Scrydon
Compliance

NIST AI RMF

How Scrydon supports the NIST AI Risk Management Framework — Govern, Map, Measure, Manage.

The NIST AI Risk Management Framework (AI RMF 1.0) is a voluntary framework for managing AI risk. Its four functions — Govern, Map, Measure, Manage — span the AI lifecycle.

This page maps Scrydon's controls to each function.

Govern

The Govern function is about establishing organisational AI risk management.

RMF itemScrydon support
GOVERN 1 — Policies and proceduresThis documentation site + your org's policy library.
GOVERN 2 — AccountabilityWorkflow ownership, ontology authorship attribution, audit log.
GOVERN 3 — Workforce(Organisational — outside platform scope.)
GOVERN 4 — AwarenessInline help, contextual disclosure on AI surfaces.
GOVERN 5 — Stakeholder engagementDocumented per workflow's impact assessment.
GOVERN 6 — Risk mapping to legalEU AI Act + GDPR + framework mappings in Compliance.

Map

The Map function is about understanding context and identifying risks.

RMF itemScrydon support
MAP 1 — ContextPer-workflow purpose statement + system inventory.
MAP 2 — ComponentsWorkflow definition shows every block + integration. The platform exposes a machine-readable inventory.
MAP 3 — Risks identifiedRisk assessment template. See AI governance.
MAP 4 — Risks characterisedRisk categorisation (likelihood × impact) per identified risk.
MAP 5 — Impacts characterisedImpact assessment template.

Measure

The Measure function is about analysing and tracking AI risks.

RMF itemScrydon support
MEASURE 1 — Approaches selectedEvaluator block + structured testing harness.
MEASURE 2 — Trustworthy characteristics assessedEvaluator scoring; bias + fairness hooks.
MEASURE 3 — Performance measuredRun logs, evaluator scores, drift signals.
MEASURE 4 — EffectivenessContinuous improvement template captures what worked.

Manage

The Manage function is about prioritising and addressing risks.

RMF itemScrydon support
MANAGE 1 — PrioritiesRisk register + business-impact ranking.
MANAGE 2 — TreatmentsGuardrails, evaluator gates, classification & masking, retraining or model swap.
MANAGE 3 — Third-party riskVendor registry + per-integration data-residency profile.
MANAGE 4 — MonitoringPost-deployment monitoring template; automated metrics.

How the lifecycle artefacts work

The platform maintains AI-specific lifecycle artefacts referenced in AI governance. These map to NIST RMF as:

  • AI system inventory → MAP 1, MAP 2.
  • Impact assessment → MAP 5.
  • Risk assessment → MAP 3, MAP 4.
  • TEVV (test, evaluate, verify, validate) → MEASURE 1, MEASURE 2.
  • Post-deployment monitoring → MEASURE 3, MANAGE 4.
  • Decommissioning record → MANAGE 4.
  • Decisions log → GOVERN 2.
  • AI governance — lifecycle artefacts in full.
  • ISO 42001 — international counterpart with significant overlap.
  • EU AI Act — regulatory framework that consumes RMF-style artefacts.
On this page

On this page