Govern, Map, Measure, Manage — for every AI system you run.
The AI Risk Management Framework organizes AI risk into four functions — Govern, Map, Measure, Manage — and is voluntary guidance, not a standard anyone certifies you against. Govern runs across the other three rather than preceding them. Map establishes context and what the system is actually for; Measure tests it; Manage decides what to do about what you found. A generative-AI profile published in 2024 applies the same four functions to models that generate content.
The hard part is not the framework. It is that Map assumes you know which AI systems you run, and most organizations do not — models arrive inside products, embedded in a vendor's feature release, or built by a team that did not think of it as an AI project. A framework applied to an inventory that is missing half its entries measures the wrong half.
Who it applies to
Any organization that designs, develops, deploys or uses AI systems — which now includes organizations that would not describe themselves as doing anything with AI. Because the framework is voluntary, nobody serves you with it. It arrives through customer due diligence, insurer questionnaires, and internal policy written by people who need a defensible structure to point at.
Voluntary is not the same as optional
The AI RMF has no enforcement behind it, and it is still the structure your obligations get expressed in. It crosswalks cleanly onto ISO 42001, which is certifiable, and onto the EU AI Act, which is law — three regimes that ask overlapping questions about the same systems in three vocabularies. Answering them from three separate inventories guarantees they disagree. One inventory of AI systems, with purpose, owner, risk classification and evidence held per system, answers all three and stays consistent because there is nothing to reconcile.
What it asks, in operating terms
Read as an operating requirement rather than voluntary guidance, the four functions reduce to four standing asks — each answerable from a live inventory rather than a survey.
| What the function asks | Where it is answered |
|---|---|
| Govern — policy, roles and accountability for AI risk | Governance workspace · named owner per AI system |
| Map — know every AI system and what it is for | AI system inventory · shared with ISO 42001 and the AI Act |
| Measure — test the system, record what you found | Assessment records · attached to the system, not to a report |
| Manage — act on what you measured, and show it | Risk management · treatment tracked to verified closure |
What you'd actually look at
In the dashboard, every figure opens on click to the system, the evidence and the person behind it. This excerpt is what an AI inventory is made of:
- Systems inventoried
- 12 · 4 vendor-embedded
- Shared with
- ISO 42001 · EU AI Act · AI RMF
- Assessments current
- 12/12 · each with a named owner
- Open risks
- 3 · treatment dated
- Export
- sealed · sha256:9a47...2d10
Where teams usually start
With a demo walked through by TruSecure — the AI systems you already run pulled into one inventory, a single system opened to its assessment and its owner, the same record answering AI RMF, ISO 42001 and the AI Act. Onboarding then produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.
Compliance roadmap
Typical timeline: 3–6 months to full compliance readiness
- 1Weeks 1–4
1.Assessment
Gap analysis against NIST AI RMF, risk review, remediation plan.
- 2Weeks 5–12
2.Implementation
Controls deployed, policies written, evidence flowing.
- 3Weeks 13–16
3.Audit prep
Gaps closed, evidence package assembled for the authority.
- 4Weeks 17–24
4.Steady state
Continuous evidence, reports on demand, drift alerts.
With TruSecure: 3× faster to audit-ready. AI does the evidence work; your team keeps the decisions.
Map once, comply everywhere
unified commitmentsOne control model
Each control exists exactly once. Every obligation cites it — a gap shows up once, as one remediation item, not six findings in six programs.
Regulations
NIS2 · DORA · GDPR · EU AI Act
Frameworks
ISO 27001 · SOC 2 · NIST · CMMC · CIS
Contracts
Customer security requirements
Internal policy
Your own security standards
When the law moves, the model moves. A new transposition or a revised annex lands as a reviewable proposal against the controls it cites — not as a gap-analysis project you commission separately.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
The NIST AI Risk Management Framework organizes AI risk management into four functions — Govern, Map, Measure, and Manage — and is voluntary guidance rather than a certifiable standard. TruSecure shares a single AI system inventory across AI RMF, ISO 42001, and the EU AI Act.