Framework Mapping · NIST AI RMF 1.0

NIST AI RMF

Live evidence mapping against the NIST AI Risk Management Framework. TrustLayers does not claim certification — it provides the evidence so you can verify compliance yourself.

How to read this page: Each NIST AI RMF control is mapped to the specific TrustLayers data field that satisfies it. The evidence is live — pulled directly from the execution database. No self-assessment. No checkboxes. Raw data.
1,325
Events in evidence base
2%
Cryptographically sealed
10
Agents under governance
0
Human overrides logged
GOVERN GOVERN
Policies, processes, roles and responsibilities for AI risk management.
GV-1.1
AI risk policies established
Blueprint pre-runtime config defines governance rules before execution.
GV-1.2
Roles and accountability defined
Every event has agent_id — author of every action is recorded.
→ 1325 events with author ID
GV-2.1
Risk tolerance documented
risk_score and severity fields captured per event.
GV-4.1
Organizational practices monitored
Continuous event monitoring across 10 agents.
→ 10 agents monitored
MAP MAP
Categorization of AI risks in context.
MP-2.1
AI context and purpose documented
agent category, description and EU AI Act article stored per agent.
MP-2.3
Sensitive data identified
sensitive_data flag captured on every execution event.
→ 4 sensitive events
MP-3.1
Impacts documented
compliance_status and policy_triggered fields track policy impact.
→ 0 violations logged
MP-5.1
Risks prioritised
anomaly_score and severity fields enable risk prioritisation.
MEASURE MEASURE
Analysis and assessment of AI risk.
MS-1.1
Metrics established and tracked
EEI score calculated across 6 evidence dimensions per agent.
MS-2.1
AI system tested and evaluated
1325 events analyzed with duration_ms, risk_score, anomaly_score.
→ 1325 events
MS-2.5
Bias and drift monitored
drift_detected field flags behavioral deviation per event.
→ 0 drift events
MS-4.1
Risk measurement shared
Public EEI page exposes live evidence scores to any stakeholder.
MANAGE MANAGE
Prioritization and treatment of AI risks.
MG-1.1
Risks treated and tracked
Immutable event log — every action and its outcome recorded.
→ 1325 immutable records
MG-2.2
Human oversight mechanisms
human_override field records every human intervention.
→ 0 overrides recorded
MG-3.1
Responses to incidents documented
error_code, compliance_status and severity logged on every error event.
→ 0 error events logged
MG-4.1
Residual risks documented
Cryptographic SHA-256 hashes seal prompt+output for every event.
→ 2% events cryptographically sealed