What you’ll be able to do
- Assign one LanePay control to Govern, Map, Measure, or Manage and say what evidence would show it.
- Keep AI RMF 1.0 distinct from a certificate, a product score, or a complete control catalog.
- Use the Generative AI Profile’s direct and indirect prompt-injection language as a Map input, not as a new framework.
- Leave Agentic SOC as the reference for investigation architecture rather than repeating it.
Four functions, one agent, no certificate
NIST AI RMF 1.0 (NIST AI 100-1, January 2023) is a voluntary framework for managing AI risk. Its core functions are Govern, Map, Measure, and Manage. NIST describes it as a living document to be reviewed over time. Using the names in a design note does not certify Riverstone, LanePay, or a vendor. There is no AI RMF certificate to hang on the pilot.
Govern is who is accountable and which policies exist: Priya owns payment approval, Sam may request drafts, and the executor identity is documented. Map is the context and the risks: customer and carrier money, indirect injection through email, and the blast radius of each tool. Measure is how you would know the gate works: a test corpus of hostile invoices, counts of blocked release attempts, and approval records that match executed debits. Manage is what you do when a measure fails: disable release_payment, keep read-only draft mode, and record the incident. The functions organize the work. They do not replace the tool scopes from G2 or the gate from G3.
| Function | LanePay question | Evidence you could keep |
|---|---|---|
| Govern | Who may approve a debit, and under which policy? | Named roles, approval limits, and the policy version on the record |
| Map | Which text is untrusted, and which actions can move money? | Data-flow of mail, retrieval, and tools, plus the blast-radius table |
| Measure | Did hostile mail produce a debit without Priya? | Synthetic test results and a sample of approval-to-debit matches |
| Manage | What stops if a test or a log shows a miss? | A disable switch for release_payment and the incident note |
Map uses the Generative AI Profile; it does not become a second course
NIST AI 600-1 (July 2024) is a profile that applies AI RMF 1.0 to generative AI. In section 2.9, Information Security, it distinguishes direct prompt injection, where the attacker supplies the prompt, from indirect prompt injection, where the instructions sit in data likely to be retrieved. LanePay’s Map entry can cite that distinction for carrier email. The profile also points human-oversight roles at GOVERN activities such as inventorying systems and naming who watches them. That is enough map for this path.
This lesson does not walk the full subcategory list, the Playbook, or a conformity assessment. If a later review needs those, open the publications. Do not promote a slide title such as “AI RMF aligned” into a claim that a product passed an audit. Riverstone has not been assessed, and this site does not award that status.
What you still practice elsewhere
Identity, least privilege, and evidence remain the foundations under the map: the executor is an identity, the tool credential is a privilege boundary, and the approval record is evidence. When the workflow is a security investigation with cases, hypotheses, and response actions, use the Agentic SOC lesson and the longer Agentic SOC article. Those pages already separate model proposals from human approval. Repeating their component list here would blur LanePay’s narrower job.
Close the pilot note with leftovers. You still do not know how often Priya will be absent, whether the bank can enforce the payee allow-list itself, or how many hostile messages a week the carrier inbox receives. Those gaps belong on the Map and Measure rows. They are not reasons to widen the credential while you wait.
CHECK YOUR JUDGMENT