Skip to main content

NIST AI Risk Management Framework

Feature row 36 — Sprint COMP-3

NIST AI RMF mapping is included on the Enterprise plan.

Scope

NIST AI RMF is the de facto reference framework for AI risk in the United States federal ecosystem. Behavry ships a mapping for 8 requirements across the four functions — GOVERN, MAP, MEASURE, MANAGE — that are directly instrumented by the product.

Source: backend/behavry/compliance/nistrmf.py. UI: Compliance → NIST AI RMF.

Covered requirements

FunctionRequirementBehavry answer
GOVERN 1.1Policies are in placePolicy Engine + Policy Writer + Change Requests
GOVERN 1.5Roles and accountabilityUser roles, audit log user attribution
MAP 1.1Context is documentedAI Surface Mapping, Dependency & Lineage
MAP 5.1Risk is characterizedBehavioral Risk Framework (BRF)
MEASURE 1.1Measurement is plannableDecision Trace + SIEM Connectors (evidence pipelines)
MEASURE 2.6Incidents are trackedAlerts & Escalations, HITL queue
MANAGE 2.4Response and recoveryGlobal Kill Switch, Restricted Mode
MANAGE 4.1Continuous monitoringBehavioral Monitor, Intent Drift, Cross-Session Trust Reset

Continuous posture

Same live evidence pattern as SOC 2 / ISO. Each function gets a card showing its overall status and the per-requirement breakdown beneath it.

Export

GET /api/v1/compliance/nist-ai-rmf/export?format=pdf|csv|json

How to use this for a federal conversation

A typical federal AI risk review wants three things for each requirement:

  1. A description of what you do to address it
  2. Evidence that you do it continuously, not just once
  3. A responsible party — who owns the control

Behavry provides (1) and (2) automatically; the export includes both. Add (3) via the optional "owner" field in the export and the PDF will pick it up.