Skip to the content.

Mappings to GOVERN/MAP/MEASURE/MANAGE functions.

This file is one self-contained piece of the AI IR Overlay™ framework. Cross-references to other pieces point to other packages in the same set, which you can obtain at jacobideji.com.


Crosswalk: AI IR Overlay ↔ NIST AI Risk Management Framework (AI RMF 1.0)

This crosswalk maps AI IR Overlay controls to NIST AI RMF functions, with emphasis on the MANAGE function (where incident response lives) and the MEASURE and GOVERN functions where preparation lives.

At a Glance

AI IR Overlay Control NIST AI RMF Function RMF Subcategory (representative)
MVO-1 Inventory GOVERN, MAP GOVERN 1.6, MAP 1.1, MAP 4.1
MVO-2 Safe Modes (Kill-Switches) MANAGE MANAGE 1.3, MANAGE 2.3, MANAGE 2.4
MVO-3 Minimum Evidence Set MEASURE, MANAGE MEASURE 2.7, MANAGE 4.1
MVO-4 Controlled Re-Enable MANAGE MANAGE 4.2, MANAGE 4.3
Six Triage Questions MAP, MEASURE MAP 2.3, MEASURE 2.5
Mental Model GOVERN GOVERN 1.1 (legal/regulatory), GOVERN 3.2 (human-AI roles)
Maturity Roadmap GOVERN, MEASURE, MANAGE GOVERN 1.4 (risk-management process), MEASURE 4.2, MANAGE 4.2 (continual improvement)

Detailed Mappings

MVO-1 Inventory ↔ GOVERN + MAP

The AI-BOM template (see README) operationalizes:

Gap note: AI RMF does not specify an inventory schema. AI-BOM fills this gap with a concrete YAML template.

MVO-2 Safe Modes ↔ MANAGE

The Kill-Switch Modes (M0–M5) operationalize:

Gap note: AI RMF specifies the requirement to disengage AI systems but not the graduated mechanism. The Kill-Switch ladder provides the operational specification.

MVO-3 Minimum Evidence Set ↔ MEASURE + MANAGE

The Minimum Evidence Set (A–F) operationalizes:

Gap note: AI RMF does not enumerate evidence types. The A–F set provides the operational specification.

MVO-4 Controlled Re-Enable ↔ MANAGE

Staged recovery operationalizes:

How to Use This Crosswalk

When responding to an auditor, regulator, or board question framed in AI RMF terms, this crosswalk lets you point to specific AI IR Overlay artifacts as evidence of conformance to the corresponding RMF subcategory.

Example: “How does your organization satisfy MANAGE 2.4?” Answer: “We implement the AI IR Overlay Kill-Switch Modes M1–M4, tested quarterly. Our AI-BOM documents implementation and last-tested dates per agent.”

Status

Source


Last revised: 2026-06-17 · Maintainer interpretation, not a NIST publication.

Source: AI IR Overlay newsletter and framework synthesis, by Jacob Ideji. https://www.linkedin.com/in/jacobideji/