NIST AI RMFAI 100-1⚙ GenAI Profile · AI 600-1Printable Checklist

NIST AI RMF Compliance Checklist

The four core functions (Govern, Map, Measure, Manage), risk-tier guidance, and the 30/60/90-day roadmap — print this, walk it with your team.

GovernIQ · Full guide at governiq-6huk.polsia.app/nist-ai-rmf-guide · Verify against NIST AI RMF — NIST

1.Govern — Policies, Roles & Accountability

The umbrella for the rest of the framework. Without a working Govern function, Map / Measure / Manage operate on an unowned problem. Spend the first 30 days here.

2.Map — Context for Every In-Scope AI System

Context-building for each AI system. The Map artifacts feed Measure and Manage; weak Map means Measure tests the wrong things. Days 31–60 of the roadmap.

3.Measure — TEVV & Continuous Evaluation

Test, Evaluation, Verification, Validation. Lifecycle-spanning practice, not a pre-deployment event. Days 61–90 of the roadmap deliver the baseline.

4.Manage — Risk Treatment & Incident Response

Operational, ongoing. Day 91+ runs continuously: risk register, incident response, vendor management, change management.

5.Risk Tiers — Apply to Every System

NIST AI RMF 1.0 does not prescribe tiers, but SMBs adopting explicit tiers spend resources proportionately and align cleanly to sector regulators.