AI governance, on the same platform as everything else.
AI risk is not a separate program. TruOps assesses it against the NIST AI RMF with the same engine, evidence, and register you use for everything else.
Mappings are typed exact, partial, or inferred, each with a citation.
The NIST AI Risk Management Framework (AI RMF 1.0), released in January 2023, is voluntary guidance for managing risks from AI systems. It is organized into four functions: Govern, Map, Measure, and Manage. NIST published a Generative AI Profile (NIST AI 600-1) in July 2024 that applies the framework to generative AI.
- Customers or the board asked how you govern AI, and the answer is a policy slide
- AI systems are not in the same inventory as the rest of GRC
- You already run ISO 27001 or SOC 2 and do not want a parallel AI program
- Published by
- NIST
- Version
- AI RMF 1.0 (January 2023)
- Functions
- Govern · Map · Measure · Manage
- Companion
- Generative AI Profile, NIST AI 600-1
The four functions
| Function | Focus |
|---|---|
| Govern | Culture, policies, roles, and accountability for AI risk |
| Map | Context: what the AI system is for, who it affects, and what could go wrong |
| Measure | Analysis and tracking of AI risks and trustworthiness characteristics |
| Manage | Prioritizing and acting on risks, and monitoring over time |
The actual challenge
AI risk is being stood up as a side spreadsheet while models ship. The RMF only works if AI systems are assessable targets with owners, evidence, and residual risk in the same register as everything else.
- Govern/Map/Measure/Manage was workshopped once.
- Vendor AI (models in SaaS you buy) is invisible.
- ISO 42001 is next and would restart the work.
Bring one real document. Watch the program get set up from it.
What you are probably using today
Almost nobody starts NIST AI RMF from zero. You already have a program somewhere. TruOps is built to take that over, not make you start again.
| What you use now | Where it breaks | With TruOps |
|---|---|---|
| Spreadsheets, shared drives, and email | The program lives in folders named after last year's audit. Owners paste screenshots the week before fieldwork. Nothing is dated, so you cannot show what was true last quarter. | Upload those same files. TruOps pre-fills the assessment from them, cites every answer, and keeps technical checks running so evidence exists for the whole period. |
| SOC 2 automation tools | They are strong at certification: automated tests, a broad framework library, and often a trust center. Maturity scoring, custom frameworks, and deep risk or vendor work can sit outside that model. | Keep the automation. Run any framework as the anchor, map the rest with partials shown as partial, and run vendor and risk on the same engine. Upload the policies and reports you already have. |
| Enterprise GRC suites | They can model almost anything. That flexibility usually comes through implementation partners and administrators, so a change can become a project. | AI reads your existing documents and sets up the program. The first assessment opens pre-filled from them, with sources. Changes are a request in plain language, not a project. |
Trustworthy AI characteristics
The framework describes trustworthy AI as valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed.
How TruOps helps with the NIST AI RMF
Pick the NIST AI RMF as your anchor, or map it to the framework you already run. TruOps keeps the NIST AI RMF's own structure, down to the individual requirement, and shows coverage per requirement as satisfied, partial, or open, with the evidence behind each.
Upload what you have (prior reports, policies, spreadsheets) and TruOps pre-fills your NIST AI RMF assessment with cited answers. Connected tools keep technical controls current on the schedule you set, and failed checks become findings with a recommended fix.
Many AI RMF outcomes overlap with ISO/IEC 42001 and with controls you already run for SOC 2 or ISO 27001. TruOps shows how much of your AI RMF readiness those controls already cover.
If this is your situation
Inventory one AI system and run an RMF questionnaire on it in a demo. TruOps will show which existing SOC 2 or ISO 27001 controls already cover it.
How TruOps helps
- Anchor or map
- Run AI RMF as your spine or map it to another framework; work counts once.
- Pre-filled assessment
- Your AI RMF assessment opens with the answers your evidence supports already filled, each cited.
- Honest coverage
- Partial coverage is reported as partial, with the remaining requirements listed.
- Continuous monitoring
- Technical controls checked against your tools hourly to quarterly.
- Findings with fixes
- Failed checks become grouped findings with a recommended action.
- Audit-ready snapshots
- Results saved as of their date, with the evidence trail attached.
Questions
Is the NIST AI RMF mandatory?
No. It is voluntary guidance, though it is increasingly referenced by customers, contracts, and policy.
How does the AI RMF relate to ISO/IEC 42001?
The AI RMF is voluntary guidance; ISO/IEC 42001 is a certifiable management-system standard. Their concepts overlap and are often mapped to each other.
Can TruOps assess our AI systems?
Yes. Scope an assessment to an AI system or business process and run an AI RMF or ISO 42001 questionnaire on the same engine.
Do we have to rip out the tools we already use?
No. Connectors are read-only: they observe cloud, identity, endpoint, vulnerability, and code tools; they do not change them. Spreadsheets, prior reports, and policies upload into the Data Room. If you are on a SOC 2 automation tool or an enterprise GRC suite, you migrate the program (frameworks, evidence, vendors, risks), not the business.
Can we bring our existing assessments, control lists, and vendor files?
Yes. Upload workbooks, reports, policies, and vendor exports. TruOps turns them into structured questionnaires, controls, and register entries, each cited back to the file they came from, for you to review.
Does TruOps replace our auditor, QSA, or certification body?
No. Only a licensed auditor, QSA, C3PAO, or accredited certification body can issue the opinion. TruOps gets the evidence current, cited, and dated so fieldwork is a review, not an archaeology project.
Related
The certifiable AI management system standard.
→Use casesAI governanceAssess AI systems against NIST AI RMF and ISO 42001.
→LearnWhat is AI GRC?When AI does the work of governance, risk, and compliance.
→LearnHuman-in-the-loop AI in GRCWhy AI should draft and people should decide.
→See it run on your own data.
Thirty minutes with a GRC expert, not an SDR. Bring one real document (a SOC 2 report, a risk register, a vendor list; redacted is fine) and watch TruOps set up a live program from it, with an assessment already pre-filled.