Standards and guidance
NIST AI RMF: Agent Risk & Control Evidence
A voluntary framework for managing AI risks; its core functions are Govern, Map, Measure and Manage.
How to use this reference
Use the framework to organise risk ownership, system context, testing and treatment. It is not a NIST certification scheme. Record the version used; NIST reports that AI RMF 1.0 is being revised.
Evidence to discuss
Identify the system scope, control owner, implementation evidence, test results, exceptions and the reviewer responsible for acceptance. Requirements are mapped to the agreed source version; missing and untested controls remain visible.
Source and status
Reference checked on 7 October 2026. This page is an engineering overview, not legal advice or a claim of accreditation, partnership or endorsement.
Govern, Map, Measure and Manage
These are engineering discussion prompts, not a substitute for the source requirements or the appointed reviewer's criteria.
- Govern: who owns the agent and its risk decisions?
- Map and Measure: which actions, contexts and tests define the risk review?
- Manage: how are findings prioritised, changes accepted and controls retested?
Use the security review checklist to organise owners, test records and gaps. The assessment method explains how coverage limits are recorded.
Start with a clear scope
Tell us which systems, actions and review requirements are in scope. We will discuss the work, responsibilities and deliverables before you commit.