NIST AI RMF vs SG Agentic AI: what they share and how they differ

NIST AI RMF and SG Agentic AI share 11 of 24 control themes and 10 checks. 89% of SG Agentic AI requirements can be proven with checks NIST AI RMF already uses, 31% the other way round.

USVoluntary frameworkVoluntary

NIST AI RMF

How to apply the NIST AI RMF to your AI systems

72 requirementsNext Dec 2026
SGVoluntary frameworkVoluntary

SG Agentic AI

How to govern AI agents under Singapore's framework

9 requirementsNext 2027
11/24shared control themes
10shared checks
89%of SG Agentic AI requirements covered by NIST AI RMF evidence
31%of NIST AI RMF requirements covered by SG Agentic AI evidence

At a glance

NIST AI RMF SG Agentic AI
JurisdictionUnited States (federal)Singapore
KindVoluntary framework sameVoluntary framework same
StatusVoluntary sameVoluntary same
BindingNo sameNo same
Object analysedAI system sameAI system same
ScopeAny organisation designing, deploying or using AI.Any organisation deploying AI agents in Singapore, built in-house or supplied by a third party.
Territorial reachNo territorial scope; de facto reference for US public buyers.Singapore; an international reference for agent governance.
PenaltiesNone (voluntary). Leverage: safe harbour in state laws.None (voluntary). The organisation remains legally accountable for its agents' actions under existing law (PDPA, contract, tort).
Qualification axesInternal risk tier (organisation-defined)Agent risk level (autonomy × access), Agent origin
RolesAI actorDeploying organisation, Agent developer
Requirements729
Next milestoneDec 2026, Expected RMF revision2027, Follow-up to the discussion paper on agents' legal responsibility

Theme by theme

requirements per theme

What they share: one piece of evidence, two frameworks

10

CodeCheckRequirements NIST AI RMFRequirements SG Agentic AI
CHK-RISK-TOLERANCERisk tolerances are defined and AI systems are assigned to risk levels
CHK-ROLES-CLARIFIEDRoles, responsibilities and delegated authorities are documented and clear to relevant stakeholders
CHK-INVENTORYA mechanism to inventory AI systems is in place and resourced
VER-008-03Competent overseers assigned to the system
VER-008-01Documented escalation and emergency stop procedure
CHK-THIRDPARTY-POLPolicies address third-party AI/data risks, incl. IP, transparency and testing
CHK-CATEGORIZATIONAI system tasks and methods are categorized (classifier, generative, recommender)
CHK-TEVVTEVV plan, test sets, metrics and data considerations are documented
VER-009-02Accuracy and robustness verified and documented
VER-008-02System designed to allow human oversight (stop button, override)

Differences: requirements specific to each framework

Requirements with no check serving the other framework: the extra work.

NIST AI RMF

50

Timelines

PastSet in the textPotentialTo verify
Jan 23, 2019SG Agentic AI · Model AI Governance Framework, 1st edition
Jan 21, 2020SG Agentic AI · Model AI Governance Framework, 2nd edition
May 25, 2022SG Agentic AI · AI Verify launched (governance testing)
Jan 26, 2023NIST AI RMF · AI RMF 1.0
May 30, 2024SG Agentic AI · Model AI Governance Framework for Generative AI
Jul 26, 2024NIST AI RMF · Generative AI Profile (NIST AI 600-1)
Jul 23, 2025NIST AI RMF · AI Action Plan asks for a revision of the framework
Jan 22, 2026SG Agentic AI · Agentic AI framework published (WEF)
May 20, 2026SG Agentic AI · Update: multi-agent systems, third-party agents, automation bias; discussion paper on legal responsibility for agents
Dec 2026NIST AI RMF · Expected RMF revision
2027SG Agentic AI · Follow-up to the discussion paper on agents' legal responsibility

Run these requirements across all your AI systems

TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.

Request a demo