Govern
Policy set, decision rights, risk appetite, third-party AI rules and workforce competency requirements.
NIST AI RMF
The framework is voluntary and outcome-based. We convert it into a defined process with owners, artefacts, measurement and review — the form auditors and clients can actually inspect.
The NIST AI Risk Management Framework organises AI risk work into four functions. Govern establishes culture, policies, accountability and oversight. Map builds context: purpose, stakeholders, assumptions and where risk can arise. Measure analyses and tracks risk using quantitative and qualitative methods, including testing for validity, robustness, bias and security. Manage allocates resources to treat, monitor and respond to identified risks across the system lifecycle.
Policy set, decision rights, risk appetite, third-party AI rules and workforce competency requirements.
Use-case intake, context documentation, stakeholder and impact analysis, and system categorisation.
Test plans for performance, robustness, bias and security; metrics definitions; and independent review points.
Treatment decisions, residual risk acceptance, monitoring, incident response and decommissioning criteria.
They serve different purposes and work well together. ISO/IEC 42001 provides a certifiable management system structure; NIST AI RMF provides a richer risk-analysis vocabulary and outcome catalogue. A common pattern is ISO/IEC 42001 as the backbone with NIST AI RMF informing the risk methodology.
Yes. It is widely used internationally as a reference risk methodology, including by organisations preparing for the EU AI Act, because its Measure and Manage functions map well onto documented risk management requirements.
Start with a maturity review against the four NIST AI RMF functions.