By HumanAudit Inc. editorial teamLast reviewed 5 August 2026
VerifiedLast reviewed 5 August 2026 by the HumanAudit Inc. editorial team.Corrections logEditorial policy
On this page
  1. What the AI RMF is
  2. Mapping identity work into the four functions
  3. MEASURE is where it gets hard
  4. Where the framework runs out
  5. Using it alongside 42001
  6. FAQ

TL;DR

  • AI RMF 1.0, published January 2023. Four functions: GOVERN, MAP, MEASURE, MANAGE. Voluntary, not certifiable, no conformity assessment.
  • Its strength is risk vocabulary and structure. Its weakness for identity work is that it is written about AI systems rather than about the credentials they hold.
  • Agent identity work lands mostly in MAP (what can this agent reach, on whose authority) and MANAGE (bounded authority, revocation, oversight).
  • MEASURE is where most programmes stall, because identity metrics for agents are not obvious and the framework does not supply them.
  • Best used as the risk language inside an ISO/IEC 42001 management system rather than as a standalone programme.

What the AI RMF is, and is not

NIST published AI RMF 1.0 in January 2023 as a voluntary framework for managing risks associated with AI systems. There is no certification, no conformity assessment, and no regulator that requires it. Organisations adopt it because it provides a defensible structure for AI risk work and a vocabulary that translates across engineering, risk and legal audiences.

For identity practitioners the honest framing is that the AI RMF was written about AI systems and their behaviour, trustworthiness characteristics, validity, safety, bias, explainability, and not about the credentials those systems hold. Identity is present by implication throughout and named almost nowhere. That is not a defect; it is a scope decision. It does mean the mapping below is inferential.

Mapping identity work into the four functions

FunctionSubstanceWhere NHI and agent identity lands
GOVERNCulture, accountability, policy, workforceNamed accountability for agent identities; policy on what agents may hold and reach; the decision that agents never carry human credentials
MAPContext, categorisation, capabilities, impactsThe densest fit. What the agent can reach, on whose authority, and what the impact is if that authority is misused. This is risk classification in the framework's language.
MEASUREMetrics, evaluation, trackingCredential lifetime distribution; delegation-chain completeness; measured revocation time; oversight refusal rate
MANAGERisk treatment, prioritisation, responseBounded per-invocation authority; tested kill paths; human-in-the-loop on irreversible actions; incident response for agents

MAP is where the framework earns its place. Its insistence on establishing context and categorising impacts before treating risk is exactly the discipline missing from most agent deployments, which classify by model capability rather than by reach.

MEASURE is where programmes stall

GOVERN, MAP and MANAGE map onto work most security teams recognise. MEASURE does not, because agent identity metrics are genuinely not obvious and the framework offers structure rather than measures.

Four that we find hold up:

  1. Delegation-chain completeness. What proportion of consequential agent actions can be traced to an authorising principal? A number between 0 and 100 that most organisations have never computed, and the one an assessor will care about most.
  2. Measured revocation time. From instruction to confirmed loss of access. See kill paths.
  3. Authority ratio. Permissions granted versus permissions exercised over 90 days, per agent. The gap is over-privilege expressed as a number.
  4. Oversight refusal rate. Approvals refused as a proportion of approvals requested. A rate of zero is evidence the control is not operating. See human-in-the-loop patterns.

All four are computable from systems you already run, and none requires a product.

Where the framework runs out

Three limits worth stating plainly rather than discovering later:

  • It is not evidence. AI RMF adoption produces no artefact an auditor accepts as conformity, because there is nothing to conform to. If you need evidence, the management system has to come from elsewhere.
  • It does not address the credential layer. Nothing in the framework tells you how an agent should authenticate, what a delegation token should carry, or how revocation should propagate. Those questions are answered in the OAuth building blocks and the agent identity standards.
  • It predates agentic deployment at scale. Published January 2023, before tool-using autonomous agents were common in enterprises. The functions generalise well; the specific guidance does not always anticipate an actor that takes thousands of actions per minute under delegated authority.

Using it alongside ISO/IEC 42001

The pairing that works: AI RMF supplies the risk language, ISO/IEC 42001 supplies the management system. Use AI RMF categories to structure your AI risk register and to communicate risk to non-specialist audiences, and use 42001 for the scope statement, documented information, internal audit and corrective action that produce evidence.

Organisations that adopt AI RMF alone frequently produce good risk analysis and no auditable artefacts. Organisations that adopt 42001 alone often produce a compliant management system with a thin risk register. Running both is not duplicated effort; each supplies what the other lacks. The framework comparison sets out how both relate to the EU AI Act, which supplies the obligations neither of them does.

Frequently asked questions

Does the NIST AI RMF address AI agent identity?

Only by implication. The framework was written about AI systems and their trustworthiness characteristics rather than about the credentials those systems hold, so identity is present throughout and named almost nowhere. Agent identity work maps most naturally into MAP, which asks what the system can reach and what the impacts are, and into MANAGE, which covers risk treatment including bounded authority and response.

Is the NIST AI RMF certifiable?

No. It is a voluntary framework published in January 2023 with no certification scheme and no conformity assessment. Adoption produces no artefact an auditor accepts as conformity, because there is nothing defined to conform to. If you need evidence, pair it with a management system standard such as ISO/IEC 42001.

What metrics should you use for the MEASURE function with AI agents?

Four that hold up and are computable from systems you already run: delegation-chain completeness, meaning the proportion of consequential agent actions traceable to an authorising principal; measured revocation time from instruction to confirmed loss of access; the authority ratio comparing permissions granted to permissions exercised over ninety days; and the oversight refusal rate, where a rate of zero is evidence the control is not operating.

Should we use NIST AI RMF or ISO/IEC 42001?

Both, for different purposes. AI RMF supplies risk vocabulary and a structure that communicates well to non-specialist audiences, but produces no auditable artefacts. ISO/IEC 42001 supplies the management system, scope, documented information, internal audit, corrective action, that produces evidence, but organisations adopting it alone often end up with a thin risk register. Each supplies what the other lacks.

Does the NIST AI RMF anticipate autonomous agents?

Not fully. It was published in January 2023, before tool-using autonomous agents were common in enterprise environments. The four functions generalise well and the MAP discipline of establishing context before treating risk is exactly what agent deployments most often skip. The specific guidance does not always anticipate an actor taking thousands of actions per minute under delegated authority.

Pairing AI RMF with a management system?

The toolkit maps ISO 42001 against ISO 27001, NIST AI RMF and the EU AI Act in one crosswalk, which is the artefact most teams end up building by hand.

See the crosswalk

Mapping NHI controls to a framework you are held to?

HumanAudit runs framework-mapping and readiness work where non-human and agent identity is in scope, and tests what you could actually produce on request rather than what the policy says.