The runtime controls and evidence behind the NIST AI RMF.
The NIST AI Risk Management Framework organizes AI risk into four functions: Govern, Map, Measure, and Manage. Swiftward gives you the enforced controls and the audit trail behind three of them at runtime — Govern, Measure, and Manage. The fourth, Map, is organizational work that stays with you.
Voluntary, and there is no certification
The AI RMF is a voluntary framework, not a standard you certify against. Anyone selling you "NIST AI RMF certified" is selling something that does not exist.
What it gives you is a shared language for managing AI risk, and four functions an auditor, a customer and a regulator all recognize.
Manage — acting on risk in production
This is where Swiftward sits. Every AI decision runs through one policy engine that allows, blocks, redacts, or routes it. Flagged cases go to a human-in-the-loop queue with an optional timeout, and you declare in advance what happens if nobody answers. A bad policy rolls back by naming the previous version, and a failed event lands in a dead-letter queue, where you can recover it and run it again. A rule can forward a decision to your SIEM over syslog. Manage is "respond, recover, and monitor," continuously.
Measure — assessing risk with evidence in hand
Before a control ships you run it in shadow mode and A/B it against live traffic, with no effect applied. You also backtest it against your own historical traffic to see what it would have changed. After it ships, every decision leaves a record, and you can account for any past decision on the exact policy version that was live. Measure is "assess, analyze, and track."
Govern — the enforced backbone
Govern is the policies, roles, accountability, and oversight that hold the other functions together. Swiftward provides the enforced, technical backbone for it: policy as versioned code with the draft, candidate, frozen, archived lifecycle, and approvals; layered RBAC and ABAC, with duties separated the way you declare them; and a tamper-evident audit of every change, with who, when, and the before-and-after. What stays with you is the organizational half — the accountability structure, the risk culture, the people and committees.
Map is yours to do
Map is establishing context, categorizing your AI system, and identifying its risks and impacts on people and rights. That is organizational analysis your team and counsel do, usually before a control is written; a vendor that claims to do it for you is taking over a judgment that is yours. What we produce is the runtime records — the decisions, the signals, the overrides — that feed your mapping and impact assessments with fact instead of assumption.
Generative and agentic AI
NIST extends the framework to generative systems through a dedicated profile, NIST AI 600-1 (July 2024). There is no NIST agentic profile; the agentic profile people cite is the Cloud Security Alliance's. That is the layer Swiftward governs: the runtime behavior of AI agents and the LLM calls behind them, controlled and recorded the same way.