Chapter 12 of 13
Integrating AI RMF with Existing Security, Privacy, and Compliance Programs
Few organizations start from a blank slate—most already have cybersecurity, privacy, and compliance frameworks in place. This module focuses on how to map AI RMF and the Generative AI Profile into existing structures so AI risk management becomes part of the fabric, not a parallel universe.
1. Why Integrate AI RMF Instead of Starting From Scratch?
You Rarely Start From Zero
Most organizations already have cybersecurity, privacy, and compliance programs (e.g., NIST CSF, ISO 27001, GDPR, HIPAA). AI should plug into these, not live in a separate universe.
Role of NIST AI RMF
The NIST AI RMF (2023) and the Generative AI Profile (draft 2024, widely used by 2026) provide voluntary guidance to manage AI risks. They are designed to integrate with existing frameworks.
Why Integration Matters
Good integration avoids duplicated work, conflicting policies, and scattered evidence. It lets you reuse existing controls and show regulators that AI risk is handled through mature processes.
What You Will Learn
You will learn to: (1) inventory existing programs, (2) map AI RMF and the Generative AI Profile into them, and (3) design an evidence and documentation strategy across frameworks.
2. Quick Refresher: AI RMF, Generative AI Profile, and Existing Frameworks
AI RMF in One Glance
AI RMF has four functions: GOVERN, MAP, MEASURE, MANAGE. Each has categories and subcategories that describe desired outcomes for managing AI risk.
Generative AI Profile
The Generative AI Profile tailors AI RMF to LLMs and other generative models, adding outcomes on prompt injection, hallucinations, content safety, and synthetic media.
Existing Frameworks
You likely use NIST CSF 2.0 or ISO 27001 for security, GDPR/CCPA and NIST Privacy Framework for privacy, and sector rules like HIPAA, PCI DSS, or EU AI Act obligations.
Layered View
Think of AI RMF + Generative AI Profile as a middle layer that connects AI use cases on top to your existing security, privacy, and compliance controls underneath.
3. Mini-Inventory: What Does Your Organization Already Have?
To integrate AI RMF, you first need to know your starting point.
Activity (2–3 minutes)
Imagine you are joining a mid-size company that is rolling out an internal generative AI assistant. Based on typical organizations in 2026, answer these questions in your notes:
- Cybersecurity
- Which of these is most likely already in place?
- A. A NIST CSF 2.0-based security program
- B. ISO/IEC 27001 certification
- C. A cloud provider shared responsibility model and security baselines
- D. All of the above in some combination
- Write down which one(s) you think apply and why.
- Privacy
- Name at least two of the following that the company probably has:
- Data Protection Officer or privacy lead
- Data Protection Impact Assessment (DPIA) or Privacy Impact Assessment (PIA) process
- Records of processing activities (GDPR Article 30)
- Cookie consent and privacy notices
- Compliance / governance
- List any of these that might already exist:
- Risk register
- Third-party vendor assessment process
- Internal audit function
- Model governance committee (for credit risk, AML, etc.)
Goal of the exercise
You do not need to be right about every detail. The point is to train yourself to look for existing structures that AI RMF can plug into, instead of inventing everything from scratch.
If you are currently in an internship or job, you can adapt this exercise to your real organization: try to map which of these elements you can actually find on your intranet or policy portal.
4. Mapping AI RMF GOVERN to Existing Governance and Compliance
GOVERN: What It Covers
GOVERN is about structures, policies, and accountability for AI. Outcomes include defined roles, integration with enterprise risk management, and documented AI lifecycle policies.
Use Existing Committees
Instead of a new AI board, expand existing risk or technology committees to include AI oversight. Update their charters to receive AI risk reports aligned with AI RMF GOVERN.
Leverage ERM and Risk Registers
Map AI risks into your enterprise risk register: add items like GenAI data leakage or AI-enabled discrimination, and manage them through your existing ERM process.
Extend Policies, Don’t Duplicate
Update information security, acceptable use, and data handling policies to cover AI tools and workflows, rather than building separate AI-only policies that may conflict.
Bank Mini-Case
A bank extends its Model Risk Committee, Risk Appetite Statement, and Model Inventory to explicitly include AI and generative systems, satisfying many AI RMF GOVERN outcomes.
