled from review answers encode regulatory constraints into machine-enforceable rules
Full audit trail with 30-day retention provides evidence for regulatory inquiries
Agent ReviewAudit Trail
GOVERN 1.2

The characteristics of trustworthy AI are integrated into organizational policies, processes, procedures, and practices.

Covered
How Clevername addresses this
Agent Review gates agent deployment — no agent activates without human quorum governance on trustworthiness criteria
Guardrail profiles enforce trustworthy AI characteristics (scope constraints, scanner levels, autonomy limits) at runtime
Review questionnaire covers safety, security, fairness, transparency, and accountability across 6 question groups
Agent ReviewGateway
GOVERN 1.3

Processes, procedures, and practices are in place to determine the appropriate level of risk management activities based on the organization's risk tolerance.

Covered
How Clevername addresses this
Trust tier scoring (trusted / standard / elevated_review / untrusted) automatically classifies agents by risk score
Organizations configure governance thresholds (50-100%) to calibrate risk tolerance for review decisions
High-risk action patterns (A4) trigger mandatory human approval via SignedApproval — risk tolerance is configurable per org
Agent ReviewGateway
GOVERN 1.4

The risk management process and its outcomes are established through transparent policies, procedures, and other controls.

Covered
How Clevername addresses this
HMAC-signed audit trail provides tamper-evident chain of custody for every API call and governance decision
SIEM forwarding (Splunk, Datadog, Elasticsearch, Sentinel) enables independent external verification
Review submission history, vote records, and guardrail profile versions are fully auditable
Audit TrailAgent Review
GOVERN 1.5

Ongoing monitoring and periodic review of the risk management process and its outcomes are planned and organizational roles and responsibilities are clearly defined.

Covered
How Clevername addresses this
Runtime scope, tool, and model drift is checked on every agent action; behavioral drift is scored against the frozen review baseline on a continuous hourly sweep
SOC console at /dashboard/security/soc provides centralized monitoring with emergency controls
Auto-restrict triggers when drift score exceeds threshold — automated response with clear escalation paths
Drift DetectionAudit Trail
GOVERN 1.6

Mechanisms are in place to inventory AI systems and are resourced per organizational risk priorities.

Covered
How Clevername addresses this
AI agent registry tracks all agents with status (draft / active / restricted), guardrail profiles, and governance state
Shadow AI discovery identifies unregistered agent patterns and surfaces them for agent review
Agent integration bindings provide a complete inventory of which tools, MCP servers, and models each agent uses
Agent ReviewGateway
GOVERN 1.7

Processes and procedures are in place for decommissioning and phasing out AI systems safely and in a manner that does not increase risks or harms.

Covered
How Clevername addresses this
Auto-restrict safely suspends agents that exceed drift thresholds without abrupt termination
90-day task retention with stale schedule auto-disable ensures clean lifecycle management
Review status tracking supports draft, active, restricted, and decommissioned states with audit trail
Drift DetectionGateway
GOVERN 2

Accountability structures are in place so that the appropriate teams and individuals are empowered, responsible, and trained for mapping, measuring, and managing AI risks.

GOVERN 2.1

Roles and responsibilities and lines of communication related to mapping, measuring, and managing AI risks are documented and are clear to individuals and teams throughout the organization.

Covered
How Clevername addresses this
Agent Review defines explicit roles: review chair, reviewers, agent owners, and SOC administrators
Organization-level RBAC with membership roles (owner / admin / member) determines who can submit, govern, or override
SignedApproval receipts for dashboard/JWT emergency SOC actions provide accountability separation
Agent ReviewGateway
GOVERN 2.2

The organization's personnel and partners receive AI risk management training.

Org-Level
How Clevername addresses this
Review questionnaire serves as a structured risk assessment training exercise for agent owners
SOC console provides operational visibility into risk events, serving as ongoing risk awareness
Agent Review
GOVERN 2.3

Executive leadership of the organization takes responsibility for decisions about risks associated with AI system development and deployment.

