Skip to main content
The AI RMF is voluntary and organizational — there is no certification to hold. NeuralTrust supplies the technical controls and evidence your risk programme cites under each function.

Coverage at a glance

GOVERN

Cultivate a culture of risk management: policies, accountable roles, documented processes.

MAP

Establish context and categorize the system — what it is, what it touches, what could go wrong.

MEASURE

Analyse and monitor AI risk with quantitative and qualitative methods.

MANAGE

Act on measured risk: prioritize, respond, recover, communicate.

Where NeuralTrust stops

GOVERN and MAP are partly organizational. Accountability structures, legal and regulatory awareness, workforce competence, intended purpose, affected populations and foreseeable misuse are written and decided by people. The products evidence that access and configuration were controlled, and inventory what is connected — not what the system is for. End-user attribution is not an authenticated identity. Model TEVV sits elsewhere. MEASURE also covers accuracy, fairness and validity benchmarks for the model itself. That is testing work, and it belongs to TrustTest rather than to the runtime path. Streaming enforcement. Streamed output is evaluated, but where enforcement can act depends on the path. Through the gateway the stream is buffered and inspected after the client drains it, so findings are recorded rather than refused; on the LiteLLM path accumulated output is scanned during the stream, where block stops later chunks. Enforce on the request leg when a response must be stopped. Profiles and tagging. Nothing produces or consumes an AI RMF profile, and findings carry no category identifiers. This page is the mapping.