NIST AI RMF mapping

What we map to. What we don’t.

CircleScope produces the AI usage inventory and continuous monitoring evidence that the NIST AI Risk Management Framework assumes an organization already has. It maps to specific subcategories under MAP, MEASURE, MANAGE, and GOVERN. It is not an AI governance program, and NIST AI RMF alignment is not certifiable — by us or anyone else. This page is the full mapping, boundaries included.

Strong fit — the core of the claim
MAP 1.1 — context and AI use established
Strong
The framework assumes you have an AI inventory. Most organizations don’t. Shadow AI discovery produces one: which AI services are actually in use, by whom, at what volume — continuously, not as a point-in-time survey.
MANAGE 4.3 — incidents and errors communicated
Strong
The alert queue, written incident summaries, resolution notes, and audit trail form a documented incident-response record for AI misuse — the artifact this subcategory asks for.
MEASURE 3.1 — identified risks tracked over time
Strong
Trend dashboards and redaction totals are longitudinal risk measurement — the part most organizations fake with an annual review. Here it accrues automatically from real usage.
GOVERN 4.3 — incident identification and information sharing
Strong
Detection plus routing to a named human within about a minute of capture, with severity-based recipients — the practice this subcategory describes, running continuously.
Good fit — supporting evidence
MEASURE 2.10 — privacy risk examined
Good
PII and PHI classification on every prompt, on-device redaction counts, and per-customer retention controls with automatic purging.
MEASURE 4.1 — post-deployment monitoring in regular use
Good
Continuous monitoring of actual AI usage rather than a point-in-time assessment — the operational definition of this subcategory.
GOVERN 1.5 — ongoing monitoring and periodic review
Good
Monthly reports are the review artifact: usage, incidents, and resolutions in a form a review meeting can actually consume.
Partial fit — we contribute, we don't complete
GOVERN 1.1 / 1.2 — policies and legal requirements documented
Partial
Our acceptable-use policy disclosure kit contributes language and the disclosure mechanism. The software itself doesn’t write or maintain your policy — that stays with you (or your counsel).
GOVERN 6.1 / 6.2, MAP 4.1 — third-party and value-chain risk
Partial
We surface which unvetted third-party AI services are in use — the discovery half. We do not assess those vendors; vendor due diligence remains your process.
The GenAI Profile

Against the twelve generative-AI risk categories

NIST’s Generative AI Profile (AI 600-1) names twelve risk categories. CircleScope contributes evidence for four, partially touches two, and does nothing for six. In our experience the vendors who claim all twelve are the reason this page exists.

Contributes

Data Privacy · Information Security · Intellectual Property · Value Chain and Component Integration — prompt-level detection, classification, and redaction evidence for each.

Partial

Human-AI Configuration (usage visibility and coaching, not system design) · Obscene, Degrading, and Abusive Content (flagged by the harmful-use classifier).

Out of scope

CBRN Information · Confabulation · Dangerous, Violent, or Hateful Content · Environmental Impacts · Harmful Bias or Homogenization · Information Integrity.

Using this mapping

For the questionnaire, not the pitch.

If a client security review, auditor, or sophisticated buyer asks how AI use is governed, cite the subcategory IDs above and attach the monthly report — usage, incidents, resolutions — as the evidence. For most organizations the practical driver isn’t NIST at all: it’s the cyber-insurance questionnaire, the client security review, HIPAA, and state notice laws. This page is for the buyer who asks the deeper question — and for showing that when we map to a framework, we mean something specific by it.

Book a demoTechnical overview