Covered
How Clevername addresses this
Review chair role enables executive-level oversight and final governance authority
Organization-level review settings (governance threshold, required environments) are admin-only configuration
Bulk governance and group review capabilities allow leadership to set precedent across similar agents
Agent Review
GOVERN 3

Workforce diversity, equity, inclusion, and accessibility processes are prioritized in the mapping, measuring, and managing of AI risks throughout the lifecycle.

GOVERN 3.2

Policies and procedures define and differentiate the roles and responsibilities for human-AI configurations and oversight of AI systems.

Covered
How Clevername addresses this
Agent Review supports human-in-the-loop sign-off before an agent goes active; when a team enables council review it is required, and high-risk actions always require human approval via SignedApproval at runtime
High-risk action patterns (A4) require explicit human sign-off via SignedApproval before execution
FP Dispute system ensures human override capability for automated scanner decisions
Trust tier scoring determines the degree of autonomy vs. oversight required per agent
Agent ReviewGatewayKey Interception
GOVERN 4

Organizational teams are committed to a culture that considers and communicates AI risk.

GOVERN 4.1

Organizational policies and practices are in place to foster a critical thinking and safety-first mindset in the design, development, deployment, and use of AI systems.

Covered
How Clevername addresses this
Review gate enforces safety-first — no agent activates without passing the full security intake assessment
Tier-0 data-label violations are fail-closed — blocked before delivery — and detected secrets are stripped from prompts before the model sees them; the ML injection/scope scanners fail open for availability (with fail-closed strict mode in development for Team+ orgs)
Guardrail profiles encode conservative defaults that must be explicitly relaxed through agent review
Agent ReviewCleverGuard Scanner
GOVERN 4.2

Organizational teams document risks and potential impacts of AI technology.

Covered
How Clevername addresses this
Review questionnaire documents risks across 6 groups: scope, security, data handling, autonomy, integration, and compliance
Guardrail profile compilation produces a structured risk document per agent
Drift events logged to cleverguard_dlp_events create a continuous risk record
Agent ReviewAudit Trail
GOVERN 4.3

Organizational practices are in place to enable AI testing, identification of incidents, and information sharing.

Covered
How Clevername addresses this
SOC console provides centralized incident identification and response coordination
SIEM forwarding enables cross-team information sharing via existing security tooling
FP Dispute system creates a feedback loop for continuous scanner improvement
SignedApproval-based emergency controls support collaborative incident handling where approval is required
GatewayAudit Trail
GOVERN 5

Processes are in place for robust engagement with relevant AI actors.

GOVERN 5.1

Organizational policies and practices are in place to collect, consider, prioritize, and integrate feedback from those external to the team that developed or deployed the AI system.

Covered
How Clevername addresses this
Gateway enables external agent teams (LangChain, CrewAI) to participate in the governance framework
External agents are submitted for agent review alongside internal agents — same governance, same standards
FP Dispute system (5 disputes/hour per user) provides a structured external feedback mechanism
GatewayAgent Review
GOVERN 5.2

Mechanisms are established to enable AI actors to regularly incorporate adjudicated feedback into system design and implementation.

Covered
How Clevername addresses this
Upheld FP disputes generate tuning suggestions that can be applied to update guardrail profiles
Similarity engine auto-governs new agents matching previously governed profiles — institutional learning
Recommendations engine surfaces governance signals from past review decisions
GatewayAgent Review
GOVERN 6

Policies and procedures are in place that address AI risks and benefits arising from third-party software and data.

GOVERN 6.1

Policies and procedures are in place that address risks associated with third-party entities, including risks of infringement of a third party's intellectual property or other rights.

Covered
How Clevername addresses this
BYOK model keeps provider keys user-owned, stored server-side in Secret Manager, and isolated with IAM-backed access controls
Agent-key bindings enforce cross-agent credential isolation for third-party services
MCP Marketplace with admin review gates third-party tool activation
Reserved MCP server name blocklist prevents third-party namespace hijacking
BYOKKey InterceptionAgent Review
GOVERN 6.2

Contingency processes are in place for handling failures or incidents in third-party data or AI systems.

