NIST AI RMF 1.0
The NIST AI Risk Management Framework organizes AI risk management into four functions: GOVERN, MAP, MEASURE, and MANAGE. AGLedger provides strong direct support across all four.
AGLedger provides the accountability infrastructure. Your organization provides the risk management strategy and decisions.
GOVERN
Establish and maintain policies, processes, and accountability structures for AI risk management.
AGLedger provides
- Structured accountability chain for every automated operation (mandate → receipt → verdict)
- Role-based access: principal, performer, accessor with defined authority scopes
- Append-only audit vault records every policy decision and oversight action
- Cross-mandate compliance attestation records linked to audit chain
Enterprise owns
- Defining governance policies and risk tolerances
- Designating responsible individuals and their authority
- Establishing organizational AI risk management strategy
MAP
Identify, categorize, and document AI risks in context.
AGLedger provides
- Risk level and domain classification per mandate (maps to Annex III categories)
- Structured records linking each automated operation to its risk context
- Federation enables cross-organizational risk mapping with sovereign data
- Custom schemas allow domain-specific risk categorization
Enterprise owns
- Performing the risk assessment
- Determining risk categories and thresholds
- Mapping AI systems to organizational context
MEASURE
Analyze, assess, and track AI risks and impacts.
AGLedger provides
- Built-in reputation scoring tracks agent reliability over time
- Tolerance bands and verification rules enforce numeric bounds
- Drift detection across model updates and provider changes
- Evidence-based measurement built on the mandate/receipt/verdict chain
Enterprise owns
- Defining measurement criteria and acceptable thresholds
- Interpreting measurement results
- Deciding what corrective action to take
MANAGE
Allocate resources and implement plans to respond to AI risks.
AGLedger provides
- 3-tier dispute resolution: self-resolution, mediation, human escalation
- Remediation states and revision workflow for corrective actions
- Settlement Signal (SETTLE/HOLD) routes outcomes to downstream systems
- Full chain exportable for regulatory submission and third-party audit
Enterprise owns
- Resource allocation decisions
- Risk response strategy and implementation
- Ongoing monitoring program design