Frameworks

AI governance, on the same platform as everything else.

AI risk is not a separate program. TruOps assesses it against the NIST AI RMF with the same engine, evidence, and register you use for everything else.

NIST AI RMF · readinessevidence current
NIST AI RMF · coverage by function
Governpartial · 52%
Mappartial · 72%
Measureopen · 24%
Managepartial · 60%
The same work also counts toward
ISO 4200161% · partials shown
ISO 2700142% · partials shown
SOC 265% · partials shown

Mappings are typed exact, partial, or inferred, each with a citation.

Illustrative example
In short

The NIST AI Risk Management Framework (AI RMF 1.0), released in January 2023, is voluntary guidance for managing risks from AI systems. It is organized into four functions: Govern, Map, Measure, and Manage. NIST published a Generative AI Profile (NIST AI 600-1) in July 2024 that applies the framework to generative AI.

This page is for you if
  • Customers or the board asked how you govern AI, and the answer is a policy slide
  • AI systems are not in the same inventory as the rest of GRC
  • You already run ISO 27001 or SOC 2 and do not want a parallel AI program
Published by
NIST
Version
AI RMF 1.0 (January 2023)
Functions
Govern · Map · Measure · Manage
Companion
Generative AI Profile, NIST AI 600-1

The four functions

FunctionFocus
GovernCulture, policies, roles, and accountability for AI risk
MapContext: what the AI system is for, who it affects, and what could go wrong
MeasureAnalysis and tracking of AI risks and trustworthiness characteristics
ManagePrioritizing and acting on risks, and monitoring over time

The actual challenge

AI risk is being stood up as a side spreadsheet while models ship. The RMF only works if AI systems are assessable targets with owners, evidence, and residual risk in the same register as everything else.

  • Govern/Map/Measure/Manage was workshopped once.
  • Vendor AI (models in SaaS you buy) is invisible.
  • ISO 42001 is next and would restart the work.

Bring one real document. Watch the program get set up from it.

What you are probably using today

Almost nobody starts NIST AI RMF from zero. You already have a program somewhere. TruOps is built to take that over, not make you start again.

What you use nowWhere it breaksWith TruOps
Spreadsheets, shared drives, and emailThe program lives in folders named after last year's audit. Owners paste screenshots the week before fieldwork. Nothing is dated, so you cannot show what was true last quarter.Upload those same files. TruOps pre-fills the assessment from them, cites every answer, and keeps technical checks running so evidence exists for the whole period.
SOC 2 automation toolsThey are strong at certification: automated tests, a broad framework library, and often a trust center. Maturity scoring, custom frameworks, and deep risk or vendor work can sit outside that model.Keep the automation. Run any framework as the anchor, map the rest with partials shown as partial, and run vendor and risk on the same engine. Upload the policies and reports you already have.
Enterprise GRC suitesThey can model almost anything. That flexibility usually comes through implementation partners and administrators, so a change can become a project.AI reads your existing documents and sets up the program. The first assessment opens pre-filled from them, with sources. Changes are a request in plain language, not a project.

Trustworthy AI characteristics

The framework describes trustworthy AI as valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed.

How TruOps helps with the NIST AI RMF

Pick the NIST AI RMF as your anchor, or map it to the framework you already run. TruOps keeps the NIST AI RMF's own structure, down to the individual requirement, and shows coverage per requirement as satisfied, partial, or open, with the evidence behind each.

Upload what you have (prior reports, policies, spreadsheets) and TruOps pre-fills your NIST AI RMF assessment with cited answers. Connected tools keep technical controls current on the schedule you set, and failed checks become findings with a recommended fix.

Many AI RMF outcomes overlap with ISO/IEC 42001 and with controls you already run for SOC 2 or ISO 27001. TruOps shows how much of your AI RMF readiness those controls already cover.

If this is your situation

Inventory one AI system and run an RMF questionnaire on it in a demo. TruOps will show which existing SOC 2 or ISO 27001 controls already cover it.

How TruOps helps

Anchor or map
Run AI RMF as your spine or map it to another framework; work counts once.
Pre-filled assessment
Your AI RMF assessment opens with the answers your evidence supports already filled, each cited.
Honest coverage
Partial coverage is reported as partial, with the remaining requirements listed.
Continuous monitoring
Technical controls checked against your tools hourly to quarterly.
Findings with fixes
Failed checks become grouped findings with a recommended action.
Audit-ready snapshots
Results saved as of their date, with the evidence trail attached.

Questions

Is the NIST AI RMF mandatory?

No. It is voluntary guidance, though it is increasingly referenced by customers, contracts, and policy.

How does the AI RMF relate to ISO/IEC 42001?

The AI RMF is voluntary guidance; ISO/IEC 42001 is a certifiable management-system standard. Their concepts overlap and are often mapped to each other.

Can TruOps assess our AI systems?

Yes. Scope an assessment to an AI system or business process and run an AI RMF or ISO 42001 questionnaire on the same engine.

Do we have to rip out the tools we already use?

No. Connectors are read-only: they observe cloud, identity, endpoint, vulnerability, and code tools; they do not change them. Spreadsheets, prior reports, and policies upload into the Data Room. If you are on a SOC 2 automation tool or an enterprise GRC suite, you migrate the program (frameworks, evidence, vendors, risks), not the business.

Can we bring our existing assessments, control lists, and vendor files?

Yes. Upload workbooks, reports, policies, and vendor exports. TruOps turns them into structured questionnaires, controls, and register entries, each cited back to the file they came from, for you to review.

Does TruOps replace our auditor, QSA, or certification body?

No. Only a licensed auditor, QSA, C3PAO, or accredited certification body can issue the opinion. TruOps gets the evidence current, cited, and dated so fieldwork is a review, not an archaeology project.

See it run on your own data.

Thirty minutes with a GRC expert, not an SDR. Bring one real document (a SOC 2 report, a risk register, a vendor list; redacted is fine) and watch TruOps set up a live program from it, with an assessment already pre-filled.