Covered
How Clevername addresses this
Key health monitoring validates stored third-party keys every 6 hours — unhealthy keys flagged proactively
Auto-detect resolves ambiguous keys via parallel provider validation
Budget enforcement with $0.01 minimum reservation prevents third-party cost overruns (TOCTOU fix)
Rate limiting (instance-count-aware) prevents cascading failures from third-party outages
Key InterceptionBYOKGateway
MAP Function

Context and risk identification

MAP 1

Context is established and understood.

MAP 1.1

Intended purposes, potentially beneficial uses, context-specific laws, norms and expectations, and prospective settings in which the AI system will be deployed are understood and documented.

Covered
How Clevername addresses this
Review questionnaire Group 1 (Scope) captures intended purpose, allowed tools, allowed models, and deployment context
Guardrail profile scope section encodes allowed_mcp_servers, allowed_skills, and mcp_tool_filter constraints
Agent registry documents deployment context (environment, integration bindings, model assignments)
Agent ReviewGateway
MAP 1.5

Organizational risk tolerances are determined and documented.

Covered
How Clevername addresses this
Per-organization governance threshold (50-100%) explicitly documents risk tolerance
Review-enabled environments (production / staging / all) define where governance is enforced
Trust tier boundaries (risk score ranges) formalize organizational risk appetite per agent
Agent Review
MAP 1.6

System requirements (including those related to relevant AI actors) are elicited from and understood by relevant AI actors. Design decisions take socio-technical implications into account.

Covered
How Clevername addresses this
Review questionnaire captures requirements across 6 groups covering technical, security, and operational dimensions
Integration bindings document system dependencies and actor relationships
Human oversight requirements (A4 high-risk patterns) explicitly encoded in guardrail profiles
Agent ReviewGateway
MAP 2

Categorization of the AI system is performed.

MAP 2.1

The specific tasks and methods used to implement the tasks that the AI system will support are defined.

Covered
How Clevername addresses this
Review questionnaire defines allowed tools, MCP servers, and skills per agent — explicit task boundaries
Guardrail profile mcp_tool_filter (Tier 1a/b/c) specifies exactly which tool methods each agent can invoke
Agent-key bindings map which API credentials an agent can use, constraining available methods
Agent ReviewScoped Tokens
MAP 2.2

Information about the AI system's knowledge limits and how system output may be utilized is documented.

Covered
How Clevername addresses this
Model whitelist (chat / economy / balanced / quality / auto) constrains which models each agent can access
Scanner config per agent documents content filtering levels and output handling rules
Guardrail profiles capture autonomy levels and human oversight requirements
Agent ReviewGateway
MAP 3

AI capabilities, targeted usage, goals, and expected benefits and costs compared with appropriate benchmarks are understood.

MAP 3.2

Potential costs, including non-monetary costs, which result from expected or potential AI errors or system functionality and trustworthiness — as connected to organizational risk tolerance — are examined and documented.

Covered
How Clevername addresses this
Budget caps per agent and per spawn tree quantify and constrain expected monetary costs
Risk score (0-100) quantifies potential cost of agent errors based on questionnaire responses
Trust tier scoring translates risk assessment into operational constraints
GatewayAgent Review
MAP 3.5

Processes for human oversight are defined, assessed, and documented in accordance with organizational policies from the GOVERN function.

Covered
How Clevername addresses this
A4 high-risk action patterns define exactly which actions require human sign-off via SignedApproval
Trust tier determines oversight level: untrusted agents require elevated review for all actions
Agent Review is a documented human oversight process with vote records and rationale
Agent ReviewGateway
MAP 4

Risks and benefits are mapped for all components of the AI system including third-party software and data.

MAP 4.1

Approaches for mapping AI technology and legal risks of the component AI systems — including the use of third-party data or software — are in place, followed, and documented, as are risks of infringement of a third party's intellectual property or other rights.

