AI Governance
Available nowNIST AI Risk Management Framework · 1.0
The NIST AI Risk Management Framework (AI RMF 1.0) is a voluntary, public-domain framework for managing AI risk, organized around four functions: Govern, Map, Measure, and Manage. It is the common US reference for building trustworthy AI.
72
requirements tracked
Core plans
Access
Add-on from $19/mo
Scope
How much of the standard Keel models
Keel authors every leaf requirement in the scope declared below, all 72 of them, with nothing inside that scope left out. A test fails the build if the authored count and the declared count ever diverge, so this framework cannot quietly lose requirements after the fact.
- Authored in Keel
- 72 requirements
- In Keel’s scored scope
- 72 leaf requirements
Keel publishes this for every framework it ships, complete or not, so a readiness percentage can be read against a denominator you can see. Compare every framework
Who it is for
Who needs NIST AI Risk Management Framework?
- US organizations and federal contractors standing up AI governance
- Teams that want a voluntary, flexible framework rather than a certification
- Risk and security leaders aligning AI risk with their existing programs
What Keel does
How Keel helps with NIST AI Risk Management Framework
- The Govern, Map, Measure, and Manage functions as a trackable control set
- Evidence shared with your other frameworks so you are not duplicating work
- A live readiness view across all four functions
Collect once, comply everywhere
NIST AI Risk Management Framework shares canonical controls with ISO/IEC 42001, AI Governance Essentials and EU AI Act and others in the catalog. Implement one of those controls and it counts toward every framework it satisfies, so adding NIST AI Risk Management Framework rarely means starting from scratch.
- ISO/IEC 27001 shares canonical controls
- CIS Critical Security Controls no shared canonical controls
- PCI DSS no shared canonical controls
- SOC 2 no shared canonical controls
- SOX (Sarbanes-Oxley) Section 404 no shared canonical controls
- NIST Cybersecurity Framework shares canonical controls
- NIST SP 800-53 shares canonical controls
- FedRAMP Rev5 Class B shares canonical controls
- FedRAMP Rev5 Class C shares canonical controls
- FedRAMP Rev5 Class D shares canonical controls
- FedRAMP 20x shares canonical controls
- FedRAMP Consolidated Rules no shared canonical controls
- NIST SP 800-171 no shared canonical controls
- HIPAA no shared canonical controls
- GDPR shares canonical controls
- COPPA no shared canonical controls
- Google Play Families no shared canonical controls
- Amazon Appstore Child-Directed Apps no shared canonical controls
- Apple App Store Kids Category no shared canonical controls
- PIPEDA no shared canonical controls
- ISO 9001 shares canonical controls
- AI Governance Essentials shares canonical controls
- ISO/IEC 42001 shares canonical controls
- EU AI Act shares canonical controls
- ESG Essentials shares canonical controls
- US Employment Law - Federal Baseline no shared canonical controls
A framework is lit when at least one canonical control satisfies both NIST AI Risk Management Framework and that framework. Unlit means none of them do, which is an absence rather than a judgment about that standard. 13 of 26 are lit here.
Other frameworks: ISO/IEC 27001 · CIS Critical Security Controls · PCI DSS · SOC 2 · SOX (Sarbanes-Oxley) Section 404 · NIST Cybersecurity Framework · All frameworks