Crosswalks / NIST AI RMF
NIST AI Risk Management Framework — execution-evidence crosswalk
- Source version
- NIST AI 100-1, AI RMF 1.0 (January 2023)
- Crosswalk version
- nist-ai-rmf@1.0.0
- Source authority
- National Institute of Standards and Technology (NIST)
- Last reviewed
- 2026-08-13
What NIST AI RMF is
A voluntary framework organised around four functions — Govern, Map, Measure, Manage — for managing risks of AI systems.
What AIEF is
AIEF is an independent, implementation-agnostic framework for AI execution integrity. It defines the evidence properties an AI or agent execution must have to be reconstructed, attributed and independently verified after the fact — execution artifacts, integrity protection, version pinning, retention and independent validation.
Where they overlap
Outcomes concerning documentation, traceability, accountability, third-party dependency awareness and post-deployment monitoring depend on records of what a system actually did.
Where they do not
AIEF does not address fairness, bias, model quality, explainability, safety, security posture generally, environmental impact or broader societal harm — all of which the AI RMF treats as first-class concerns.
Control mapping — 8 AIEF controls, 9 mapped references
Relationship strength is stated explicitly and deliberately conservative. Where a relationship is uncertain it is downgraded rather than overstated. Provisions with no credible execution-evidence relationship are left unmapped.
| AIEF control | External reference | Relationship | Rationale | Limitation |
|---|---|---|---|---|
| AIEF-01Execution Artifact Completeness | MEASURE 2.8Risks associated with transparency and accountability are examined and documented | Supporting relevance | Examining transparency and accountability risks depends on being able to say what a system actually did. Structured execution records make that determinable rather than inferred. | AIEF supplies evidence of execution. It does not examine or document transparency and accountability risk, which remains an organisational activity. |
| AIEF-01Execution Artifact Completeness | MANAGE 4.1Post-deployment monitoring plans are implemented | Supporting relevance | Post-deployment monitoring consumes operational records. Automatic, structured execution records are a reliable source for that monitoring. | AIEF neither creates a monitoring plan nor evaluates whether monitoring detects the risks that matter. |
| AIEF-04Version Preservation and Context Pinning | MEASURE 2.8Transparency and accountability — traceability of system behaviour over time | Supporting relevance | Accountability degrades when historical behaviour cannot be interpreted against the versions and configuration in force at the time. AIEF-04 preserves that context in the artifact. | This is narrow technical traceability, not model transparency, interpretability or explainability. |
| AIEF-06External Dependency Evidence / Tool Calls | MAP 4.1Approaches for mapping risks of third-party technology and data are in place | Supporting relevance | Mapping third-party risk requires knowing which external dependencies actually influenced an outcome. AIEF-06 records those calls in the evidence. | AIEF-06 identifies dependencies that ran; it does not assess or rate the risk those dependencies carry. |
| AIEF-08Retention, Portability and Offline Verification | GOVERN 1.5Ongoing monitoring and periodic review of the risk management process | Supporting relevance | Periodic review across time requires records that outlive the running system. Retained, portable evidence makes retrospective review possible. | AIEF does not define the review cadence, scope, governance structure or the risk management process being reviewed. |
| AIEF-05Independent Validation Capability | GOVERN 4.2Organisational teams document risks and impacts of the technology they design and deploy | Related consideration | Documented claims about system behaviour become materially more credible when the underlying evidence can be validated by someone other than the team that produced it. | Independent verifiability of evidence is not the same as independent review of risk documentation. |
| AIEF-07Multi-Step Chain Integrity | MEASURE 1.3Internal experts and independent assessors are able to evaluate system performance | Related consideration | Evaluating multi-step or agentic behaviour requires the sequence of actions to be preserved and its integrity checkable, not reassembled from unrelated events. | AIEF assesses chain integrity, not the correctness, quality or safety of the behaviour the chain records. |
| AIEF-02Tamper-Evidence | MANAGE 2.4Mechanisms are in place and applied to supersede, disengage or deactivate systems that demonstrate performance inconsistent with intended use | Contextual only | Acting on inconsistent performance presumes the records evidencing it are trustworthy and have not been altered after the fact. | AIEF-02 concerns detectability of evidence tampering only, and says nothing about intervention or deactivation mechanisms. |
| AIEF-09Privacy, Minimization and Redaction Controls | MAP 5.1Likelihood and magnitude of impacts, including privacy considerations, are understood | Contextual only | Capturing execution evidence can itself create privacy exposure. AIEF-09 requires minimisation and redaction that does not silently break integrity guarantees. | AIEF-09 does not assess privacy impact, lawful basis or data subject rights. |
- Strong supporting relevance
- The AIEF capability produces evidence of the kind the external provision is concerned with. It does not satisfy the provision.
- Supporting relevance
- The AIEF capability may help provide relevant evidence, but does not itself satisfy the external requirement.
- Related consideration
- A material conceptual relationship. Satisfying one does not imply satisfying the other.
- Contextual only
- Useful context only. No evidentiary claim is made.
Limitations and source
AIEF does not address fairness, bias, model quality, explainability, safety, security posture generally, environmental impact or broader societal harm — all of which the AI RMF treats as first-class concerns.
The AI RMF can evolve. This crosswalk is pinned to AI RMF 1.0 and must be re-reviewed against any successor edition rather than assumed equivalent.
Authored against National Institute of Standards and Technology (NIST) — https://doi.org/10.6028/NIST.AI.100-1 (NIST AI 100-1, AI RMF 1.0 (January 2023)). Crosswalk nist-ai-rmf@1.0.0, reviewed 2026-08-13.
Run an AIEF assessment