NIST’s AI RMF is a governance language. PE still has to price the exposure.
AI RMF 1.0 gives portfolio companies a voluntary vocabulary — Govern, Map, Measure, Manage. It does not tell an operating partner what residual loss remains if a portco agent is allowed to act.
When a portfolio company says it has “adopted AI,” the operating partner needs a more precise description. Sometimes it means a copilot in the shared inbox. Sometimes it means a model sitting on customer data. Sometimes it means an agent that can open a ticket, change a price, or talk to a supplier without a person in the loop. Those are different authorization problems, and they do not become the same problem because someone filed a model card.
The most useful public language for that distinction is still NIST’s Artificial Intelligence Risk Management Framework (AI RMF 1.0), published January 26, 2023 as NIST AI 100-1. It is voluntary, rights-preserving, non-sector-specific, and use-case agnostic. That last clause is the one operators skip. A framework that is use-case agnostic cannot tell you what a specific agent is allowed to commit at a specific company.
What NIST actually standardized
AI RMF 1.0 organizes work into four functions: Govern, Map, Measure, and Manage. Govern is meant to apply across the organization’s AI risk process. Map, Measure, and Manage can be applied to a particular system and lifecycle stage. The document also names trustworthiness characteristics — valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed.
None of that is a product claim for Valty, and none of it is a dollar. NIST is explicit that the framework is a resource for organizations designing, developing, deploying, or using AI systems. It is not a certification. It is not a sector rule. A later review with formal community input is expected no later than 2028; until then, 1.0 is the current generation.
If a portco says they are “aligned to the AI RMF,” the only honest follow-up is: show me Govern for the company, then Map/Measure/Manage for the two systems that can move money, data, or production. A slide with the four words and no system boundary is a poster.
The questions that survive the framework
An operating partner can keep the RMF and still ask a shorter list.
Who can commit the company? If an agent can send a customer-facing message, change a quote, or trigger a payment, that is an authorization decision. The RMF will help you name the system. It will not set the dollar threshold.
What data does it see? Training data, retrieval stores, and logs are different exposure surfaces. “We do not train on customer data” can be true and still leave a retrieval layer that holds the same records.
What happens when it is wrong? Measure is where most programs stall. Accuracy on a benchmark is not residual loss if the failure mode is a bad refund, a leaked file, or a shut-down line.
Who owns the exception? Govern without an exception path is how shadow tools return. Someone has to be allowed to say no, and someone has to be allowed to accept a residual and write it down.
What the RMF does not do
The framework does not supply a company-specific annual loss estimate, determine insurance response or choose between prompt logging and network segmentation under a budget. Those decisions require the relevant business scenario, evidence, costs and accountable approver.
Valty’s platform evaluation starts with a defined company decision and supported evidence sources. Its separate fictional sample reports modeled mean, median and P95 annual gross loss; it does not model insurance recovery or adjust earnings. An AI system can be part of a scoped scenario when the necessary evidence exists. Inspect the sample, or request a platform demo with illustrative data. Company scope, supported workflows, evidence handling and terms are agreed before evaluation access.
Sources
- NIST, AI Risk Management Framework (overview)
- Tabassi, E. (2023), Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1
- NIST AI 100-1 PDF
Limitations
This note cites the published 1.0 framework and NIST’s public overview. It does not evaluate any portfolio company’s AI program, and it does not treat “RMF aligned” as a measured control state. Trustworthiness characteristics are design goals, not evidence of residual loss.
