NIST AI RMF MEASURE
Analyse, benchmark and monitor risk
AIGE-OBL-NISTRMF-MEASURE. Drawn from chapter 08.
Text alternative
- Clause: NIST AI RMF, MEASURE.
- Duty holder: Not stated.
- Applies from: No date, Voluntary.
- Artefact: Eval gates.
- Layer: Layer 03 Evals & Red Teaming as Evidence.
- Evidence record: Eval result, +7 more.
- Record schemas: Eval result , Dataset admission record , Test report , Evidence record , Control observation , Test plan , Post-market monitoring plan , Model card .
- The same topic in 28 other frameworks; the crosswalk section below links each clause.
- Id
AIGE-OBL-NISTRMF-MEASURE- Instrument
- NIST AI RMF framework
- Compared side by side
- NIST AI RMF vs ISO 42001 · NIST AI RMF vs EU AI Act
- Clause
- MEASURE
- Applies from
- No date Voluntary · Voluntary (AI RMF 1.0, January 2023)
The artefact that evidences it
Eval gates; adversarial red-team suite; metrics per failure mode.
Patterns that build it
- Eval Gate in CI (layer 3)
- Adversarial Red-Team Suite (layer 3)
- Model Card as Control Evidence (layer 2)
- AI Threat Model (layer 1 and 3)
- Fairness Eval Suite (layer 3)
- Explanation Artefact (layer 4 and 5)
- Model Artefact Integrity (layer 2 and 4)
- Claims Substantiation Gate (layer 5 and 3)
- Decision Notice & Contest Path (layer 4 and 5)
- Rights Requests Against Models (layer 2 and 5)
- Staged Rollout with Rollback Criteria (layer 4)
- Drift & Fairness Monitor (layer 4 and 5)
The same topic in other frameworks
From the topic crosswalk: the clauses filed under the same topics as this one. Mappings are illustrative, not a claim of conformity.
Risk management
- EU AI Act Art. 9 Risk management system (core)
- ISO 42001 6.1.2 AI risk assessment (core)
- ISO 42001 6.1.3 AI risk treatment (core)
- ISO 42001 8.2 AI risk assessment (operation) (core)
- ISO 42001 8.3 AI risk treatment (operation) (core)
- NIST AI RMF MAP 1 MAP 1: Context is established and understood (core)
- NIST AI RMF MAP 5 MAP 5: Impacts to individuals, groups, communities, organizations, and society are characterized (core)
- NIST AI RMF MANAGE 1 MANAGE 1: AI risks based on assessments and other analytical output are prioritized, responded to, and managed (core)
- TC260 Framework 3.0 TC260 2 Classification of AI safety risks (core)
- TC260 Framework 3.0 TC260 Summary table Risks × technological × governance measures (core)
- ISO 23894 23894 6.4 Risk assessment (core) (clause not verified)
- ISO 23894 23894 6.5 Risk treatment (core) (clause not verified)
- NIST AI RMF GOVERN 1.3 GOVERN 1.3: Processes, procedures, and practices are in place to determine the needed level of risk management activities based on the organization's risk tolerance (core)
- NIST AI RMF MAP 1.5 MAP 1.5: Organizational risk tolerances are determined and documented (core)
- NIST AI RMF MANAGE 1.3 MANAGE 1.3: Responses to the AI risks deemed high priority, as identified by the MAP function, are developed, planned, and documented (core)
- NIST AI RMF MANAGE 1.4 MANAGE 1.4: Negative residual risks to both downstream acquirers of AI systems and end users are documented (core)
- CSA AICM GRC-02 Risk Management Program (core)
- Korea AI Act Art. 34(1)(1) Risk management plan for high-impact AI (core)
- UK ATRS ATRS 2.5.2 Risks and mitigations (core)
- Singapore Agentic Agentic 2.1 Assess and bound the risks upfront (core)
- CoE Convention CoE Art. 16 Risk and impact management framework (core)
- prEN 18228 prEN 18228 AI risk management (draft; supports Art. 9) (core) (clause not verified)
- GAO AI Accountability 1.6 Risk management: implement an AI-specific risk management plan to systematically identify, analyze, and mitigate risks (core)
- ISO 42001 A.6 AI system life cycle
- TC260 Framework 3.0 TC260 5.3.19 Re-assessment on material change
- China GenAI Measures GenAI Art. 17 Security assessment and algorithm filing
- China Algo. Rec. AlgoRec Art. 27 Security assessment
- EU AI Act Art. 3 Definitions
- ISO 42001 6.1.4 AI system impact assessment
- ISO 23894 23894 6.6 Monitoring and review (clause not verified)
- GPAI Code Safety C1 Commitment 1: Safety and Security Framework
- GPAI Code Safety C3 Commitment 3: Systemic risk analysis
