NIST AI RMF MAP
Context and risk framing for each AI system
AIGE-OBL-NISTRMF-MAP. Drawn from chapter 08.
Text alternative
- Clause: NIST AI RMF, MAP.
- Duty holder: Not stated.
- Applies from: No date, Voluntary.
- Artefact: Threat models.
- Layers: Layer 02, Layer 03.
- Evidence record: Use-case record, +8 more.
- Record schemas: Use-case record , Instructions for use , Model card , Impact assessment , Dataset admission record , Risk register entry , Dataset card , Training record , Design record .
- The same topic in 26 other frameworks; the crosswalk section below links each clause.
- Id
AIGE-OBL-NISTRMF-MAP- Instrument
- NIST AI RMF framework
- Compared side by side
- NIST AI RMF vs ISO 42001 · NIST AI RMF vs EU AI Act
- Clause
- MAP
- Applies from
- No date Voluntary · Voluntary (AI RMF 1.0, January 2023)
The artefact that evidences it
Threat models; use-case and impact mapping; data/model cards.
Patterns that build it
- Agent Registry (layer 2)
- AIBOM (layer 2)
- Model Card as Control Evidence (layer 2)
- FRIA-as-Code (layer 1 and 2)
- Shadow-AI Discovery (layer 2)
- Vendor / Model Due-Diligence Gate (layer 2 and 5)
- Use-Case Intake & Risk Tiering (layer 1 and 2)
- AI Threat Model (layer 1 and 3)
- Training-Data Rights Ledger (layer 2)
- Dataset Admission Gate (layer 1 and 2)
- Decision Notice & Contest Path (layer 4 and 5)
- Downstream Use Register (layer 2 and 1)
The same topic in other frameworks
From the topic crosswalk: the clauses filed under the same topics as this one. Mappings are illustrative, not a claim of conformity.
Risk management
- EU AI Act Art. 9 Risk management system (core)
- ISO 42001 6.1.2 AI risk assessment (core)
- ISO 42001 6.1.3 AI risk treatment (core)
- ISO 42001 8.2 AI risk assessment (operation) (core)
- ISO 42001 8.3 AI risk treatment (operation) (core)
- NIST AI RMF MANAGE 1 MANAGE 1: AI risks based on assessments and other analytical output are prioritized, responded to, and managed (core)
- TC260 Framework 3.0 TC260 2 Classification of AI safety risks (core)
- TC260 Framework 3.0 TC260 Summary table Risks × technological × governance measures (core)
- ISO 23894 23894 6.4 Risk assessment (core) (clause not verified)
- ISO 23894 23894 6.5 Risk treatment (core) (clause not verified)
- NIST AI RMF GOVERN 1.3 GOVERN 1.3: Processes, procedures, and practices are in place to determine the needed level of risk management activities based on the organization's risk tolerance (core)
- NIST AI RMF MANAGE 1.3 MANAGE 1.3: Responses to the AI risks deemed high priority, as identified by the MAP function, are developed, planned, and documented (core)
- NIST AI RMF MANAGE 1.4 MANAGE 1.4: Negative residual risks to both downstream acquirers of AI systems and end users are documented (core)
- NIST AI RMF MEASURE 3 MEASURE 3: Mechanisms for tracking identified AI risks over time are in place (core)
- CSA AICM GRC-02 Risk Management Program (core)
- Korea AI Act Art. 34(1)(1) Risk management plan for high-impact AI (core)
- UK ATRS ATRS 2.5.2 Risks and mitigations (core)
- Singapore Agentic Agentic 2.1 Assess and bound the risks upfront (core)
- CoE Convention CoE Art. 16 Risk and impact management framework (core)
- prEN 18228 prEN 18228 AI risk management (draft; supports Art. 9) (core) (clause not verified)
- GAO AI Accountability 1.6 Risk management: implement an AI-specific risk management plan to systematically identify, analyze, and mitigate risks (core)
- ISO 42001 A.6 AI system life cycle
- NIST AI RMF MEASURE 2 MEASURE 2: AI systems are evaluated for trustworthy characteristics
