Regulation (voluntary but referenced)

NIST AI RMF 1.0 — GOVERN / MAP / MEASURE / MANAGE

Voluntary framework, but cited by CMS AI Interpretive Guidance, HHS ONC, SEC risk-alert language, OCC bulletin references, and multiple state AG healthcare-AI enforcement actions. "Voluntary" is the label; "load-bearing baseline" is the operational reality once litigation or a survey question uses it as the yardstick.

The four core functions

FunctionWhat it demands
GOVERNNamed owner, policies, accountability structure for the AI system. Board or C-suite visible.
MAPInventory of every AI surface + purpose + inputs + affected populations + regulatory-context tags.
MEASUREOngoing measurement of accuracy, drift, group-differential, adverse-impact, robustness. Not annual point-in-time.
MANAGEResponse protocol when MEASURE surfaces a problem. Human-in-the-loop escalation, freeze/hold criteria, disclosure obligations.
"AI risk management should be integrated and incorporated into broader enterprise risk management strategies and processes … treating AI risks along with other critical risks … will yield a more integrated outcome and organizational efficiencies." NIST AI 100-1 (AI RMF 1.0) §1

Where most orgs quietly fail

MEASURE. Vendor dashboards typically show aggregate metrics (accuracy, latency, throughput). Aggregate metrics stay green while group-differential fails silently. NIST MEASURE demands per-group + adverse-impact + drift measurement, distinct from the production model's own self-reporting.

The independent-verifier principle is the practical translation of MEASURE + MANAGE: the entity that owns the AI cannot also be the entity that measures the AI's failure modes on patient groups it economically prefers not to see.

What the $499 Snapshot shows against NIST

See how a Category-C determination is derived →

How does this help me?

NIST is voluntary. The consequence of NOT meeting it is not a NIST fine — it's the follow-on regulator, court, or auditor citing NIST as the reasonable-person baseline and asking why you didn't.

Read: NIST AI RMF -- what it saves you when someone else weaponizes "voluntary" →

Continue to your vertical's sample

Healthcare Legal Insurance Banking Pharma RIA / Wealth Education Housing Energy Federal

$499 Snapshot. 3 business days.

Independent-verifier determination on ONE of your AI systems + 3 fix-first items + counterparty-question rehearsal + signed declaration.

Buy $499
Snapshot credit applies to Baseline ($2,500) or Enterprise Attestation ($35-55K) upgrade within 30 days.