- CSA AICM MDS-12 Open Model Risk Assessment
- OECD AI Principles OECD 1.5(c) Systematic risk management at each lifecycle phase
Data governance
- EU AI Act Art. 10 Data and data governance (core)
- ISO 42001 A.7 Data for AI systems (core)
- TC260 Framework 3.0 TC260 2.1.3 Data safety risks (core)
- China GenAI Measures GenAI Art. 7 Training-data lawful sourcing (core)
- China GenAI Measures GenAI Art. 8 Data-annotation standards (core)
- China GenAI Measures GenAI Art. 11 Protection of user input and records (core)
- China Deep Synthesis DeepSyn Art. 14 Training-data management (core)
- GB/T 45654 GB/T 45654 Corpus security Training-corpus (data) security requirements (core) (clause not verified)
- EU AI Act Art. 10(2)(f)–(g) Examination for possible biases; measures to detect, prevent and mitigate them (core)
- GDPR Art. 5(1)(c) Data minimisation (core)
- GDPR Art. 25 Data protection by design and by default (core)
- ISO 42001 A.7.3 Acquisition of data (core) (clause not verified)
- CSA AICM DSP-20 Data Provenance and Transparency (core)
- UK ATRS ATRS 2.4.3 Development data specification (core)
- Singapore GenAI GenAI 2 Data (core)
- GAO AI Accountability 2.1 Sources: document sources and origins of data used to develop the models (core)
- GAO AI Accountability 2.2 Reliability: assess reliability of data used to develop the models (core)
- EU AI Act Art. 4a Special-category data for bias detection
- ISO 42001 A.4 Resources for AI systems
- NIST AI RMF MAP 2 MAP 2: Categorization of the AI system is performed
- TC260 Framework 3.0 TC260 5.1 Model R&D safety guidelines
- EU AI Act Art. 53 Obligations for providers of general-purpose AI models
- EU AI Act Art. 53(1)(c) Copyright policy, including rights reservations
- EU AI Act Art. 5(1)(e) Prohibited: untargeted scraping of facial images
- GPAI Code Copyright 1.1–1.5 Commitment 1: Copyright policy (Measures 1.1 to 1.5)
- GDPR Art. 9 Processing of special categories of personal data
- CSA AICM DSP-21 Data Poisoning Prevention & Detection
- OWASP LLM LLM05:2026 Data and Model Poisoning
- GAO AI Accountability 2.4 Variable selection: assess data variables used in the AI component models
- GAO AI Accountability 2.5 Enhancement: assess the use of synthetic, imputed, and/or augmented data
Documentation and transparency
- EU AI Act Art. 11 Technical documentation (core)
- EU AI Act Art. 13 Transparency and provision of information to deployers (core)
- EU AI Act Art. 53 Obligations for providers of general-purpose AI models (core)
- ISO 42001 7.5 Documented information (core)
- ISO 42001 A.6 AI system life cycle (core)
- ISO 42001 A.8 Information for interested parties (core)
- China AI Labelling Label Art. 4 Explicit labels for generated content (core)
- China AI Labelling Label Art. 5 Implicit (metadata) labels (core)
- China GenAI Measures GenAI Art. 12 Labelling of generated content (core)
- China Deep Synthesis DeepSyn Art. 16 Implicit technical labels (core)
- China Deep Synthesis DeepSyn Art. 17 Conspicuous labels for confusable content (core)
- GPAI Code Transparency 1.1 Drawing up and keeping up-to-date model documentation (core)
- GDPR Arts. 13–14 Information to be provided to the data subject (core)
- CSA AICM MDS-03 Model Documentation (core)
- Korea AI Act Art. 31 Transparency: prior notice, output labelling, realistic synthetic content (core)
- UK ATRS ATRS Tier 1 Summary information (core)
- Singapore GenAI GenAI 3 Trusted Development and Deployment (core)
- CoE Convention CoE Art. 14(2) Documentation sufficient to contest decisions; complaint to authorities (core)
- OECD AI Principles OECD 1.3 Transparency and explainability (core)
- G7 Code G7 Action 3 Publicly report capabilities, limitations and domains of use (core)
- GAO AI Accountability 1.9 Transparency: enable external stakeholders to access information on the design, operation, and limitations of the AI system (core)
- GAO AI Accountability 3.5 Documentation: document the methods for assessment, performance metrics, and outcomes of the AI system (core)
- EU AI Act Art. 50 Transparency obligations for providers and deployers of certain AI systems
- NIST AI RMF MAP 1 MAP 1: Context is established and understood
