Trust Center
NIST AI RMF
NIST AI RMF 1.0 is voluntary guidance. Your organization implements the program. Corveil is the control plane for the models, agents, and tools that route through it. This page maps a category to the Corveil control and the artifact a reviewer can ask to see. It is not a certification.
The inventory covers models, keys, MCP servers, sensors, and workers connected to Corveil. Anything that never hits the gateway is outside that record.
NIST publishes a crosswalk between the AI RMF and ISO/IEC 42001. The controls overlap. That page is the management-system mapping.
01
Controls a reviewer can ask to see
| Category | Corveil control | Artifact |
|---|---|---|
| GOVERN 1, GOVERN 2 | Guardrails (keyword, regex, PII, custom, and spend limit; block or sanitize), ontology policies, behavioral guidance, organization and team roles, virtual keys, and per-tool allow or deny. | Guardrail audit event, role or key record |
| GOVERN 6, MAP 4, MANAGE 3 | Provider credentials, the model catalog and per-organization toggles, per-key model allow-lists, and the MCP gateway (an organization-held credential, tool permissions, and rate limits). | Model toggle, MCP permission, audit row |
| MAP 3, MANAGE 1, MANAGE 2 | Spend, rate, and budget caps, and human gates: ontology merge approval, confirmation on destructive control actions, and worker dry-run. | Approval or confirmation record, dry-run grant |
| MEASURE 2, MEASURE 3 | Request logs, decision diffs, provenance, per-run tool traces, and export, plus analytics and usage rollups for cost, tokens, and guardrail hits. | Log, export, usage rollup |
| MANAGE 4 | Decision undo, schema rollback, and worker revive. | Undo or rollback record |
The security-review pack covers categories beyond this crosswalk. Request it from security@corveil.com, the same path at the bottom of the Trust Center.