Framework Mapping · NIST AI RMF 1.0
NIST AI RMF
Live evidence mapping against the NIST AI Risk Management Framework. TrustLayers does not claim certification — it provides the evidence so you can verify compliance yourself.
How to read this page: Each NIST AI RMF control is mapped to the specific TrustLayers data field that satisfies it. The evidence is live — pulled directly from the execution database. No self-assessment. No checkboxes. Raw data.
1,325
Events in evidence base
2%
Cryptographically sealed
10
Agents under governance
Policies, processes, roles and responsibilities for AI risk management.
GV-1.1
AI risk policies established
Blueprint pre-runtime config defines governance rules before execution.
✓
GV-1.2
Roles and accountability defined
Every event has agent_id — author of every action is recorded.
→ 1325 events with author ID
✓
GV-2.1
Risk tolerance documented
risk_score and severity fields captured per event.
✓
GV-4.1
Organizational practices monitored
Continuous event monitoring across 10 agents.
→ 10 agents monitored
✓
Categorization of AI risks in context.
MP-2.1
AI context and purpose documented
agent category, description and EU AI Act article stored per agent.
✓
MP-2.3
Sensitive data identified
sensitive_data flag captured on every execution event.
→ 4 sensitive events
✓
MP-3.1
compliance_status and policy_triggered fields track policy impact.
→ 0 violations logged
✓
MP-5.1
anomaly_score and severity fields enable risk prioritisation.
✓
Analysis and assessment of AI risk.
MS-1.1
Metrics established and tracked
EEI score calculated across 6 evidence dimensions per agent.
✓
MS-2.1
AI system tested and evaluated
1325 events analyzed with duration_ms, risk_score, anomaly_score.
→ 1325 events
✓
MS-2.5
drift_detected field flags behavioral deviation per event.
→ 0 drift events
✓
MS-4.1
Public EEI page exposes live evidence scores to any stakeholder.
✓
Prioritization and treatment of AI risks.
MG-1.1
Risks treated and tracked
Immutable event log — every action and its outcome recorded.
→ 1325 immutable records
✓
MG-2.2
Human oversight mechanisms
human_override field records every human intervention.
→ 0 overrides recorded
✓
MG-3.1
Responses to incidents documented
error_code, compliance_status and severity logged on every error event.
→ 0 error events logged
✓
MG-4.1
Residual risks documented
Cryptographic SHA-256 hashes seal prompt+output for every event.
→ 2% events cryptographically sealed
✓