NIST AI RMF MANAGE
Prioritise, respond and recover
AIGE-OBL-NISTRMF-MANAGE. Drawn from chapter 08.
Text alternative
- Clause: NIST AI RMF, MANAGE.
- Duty holder: Not stated.
- Applies from: No date, Voluntary.
- Artefact: Runtime guardrails.
- Layers: Layer 04, Layer 05.
- Evidence record: AI incident record, +9 more.
- Record schemas: AI incident record , Decommissioning runbook , Go/no-go decision , Post-market monitoring plan , Risk register entry , Evidence record , Control observation , Agent register entry , Vendor due-diligence response , Deployment decision record .
- The same topic in 25 other frameworks; the crosswalk section below links each clause.
- Id
AIGE-OBL-NISTRMF-MANAGE- Instrument
- NIST AI RMF framework
- Compared side by side
- NIST AI RMF vs ISO 42001 · NIST AI RMF vs EU AI Act
- Clause
- MANAGE
- Applies from
- No date Voluntary · Voluntary (AI RMF 1.0, January 2023)
The artefact that evidences it
Runtime guardrails; incident pipeline; continuous assurance.
Patterns that build it
- Continuous Assurance Telemetry (layer 5)
- Runtime Guardrail (layer 4)
- Kill Switch / Circuit Breaker (layer 4)
- Incident Pipeline (layer 5)
- Machine-Readable Evidence (OSCAL) (layer 5)
- Agent Identity & Scoped Credentials (layer 4)
- Human-in-the-loop Gate (layer 4)
- Model Artefact Integrity (layer 2 and 4)
- Decision Notice & Contest Path (layer 4 and 5)
- Sanctioned AI Gateway (layer 4 and 2)
- Staged Rollout with Rollback Criteria (layer 4)
- Drift & Fairness Monitor (layer 4 and 5)
- Downstream Use Register (layer 2 and 1)
- Disclosure & Notification Pipeline (layer 5 and 2)
- Deactivation, Localisation & Retirement Runbook (layer 4 and 2)
The same topic in other frameworks
From the topic crosswalk: the clauses filed under the same topics as this one. Mappings are illustrative, not a claim of conformity.
Risk management
- EU AI Act Art. 9 Risk management system (core)
- ISO 42001 6.1.2 AI risk assessment (core)
- ISO 42001 6.1.3 AI risk treatment (core)
- ISO 42001 8.2 AI risk assessment (operation) (core)
- ISO 42001 8.3 AI risk treatment (operation) (core)
- NIST AI RMF MAP 1 MAP 1: Context is established and understood (core)
- NIST AI RMF MAP 5 MAP 5: Impacts to individuals, groups, communities, organizations, and society are characterized (core)
- TC260 Framework 3.0 TC260 2 Classification of AI safety risks (core)
- TC260 Framework 3.0 TC260 Summary table Risks × technological × governance measures (core)
- ISO 23894 23894 6.4 Risk assessment (core) (clause not verified)
- ISO 23894 23894 6.5 Risk treatment (core) (clause not verified)
- NIST AI RMF GOVERN 1.3 GOVERN 1.3: Processes, procedures, and practices are in place to determine the needed level of risk management activities based on the organization's risk tolerance (core)
- NIST AI RMF MAP 1.5 MAP 1.5: Organizational risk tolerances are determined and documented (core)
- NIST AI RMF MEASURE 3 MEASURE 3: Mechanisms for tracking identified AI risks over time are in place (core)
- CSA AICM GRC-02 Risk Management Program (core)
- Korea AI Act Art. 34(1)(1) Risk management plan for high-impact AI (core)
- UK ATRS ATRS 2.5.2 Risks and mitigations (core)
- Singapore Agentic Agentic 2.1 Assess and bound the risks upfront (core)
- CoE Convention CoE Art. 16 Risk and impact management framework (core)
- prEN 18228 prEN 18228 AI risk management (draft; supports Art. 9) (core) (clause not verified)
- GAO AI Accountability 1.6 Risk management: implement an AI-specific risk management plan to systematically identify, analyze, and mitigate risks (core)
- ISO 42001 A.6 AI system life cycle
- NIST AI RMF MEASURE 2 MEASURE 2: AI systems are evaluated for trustworthy characteristics
- TC260 Framework 3.0 TC260 5.3.19 Re-assessment on material change
- China GenAI Measures GenAI Art. 17 Security assessment and algorithm filing
- China Algo. Rec. AlgoRec Art. 27 Security assessment