Covered
How Clevername addresses this
Integration binding fingerprints track all third-party dependencies per agent; changes trigger re-review
BYOK model maps third-party API provider risk to specific user-owned credentials
MCP Marketplace review process documents risks of each third-party tool integration
Agent ReviewBYOKGateway
MAP 4.2

Internal risk controls for components of the AI system are identified and documented.

Covered
How Clevername addresses this
Guardrail profiles document all internal controls per agent: scanner config, tool allowlists, budget limits, autonomy constraints
Scoped token parameters (tool allowlist, budget, expiry) serve as documented risk control specifications
Version hash tracks control configuration — any modification requires re-governance
GatewayScoped TokensAgent Review
MAP 5

Impacts to individuals, groups, communities, organizations, and society are characterized.

MAP 5.1

Likelihood and magnitude of each identified impact (both potentially beneficial and harmful) based on expected use, past uses of similar systems, public incident reports, feedback, or other data are identified and documented.

Covered
How Clevername addresses this
Risk score calculation quantifies likelihood and magnitude of potential harm per agent (0-100 scale)
Review similarity engine compares new submissions against historical governed/denied profiles
Per-agent usage tracking and drift event history provide empirical impact data
Agent ReviewDrift DetectionAudit Trail
MEASURE Function

Risk assessment and analysis

MEASURE 1

Appropriate methods and metrics are identified and applied.

MEASURE 1.1

Approaches and metrics for measurement of AI risks enumerated during the MAP function are selected for implementation starting with the most significant AI risks.

Covered
How Clevername addresses this
CleverGuard 4-tier scanner (data-label gate, regex pattern shield, Gemma 3 4B ML classifier, LLM classification) provides layered risk measurement
ML classifier (Gemma 3 4B + LoRA) contributes to the governed pipeline, which (including the beta Tier-3 deep scan, which runs on every request for governed agents and escalates on ambiguity/disagreement for ungoverned traffic) reaches 94.8% detection / 14.75% FP across a 310-attack corpus — the always-on Tiers 0–2 baseline measured against live traffic is 94.7% / 2.66% FP (see /cleverguard); metrics are tracked and documented
Risk score computation prioritizes significant risks: high-risk patterns weighted more heavily in scoring
CleverGuard ScannerAgent Review
MEASURE 1.2

Appropriateness of AI metrics and effectiveness of existing measures are regularly assessed and updated, including reports of errors and impacts on affected communities.

Covered
How Clevername addresses this
FP Dispute system provides continuous feedback on scanner accuracy — upheld disputes drive metric recalibration
Tuning suggestions generated from disputes can be applied to update guardrail profiles and scanner config
Red team testing (310 attacks + 278 benign) validates scanner effectiveness with documented results
CleverGuard ScannerGateway
MEASURE 2

AI systems are evaluated for trustworthy characteristics.

MEASURE 2.3

AI system performance or assurance criteria are measured qualitatively or quantitatively and demonstrated for conditions similar to deployment conditions.

Covered
How Clevername addresses this
Gateway requests enforce the same scanner config and guardrail profiles in testing as in production
Review questionnaire validates agent behavior against deployment-condition criteria before activation
Version hash ensures deployment configuration matches exactly what was reviewed and governed
GatewayAgent Review
MEASURE 2.4

The functionality and behavior of the AI system and its components — as identified in the MAP function — are monitored when the system is deployed.

Covered
How Clevername addresses this
In-session drift detection checks every tool call, model selection, and scope boundary in real time and pauses the session on violation
Combined drift scoring tracks tool drift, model drift, and scope violations with auto-restrict capability
SOC console provides live dashboards of deployed agent behavior and anomaly detection
Drift DetectionGatewayAudit Trail
MEASURE 2.6

The AI system is evaluated regularly for safety risks — as identified in the MAP function. The AI system is demonstrated to be safe, its residual negative risk does not exceed the risk tolerance, and it can fail safely.

Covered
How Clevername addresses this
CleverGuard scanner evaluates every input and output for safety risks in real time (10-20ms per classification)
Auto-restrict suspends agents exceeding drift thresholds — safe failure mode that preserves system integrity
Fail-closed design: gateway, session checks, and budget enforcement default to deny on uncertainty
CleverGuard ScannerDrift DetectionGateway
MEASURE 2.7

AI system security and resilience — as identified in the MAP function — are evaluated and documented.

