1.Govern — Policies, Roles & Accountability
The umbrella for the rest of the framework. Without a working Govern function, Map / Measure / Manage operate on an unowned problem. Spend the first 30 days here.
- AI acceptable-use policy documented and signed by accountable executive
- AI system inventory: every AI tool in production today
- Named AI risk owner with documented line of accountability
- Escalation path for AI-related incidents
- Vendor procurement clause library for AI assurance
- Mandatory AI literacy training brief for staff operating in-scope systems
- Regulatory mapping updated on rule changes (SB 24-205, EU AI Act, sectoral)
- Internal grievance channel operational
- Annual governance review by accountable executive
2.Map — Context for Every In-Scope AI System
Context-building for each AI system. The Map artifacts feed Measure and Manage; weak Map means Measure tests the wrong things. Days 31–60 of the roadmap.
- Intended purpose documented per system
- Deployment surface recorded (internal / B2B / B2C)
- Out-of-scope uses explicitly listed
- Regulatory context mapped (HIPAA, GDPR, state, EU, sector)
- System capability + data modalities logged
- Stakeholder register: users, operators, executives, consumers, partners
- Direct, disparate-impact, IP, and security risks enumerated
- Lifecycle stage and next transition tracked
- Re-Map on material change (typically 30-day trigger from vendor)
3.Measure — TEVV & Continuous Evaluation
Test, Evaluation, Verification, Validation. Lifecycle-spanning practice, not a pre-deployment event. Days 61–90 of the roadmap deliver the baseline.
- TEVV plan written before deployment (metrics, datasets, owners)
- Baseline accuracy / F1 / calibration recorded per system
- Drift monitoring on production traffic enabled
- Disparate-impact tests across protected classes (re-evaluation on rolling 90-day cadence)
- Robustness tests: prompt injection, adversarial inputs, output filters
- GenAI extensions (NIST AI 600-1): confabulation probes, IP / copyright reproduction tests, provenance / watermarking
- Output traceability / confidence surfaced at decision points
- Test data held out from training (clean separation)
- Evaluation suite version-tagged and archived
4.Manage — Risk Treatment & Incident Response
Operational, ongoing. Day 91+ runs continuously: risk register, incident response, vendor management, change management.
- AI risk register with priority ranking tied to Map / Measure outputs
- Resource allocation documented to register entries
- AI incident response plan with severity classification
- Customer / regulator notification templates ready and rehearsed
- Vendor risk register per in-scope AI system
- Material-change clauses in vendor contracts (typically 30-day notice)
- Model + prompt version control with rollback procedure tested annually
- Records retention ≥3 years (SB 26-189 cadence; longer for HIPAA / financial)
- Post-incident remediation loop documented
5.Risk Tiers — Apply to Every System
NIST AI RMF 1.0 does not prescribe tiers, but SMBs adopting explicit tiers spend resources proportionately and align cleanly to sector regulators.
- Tier 1 — Critical: full TEVV, bias tests, adversarial evaluation, continuous monitoring, executive accountability
- Tier 2 — High: standard TEVV, weekly drift checks, periodic bias tests, vendor docs, 30-day triggers
- Tier 3 — Medium: smoke TEVV, monthly drift checks, enforced human-in-the-loop, quarterly owner review
- Tier 4 — Low / Minimal: output sanity checks, quarterly owner confirmation, document use rationale
- Re-tier when use case shifts, vendor updates land, or incidents occur