NIST AI RMF
Voluntary guidance from NIST AI 100-1 for AI agent risk programmes
The NIST AI Risk Management Framework is voluntary guidance, not a binding regulation. Organisations adopt it as a programme structure for trustworthy AI: GOVERN, MAP, MEASURE, and MANAGE. Federal contractors and many state-level rules (including the Colorado AI Act and Texas TRAIGA) reference NIST guidance as a substantial-compliance benchmark.
Asqav supplies the MEASURE function with cryptographic evidence per AI agent action, and provides structured input to GOVERN and MAP through retained policy artefacts and incident vocabularies. The audit pack converts that evidence into a regulator-ready report.
The receipt format is profiled in the IETF Internet-Draft draft-marques-asqav-compliance-receipts, which binds the format to AI RMF GOVERN, MAP, MEASURE, and MANAGE outcomes.
Function mapping
| Function | Outcome | Asqav binding |
|---|---|---|
| GOVERN | Policies, processes, and accountability structures for trustworthy AI. | Every action carries a policy_digest resolving to the in-force policy artefact. The retention floor and revocation manifest evidence accountability decisions. |
| MAP | Context establishment, including AI system characterisation and stakeholder identification. | Receipts bind issuer_id (LEI / EIN / CIK / DID) and action_ref to a stable identity, so the AI system map persists across policy revisions. |
| MEASURE | Quantitative and qualitative measurement of AI risks and trustworthiness characteristics. | Per-action signed evidence with anchored timestamps, hash-chain integrity, and duplicate-emission flagging. Audit pack export packages a measurement window for review. |
| MANAGE | Risk treatment, monitoring, and continuous improvement. | Conflict-refusal lifecycle receipts capture risk decisions. Cross-regime incident_class categorises managed events for downstream MITRE / sectoral mapping. |
NIST AI RMF substantial-compliance evidence is recognised under several US frameworks (Texas TRAIGA HB 149, federal procurement). The audit pack export plus the per-receipt attestation chain supplies the structured input the framework expects. See the docs for the full mapping and the IETF draft for the binding text.