- TC260 Framework 3.0 TC260 5.3.19 Re-assessment on material change
- China GenAI Measures GenAI Art. 17 Security assessment and algorithm filing
- China Algo. Rec. AlgoRec Art. 27 Security assessment
- EU AI Act Art. 3 Definitions
- ISO 42001 6.1.4 AI system impact assessment
- ISO 23894 23894 6.6 Monitoring and review (clause not verified)
- GPAI Code Safety C1 Commitment 1: Safety and Security Framework
- GPAI Code Safety C3 Commitment 3: Systemic risk analysis
- CSA AICM MDS-12 Open Model Risk Assessment
- OECD AI Principles OECD 1.5(c) Systematic risk management at each lifecycle phase
Impact assessment
- EU AI Act Art. 27 Fundamental rights impact assessment for high-risk AI systems (core)
- ISO 42001 6.1.4 AI system impact assessment (core)
- ISO 42001 8.4 AI system impact assessment (operation) (core)
- ISO 42001 A.5 Assessing impacts of AI systems (core)
- TC260 Framework 3.0 TC260 Appendix 1 Grading principles (core)
- China GenAI Measures GenAI Art. 17 Security assessment (core)
- GDPR Art. 35 Data protection impact assessment (core)
- ISO 42005 42005 5.8 Performing the AI system impact assessment (core) (clause not verified)
- ISO 42005 42005 6.8 Actual and reasonably foreseeable impacts (core) (clause not verified)
- CSA AICM GRC-10 AI Impact Assessment (core)
- Korea AI Act Art. 35 Impact assessment (best-effort duty) (core)
- UK ATRS ATRS 2.5.1 Impact assessments (core)
- EU AI Act Art. 9 Risk management system
- TC260 Framework 3.0 TC260 2.2 Safety risks in the application of AI
- GDPR Art. 36 Prior consultation
- ISO 42005 42005 5.12 Monitoring and review (clause not verified)
- CSA AICM DSP-09 Data Protection Impact Assessment
- CoE Convention CoE Art. 16 Risk and impact management framework
- GAO AI Accountability 1.5 Stakeholder involvement: include diverse perspectives from a community of stakeholders throughout the AI life cycle
Data governance
- EU AI Act Art. 10 Data and data governance (core)
- ISO 42001 A.7 Data for AI systems (core)
- TC260 Framework 3.0 TC260 2.1.3 Data safety risks (core)
- China GenAI Measures GenAI Art. 7 Training-data lawful sourcing (core)
- China GenAI Measures GenAI Art. 8 Data-annotation standards (core)
- China GenAI Measures GenAI Art. 11 Protection of user input and records (core)
- China Deep Synthesis DeepSyn Art. 14 Training-data management (core)
- GB/T 45654 GB/T 45654 Corpus security Training-corpus (data) security requirements (core) (clause not verified)
- EU AI Act Art. 10(2)(f)–(g) Examination for possible biases; measures to detect, prevent and mitigate them (core)
- GDPR Art. 5(1)(c) Data minimisation (core)
- GDPR Art. 25 Data protection by design and by default (core)
- ISO 42001 A.7.3 Acquisition of data (core) (clause not verified)
- CSA AICM DSP-20 Data Provenance and Transparency (core)
- UK ATRS ATRS 2.4.3 Development data specification (core)
- Singapore GenAI GenAI 2 Data (core)
- GAO AI Accountability 2.1 Sources: document sources and origins of data used to develop the models (core)
- GAO AI Accountability 2.2 Reliability: assess reliability of data used to develop the models (core)
- EU AI Act Art. 4a Special-category data for bias detection
- ISO 42001 A.4 Resources for AI systems
- NIST AI RMF MEASURE 2.10 MEASURE 2.10: Privacy risk of the AI system is examined and documented
- NIST AI RMF MEASURE 2.11 MEASURE 2.11: Fairness and bias are evaluated and results are documented
- TC260 Framework 3.0 TC260 5.1 Model R&D safety guidelines
- EU AI Act Art. 53 Obligations for providers of general-purpose AI models