- China GenAI Measures GenAI Art. 19 Disclosure to regulators
- China Algo. Rec. AlgoRec Art. 16 Notice that recommendation is used
- GB/T 45654 GB/T 45654 Content labelling Generated-content labelling requirements (clause not verified)
- EU AI Act Art. 86 Right to explanation of individual decision-making
- EU AI Act Art. 18 Documentation keeping
- EU AI Act Art. 43 Conformity assessment
- EU AI Act Art. 53(1)(d) Public summary of the content used for training
- EU AI Act Art. 50(2), 50(4) Machine-readable marking of synthetic content; disclosure of deep fakes
- GPAI Code Transparency 1.2 Providing relevant information
- GDPR Art. 30 Records of processing activities
- NIST AI RMF MAP 1.6 MAP 1.6: System requirements are elicited from and understood by relevant AI actors. Design decisions take socio-technical implications into account to address AI risks
- CSA AICM MDS-04 Model Documentation Requirements
- Korea AI Act Art. 34(1)(2) Explanation plan: result, main criteria, training-data overview
- UK ATRS ATRS 2.2 Description and rationale
- CoE Convention CoE Art. 15(2) Notification of interaction with an AI system
- GAO AI Accountability 1.7 Specifications: establish and document technical specifications
Logging and traceability
- EU AI Act Art. 12 Record-keeping (core)
- ISO 42001 A.6 AI system life cycle (core)
- TC260 Framework 3.0 TC260 App. 2 II.6 Continuous monitoring and auditing (core)
- TC260 Framework 3.0 TC260 5.3.6 Logs kept and audited (core)
- EU AI Act Art. 26(6) Deployers keep the automatically generated logs (core)
- ISO 42001 A.6.2.8 AI system recording of event logs (core) (clause not verified)
- CSA AICM LOG-09 Log Records (core)
- Korea AI Act Art. 34(1)(5) Documents showing the measures taken (core)
- OECD AI Principles OECD 1.5(b) Traceability of datasets, processes and decisions (core)
- prEN 18229-1 prEN 18229-1 AI trustworthiness framework, Part 1: logging (draft; supports Art. 12) (core) (clause not verified)
- GAO AI Accountability 4.3 Traceability: document results of monitoring activities and any corrective actions taken (core)
- EU AI Act Art. 26 Obligations of deployers of high-risk AI systems
- NIST AI RMF MANAGE 4 MANAGE 4: Risk treatments, including response and recovery, and communication plans for the identified and measured AI risks are documented and monitored
- China AI Labelling Label Art. 5 Implicit metadata labels
- EU AI Act Art. 19 Automatically generated logs
- CSA AICM LOG-12 Transaction/Activity Logging
- Singapore Agentic Agentic 2.3.3 When deploying, continuously monitor and test
Robustness, security and evaluations
- EU AI Act Art. 15 Accuracy, robustness and cybersecurity (core)
- EU AI Act Art. 55 Obligations for providers of general-purpose AI models with systemic risk (core)
- ISO 42001 A.6 AI system life cycle (core)
- TC260 Framework 3.0 TC260 3 Technological countermeasures (core)
- TC260 Framework 3.0 TC260 App. 2 II.6 Sandbox validation and red teaming (core)
- China Deep Synthesis DeepSyn Art. 15 Technology management and algorithm verification (core)
- China Deep Synthesis DeepSyn Art. 20 Security assessment of new products (core)
- GB/T 45654 GB/T 45654 Security assessment Security-assessment requirements for generative AI services (core) (clause not verified)
- GPAI Code Safety 3.2 Measure 3.2: Model evaluations (core)
- CSA AICM MDS-06 Adversarial Attack Analysis (core)
- CSA AICM MDS-07 Robustness against Adversarial Attack / Model Hardening (core)
- Singapore GenAI GenAI 5 Testing and Assurance (core)
- Singapore GenAI GenAI 6 Security (core)
- Singapore Agentic Agentic 2.3.2 Before deploying, test agents (core)
- CoE Convention CoE Art. 16(2)(g) Testing before first use and when significantly modified (core)
- OECD AI Principles OECD 1.4 Robustness, security and safety (core)
- G7 Code G7 Action 1 Identify, evaluate and mitigate risks across the lifecycle, including testing (core)
- GAO AI Accountability 3.7 Assessment: assess performance against defined metrics to ensure the AI system functions as intended and is sufficiently robust (core)
- EU AI Act Art. 60 Testing of high-risk AI systems in real-world conditions outside AI regulatory sandboxes
