Skip to content
Cyber Horizon
All frameworks

// US Standards

NIST AI Risk Management Framework Compliance Software

Voluntary framework to help organisations manage risks in AI systems.

Framework at a glance

Short name

NIST AI RMF

Version

Category

US Standards

Controls

30

What NIST AI RMF covers

30 controls across 28 domains — every one tracked, owned and evidenced in Cyber Horizon.

Policy

1 controls
  • GV-1.1 AI risk management policy

Risk Tolerance

2 controls
  • GV-1.2 AI risk tolerance
  • MP-1.5 Organisational risk tolerance

Governance

2 controls
  • GV-1.3 AI risk roles
  • GV-1.4 Organisational teams for AI risk

Culture

1 controls
  • GV-1.5 AI risk culture

Communication

1 controls
  • GV-1.6 AI policies communicated

Integration

1 controls
  • GV-1.7 AI risk management integrated

Inventory

1 controls
  • GV-2.1 AI inventory

Documentation

1 controls
  • GV-2.2 AI use case documentation

Accountability

1 controls
  • GV-3.1 AI developer accountability

Teams

1 controls
  • GV-4.1 Organisational teams for AI

Maintenance

1 controls
  • GV-5.1 Policies updated

Third-Party

1 controls
  • GV-6.1 Policies for third-party AI

Context

1 controls
  • MP-1.1 Context and goals

Scope

1 controls
  • MP-1.2 AI system scope

Stakeholders

1 controls
  • MP-1.3 Stakeholders identified

Research

1 controls
  • MP-2.1 Scientific findings

Impact

1 controls
  • MP-2.2 Societal context

Classification

1 controls
  • MP-2.3 AI risk categories

Prioritisation

1 controls
  • MP-3.4 AI risks prioritised

Metrics

1 controls
  • MS-1.1 Metrics established

Testing

1 controls
  • MS-2.1 AI testing and evaluation

Performance

1 controls
  • MS-2.2 Evaluating AI performance

Bias

1 controls
  • MS-2.3 AI bias testing

Explainability

1 controls
  • MS-2.5 Explainability measurement

Evaluation

1 controls
  • MS-3.1 Effectiveness of risk treatments

Treatment

1 controls
  • MG-1.1 Risk treatment plans

Response

1 controls
  • MG-2.1 Mechanisms to respond

Monitoring

1 controls
  • MG-3.1 AI risk monitoring

How Cyber Horizon automates NIST AI RMF

Every NIST AI RMF control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.

Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.

Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.

Frequently asked questions

What is NIST AI Risk Management Framework?

Voluntary framework to help organisations manage risks in AI systems.

How many controls does NIST AI Risk Management Framework have?

NIST AI Risk Management Framework has 30 controls in Cyber Horizon's catalogue, organised across 28 domains.

How does Cyber Horizon help with NIST AI Risk Management Framework?

Cyber Horizon maps NIST AI Risk Management Framework into a shared control library alongside every other framework you run, so evidence collected once counts towards NIST AI RMF and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.

See NIST AI RMF mapped to your environment

Start with the free 20-question readiness check — no signup — or get a personal walkthrough of NIST AI RMF in Cyber Horizon.