Framework mapping

Operationalizing NIST AI RMF with governed autonomous AI.

The NIST AI Risk Management Framework is voluntary guidance from the US National Institute of Standards and Technology. It organizes trustworthy AI around four functions: Govern, Map, Measure and Manage. It tells an organization what to achieve; it does not run inside the system. This page shows how NeueCode 7 turns each function into a control that operates while an autonomous agent is working.

NIST does not endorse products. This is NeueCode's mapping of its own controls to the framework's functions, offered as a starting point for your risk program, not a certification.

How does each function become a runtime control?

For each function: what the framework asks for, the control that runs in NeueCode 7, and the evidence it produces.

Govern GOVERN

What the framework asks for
Policies, processes, accountability and culture for AI risk across the organization: roles are defined, risk tolerance is set, and oversight is real.
The control in NeueCode 7
A deny-by-default capability registry set org-wide and per role; a least-privilege check on every tool call; SSO via AD/LDAP and SAML 2.0 with group-to-role mapping and instant deprovisioning; break-glass dual control for the highest-risk actions.
The evidence it produces
Every policy decision and approval is a named entry in the Flight Recorder.

Map MAP

What the framework asks for
Context is established: what the system is for, who it affects, where it runs, what it may reach, and what risks follow.
The control in NeueCode 7
Three sovereignty modes (strict, hybrid, open) make the boundary explicit and switchable live; per-run scope is bounded by iteration, token and wall-clock budgets; sub-agents are sandboxed to their own tools and budgets; optional cloud providers are off by default and unreachable in strict mode.
The evidence it produces
The run's mode, budgets and reachable tools are recorded with the run.

Measure MEASURE

What the framework asks for
Risks are analysed and tracked with appropriate methods; trustworthiness is tested, not assumed.
The control in NeueCode 7
A deterministic external verifier checks the agent's claims against what its tools actually returned; untrusted tool, web and memory content is fenced as data; a versioned model registry with eval-gated automatic rollback; a secret scan before any socket opens.
The evidence it produces
Verifier outcomes and model evaluations land in the record; the compliance portal exports it, mapped to the frameworks you report against.

Manage MANAGE

What the framework asks for
Risks are prioritized and treated; incidents are responded to; monitoring continues after deployment.
The control in NeueCode 7
Risky actions pause for human approval as reviewable diffs; a two-person rule for the highest-risk; a deny-by-default egress broker with signed per-run non-egress manifests; capability tokens scope every privileged call; total deprovisioning on the next request.
The evidence it produces
A tamper-evident, hash-chained Agent Flight Recorder that auditors verify offline, and a signed, integrity-tiered evidence-export endpoint.

Where this matters in the United States

NIST AI RMF is the common reference for AI risk management in the United States, including in guidance to federal agencies and critical-infrastructure sectors. NIST has also published a generative-AI profile of the same framework, and the same runtime controls apply. Organizations that must show how autonomous AI is controlled, banks, government agencies, energy operators, healthcare systems and the contractors that serve them, can use this mapping as the starting point of their own risk documentation.

What this page does not claim

  • NIST does not certify or endorse products. This page is NeueCode's mapping of its own controls to the framework's functions.
  • A mapping is not conformance. Your organization's risk program decides what conforms.
  • NeueCode holds no SOC 2, ISO or FIPS certification; its evidence export is mapped, not certified.

Frequently asked questions

Is NeueCode NIST AI RMF certified?
No. NIST does not certify or endorse products, and the framework itself is voluntary guidance. NeueCode maps its controls and evidence export to the framework's functions so your risk program has a starting point. A mapping, not a certification.
Which functions of the framework does NeueCode 7 cover?
All four, at runtime: the capability registry and approvals for Govern, sovereignty modes and budgets for Map, the verifier and evidence export for Measure, and dual control, the egress broker and the Flight Recorder for Manage. The governance program itself, roles, risk tolerance, documentation, remains your organization's.
Does this apply to GitHub Copilot, Cursor and Claude Code?
Yes. Through the AI Governance Gateway those tools use NeueCode as their model endpoint, so every outbound prompt is scanned, classified, allowed, redacted or blocked, then signed into the audit trail before any upstream call. Existing tools come under the same mapping.
Does it apply outside the United States?
Yes. The same controls are mapped to ISO/IEC 42001, the EU AI Act, the SDAIA AI Ethics Principles and Saudi SAMA/NCA controls. The full picture is on the autonomous AI governance page.

Start with the evidence, not the slide deck.

A scoped pilot on one test repository inside your network, ending with a security review and exported audit evidence your risk team can set against the framework themselves.