- ISO 42001 9.1 Monitoring, measurement, analysis and evaluation
- TC260 Framework 3.0 TC260 5.3.14 Resilience
- China GenAI Measures GenAI Art. 17 Security assessment
- EU AI Act Art. 15(3) Declared accuracy levels and metrics
- EU AI Act Art. 9 Risk management system
- EU AI Act Art. 42(3) Presumption of conformity for cybersecurity (Cyber Resilience Act)
- GPAI Code Safety C6 Commitment 6: Security mitigations
- GDPR Art. 32 Security of processing
- CSA AICM AIS-05 Application Security Testing
- OWASP LLM LLM01:2026 Prompt Injection
- OWASP Agentic ASI05 Unexpected Code Execution (RCE)
- Korea AI Act Art. 32(1) Safety duties for AI above the compute threshold
- GAO AI Accountability 3.2 Metrics: define performance metrics that are precise, consistent, and reproducible
Fairness and non-discrimination
- EU AI Act Art. 10(2)(f)–(g) Examination for possible biases; measures to detect, prevent and mitigate them (core)
- EU AI Act Art. 4a Special-category data for bias detection (core)
- GDPR Art. 5(1)(a) Lawfulness, fairness and transparency (core)
- CSA AICM GRC-11 Bias and Fairness Assessment (core)
- CoE Convention CoE Art. 10 Equality and non-discrimination (core)
- China GenAI Measures GenAI Art. 4(2) Prevent discrimination in design, data, training and service (core)
- GAO AI Accountability 2.7 Bias: assess reliability, quality, and representativeness of the data used in operation, including potential biases (core)
- GAO AI Accountability 3.8 Bias: identify potential biases, inequities, and other societal concerns resulting from the AI system (core)
- GDPR Art. 9 Processing of special categories of personal data
- ISO 42001 A.5.4 Assessing AI system impact on individuals or groups of individuals (clause not verified)
- NIST AI RMF GOVERN 3.1 GOVERN 3.1: Decision-making related to mapping, measuring, and managing AI risks throughout the lifecycle is informed by a diverse team
- UK ATRS ATRS 2.4.2 Model specification
- OECD AI Principles OECD 1.2 Rule of law, human rights and democratic values, including fairness and privacy
- China Algo. Rec. AlgoRec Art. 21 No unreasonable differential treatment in trading conditions
Privacy and data protection
- GDPR Art. 5 Principles relating to processing of personal data (core)
- GDPR Art. 6 Lawfulness of processing (core)
- GDPR Art. 25 Data protection by design and by default (core)
- CSA AICM DSP-08 Data Privacy by Design and Default (core)
- OWASP LLM LLM02:2026 Sensitive Information Disclosure (core)
- CoE Convention CoE Art. 11 Privacy and personal data protection (core)
- China GenAI Measures GenAI Art. 7(3) Consent or another lawful basis for personal information in training data (core)
- China GenAI Measures GenAI Art. 11 Protection of user input and records (core)
- GAO AI Accountability 2.8 Security and privacy: assess data security and privacy for the AI system (core)
- EU AI Act Art. 59 Further processing of personal data in the AI regulatory sandbox
- EU AI Act Art. 4a Special-category data for bias detection
- GDPR Art. 35 Data protection impact assessment
- ISO 42001 A.7 Data for AI systems
- CSA AICM DSP-22 Privacy Enhancing Technologies
- UK DUAA UK GDPR Art. 22B Restrictions on automated decision-making
- Singapore GenAI GenAI 2 Data
- OECD AI Principles OECD 1.2 Rule of law, human rights and democratic values, including fairness and privacy
- G7 Code G7 Action 11 Implement data input measures and protect personal data and intellectual property
Explainability and right to explanation
- EU AI Act Art. 86 Right to explanation of individual decision-making (core)
- EU AI Act Art. 13(3)(b)(iv)–(v) Information relevant to explain output; performance for specific persons or groups (core)
- GDPR Art. 15(1)(h) Meaningful information about the logic involved (core)
- CSA AICM GRC-13 Explainability Requirement (core)
- CSA AICM GRC-14 Explainability Evaluation (core)
- Korea AI Act Art. 34(1)(2) Explanation plan: result, main criteria, training-data overview (core)
- UK DUAA UK GDPR Art. 22C Safeguards for automated decision-making (core)
- OECD AI Principles OECD 1.3 Transparency and explainability (core)
- GDPR Art. 13(2)(f) Existence of automated decision-making
