27% of NIST AI Risk Management Framework (AI RMF 1.0) you already have
Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct already covers about 27% of NIST AI Risk Management Framework (AI RMF 1.0), leaving
38 of 52 controls as genuinely new work.
Already covered 5
Likely covered 9
New work 38
What is genuinely new work
Nothing in Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct reaches these. This is the list to scope.
AIRMF-GOV-02AI Risk Culture
AIRMF-GOV-03AI Compliance and Legal
AIRMF-GOV-04Third-Party AI Risk
AIRMF-GV-1.1Legal and regulatory requirements involving AI are understood, managed, and documented
AIRMF-GV-1.2Trustworthy AI characteristics are integrated into organisational policies, processes, and procedures
AIRMF-GV-2.1Roles and responsibilities related to AI risk management are documented and clear
AIRMF-GV-3.1Decision making related to mapping, measuring, and managing AI risks is informed by diverse perspectives
AIRMF-GV-4.1Organisational culture and incentives prioritise AI risk management
AIRMF-MAN-02AI Monitoring and Maintenance
AIRMF-MAP-01AI System Context
AIRMF-MEA-02Bias and Fairness Assessment
AIRMF-MEA-03AI Transparency and Explainability
AIRMF-MN-1.1AI risks are prioritised and resources are allocated to manage them
AIRMF-MN-2.1Mechanisms for tracking identified risks over time are in place
AIRMF-MN-3.1AI risks and benefits from third party resources are managed
AIRMF-MN-4.1AI risk management documentation and processes are improved continuously
AIRMF-MN-4.3Incidents and errors are communicated to relevant AI actors
AIRMF-MP-1.1Context of AI system use is established and understood
AIRMF-MP-2.1Categorisation of AI systems is performed
AIRMF-MP-3.1AI capabilities, targeted usage, goals, and expected benefits and costs are understood
AIRMF-MP-4.1Approaches and metrics for risk identification are established
AIRMF-MP-5.1Risks and benefits are characterised for components, including third party components
AIRMF-MS-1.1Appropriate methods and metrics for measuring AI risk are identified and applied
AIRMF-MS-2.1Test sets, evaluation criteria, and ongoing tracking are documented
AIRMF-MS-2.11Fairness and bias are evaluated and results documented
AIRMF-MS-2.7AI system security and resilience are evaluated
AIRMF-MS-2.8AI system explainability and interpretability are evaluated
AIRMF-MS-3.1Approaches and metrics for risk measurement are validated by stakeholders
NIST-AI600-GOV-2Safety-First Culture
NIST-AI600-GOV-3Content Provenance Governance
NIST-AI600-GOV-4Pre-Deployment Testing Governance
NIST-AI600-GOV-5Incident Disclosure Governance
NIST-AI600-MAP-3Third-Party Risk Mapping
NIST-AI600-MEA-1Confabulation Testing
NIST-AI600-MEA-2Bias and Fairness Evaluation
NIST-AI600-MEA-4Environmental Impact Measurement
NIST-AI600-MEA-5Red-Teaming and Adversarial Testing
NIST-AI600-MGT-2Human Oversight Integration
Show the 14 you already have
AIRMF-GOV-01AI Risk Management Policies
AIRMF-MAN-01AI Risk Treatment
AIRMF-MAP-02AI Risk Identification
AIRMF-MAP-03AI Impact Assessment
AIRMF-MEA-01AI Performance Metrics
AIRMF-MAN-03AI Incident Response
NIST-AI600-GOV-1Legal and Regulatory Compliance
NIST-AI600-MAP-1GAI Risk Identification
NIST-AI600-MAP-2Stakeholder Impact Assessment
NIST-AI600-MEA-3Privacy Leak Assessment
NIST-AI600-MGT-1Content Provenance Implementation
NIST-AI600-MGT-3Third-Party Dependency Management
NIST-AI600-MGT-4Incident Response for GAI
NIST-AI600-MGT-5Decommissioning Procedures
How this is calculated
Already covered means a mapping runs from a control in Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition