01 / Source and scope
Who acts, and what changes?
Principal and authority origin
Organization operating AI systems. Voluntary NIST AI RMF governance process.
Consequential action
Map, measure and manage risks from agent actions.
02 / Action-time control
Make the requested effect testable.
The RMF is guidance, not a product certification or blanket authorization rule. Use task and action decisions as evidence for mapped risks; assign risk acceptance to human governance.
OriginVoluntary NIST AI RMF governance process
RequestMap, measure and manage risks from agent actions
DecisionEvaluate and enforce before effect
03 / Evidence and responsibility
Permission, execution, and outcome are separate.
Risk register, control design, test results, exceptions and monitored outcomes.
ProofGrid can contribute action-level control evidence. The organization still performs the RMF governance, impact assessment and monitoring.
Primary source