- GDPR Art. 22(3) Right to obtain human intervention and to contest the decision
- ISO 42001 A.8.2 System documentation and information for users (clause not verified)
- UK ATRS ATRS 2.3.5 Appeals and review
- Singapore GenAI GenAI 3 Trusted Development and Deployment
- CoE Convention CoE Art. 14(2) Documentation sufficient to contest decisions; complaint to authorities
- China Algo. Rec. AlgoRec Art. 17 Explain where an algorithm significantly affects user rights
Conformity assessment and certification
- EU AI Act Art. 43 Conformity assessment (core)
- ISO 42006 ISO/IEC 42006 Requirements for bodies providing audit and certification of AI management systems (core)
- CSA AICM A&A-02 Independent Assessments (core)
- EU AI Act Art. 47 EU declaration of conformity
- EU AI Act Art. 48 CE marking
- EU AI Act Art. 40 Harmonised standards and standardisation deliverables
- GDPR Art. 42 Certification (clause not verified)
- ISO 42001 9.2 Internal audit (clause not verified)
- CSA AICM A&A-04 Requirements Compliance
- Korea AI Act Art. 33 Confirmation of high-impact AI
- Singapore GenAI GenAI 5 Testing and Assurance
- EN 18286 EN 18286 Quality management system for EU AI Act regulatory purposes
- China GenAI Measures GenAI Art. 17 Security assessment and algorithm filing
- GAO AI Accountability 1.8 Compliance: ensure the AI system complies with relevant laws, regulations, standards, and guidance
Sandboxes and real-world testing
- EU AI Act Art. 57 AI regulatory sandboxes (core)
- EU AI Act Art. 60 Testing of high-risk AI systems in real world conditions outside AI regulatory sandboxes (core)
- CoE Convention CoE Art. 13 Safe innovation (controlled testing environments) (core)
- EU AI Act Art. 58 Detailed arrangements for, and functioning of, AI regulatory sandboxes
- EU AI Act Art. 59 Further processing of personal data in the AI regulatory sandbox
- EU AI Act Art. 61 Informed consent to participate in testing in real world conditions
- ISO 42001 A.6.2.4 AI system verification and validation (clause not verified)
- CSA AICM AIS-13 AI Sandboxing
- Singapore Agentic Agentic 2.3.2 Before deploying, test agents
- TC260 Framework 3.0 TC260 App. 2 II.6 Sandbox validation and red teaming
Environmental impact
- EU AI Act Annex XI 1(2)(e) Known or estimated energy consumption of the GPAI model (core)
- GPAI Code Transparency 1.1 Drawing up and keeping up-to-date model documentation (core)
- OECD AI Principles OECD 1.1 Inclusive growth, sustainable development and well-being (core)
- EU AI Act Art. 40(2) Standardisation deliverables on energy and resource performance
- EU AI Act Art. 95(2)(b) Codes of conduct: environmental sustainability
- Singapore GenAI GenAI 9 AI for Public Good
Open controls that evidence it
Draft controls in the open control profiles that map to this row: each states a requirement and the evidence it must leave behind.
-
AIGE-CTL-EVAL-005Monitoring Integrity (Evaluation environment profile) -
AIGE-CTL-EVAL-009Evaluation Validity Checks (Evaluation environment profile) -
AIGE-CTL-ASSURE-001Test Plan Frozen Before Evaluation (Assurance and evidence profile) -
AIGE-CTL-ASSURE-002Release Blocked Below the Eval Threshold (Assurance and evidence profile) -
AIGE-CTL-ASSURE-003Signed Test Report Against the Plan (Assurance and evidence profile)
Source
Chapter 08, section NIST AI RMF, checked against its sources on the review date above.
Machine-readable
- This obligation:
/api/v1/obligations/aige-obl-nistrmf-measure.json - The register:
/api/v1/obligations.json· CSV - Schema and stability promise: open data and API
Cite this obligation
García Aibar, J. (2026). NIST AI RMF MEASURE (AIGE-OBL-NISTRMF-MEASURE). In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0). https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure. CC BY 4.0
BibTeX
@misc{aige2026obligation,
author = {Jorge García Aibar},
title = {{NIST AI RMF MEASURE (AIGE-OBL-NISTRMF-MEASURE)}},
howpublished = {In AI Governance Engineering: The Thesis \& Body of Knowledge},
year = {2026},
version = {0.5.0},
doi = {10.5281/zenodo.22956197},
url = {https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure},
note = {Version 0.5.0}
}