Covered
How Clevername addresses this
4-tier scanner architecture with ML classifier resistant to character-level mutation attacks (genetic algorithm fuzzing)
P4 unicode homoglyph and zero-width evasion detection (NFKC normalization + strip)
3 rounds of security hardening documented: IDOR fixes, fail-open elimination, TOCTOU budget fix, IP binding
Red team results documented: ~60% (zero-setup default, T1+ML+NER config) to 94.8% (full governed pipeline, including the beta Tier-3 deep scan) detection rates, at a 14.75% false-positive rate on the governed pipeline — 310 attacks + 278 benign, internal test set. The always-on Tiers 0–2 baseline measured against live traffic is 94.7% / 2.66% FP (see /cleverguard)
CleverGuard ScannerGateway
MEASURE 2.8

Risks associated with transparency and accountability — as identified in the MAP function — are examined and documented.

Covered
How Clevername addresses this
HMAC-signed audit trail creates tamper-evident accountability chain for every action
Review vote records provide transparent decision rationale for governance outcomes
SIEM forwarding enables independent third-party verification of all governance decisions
Audit TrailAgent Review
MEASURE 2.10

Privacy risk of the AI system — as identified in the MAP function — is examined and documented.

Covered
How Clevername addresses this
Regex + ML PII detection (SSN, credit card, phone, email) flags sensitive entities in agent inputs and outputs
Key Interception strips API credentials from prompts before they reach the LLM — prevents credential exposure
Bare 9-digit SSN detection catches unformatted social security numbers that regex patterns miss
Output scanning redacts sensitive data before it leaves the gateway in agent responses
CleverGuard ScannerKey Interception
MEASURE 3

Mechanisms for tracking identified AI risks over time are in place.

MEASURE 3.1

Approaches, personnel, and the frequency of periodic risk tracking are in place to regularly identify and track existing, unanticipated, and emergent AI risks based on factors such as intended and actual performance.

Covered
How Clevername addresses this
In-session scope/tool/model drift is tracked in real time on every action; behavioral-baseline drift is swept hourly — continuous coverage across both cadences
Shadow AI discovery identifies unanticipated agent patterns appearing outside the governance framework
Combined drift scoring aggregates tool drift, model drift, and scope violations into a single trackable metric
Per-agent usage tracking provides historical performance data for trend analysis
Drift DetectionGatewayAudit Trail
MEASURE 3.2

Risk tracking approaches are considered for settings where AI risks are difficult to assess using currently available measurement techniques or where metrics are not yet available.

Covered
How Clevername addresses this
LLM classifier (T5) provides semantic analysis for risks that cannot be captured by pattern matching or statistical methods
Questionnaire-based context scoring adds +12% detection on scope-violation attacks where pure scanning fails
Human review fills measurement gaps — quorum voting applies expert judgment where automation is insufficient
CleverGuard ScannerAgent Review
MEASURE 3.3

Feedback processes for end users and impacted communities to report problems and appeal outcomes are established.

Covered
How Clevername addresses this
FP Dispute system at /v1/guard/disputes allows users to challenge false positive scanner blocks
LLM-powered dispute review with full conversation context returns verdicts: false_positive / true_positive / inconclusive
SOC admin human override ensures disputed decisions receive expert review
Rate limited (5 disputes/hour) to prevent abuse while maintaining accessibility
GatewayCleverGuard Scanner
MEASURE 4

Feedback about efficacy of measurement is collected and assessed.

MEASURE 4.1

Measurement approaches for identifying AI risks are connected to deployment context(s) and informed through consultation with domain experts and relevant AI actors.

Covered
How Clevername addresses this
Gateway requests carry deployment context (agent ID, org, guardrail profile) into every scanner evaluation
Review questionnaire answers inform scanner configuration per agent — measurement is context-aware
Tuning suggestions from FP disputes feed deployment-specific learnings back into measurement approaches
GatewayAgent ReviewCleverGuard Scanner
MANAGE Function

Risk treatment and monitoring

MANAGE 1

AI risks based on the outcomes of the MAP and MEASURE functions are prioritized, responded to, and managed.

