What is NIST AI RMF?
Governance & ControlThe US NIST AI Risk Management Framework: govern, map, measure, manage. Voluntary but increasingly the default scaffold auditors and enterprise security reviews reach for when they ask how an AI system is controlled.
Why It Matters
The NIST AI Risk Management Framework is voluntary, and it is also the document enterprise security reviews and auditors reach for when they ask how an AI system is controlled. Voluntary in the regulatory sense does not mean optional in the commercial one: a procurement questionnaire that asks how you govern, map, measure, and manage AI risk is asking the RMFโs questions whether it names the framework or not. For teams selling agentic systems into enterprises, the RMF is the shared vocabulary the review happens in.
The Four Functions
Govern. The accountability layer: policies, roles, and a culture where AI risk has a named owner. For agents this is where the governance operating model lives, upstream of any technical control.
Map. Identifying where AI risk actually sits: which systems, which decisions, which stakeholders. For agents, mapping means inventorying what each agent can reach and act on, which is blast-radius work.
Measure. Quantifying the risk: eval coverage, failure rates, oversight quality. The function where eval harnesses, approval-rate monitoring, and drift measurement belong.
Manage. Acting on what the measurement finds: controls, mitigations, incident response. Runtime governance, escalation design, and rollback paths live here.
Where It Breaks
The framework is a scaffold, not a specification, and teams break it in both directions. Some treat it as a checklist, producing governance documents that satisfy the Govern function on paper while no technical control exists. Others treat it as purely technical, measuring and managing without the accountability structure that makes the measurements reach a decision-maker. The RMF works when all four functions connect: governance decides, mapping finds, measurement informs, management acts.
How Flytebit Handles It
We use the RMF as the organizing frame for governance engagements: Map becomes the agent inventory and blast-radius assessment, Measure becomes the eval and oversight instrumentation, Manage becomes the runtime governance layer, and Govern becomes the accountability model that owns all of it. The engagement version is our AI governance and risk work.