- EU AI Act Art. 53(1)(c) Copyright policy, including rights reservations
- EU AI Act Art. 5(1)(e) Prohibited: untargeted scraping of facial images
- GPAI Code Copyright 1.1–1.5 Commitment 1: Copyright policy (Measures 1.1 to 1.5)
- GDPR Art. 9 Processing of special categories of personal data
- CSA AICM DSP-21 Data Poisoning Prevention & Detection
- OWASP LLM LLM05:2026 Data and Model Poisoning
- GAO AI Accountability 2.4 Variable selection: assess data variables used in the AI component models
- GAO AI Accountability 2.5 Enhancement: assess the use of synthetic, imputed, and/or augmented data
Documentation and transparency
- EU AI Act Art. 11 Technical documentation (core)
- EU AI Act Art. 13 Transparency and provision of information to deployers (core)
- EU AI Act Art. 53 Obligations for providers of general-purpose AI models (core)
- ISO 42001 7.5 Documented information (core)
- ISO 42001 A.6 AI system life cycle (core)
- ISO 42001 A.8 Information for interested parties (core)
- China AI Labelling Label Art. 4 Explicit labels for generated content (core)
- China AI Labelling Label Art. 5 Implicit (metadata) labels (core)
- China GenAI Measures GenAI Art. 12 Labelling of generated content (core)
- China Deep Synthesis DeepSyn Art. 16 Implicit technical labels (core)
- China Deep Synthesis DeepSyn Art. 17 Conspicuous labels for confusable content (core)
- GPAI Code Transparency 1.1 Drawing up and keeping up-to-date model documentation (core)
- GDPR Arts. 13–14 Information to be provided to the data subject (core)
- CSA AICM MDS-03 Model Documentation (core)
- Korea AI Act Art. 31 Transparency: prior notice, output labelling, realistic synthetic content (core)
- UK ATRS ATRS Tier 1 Summary information (core)
- Singapore GenAI GenAI 3 Trusted Development and Deployment (core)
- CoE Convention CoE Art. 14(2) Documentation sufficient to contest decisions; complaint to authorities (core)
- OECD AI Principles OECD 1.3 Transparency and explainability (core)
- G7 Code G7 Action 3 Publicly report capabilities, limitations and domains of use (core)
- GAO AI Accountability 1.9 Transparency: enable external stakeholders to access information on the design, operation, and limitations of the AI system (core)
- GAO AI Accountability 3.5 Documentation: document the methods for assessment, performance metrics, and outcomes of the AI system (core)
- EU AI Act Art. 50 Transparency obligations for providers and deployers of certain AI systems
- NIST AI RMF MEASURE 2.8 MEASURE 2.8: Risks associated with transparency and accountability are examined and documented
- China GenAI Measures GenAI Art. 19 Disclosure to regulators
- China Algo. Rec. AlgoRec Art. 16 Notice that recommendation is used
- GB/T 45654 GB/T 45654 Content labelling Generated-content labelling requirements (clause not verified)
- EU AI Act Art. 86 Right to explanation of individual decision-making
- EU AI Act Art. 18 Documentation keeping
- EU AI Act Art. 43 Conformity assessment
- EU AI Act Art. 53(1)(d) Public summary of the content used for training
- EU AI Act Art. 50(2), 50(4) Machine-readable marking of synthetic content; disclosure of deep fakes
- GPAI Code Transparency 1.2 Providing relevant information
- GDPR Art. 30 Records of processing activities
- NIST AI RMF MEASURE 2.9 MEASURE 2.9: The AI model is explained, validated, and documented, and AI system output is interpreted within its context as identified in the MAP function to inform responsible use and governance
- CSA AICM MDS-04 Model Documentation Requirements
- Korea AI Act Art. 34(1)(2) Explanation plan: result, main criteria, training-data overview
