NIST AI RMF crosswalk: the four functions, mapped

If your AI risk program needs to implement the four NIST AI RMF functions - GOVERN, MAP, MEASURE, and MANAGE - here is how each maps to the AGLedger record, the Signed Statement chain, the dispute path, and the Settlement Signal surface.

The crosswalk is a capability mapping. AGLedger provides the evidence pattern; your program provides the risk methodology, the tolerances, and the response decisions.

If your AI program needs to evidence NIST AI RMF MEASURE controls, the crosswalk below applies. The same evidence pattern - signed records, hash-chained, append-only - also supports non-AI automated work under SOX, GLBA, HIPAA, and other control families that require tamper-evident audit trails for RPA, CI pipelines, and microservice handoffs. AGLedger is software you self-host; the regulations are AI-framed, the underlying evidence pattern is not.

The crosswalk at a glance

FunctionAGLedger evidencesYour program owns
GOVERNWho held which authority, and every oversight action, on a signed chain (record → completion → verdict)Policies, risk tolerances, who is responsible
MAPRisk level and domain classification per record; each operation tied to its risk contextThe risk assessment itself; categories and thresholds
MEASURETolerance bands on criteria, signed timestamps on every transition, queryable acceptance and rejection ratesMeasurement criteria; interpreting results
MANAGEDispute and remediation states on the chain; Settlement Signals routing outcomes; full export for third-party auditRisk response strategy; resource allocation

Each function is expanded below. For NIST's own mappings to ISO/IEC 42001 and the EU AI Act, see the official AI RMF crosswalks.

GOVERN

Establish and maintain policies, processes, and accountability structures for AI risk management.

AGLedger provides

  • Structured accountability chain for every automated operation (record → completion → verdict)
  • Role-based access: principal, performer, accessor with defined authority scopes
  • Append-only audit vault records every policy decision and oversight action
  • Cross-record compliance attestation records linked to audit chain

You own

  • Defining governance policies and risk tolerances
  • Designating responsible individuals and their authority
  • Establishing organizational AI risk management strategy

MAP

Identify, categorize, and document AI risks in context.

AGLedger provides

  • Risk level and domain classification per record (maps to Annex III categories)
  • Structured records linking each automated operation to its risk context
  • Federation enables cross-organizational risk mapping with sovereign data
  • Custom schemas allow domain-specific risk categorization

You own

  • Performing the risk assessment
  • Determining risk categories and thresholds
  • Mapping AI systems to organizational context

MEASURE

Analyze, assess, and track AI risks and impacts.

AGLedger provides

  • Tolerance bands enforce numeric bounds on record criteria
  • Timeliness evidence - every state transition timestamped and signed
  • Reputation scoring tracks agent reliability across records
  • Drift detection across model updates and provider changes (most useful in federated deployments)
  • Audit vault queryable for cross-record analysis of acceptance, rejection, and revision rates

You own

  • Defining measurement criteria and acceptable thresholds
  • Interpreting measurement results
  • Deciding what corrective action to take

MANAGE

Allocate resources and implement plans to respond to AI risks.

AGLedger provides

  • 3-tier dispute resolution: self-resolution, mediation, human escalation
  • Remediation states and revision workflow for corrective actions
  • Settlement Signal™ (SETTLE/HOLD/RELEASE) routes outcomes to downstream systems
  • Full chain exportable for regulatory submission and third-party audit

You own

  • Resource allocation decisions
  • Risk response strategy and implementation
  • Ongoing monitoring program design

The AI RMF is voluntary, but its GOVERN, MAP, MEASURE, and MANAGE functions all assume durable evidence of how your AI systems actually behave in production. AGLedger provides that evidence pattern - signed, hash-chained, exportable for third-party audit; your risk-management program provides the policy and process around it.

Frequently asked

How does AGLedger map to the NIST AI RMF GOVERN function?
GOVERN establishes and maintains policies, processes, and accountability structures for AI risk management. AGLedger provides a structured accountability chain for every automated operation (record to completion to verdict), role-based access with defined authority scopes, an append-only audit vault that records every policy decision and oversight action, and cross-record compliance attestation records linked to the audit chain. You own defining governance policies and risk tolerances, designating responsible individuals, and establishing the organizational AI risk management strategy.
How does AGLedger support the MAP function?
MAP identifies, categorizes, and documents AI risks in context. AGLedger provides risk level and domain classification per record (mapping to Annex III categories), structured records linking each automated operation to its risk context, federation for cross-organizational risk mapping with sovereign data, and custom schemas for domain-specific risk categorization. You own performing the risk assessment, determining risk categories and thresholds, and mapping AI systems to organizational context.
How does AGLedger support the MEASURE function?
MEASURE analyzes, assesses, and tracks AI risks and impacts. AGLedger provides tolerance bands that enforce numeric bounds on record criteria, timeliness evidence with every state transition timestamped and signed, reputation scoring across records, drift detection across model updates and provider changes, and an audit vault queryable for cross-record analysis of acceptance, rejection, and revision rates. You own defining measurement criteria, interpreting results, and deciding what corrective action to take.
How does AGLedger support the MANAGE function?
MANAGE allocates resources and implements plans to respond to AI risks. AGLedger provides 3-tier dispute resolution (self-resolution, mediation, human escalation), remediation states and a revision workflow for corrective actions, Settlement Signals (SETTLE/HOLD/RELEASE) that route outcomes to downstream systems, and a full chain exportable for regulatory submission and third-party audit. You own resource allocation decisions, risk response strategy, and ongoing monitoring program design.

Primary sources