- EU AI Act Art. 3 Definitions
- ISO 42001 6.1.4 AI system impact assessment
- ISO 23894 23894 6.6 Monitoring and review (clause not verified)
- GPAI Code Safety C1 Commitment 1: Safety and Security Framework
- GPAI Code Safety C3 Commitment 3: Systemic risk analysis
- CSA AICM MDS-12 Open Model Risk Assessment
- OECD AI Principles OECD 1.5(c) Systematic risk management at each lifecycle phase
Logging and traceability
- EU AI Act Art. 12 Record-keeping (core)
- ISO 42001 A.6 AI system life cycle (core)
- TC260 Framework 3.0 TC260 App. 2 II.6 Continuous monitoring and auditing (core)
- TC260 Framework 3.0 TC260 5.3.6 Logs kept and audited (core)
- EU AI Act Art. 26(6) Deployers keep the automatically generated logs (core)
- ISO 42001 A.6.2.8 AI system recording of event logs (core) (clause not verified)
- CSA AICM LOG-09 Log Records (core)
- Korea AI Act Art. 34(1)(5) Documents showing the measures taken (core)
- OECD AI Principles OECD 1.5(b) Traceability of datasets, processes and decisions (core)
- prEN 18229-1 prEN 18229-1 AI trustworthiness framework, Part 1: logging (draft; supports Art. 12) (core) (clause not verified)
- GAO AI Accountability 4.3 Traceability: document results of monitoring activities and any corrective actions taken (core)
- EU AI Act Art. 26 Obligations of deployers of high-risk AI systems
- NIST AI RMF MEASURE 3 MEASURE 3: Mechanisms for tracking identified AI risks over time are in place
- China AI Labelling Label Art. 5 Implicit metadata labels
- EU AI Act Art. 19 Automatically generated logs
- CSA AICM LOG-12 Transaction/Activity Logging
- Singapore Agentic Agentic 2.3.3 When deploying, continuously monitor and test
Human oversight
- EU AI Act Art. 14 Human oversight (core)
- ISO 42001 A.9 Use of AI systems (core)
- TC260 Framework 3.0 TC260 App. 2 II.3 Strengthen human approval (core)
- GDPR Art. 22 Automated individual decision-making, including profiling (core)
- NIST AI RMF MAP 3.5 MAP 3.5: Processes for human oversight are defined, assessed, and documented in accordance with organizational policies from the GOVERN function (core)
- CSA AICM GRC-15 Human supervision (core)
- Korea AI Act Art. 34(1)(4) Human management and supervision (core)
- UK DUAA UK GDPR Art. 22C Safeguards for automated decision-making (core)
- UK ATRS ATRS 2.3.2 Human review (core)
- Singapore Agentic Agentic 2.2.2 Design for meaningful human oversight (core)
- GAO AI Accountability 3.9 Human supervision: define and develop procedures for human supervision of the AI system (core)
- EU AI Act Art. 26 Obligations of deployers of high-risk AI systems
- NIST AI RMF GOVERN 3.2 GOVERN 3.2: Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight of AI systems
- China Algo. Rec. AlgoRec Art. 17 User option to switch off
- China GenAI Measures GenAI Art. 10 User guidance and protection
- EU AI Act Art. 14(4)(b) Awareness of automation bias
- OWASP Agentic ASI09 Human-Agent Trust Exploitation
- CoE Convention CoE Art. 8 Transparency and oversight
- OECD AI Principles OECD 1.2(b) Human agency and oversight safeguards
Runtime guardrails
- ISO 42001 A.9 Use of AI systems (core)
- TC260 Framework 3.0 TC260 App. 2 II.5 Dynamic runtime management (core)
- TC260 Framework 3.0 TC260 3.2.1 Technological countermeasures for agentic AI (core)
- China GenAI Measures GenAI Art. 10 Guided, bounded use (core)
- China GenAI Measures GenAI Art. 14 Stop unlawful generation (core)
- China Deep Synthesis DeepSyn Art. 10 Input and output review (core)
- CSA AICM TVM-13 Guardrails (core)
- CSA AICM AIS-09 Input Validation (core)
- CSA AICM AIS-10 Output Validation (core)
- OWASP LLM LLM01:2026 Prompt Injection (core)
- OWASP LLM LLM10:2026 Improper Output Handling (core)
- Singapore Agentic Agentic 2.3.1 During design and development, use technical controls (core)
- EU AI Act Art. 5 Prohibited AI practices
- EU AI Act Art. 15 Accuracy, robustness and cybersecurity
