Frameworks

July 19, 2026

NIST AI RMF 1.1 — what actually changed for auditors.

Version 1.1 clarified more than it changed — but three sections rewrote how auditors sample controls. The 1.1 revision to the NIST AI Risk Management…

Unlimited SkiesTech

Founder, Unlimited SkiesTech — writing the ML & AI Literacy for GRC Professionals series.

Version 1.1 clarified more than it changed — but three sections rewrote how auditors sample controls.

The 1.1 revision to the NIST AI Risk Management Framework arrived quietly, but if you read it as an auditor rather than a policy author, three sections stand out.

  1. The Map function got sharper
    ‘Map 3.5’ now explicitly names third-party AI components as in-scope. If your firm consumes a foundation model through an API, that dependency is part of your risk surface — and your evidence trail.
  2. Measure introduced continuous monitoring
    The framework now treats measurement as an ongoing activity, not a one-time validation. This is the change that most affects audit sampling: you can no longer test the model once and call it governed.

Dr. Anaya Rao

Founder, Unlimited SkiesTech — writing the ML & AI Literacy for GRC Professionals series.

Related essays.