- UK ATRS ATRS 2.2 Description and rationale
- CoE Convention CoE Art. 15(2) Notification of interaction with an AI system
- GAO AI Accountability 1.7 Specifications: establish and document technical specifications
Supply chain and third parties
- EU AI Act Art. 25 Responsibilities along the AI value chain (core)
- ISO 42001 A.10 Third-party and customer relationships (core)
- NIST AI RMF GOVERN 6 GOVERN 6: Policies and procedures are in place to address AI risks and benefits arising from third-party software and data and other supply chain issues (core)
- NIST AI RMF MANAGE 3 MANAGE 3: AI risks and benefits from third-party entities are managed (core)
- TC260 Framework 3.0 TC260 App. 2 II.4 Supply chain and tool management (core)
- EU AI Act Art. 25(4) Written agreement with third-party suppliers (core)
- GDPR Art. 28 Processor (core)
- NIST AI RMF MANAGE 3.1 MANAGE 3.1: AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented (core)
- CSA AICM STA-10 Supply Chain Risk Management (core)
- CSA AICM STA-09 Service Bill of Material (BOM) (core)
- OWASP LLM LLM04:2026 Supply Chain (core)
- OWASP Agentic ASI04 Agentic Supply Chain Vulnerabilities (core)
- EU AI Act Art. 26 Obligations of deployers of high-risk AI systems
- TC260 Framework 3.0 TC260 4.4.4 Open-source ecosystem
- China GenAI Measures GenAI Art. 7 Lawful data and model sources
- China Deep Synthesis DeepSyn Art. 14 Providers and technical supporters
- EU AI Act Art. 22 Authorised representatives of providers of high-risk AI systems
- EU AI Act Art. 23 Obligations of importers
- EU AI Act Art. 24 Obligations of distributors
- EU AI Act Art. 54 Authorised representatives of providers of general-purpose AI models
- GPAI Code Transparency 1.2 Providing relevant information
- GDPR Arts. 44–46 Transfers to third countries
- NIST AI RMF GOVERN 6.2 GOVERN 6.2: Contingency processes are in place to handle failures or incidents in third-party data or AI systems deemed to be high-risk
- UK ATRS ATRS 2.1.4 Third party involvement
- G7 Code G7 Action 11 Implement data input measures and protect personal data and intellectual property
- GAO AI Accountability 2.6 Dependency: assess interconnectivities and dependencies of data streams that operationalize the AI system
Human oversight
- EU AI Act Art. 14 Human oversight (core)
- ISO 42001 A.9 Use of AI systems (core)
- NIST AI RMF MANAGE 2.4 MANAGE 2.4: Mechanisms are in place and applied, and responsibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use (core)
- TC260 Framework 3.0 TC260 App. 2 II.3 Strengthen human approval (core)
- GDPR Art. 22 Automated individual decision-making, including profiling (core)
- CSA AICM GRC-15 Human supervision (core)
- Korea AI Act Art. 34(1)(4) Human management and supervision (core)
- UK DUAA UK GDPR Art. 22C Safeguards for automated decision-making (core)
- UK ATRS ATRS 2.3.2 Human review (core)
- Singapore Agentic Agentic 2.2.2 Design for meaningful human oversight (core)
- GAO AI Accountability 3.9 Human supervision: define and develop procedures for human supervision of the AI system (core)
- EU AI Act Art. 26 Obligations of deployers of high-risk AI systems
- NIST AI RMF GOVERN 3.2 GOVERN 3.2: Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight of AI systems
- China Algo. Rec. AlgoRec Art. 17 User option to switch off
- China GenAI Measures GenAI Art. 10 User guidance and protection
- EU AI Act Art. 14(4)(b) Awareness of automation bias
- OWASP Agentic ASI09 Human-Agent Trust Exploitation
- CoE Convention CoE Art. 8 Transparency and oversight