- ISO 42001 A.6 AI system life cycle
- China Algo. Rec. AlgoRec Art. 8 Periodic algorithm review
- China Algo. Rec. AlgoRec Art. 9 Feature database for unlawful content
- EU AI Act Art. 5(1)(a)–(b) Manipulative techniques; exploitation of vulnerabilities
- GPAI Code Safety C5 Commitment 5: Safety mitigations
- OWASP LLM LLM06:2026 Unbounded Consumption
Incident response and monitoring
- EU AI Act Art. 72 Post-market monitoring by providers and post-market monitoring plan (core)
- EU AI Act Art. 73 Reporting of serious incidents (core)
- ISO 42001 A.8 Information for interested parties (core)
- ISO 42001 10.2 Nonconformity and corrective action (core)
- TC260 Framework 3.0 TC260 5.3.7 Real-time risk monitoring (core)
- TC260 Framework 3.0 TC260 5.3.18 Incident reporting (core)
- China GenAI Measures GenAI Art. 14 Handle and report unlawful content (core)
- China GenAI Measures GenAI Art. 15 Complaint and reporting mechanism (core)
- EU AI Act Art. 26(5) Deployer monitoring, informing the provider and suspending use (core)
- GPAI Code Safety C9 Commitment 9: Serious incident reporting (core)
- GDPR Arts. 33–34 Notification and communication of a personal data breach (core)
- CSA AICM SEF-07 Incident Management and Response (core)
- CSA AICM SEF-08 Security Breach Notification (core)
- Korea AI Act Art. 32(1) Safety duties for AI above the compute threshold (core)
- Singapore GenAI GenAI 4 Incident Reporting (core)
- Singapore Agentic Agentic 2.3.3 When deploying, continuously monitor and test (core)
- G7 Code G7 Action 2 Identify and mitigate vulnerabilities, incidents and misuse after deployment (core)
- G7 Code G7 Action 4 Responsible information sharing and reporting of incidents (core)
- GAO AI Accountability 4.1 Planning: develop plans for continuous or routine monitoring of the AI system (core)
- GAO AI Accountability 4.2 Drift: establish the range of data and model drift that is acceptable (core)
- EU AI Act Art. 55 Obligations for providers of general-purpose AI models with systemic risk
- TC260 Framework 3.0 TC260 App. 2 II.6 Emergency plans
- China Algo. Rec. AlgoRec Art. 7 Security management and emergency response
- EU AI Act Art. 3(49) Definition of serious incident
- EU AI Act Art. 20 Corrective actions and duty of information
- GPAI Code Safety 3.5 Measure 3.5: Post-market monitoring
- NIST AI RMF GOVERN 4.3 GOVERN 4.3: Organizational practices are in place to enable AI testing, identification of incidents, and information sharing
Supply chain and third parties
- EU AI Act Art. 25 Responsibilities along the AI value chain (core)
- ISO 42001 A.10 Third-party and customer relationships (core)
- NIST AI RMF GOVERN 6 GOVERN 6: Policies and procedures are in place to address AI risks and benefits arising from third-party software and data and other supply chain issues (core)
- NIST AI RMF MAP 4 MAP 4: Risks and benefits are mapped for all AI system components including third-party software and data (core)
- TC260 Framework 3.0 TC260 App. 2 II.4 Supply chain and tool management (core)
- EU AI Act Art. 25(4) Written agreement with third-party suppliers (core)
- GDPR Art. 28 Processor (core)
- CSA AICM STA-10 Supply Chain Risk Management (core)
- CSA AICM STA-09 Service Bill of Material (BOM) (core)
- OWASP LLM LLM04:2026 Supply Chain (core)
- OWASP Agentic ASI04 Agentic Supply Chain Vulnerabilities (core)
- EU AI Act Art. 26 Obligations of deployers of high-risk AI systems
- TC260 Framework 3.0 TC260 4.4.4 Open-source ecosystem
- China GenAI Measures GenAI Art. 7 Lawful data and model sources
- China Deep Synthesis DeepSyn Art. 14 Providers and technical supporters
- EU AI Act Art. 22 Authorised representatives of providers of high-risk AI systems
- EU AI Act Art. 23 Obligations of importers
- EU AI Act Art. 24 Obligations of distributors
- EU AI Act Art. 54 Authorised representatives of providers of general-purpose AI models
