ProvenantAI Get in touch
← Standards register Assessment

NIST AI RMF

Risk-management framework · 19 categories

Instead of interviewing your teams to work out what your AI can do, Provenant tells you — and it stays true as the system changes.

3

Enforced

Provenant does it. You can show it before your agent runs.

3

Contained

Where the standard asks you to prevent something the model might do, Provenant limits how far it gets.

10

Evidenced

Where the standard asks you for a plan, a policy or a test, Provenant hands you what it needs.

RefRequirementHowMechanism
GOVERN 1Policies, processes and practices for AI riskEvidencedYour policy and your enforcement are the same document
GOVERN 2Accountability structuresEvidencedYou know who approved what, and what they saw
GOVERN 3Workforce diversity, equity and accessibilityN/A
GOVERN 4Culture that considers and communicates AI riskN/A
GOVERN 5Engagement with relevant AI actorsN/A
GOVERN 6Third-party software, data and supply chainEvidencedYour vendor list writes itself
MAP 1Context established and understoodEvidencedYou start from a complete picture of what the system does and sees
MAP 2Categorisation of the AI systemEvidencedWritten for you instead of surveyed
MAP 3AI capabilities, usage, goals and expected benefitsEnforcedYou can see everything your AI can do before it runs
MAP 4Risks and benefits mapped across all componentsEvidencedYou start from a complete list
MAP 5Impacts to people and society characterisedContainedYou know how far an impact could reach
MEASURE 1Appropriate methods and metrics appliedEvidencedYou can evaluate everything instead of sampling
MEASURE 2Systems evaluated for trustworthy characteristicsContainedHow far the model's weaknesses can reach is capped
MEASURE 3Mechanisms for tracking risks over timeEnforcedEvery decision recorded as it happens
MEASURE 4Feedback about efficacy gathered and assessedEvidencedThe record is what you feed back
MANAGE 1Risks prioritised, responded to and managedEvidencedYou prioritise over a complete list, not a discovered one
MANAGE 2Strategies to maximise benefit and minimise harmContainedHow far harm can reach is capped
MANAGE 3Third-party risks and benefits managedEvidencedYour vendor list writes itself
MANAGE 4Risk treatments, response and recovery documentedEnforcedYou have both halves — what happened, and what could have