MANAGE 1.1

A determination is made as to whether the AI system achieves its intended purposes and whether its development or deployment should proceed.

Covered
How Clevername addresses this
Review gate enforces go/no-go decisions: agents are governed, denied, or require resubmission based on quorum vote
Version hash revalidation catches configuration drift between governance and activation — blocks stale configurations
Auto-govern with similarity scoring provides rapid decisions for low-risk agents matching governed precedents
Agent ReviewGateway
MANAGE 1.2

Treatment of documented AI risks is prioritized based on impact, likelihood, and available resources or methods.

Covered
How Clevername addresses this
Risk score (0-100) combines impact and likelihood factors from review questionnaire for prioritized treatment
Trust tier mapping translates risk scores into graduated enforcement: 0-30 trusted, 31-60 standard, 61+ elevated review
High-risk action patterns receive the most aggressive treatment: mandatory human approval before execution
Agent ReviewGateway
MANAGE 1.3

Responses to the AI risks deemed high priority are developed, planned, and documented. Risk response options can include mitigating, transferring, avoiding, or accepting.

Covered
How Clevername addresses this
Mitigate: guardrail profiles constrain scope, scanner levels, and tool access to reduce risk
Avoid: review denial blocks deployment of agents that exceed risk tolerance
Accept: auto-govern with documented similarity scoring for agents matching governed low-risk profiles
Transfer: SignedApproval delegates high-risk decisions to authorized human approvers
Agent ReviewGatewayScoped Tokens
MANAGE 1.4

Negative residual risks (defined as the risks remaining after risk treatment) for each AI system are documented.

Covered
How Clevername addresses this
Guardrail profiles with partial coverage status explicitly document areas where residual risk exists
Review submission records capture known limitations and risk acceptance rationale
Drift detection provides ongoing quantification of residual risk through combined drift scoring
Agent ReviewDrift Detection
MANAGE 2

Strategies to maximize AI benefits and minimize negative impacts are planned, prepared, implemented, documented, and informed by input from relevant AI actors.

MANAGE 2.2

Mechanisms are in place and applied, and continue to be effective, to sustain the value of deployed AI systems.

Covered
How Clevername addresses this
Continuous drift detection ensures deployed agents maintain alignment with governed behavior over time
Key health monitoring validates third-party credentials every 6 hours, flagging degradation before it impacts value
Stale schedule auto-disable and 90-day task retention prevent abandoned agents from consuming resources
Drift DetectionKey InterceptionGateway
MANAGE 2.3

Procedures are followed to respond to and recover from a previously unknown risk when it is identified.

Covered
How Clevername addresses this
SOC emergency controls enable immediate response to newly discovered risks with SignedApproval receipts or audited SOAR-key execution
Auto-restrict automatically suspends agents when drift scoring identifies previously unknown risk patterns
FP Dispute system provides a structured process for recalibrating after false classifications
SIEM forwarding ensures external security teams are immediately informed of new risk events
GatewayDrift DetectionAudit Trail
MANAGE 2.4

Mechanisms are in place and applied, and continue to be effective, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use.

Covered
How Clevername addresses this
Auto-restrict suspends agents exceeding drift score thresholds on the hourly behavioral sweep — automatic disengagement
SOC emergency controls provide manual override to deactivate any agent instantly
Review status transitions (active to restricted) provide formal deactivation with audit trail
Spawn policy enforcement limits (max depth, concurrency) prevent cascading impact from underperforming agents
Drift DetectionGatewayAgent Review
MANAGE 3

AI risks and benefits from third-party entities are managed.

MANAGE 3.1

AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented.