- GPAI Code Transparency 1.2 Providing relevant information
- GDPR Arts. 44–46 Transfers to third countries
- NIST AI RMF GOVERN 6.2 GOVERN 6.2: Contingency processes are in place to handle failures or incidents in third-party data or AI systems deemed to be high-risk
- UK ATRS ATRS 2.1.4 Third party involvement
- G7 Code G7 Action 11 Implement data input measures and protect personal data and intellectual property
- GAO AI Accountability 2.6 Dependency: assess interconnectivities and dependencies of data streams that operationalize the AI system
Deployment, change and decommissioning
- EU AI Act Art. 26 Obligations of deployers of high-risk AI systems (core)
- ISO 42001 A.6.2.5 AI system deployment (core) (clause not verified)
- ISO 42001 A.6.2.6 AI system operation and monitoring (core) (clause not verified)
- NIST AI RMF GOVERN 1.7 GOVERN 1.7: Processes and procedures are in place for decommissioning and phasing out AI systems safely and in a manner that does not increase risks or decrease the organization's trustworthiness (core)
- CSA AICM AIS-06 Secure Application Deployment (core)
- EU AI Act Art. 25 Responsibilities along the AI value chain
- EU AI Act Art. 43(4) New conformity assessment on substantial modification
- EU AI Act Art. 20 Corrective actions and duty of information
- EU AI Act Art. 79 Procedure at national level for dealing with AI systems presenting a risk
- EU AI Act Art. 86 Right to explanation of individual decision-making
- ISO 42001 A.9 Use of AI systems
- CSA AICM CCC-01 Change Management Policy and Procedures
- CSA AICM DSP-02 Secure Disposal
- Singapore Agentic Agentic 2.3.3 When deploying, continuously monitor and test
- CoE Convention CoE Art. 16(2)(g) Testing before first use and when significantly modified
- OECD AI Principles OECD 1.4 Robustness, security and safety
- TC260 Framework 3.0 TC260 5.3 Operators' safety guidelines
- TC260 Framework 3.0 TC260 5.3.19 Re-assessment on material change
- GAO AI Accountability 4.4 Ongoing assessment: assess the utility of the AI system to ensure its relevance to the current context
- GAO AI Accountability 4.5 Scaling: identify conditions, if any, under which the AI system may be scaled or expanded beyond its current use
Open controls that evidence it
Draft controls in the open control profiles that map to this row: each states a requirement and the evidence it must leave behind.
-
AIGE-CTL-EVAL-006Stop Conditions (Evaluation environment profile) -
AIGE-CTL-AGENT-008Execution budgets (Agent runtime profile) -
AIGE-CTL-AGENT-010Per-agent circuit breaker (Agent runtime profile) -
AIGE-CTL-AGENT-025Accountability across hops (Agent runtime profile) -
AIGE-CTL-ASSURE-004Common Signed Evidence Record (Assurance and evidence profile) -
AIGE-CTL-ASSURE-005Live Control Status from the Assurance Store (Assurance and evidence profile) -
AIGE-CTL-ASSURE-007Machine-Readable Evidence in OSCAL (Assurance and evidence profile) -
AIGE-CTL-ASSURE-010Model Artefacts Signed at Build and Verified Before Load (Assurance and evidence profile)
Source
Chapter 08, section NIST AI RMF, checked against its sources on the review date above.
Machine-readable
- This obligation:
/api/v1/obligations/aige-obl-nistrmf-manage.json - The register:
/api/v1/obligations.json· CSV - Schema and stability promise: open data and API
Cite this obligation
García Aibar, J. (2026). NIST AI RMF MANAGE (AIGE-OBL-NISTRMF-MANAGE). In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0). https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage. CC BY 4.0
BibTeX
@misc{aige2026obligation,
author = {Jorge García Aibar},
title = {{NIST AI RMF MANAGE (AIGE-OBL-NISTRMF-MANAGE)}},
howpublished = {In AI Governance Engineering: The Thesis \& Body of Knowledge},
year = {2026},
version = {0.5.0},
doi = {10.5281/zenodo.22956197},
url = {https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage},
note = {Version 0.5.0}
}