5. Mapping MAP, MEASURE, MANAGE to NIST CSF and Privacy Programs
MAP: Know Your AI
MAP is like NIST CSF Identify: describe AI use cases, build an AI system inventory, and analyze affected stakeholders and harms. Tag AI assets in existing inventories and PIAs.
MEASURE: Test and Evaluate
MEASURE aligns with security testing and audits. For GenAI, add jailbreak tests, prompt-injection checks, and content safety scoring to your regular testing calendar.
MANAGE: Operate and Improve
MANAGE connects to Protect, Detect, Respond, Recover. Reuse incident response and change management processes, extending them with AI-specific scenarios and controls.
Privacy Mapping
Map AI RMF outcomes to GDPR principles: lawful basis, purpose limitation, minimization, and rights. Update PIAs to cover AI-specific issues like explainability and profiling.
Email Summarization Example
For an LLM summarizing customer emails: MAP via PIA updates, MEASURE by testing for data leakage, MANAGE by setting retention, logging, and rights-handling processes.
6. Hands-On Mapping: GenAI Chatbot to NIST CSF and Privacy
Apply what you learned to a concrete case.
Scenario
Your company deploys a customer-support chatbot powered by a large language model (LLM). It can:
- Answer FAQs
- View a subset of customer account data (name, products, support history)
- Suggest next steps or upgrades
Task 1: Map to NIST CSF 2.0
In your notes, write one example control or activity for each of these CSF functions, specifically for the chatbot:
- Identify
- Example prompt: How would you record this chatbot in your asset inventory and risk register?
- Protect
- Example prompt: What access controls or data minimization steps would you apply?
- Detect
- Example prompt: How would you detect misuse, prompt injection, or abuse of the chatbot?
- Respond
- Example prompt: What is your plan if the chatbot starts giving harmful or incorrect advice?
- Recover
- Example prompt: How would you restore safe operation and communicate with users after an incident?
Task 2: Map to privacy requirements
Assume your customers are in the EU (GDPR applies).
Write short answers to:
- What lawful basis might you use for processing customer data via the chatbot (e.g., contract, legitimate interests, consent)?
- How would you explain the use of AI in your privacy notice?
- How would you handle a request from a customer who says: "I do not want my data used by the chatbot"?
You do not need perfect legal answers; the goal is to practice thinking about security and privacy mappings at the same time.
7. Evidence and Documentation Strategy Across Frameworks
Why Evidence Matters
Auditors and regulators will ask for proof that AI risks are managed. A unified evidence strategy avoids separate AI binders and reuses what you already collect.
Extend Existing Evidence
Reuse security tests, access reviews, change tickets, and PIAs. Add AI-specific items like AI inventories, GenAI evaluation reports, model cards, and prompt documentation.
Control and Evidence Matrix
Create a matrix where each control maps to AI RMF, GenAI Profile, NIST CSF, ISO 27001, GDPR, and more, all pointing to the same underlying evidence artifacts.
AI System Dossier
For each important AI system, keep a dossier with purpose, risk level, framework mappings, key controls, evidence locations, evaluation summaries, and incident history.
8. Simple Control Mapping Table (No Programming Required)
You can represent mappings in a spreadsheet or even a simple text table. Here is a markdown-style example you could adapt to Excel, Airtable, or a GRC tool.
```text
Control ID | Control Description | AI RMF Function | GenAI Profile Topic | NIST CSF 2.0 | Privacy / Regs | Evidence
----------|--------------------------------------------------------|-----------------|-----------------------------|-------------|-------------------------|-------------------------------
AI-01 | AI systems inventoried and risk-rated | MAP, GOVERN | System inventory | ID.AM | GDPR Art. 30 (records) | AI inventory spreadsheet
AI-02 | GenAI outputs scanned for harmful content | MEASURE, MANAGE | Content safety, misuse | PR.DS, DE.AE| GDPR Art. 25 (design) | Quarterly safety reports
AI-03 | Prompt changes reviewed via change management process | MANAGE | Prompt governance | PR.IP | EU AI Act documentation | Change tickets in ITSM tool
AI-04 | Red-teaming for jailbreak and prompt injection yearly | MEASURE | Adversarial testing | DE.TE | Internal policy | Red-team test report
AI-05 | DPIA updated for new AI use cases | MAP, GOVERN | Impact assessment | ID.RA | GDPR DPIA, CCPA | DPIA documents in privacy repo
```
In practice, organizations often build this kind of table into their Governance, Risk, and Compliance (GRC) tools so that a single control can satisfy multiple frameworks at once.
