It considers effects on people, organizations, society, and the environment, including security, safety, privacy, reliability, bias, accountability, legal, and business risks across the AI lifecycle.
The National Institute of Standards and Technology AI Risk Management Framework (NIST AI RMF) organizes voluntary outcomes under Govern, Map, Measure, and Manage. Its 1.0 edition remains the published framework but is being revised. Organizations should adapt methods to the use case, affected parties, available evidence, risk tolerance, and applicable obligations.
Key points
GovernAssign accountable owners, policies, decision rights, documentation, independent challenge, incident routes, supplier expectations, and criteria for restricting or stopping a system.
Map and measureDefine intended use and context, affected parties, dependencies, foreseeable misuse, uncertainty, metrics, test conditions, limitations, and changes from development to operation.
Manage continuouslyPrioritize risks, implement and verify treatment, monitor performance and impacts, handle incidents and appeals, reassess material changes, and retire systems safely.
Important limitationA framework, score, benchmark, or model card cannot prove that an AI system is trustworthy or acceptable. Measurements are incomplete and context-dependent, while harms and interactions may emerge after deployment.