# What is AI Risk Management?

> Artificial intelligence (AI) risk management is the coordinated process of identifying, assessing, treating, monitoring, and communicating risks arising from the design, development, acquisition, deployment, use, and retirement of AI systems.

- Canonical URL: https://yellowcube.eu/glossary/ai-risk-management/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

It considers effects on people, organizations, society, and the environment, including security, safety, privacy, reliability, bias, accountability, legal, and business risks across the AI lifecycle.

The National Institute of Standards and Technology AI Risk Management Framework (NIST AI RMF) organizes voluntary outcomes under Govern, Map, Measure, and Manage. Its 1.0 edition remains the published framework but is being revised. Organizations should adapt methods to the use case, affected parties, available evidence, risk tolerance, and applicable obligations.

### Key points

- **Govern:** Assign accountable owners, policies, decision rights, documentation, independent challenge, incident routes, supplier expectations, and criteria for restricting or stopping a system.
- **Map and measure:** Define intended use and context, affected parties, dependencies, foreseeable misuse, uncertainty, metrics, test conditions, limitations, and changes from development to operation.
- **Manage continuously:** Prioritize risks, implement and verify treatment, monitor performance and impacts, handle incidents and appeals, reassess material changes, and retire systems safely.
- **Important limitation:** A framework, score, benchmark, or model card cannot prove that an AI system is trustworthy or acceptable. Measurements are incomplete and context-dependent, while harms and interactions may emerge after deployment.

### Related terms

[AI security](<https://yellowcube.eu/glossary/ai-security/>) · [AI red teaming](<https://yellowcube.eu/glossary/ai-red-teaming/>) · [Data governance](<https://yellowcube.eu/glossary/data-governance/>) · [Model poisoning](<https://yellowcube.eu/glossary/model-poisoning/>) · [Data poisoning](<https://yellowcube.eu/glossary/data-poisoning/>) · [AI governance](<https://yellowcube.eu/glossary/ai-governance/>) · [Artificial Intelligence Act (AI Act)](<https://yellowcube.eu/glossary/artificial-intelligence-act/>)

### Sources

[NIST, AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework) · [NIST AI 100-1, Artificial Intelligence Risk Management Framework 1.0](https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10) · [NIST, AI RMF Playbook](https://www.nist.gov/itl/ai-risk-management-framework/nist-ai-rmf-playbook)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

