Govern, Map, Measure, Manage — for every AI system you run.
The AI Risk Management Framework organizes AI risk into four functions — Govern, Map, Measure, Manage — and is voluntary guidance, not a standard anyone certifies you against. Govern runs across the other three rather than preceding them. Map establishes context and what the system is actually for; Measure tests it; Manage decides what to do about what you found. A generative-AI profile published in 2024 applies the same four functions to models that generate content.
The hard part is not the framework. It is that Map assumes you know which AI systems you run, and most organizations do not — models arrive inside products, embedded in a vendor's feature release, or built by a team that did not think of it as an AI project. A framework applied to an inventory that is missing half its entries measures the wrong half.
Who it applies to
Any organization that designs, develops, deploys or uses AI systems — which now includes organizations that would not describe themselves as doing anything with AI. Because the framework is voluntary, nobody serves you with it. It arrives through customer due diligence, insurer questionnaires, and internal policy written by people who need a defensible structure to point at.
Voluntary is not the same as optional
The AI RMF has no enforcement behind it, and it is still the structure your obligations get expressed in. It crosswalks cleanly onto ISO 42001, which is certifiable, and onto the EU AI Act, which is law — three regimes that ask overlapping questions about the same systems in three vocabularies. Answering them from three separate inventories guarantees they disagree. One inventory of AI systems, with purpose, owner, risk classification and evidence held per system, answers all three and stays consistent because there is nothing to reconcile.
What it asks, in operating terms
Read as an operating requirement rather than voluntary guidance, the four functions reduce to four standing asks — each answerable from a live inventory rather than a survey.
| What the function asks | Where it is answered |
|---|---|
| Govern — policy, roles and accountability for AI risk | Governance workspace · named owner per AI system |
| Map — know every AI system and what it is for | AI system inventory · shared with ISO 42001 and the AI Act |
| Measure — test the system, record what you found | Assessment records · attached to the system, not to a report |
| Manage — act on what you measured, and show it | Risk management · treatment tracked to verified closure |
What you'd actually look at
In the dashboard, every figure opens on click to the system, the evidence and the person behind it. This excerpt is what an AI inventory is made of:
- Systems inventoried
- 12 · 4 vendor-embedded
- Shared with
- ISO 42001 · EU AI Act · AI RMF
- Assessments current
- 12/12 · each with a named owner
- Open risks
- 3 · treatment dated
- Export
- sealed · sha256:9a47...2d10
Where teams usually start
With a demo walked through by TruSecure — the AI systems you already run pulled into one inventory, a single system opened to its assessment and its owner, the same record answering AI RMF, ISO 42001 and the AI Act. A Resilience Sprint then produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
The NIST AI Risk Management Framework organizes AI risk management into four functions — Govern, Map, Measure, and Manage — and is voluntary guidance rather than a certifiable standard. TruSecure shares a single AI system inventory across AI RMF, ISO 42001, and the EU AI Act.