Framework overlap

Does NIST AI Risk Management Framework (AI RMF 1.0) cover DAMA-DMBOK2?

You hold NIST AI Risk Management Framework (AI RMF 1.0) and have been told to do DAMA-DMBOK2. Here is how much overlaps, control by control.

17% of DAMA-DMBOK2 you already have

NIST AI Risk Management Framework (AI RMF 1.0) already covers about 17% of DAMA-DMBOK2, leaving 38 of 46 controls as genuinely new work.

Already covered 3 Likely covered 5 New work 38

What is genuinely new work

Nothing in NIST AI Risk Management Framework (AI RMF 1.0) reaches these. This is the list to scope.

DA-2
Data Modeling and Design
DA-3
Data Architecture Standards
DCB-1
Document and Content Management
DCB-2
Data Warehousing
DCB-3
Business Intelligence and Analytics
DEM-1
Data Ethics
DEM-2
Data Management Maturity Assessment
DEM-3
Big Data and Data Science
DG-1
Data Governance Strategy
DG-2
Data Stewardship
DG-3
Data Policies and Standards
DMBOK-DA-01
Enterprise Data Architecture
DMBOK-DA-02
Data Architecture Governance
DMBOK-DG-01
Data Governance Strategy and Operating Model
DMBOK-DG-02
Data Policies and Standards
DMBOK-DG-03
Data Stewardship Network
DMBOK-DG-04
Data Management Maturity Assessment
DMBOK-DI-01
Data Integration Architecture
DMBOK-DI-02
Data Lineage and Movement
DMBOK-DM-01
Conceptual, Logical, and Physical Data Models
DMBOK-DM-02
Modeling Standards and Naming Conventions
DMBOK-DOC-01
Document and Content Management
DMBOK-DQ-01
Data Quality Management Program
DMBOK-DQ-02
Data Profiling and Monitoring
DMBOK-DQ-03
Data Quality Issue Resolution
DMBOK-DS-01
Database Design and Operations
DMBOK-DS-02
Database Performance and Capacity Management
DMBOK-DSec-01
Data Security Classification
DMBOK-DSec-02
Access Controls and Privileged Access
DMBOK-DSec-03
Data Masking and Encryption
DMBOK-DW-01
Data Warehouse and BI Architecture
DMBOK-DW-02
Analytical Data Quality and Reconciliation
DMBOK-META-01
Metadata Management Strategy
DMBOK-META-02
Business Glossary and Data Dictionary
DMBOK-RMD-01
Reference Data Management
DMBOK-RMD-02
Master Data Management
DSO-1
Data Storage and Operations
RMD-3
Data Matching and Linking
Show the 8 you already have
DA-1
Enterprise Data Architecture
DIQ-2
Data Quality Management
RMD-1
Reference Data Management
DIQ-1
Data Integration and Interoperability
DIQ-3
Metadata Management
DSO-2
Data Security
DSO-3
Data Access Management
RMD-2
Master Data Management

How this is calculated

Already covered means a mapping runs from a control in NIST AI Risk Management Framework (AI RMF 1.0) to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition