In this article
Browse the research library
Rules and standards
The NIST AI Risk Management Framework
A voluntary US framework: govern, map, measure, manage
Published 9 September 20262 min read
In one paragraph
The NIST AI Risk Management Framework is a voluntary US framework for managing the risks of artificial intelligence. It was published by the National Institute of Standards and Technology on 26 January 2023 and organises the work into four functions: govern, map, measure and manage. There is no certification attached to it, and no organisation is required to adopt it, but it has become a common reference point for what good AI risk management looks like, including for organisations outside the United States.
Who it applies to
Any organisation, anywhere, that wants a structured way to manage AI risk. There is no legal requirement to use it and no certification attached to it, which makes it as available to a small team as to a large regulated one. It is published by NIST, part of the US Department of Commerce, but its use is not limited to organisations operating in the United States.
What it asks for
- Govern: set the policies, roles and accountability for AI risk across the organisation, before any single system is assessed.
- Map: understand the context an AI system operates in, what it is for, who it affects and what could go wrong.
- Measure: put a method, and where possible a number, behind each risk identified, so it can be tracked rather than only described.
- Manage: act on what measurement shows, treating, monitoring or knowingly accepting a risk, with the decision recorded.
- Work through a companion Playbook of suggested actions under each function, useful where a team wants a starting point rather than a blank page.
- For generative systems specifically, work through the twelve risk categories set out in the Generative AI Profile, among them confabulation, data privacy and intellectual property.
What it looks like in practice
A first generative AI assistant is going in, and what the team wants is a structure to work through rather than a checklist borrowed from somewhere else. Mapping the four functions against the assistant, what it is for, what could go wrong, how that is measured, how it is managed, gives the team a shared way to talk about risk with people who were not involved in building it, and a document that holds up when someone senior asks how the risk was assessed.
Where it stands now
AI RMF 1.0 was published on 26 January 2023. The Generative AI Profile, NIST AI 600-1, was published on 26 July 2024 as a companion covering generative systems specifically. Both remain voluntary, with no certification scheme attached. Dates change; the official text linked below is the authority.
How this connects to our work
The four functions are one of the structures we map your controls against when building a private AI setup, and they are a useful starting point even where no other rule yet applies directly to a system.
Read the original
Every link goes to the publisher. Dates and status change; the text linked below is the authority.
- Artificial Intelligence Risk Management Framework (AI RMF 1.0) (opens in a new tab)
NIST · Regulator or statute · 2023
Voluntary US framework: govern, map, measure, manage.
- AI RMF Generative AI Profile (NIST AI 600-1) (opens in a new tab)
NIST · Regulator or statute · 2024
The generative-AI companion to the framework.