Cerberus blocks the lethal trifecta at the tool boundary — see the 525-run evidence set.

Warden · AI Governance

A voluntary framework still has to be evidenced to be worth citing

An alignment engagement against NIST AI RMF 1.0 — establishing the Govern, Map, Measure and Manage functions as practices your teams actually run, with artifacts that support the claim when a customer or regulator asks.

The framework is not prescriptive, which is the difficulty

AI RMF describes outcomes rather than controls. That flexibility is why it is widely adopted and also why self-declared alignment is frequently thin — the framework does not tell you what evidence is sufficient.

  1. Measure is where programs stallOrganizations describe governance comfortably and then have nothing quantitative to show for trustworthiness characteristics.
  2. Profiles matter more than the coreA use-case profile makes the framework actionable; the core alone produces a generic maturity statement.
  3. Nobody certifies itThere is no NIST certification. The value is the discipline and the artifacts, so those have to be real.

How the engagement runs

1

Current-state profile

Assess practice against the four functions and their categories, per AI use case rather than in the abstract.

2

Target profile

Set the level of rigor appropriate to your risk tolerance and sector, and record why.

3

Close the Measure gap

Define the metrics and test procedures for the trustworthiness characteristics that matter to your use cases.

4

Operationalize Manage

Wire monitoring, incident handling and third-party risk into the functions that already run.

What you hold at the end

  • Current-state and target profiles across Govern, Map, Measure and Manage
  • A use-case profile for each significant AI application
  • Defined metrics and test procedures for the trustworthiness characteristics in scope
  • An artifact register showing what evidences each claimed outcome
  • A crosswalk to ISO/IEC 42001 and the EU AI Act so the work counts once

The instrument itself

NIST AI RMF 1.0
Voluntary, outcome-based, organized into Govern, Map, Measure and Manage.
Generative AI Profile
The companion profile addressing risks specific to generative systems.
NIST CSF 2.0
Where a cyber program already runs on CSF, the governance function is the natural anchor point.

What carries the evidence

Alignment you can substantiate

Saying you follow AI RMF is easy. Being able to show the profile, the metrics and the records is the part that survives a question.