Reference
NIST AI RMF Mapping
How Beltic credentials map to NIST AI Risk Management Framework functions and categories.
Beltic credentials align with NIST AI Risk Management Framework (AI RMF) to support AI governance and risk management.
NIST AI RMF Overview
The NIST AI RMF defines 4 core functions:
- GOVERN - Policies, processes, and oversight
- MAP - Context, categorization, and risk identification
- MEASURE - Testing, evaluation, and validation
- MANAGE - Response, monitoring, and continuous improvement
Credential Field Mapping
GOVERN
Fields establishing accountability and governance:
DeveloperCredential:
legalName- Legal accountabilityentityType- Organizational structureincorporationJurisdiction- Regulatory contextkybTier- Verification levelsanctionsScreeningStatus- Compliance screeningoverallRiskRating- Risk classification
AgentCredential:
agentId- Unique identifier for trackingdeveloperCredentialId- Developer accountability linkincidentResponseContact- Governance processdeprecationPolicy- Lifecycle management
MAP
Fields describing context and intended use:
AgentCredential:
agentDescription- Intended purposeapprovedUseCases- Authorized applicationsprohibitedUseCases- RestrictionsdataCategoriesProcessed- Data contexttoolsList- Capability inventory with risk categoriesdeploymentEnvironment- Technical contextageRestrictions- User appropriateness
MEASURE
Fields tracking evaluation and testing:
AgentCredential:
harmfulContentRefusalScore- Safety testingpromptInjectionRobustnessScore- Security testingtoolAbuseRobustnessScore- Capability testingpiiLeakageRobustnessScore- Privacy testing- All benchmark metadata (name, version, date, source)
systemConfigFingerprint- Integrity verification
MANAGE
Fields supporting monitoring and response:
AgentCredential:
humanOversightMode- Control mechanismfailSafeBehavior- Risk mitigationmonitoringCoverage- ObservabilityupdateCadence- Maintenance schedulecredentialStatus- Lifecycle staterevocationListUrl- Revocation capability
DeveloperCredential:
credentialStatus- Active/suspended/revokedlastUpdatedDate- Freshness trackingrevocationListUrl- Accountability enforcement
Use Cases for Compliance
AI Governance Dashboard
Display NIST function coverage:
function getNISTCoverage(credential) {
return {
govern: {
accountability: credential.legalName,
verification: credential.kybTier,
compliance: credential.sanctionsScreeningStatus
},
map: {
purpose: credential.agentDescription,
capabilities: credential.toolsList,
restrictions: credential.prohibitedUseCases
},
measure: {
safety: credential.harmfulContentRefusalScore,
security: credential.promptInjectionRobustnessScore,
privacy: credential.piiLeakageRobustnessScore
},
manage: {
oversight: credential.humanOversightMode,
monitoring: credential.monitoringCoverage,
response: credential.incidentResponseContact
}
};
}Regulatory Reporting
Generate NIST compliance reports:
const nistReport = {
agent: credential.agentName,
functions: {
govern: ['KYB verification completed', 'Sanctions screening: clear'],
map: ['Approved use cases documented', 'Risk taxonomy applied'],
measure: ['Safety evaluation: 96/100', 'Security testing: 92/100'],
manage: ['Human oversight enabled', 'Incident response configured']
}
};Related Frameworks
Beltic credentials also align with:
- ISO/IEC 42001 - AI management system standard
- EU AI Act - High-risk AI system requirements
- OECD AI Principles - Responsible AI development