- OECD AI Principles OECD 1.2(b) Human agency and oversight safeguards
AI literacy and competence
- EU AI Act Art. 4 AI literacy (core)
- ISO 42001 7.2 Competence (core) (clause not verified)
- NIST AI RMF GOVERN 2.2 GOVERN 2.2: The organization's personnel and partners receive AI risk management training to enable them to perform their duties and responsibilities consistent with related policies, procedures, and agreements (core)
- CSA AICM HRS-14 AI Competency Training (core)
- Singapore Agentic Agentic 2.4 Enable end-user responsibility (core)
- EU AI Act Art. 26(2) Oversight by people with the competence, training and authority it needs
- EU AI Act Art. 95(2)(c) Codes of conduct: promoting AI literacy
- GDPR Art. 39(1)(b) DPO tasks: awareness-raising and training of staff (clause not verified)
- ISO 42001 7.3 Awareness (clause not verified)
- CSA AICM HRS-11 Security Awareness Training
- UK ATRS ATRS 2.3.4 Required training
- Singapore GenAI GenAI 9 AI for Public Good
- China GenAI Measures GenAI Art. 10 Guide users to understand and use generative AI rationally
- GAO AI Accountability 1.4 Workforce: recruit, develop, and retain personnel with multidisciplinary skills and experiences
IP and copyright
- EU AI Act Art. 53(1)(c) Copyright policy, including rights reservations (core)
- GPAI Code Copyright 1.1 Draw up, keep up-to-date and implement a copyright policy (core)
- GPAI Code Copyright 1.2 Reproduce and extract only lawfully accessible copyright-protected content (core)
- GPAI Code Copyright 1.3 Identify and comply with rights reservations when crawling the World Wide Web (core)
- GPAI Code Copyright 1.4 Mitigate the risk of copyright-infringing outputs (core)
- NIST AI RMF GOVERN 6.1 GOVERN 6.1: Policies and procedures are in place that address AI risks associated with third-party entities, including risks of infringement of a third-party's intellectual property or other rights (core)
- G7 Code G7 Action 11 Implement data input measures and protect personal data and intellectual property (core)
- China GenAI Measures GenAI Art. 7(2) No infringement of IP rights in training data (core)
- EU AI Act Art. 53(1)(d) Public summary of the content used for training
- GPAI Code Copyright 1.5 Designate a point of contact and enable the lodging of complaints
- CSA AICM DSP-20 Data Provenance and Transparency
- Singapore GenAI GenAI 2 Data
- China GenAI Measures GenAI Art. 4(3) Respect IP rights and business ethics
Open controls that evidence it
Draft controls in the open control profiles that map to this row: each states a requirement and the evidence it must leave behind.
-
AIGE-CTL-ASSURE-012AI Bill of Materials per Build (Assurance and evidence profile)
Source
Chapter 08, section NIST AI RMF, checked against its sources on the review date above.
Machine-readable
- This obligation:
/api/v1/obligations/aige-obl-nistrmf-map.json - The register:
/api/v1/obligations.json· CSV - Schema and stability promise: open data and API
Cite this obligation
García Aibar, J. (2026). NIST AI RMF MAP (AIGE-OBL-NISTRMF-MAP). In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0). https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-map. CC BY 4.0
BibTeX
@misc{aige2026obligation,
author = {Jorge García Aibar},
title = {{NIST AI RMF MAP (AIGE-OBL-NISTRMF-MAP)}},
howpublished = {In AI Governance Engineering: The Thesis \& Body of Knowledge},
year = {2026},
version = {0.5.0},
doi = {10.5281/zenodo.22956197},
url = {https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-map},
note = {Version 0.5.0}
}