9. Quick Knowledge Check
Answer this multiple-choice question to check your understanding of integration and evidence.
Your organization already runs regular penetration tests and has a strong NIST CSF 2.0-based security program. You are adding a generative AI feature to your product. Which approach best reflects good integration of AI RMF and the Generative AI Profile?
- Create a completely separate AI security program with its own tests, policies, and evidence, unrelated to existing processes.
- Reuse existing security testing processes, but add GenAI-specific evaluations (like jailbreak and content safety tests) and map their results to both AI RMF and NIST CSF controls.
- Stop doing traditional penetration tests and only run GenAI red-teaming, because AI risks are different from classic security risks.
- Rely entirely on your cloud provider’s assurances about the underlying model and do not add any new tests.
Show Answer
Answer: B) Reuse existing security testing processes, but add GenAI-specific evaluations (like jailbreak and content safety tests) and map their results to both AI RMF and NIST CSF controls.
The best approach is to integrate: reuse existing testing processes while adding GenAI-specific evaluations and mapping their evidence to both AI RMF and NIST CSF. Creating a fully separate program, dropping traditional tests, or relying only on the provider would leave important gaps.
10. Key Term Review
Use these flashcards to reinforce the main concepts from this module.
- NIST AI RMF
- A voluntary framework (released 2023) with four functions (GOVERN, MAP, MEASURE, MANAGE) that helps organizations manage risks of AI systems, designed to integrate with existing cybersecurity and privacy frameworks.
- Generative AI Profile
- A NIST profile that tailors the AI RMF to generative systems like LLMs, adding outcomes for risks such as prompt injection, hallucinations, content safety, and synthetic media misuse.
- Control and evidence matrix
- A table that links each control or outcome to multiple frameworks (AI RMF, NIST CSF, ISO 27001, GDPR, EU AI Act, etc.) and points to shared evidence artifacts, reducing duplication.
- AI system inventory
- A catalog of AI and GenAI systems, including purpose, owners, data used, risk level, and dependencies (such as third-party models or APIs), often integrated into existing asset inventories.
- AI system dossier
- A concise documentation package for a specific AI system, summarizing purpose, risks, control mappings, evaluations, and key evidence locations, used to support audits and governance.
Key Terms
- EU AI Act
- A European Union regulation adopted in 2024, with phased application from 2025 onward, that sets risk-based requirements for AI systems, including high-risk and general-purpose AI.
- DPIA / PIA
- Data Protection Impact Assessment / Privacy Impact Assessment, processes used to analyze and mitigate privacy risks of data processing activities, required under GDPR for high-risk processing.
- NIST AI RMF
- NIST Artificial Intelligence Risk Management Framework, a voluntary framework released in 2023 to help organizations manage AI risks through four core functions: GOVERN, MAP, MEASURE, MANAGE.
- NIST CSF 2.0
- The 2024 update to the NIST Cybersecurity Framework, organizing cybersecurity activities into Identify, Protect, Detect, Respond, and Recover functions.
- AI system dossier
- A focused documentation package for a particular AI system, summarizing its purpose, risk, control mappings, evaluations, and evidence to support audits and governance.
- AI system inventory
- A structured list of AI and GenAI systems used by an organization, with metadata like owner, purpose, data types, risk classification, and dependencies.
- Generative AI Profile
- A NIST profile that adapts the AI RMF for generative AI systems, providing more detailed guidance on risks like hallucination, prompt injection, and harmful content.
- NIST Privacy Framework
- A NIST framework that helps organizations manage privacy risk, structured in functions and categories similar to the Cybersecurity Framework.
- Control and evidence matrix
- A mapping tool that links controls or desired outcomes to multiple frameworks and references to specific evidence, enabling one control to satisfy several requirements.
- Model risk management (MRM)
- A set of policies and processes, common in financial services, for governing models across their lifecycle, including validation, documentation, and periodic review.