Strategy & governance

NIST AI RMF

NIST AI Risk Management Framework

A voluntary framework from the US National Institute of Standards and Technology that gives organisations a common structure for identifying, measuring and managing the risks of AI systems.

GOVERNculture, roles, policies: runs across the other three functionsMAPcontext, people affected, risksMEASUREtest and track the risksMANAGEprioritise, actagain as the system and its context changeA voluntary framework: there is no certificate; it provides a shared vocabulary and structure.

swipe to see the whole diagram →

MEmehmeterkek.com/glossary/nist-ai-rmf

In plain terms

The framework is a well-organised checklist of questions, written by a neutral body, for anyone responsible for an AI system. It sorts the work into four activities. Govern: who is responsible and what are the rules? Map: what is this system for, who is affected and what could go wrong? Measure: how big are those risks, on what evidence? Manage: what is done about them, and who decides which risks are accepted?

Why it matters

Its value is a shared vocabulary. Legal, technical and business people use the same four headings, which shortens the discussion of every new use case. It is free, it prescribes no tools and it suits organisations of any size, so it is a reasonable starting point for a company with no AI risk process at all. The limits follow from the same features: nobody certifies it, nothing in it is mandatory, and it says what to consider and leaves the how to the organisation. It is widely referenced in US procurement and in the policies of multinational companies.

Example

A hospital group assesses an AI tool that drafts discharge summaries, using the four functions as its agenda. Govern: the chief medical officer is named as owner. Map: the tool affects patients and family doctors, and the main risk is an omitted medication. Measure: on 400 past summaries, drafts omit a medication in 3% of cases. Manage: a doctor signs every summary, the medication list is checked automatically against the prescription record, and the error rate is reviewed monthly.

Most often confused with

NIST AI RMF vs. ISO/IEC 42001

NIST AI RMFVoluntary guidance; no audit and no certificate
ISO/IEC 42001A management-system standard that can be certified

The NIST framework is a detailed guide to thinking about AI risk; ISO/IEC 42001 is a set of requirements that an auditor can verify. Many organisations use the first to design their approach and the second to demonstrate it to others. NIST publishes a crosswalk between the two.

Under the hood

Version 1.0 (NIST AI 100-1) was published on 26 January 2023. It has two parts: a description of AI risks and of the characteristics of trustworthy AI, and the core of four functions, Govern, Map, Measure and Manage, each divided into categories and subcategories. Govern runs across the other three. The characteristics of trustworthy AI are: valid and reliable; safe; secure and resilient; accountable and transparent; explainable and interpretable; privacy-enhanced; and fair, with harmful bias managed. Companion resources: the AI RMF Playbook, with suggested actions for each subcategory, and profiles that apply the framework to a setting. The Generative AI Profile (NIST AI 600-1, July 2024) lists twelve risks that are new or heightened with generative AI, among them confabulation, information security, data privacy and harmful bias, with actions for each. Use is voluntary and there is no certification. NIST has stated that version 1.0 is being revised, so the current edition should be checked. The position described is that of October 2026.

Written by Mehmet Erkek · Last updated: