NIST AI RMF

NIST AI RMF turned into a working risk process

The framework is voluntary and outcome-based. We convert it into a defined process with owners, artefacts, measurement and review — the form auditors and clients can actually inspect.

What are the four functions of the NIST AI RMF?

The NIST AI Risk Management Framework organises AI risk work into four functions. Govern establishes culture, policies, accountability and oversight. Map builds context: purpose, stakeholders, assumptions and where risk can arise. Measure analyses and tracks risk using quantitative and qualitative methods, including testing for validity, robustness, bias and security. Manage allocates resources to treat, monitor and respond to identified risks across the system lifecycle.

How we operationalise each function

Govern

Policy set, decision rights, risk appetite, third-party AI rules and workforce competency requirements.

Map

Use-case intake, context documentation, stakeholder and impact analysis, and system categorisation.

Measure

Test plans for performance, robustness, bias and security; metrics definitions; and independent review points.

Manage

Treatment decisions, residual risk acceptance, monitoring, incident response and decommissioning criteria.

Frequently asked questions

Should we use NIST AI RMF or ISO/IEC 42001?

They serve different purposes and work well together. ISO/IEC 42001 provides a certifiable management system structure; NIST AI RMF provides a richer risk-analysis vocabulary and outcome catalogue. A common pattern is ISO/IEC 42001 as the backbone with NIST AI RMF informing the risk methodology.

Is NIST AI RMF relevant outside the United States?

Yes. It is widely used internationally as a reference risk methodology, including by organisations preparing for the EU AI Act, because its Measure and Manage functions map well onto documented risk management requirements.

Build your AI risk process

Start with a maturity review against the four NIST AI RMF functions.