Covered
How Clevername addresses this
Key health monitoring validates third-party API keys every 6 hours with proactive alerting
BYOK model isolates third-party credential risk to individual users — no shared key exposure
Agent-key bindings enforce per-agent credential isolation for third-party services
Budget enforcement with aggregate spend tracking prevents third-party cost overruns
Key InterceptionBYOKScoped Tokens
MANAGE 3.2

Pre-trained models used for deployment are monitored as part of AI system regular monitoring and maintenance.

Covered
How Clevername addresses this
Model drift detection flags unauthorized model changes against the frozen review baseline
Model whitelist enforcement ensures agents can only use governance-approved models
Version hash includes model configuration — model changes trigger mandatory re-review
Drift DetectionAgent Review
MANAGE 4

Risk treatments, including response and recovery, and communication plans for the identified and measured AI risks are documented and monitored regularly.

MANAGE 4.1

Post-deployment AI system monitoring plans are implemented, including mechanisms for capturing and evaluating input from users and other relevant AI actors, appeal and override mechanisms, and decommissioning.

Covered
How Clevername addresses this
Continuous drift detection is the primary post-deployment monitoring mechanism — real-time in-session checks plus an hourly behavioral sweep
FP Dispute system provides structured appeal and override for scanner decisions
SOC console captures operational input from security administrators and agent owners
Stale schedule auto-disable and agent lifecycle management support decommissioning
Drift DetectionGatewayAudit Trail
MANAGE 4.2

Measurable activities for continual improvements are integrated into AI system updates and include regular engagement with interested parties.

Covered
How Clevername addresses this
FP Dispute tuning suggestions provide measurable improvement actions that can be applied to guardrail profiles
Similarity engine learns from past review decisions — auto-govern accuracy improves with each reviewed agent
Recommendations engine surfaces historical patterns to inform ongoing governance improvement
GatewayAgent Review
MANAGE 4.3

Responses to the AI risk management are documented and monitored regularly, and AI risk management plans are updated including when events, incidents, or errors are identified.

Covered
How Clevername addresses this
HMAC-signed audit trail provides tamper-evident documentation of all risk management responses
Drift events create an immutable record of incidents with timestamps, affected agents, and responses taken
SIEM forwarding ensures incident records flow to external monitoring systems for independent tracking
Review resubmission workflow handles plan updates: version hash change triggers re-review of risk management approach
Audit TrailDrift DetectionAgent Review
Our Approach

How Clevername maps to the four AI RMF functions

The NIST AI RMF is designed for the full AI lifecycle. Clevername provides platform-level enforcement for each function — from organizational governance policies to runtime risk treatment — so that compliance is continuous rather than a point-in-time audit.

GOVERN: Organizational oversight

Agent Review provides structured human oversight with quorum-based governance, role-based accountability, and organization-level policy configuration. Every agent passes a 27-question security intake before activation.

MAP: Risk identification

Review questionnaire systematically identifies risks across scope, security, data handling, autonomy, integration, and compliance. Guardrail profiles document all identified risks and their treatment.

MEASURE: Risk assessment

CleverGuard 4-tier scanner provides quantitative risk measurement — the full governed pipeline (including the beta Tier-3 deep scan, which runs on every request for governed agents and escalates on ambiguity/disagreement for ungoverned traffic) reaches 94.8% detection / 14.75% FP across a 310-attack corpus (internal test set); the always-on Tiers 0–2 baseline against live traffic is 94.7% / 2.66% FP (see /cleverguard). Continuous drift detection tracks risks over time. FP dispute system ensures measurement accuracy through feedback loops.

MANAGE: Risk treatment

Gateway enforces risk treatments inline — scoped tokens, budget caps, tool allowlists, and auto-restrict. Key Interception prevents credential exposure. BYOK isolates third-party risk. Every action is audited.

By the Numbers
4RMF functionsGOVERN, MAP, MEASURE, MANAGE
52SubcategoriesAddressed by platform controls
27Review questions6-group security intake
94.8%Detection rateFull governed pipeline (incl. beta Tier-3) · 14.75% false-positive rate

Ready to govern your AI agents?

Start with a free account, or explore the Gateway to add NIST-aligned governance to your existing agent stack in minutes.