Skip to main content
PARTIAL TECHNICAL SUPPORTSUPPORTEDLast reviewed: 2026-07-01

AI-RMF-MAP-3: Categorize AI risks based on likelihood, severity, and reversibility

Vallum evidence mapping for NIST AI RMF AI-RMF-MAP-3 — categorize ai risks based on likelihood, severity, and reversibility. Documents evidence produced, gaps, and customer responsibilities.

Source Attribution

Framework
NIST AI RMF 1.0
Control ID
AI-RMF-MAP-3
Source Organization
NIST
Control Objective
Categorize AI risks based on likelihood, severity, and reversibility

Evidence Vallum Produces

Partial evidence through operation receipts and evidence-package metadata relevant to this control's objectives

Evidence Vallum Does NOT Produce

Model training documentation, bias testing results, stakeholder impact assessments, or organizational governance records

Known Limitations

Vallum provides evidence relevant to this NIST AI RMF requirement but does not constitute complete control implementation. Full compliance requires complementary controls at infrastructure, organizational, and procedural levels. Evidence covers Vallum-managed operations only and does not extend to customer applications, third-party systems, or physical infrastructure.

Your Responsibilities

Establish AI governance structure, conduct organizational risk assessments, maintain AI system documentation, and implement stakeholder engagement processes

External Controls Required

Identity provider, infrastructure security controls, organizational policies and procedures, third-party assessments, and legal/regulatory counsel

Residual Risk

Evidence gaps exist between Vallum-managed operations and full control implementation. Time-of-check to time-of-use windows, infrastructure-level vulnerabilities, and organizational process failures remain outside Vallum's evidence boundary.

Relevant Titan Components

Titan ForgeTitan Verify

Need a detailed evidence mapping for your specific compliance program?

Request a Control Evidence Mapping

Legal boundary: This mapping is technical reference documentation. It does not constitute compliance certification, legal advice, or audit opinion. The control description is sourced from NIST's publicly available AI Risk Management Framework (public license) and summarized for educational reference. Consult qualified compliance professionals for your specific regulatory obligations.