Skip to main content
FRAMEWORK

Govern, Map, Measure, Manage — for every AI system you run.

The AI Risk Management Framework organizes AI risk into four functions — Govern, Map, Measure, Manage — and is voluntary guidance, not a standard anyone certifies you against. Govern runs across the other three rather than preceding them. Map establishes context and what the system is actually for; Measure tests it; Manage decides what to do about what you found. A generative-AI profile published in 2024 applies the same four functions to models that generate content.

The hard part is not the framework. It is that Map assumes you know which AI systems you run, and most organizations do not — models arrive inside products, embedded in a vendor's feature release, or built by a team that did not think of it as an AI project. A framework applied to an inventory that is missing half its entries measures the wrong half.

Who it applies to

Any organization that designs, develops, deploys or uses AI systems — which now includes organizations that would not describe themselves as doing anything with AI. Because the framework is voluntary, nobody serves you with it. It arrives through customer due diligence, insurer questionnaires, and internal policy written by people who need a defensible structure to point at.

Voluntary is not the same as optional

The AI RMF has no enforcement behind it, and it is still the structure your obligations get expressed in. It crosswalks cleanly onto ISO 42001, which is certifiable, and onto the EU AI Act, which is law — three regimes that ask overlapping questions about the same systems in three vocabularies. Answering them from three separate inventories guarantees they disagree. One inventory of AI systems, with purpose, owner, risk classification and evidence held per system, answers all three and stays consistent because there is nothing to reconcile.

What it asks, in operating terms

Read as an operating requirement rather than voluntary guidance, the four functions reduce to four standing asks — each answerable from a live inventory rather than a survey.

AI RMF functions · how TruSecure answers them
What the function asksWhere it is answered
Govern — policy, roles and accountability for AI riskGovernance workspace · named owner per AI system
Map — know every AI system and what it is forAI system inventory · shared with ISO 42001 and the AI Act
Measure — test the system, record what you foundAssessment records · attached to the system, not to a report
Manage — act on what you measured, and show itRisk management · treatment tracked to verified closure

What you'd actually look at

In the dashboard, every figure opens on click to the system, the evidence and the person behind it. This excerpt is what an AI inventory is made of:

AI system inventory · excerptSample data
Systems inventoried
12 · 4 vendor-embedded
Shared with
ISO 42001 · EU AI Act · AI RMF
Assessments current
12/12 · each with a named owner
Open risks
3 · treatment dated
Export
sealed · sha256:9a47...2d10

Where teams usually start

With a demo walked through by TruSecure — the AI systems you already run pulled into one inventory, a single system opened to its assessment and its owner, the same record answering AI RMF, ISO 42001 and the AI Act. A Resilience Sprint then produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

The NIST AI Risk Management Framework organizes AI risk management into four functions — Govern, Map, Measure, and Manage — and is voluntary guidance rather than a certifiable standard. TruSecure shares a single AI system inventory across AI RMF, ISO 42001, and the EU AI Act.