A widely used US government framework that helps organisations manage AI risks in a structured way — covering governance, risk identification, measurement, and ongoing management.
A widely used US government framework that helps organisations manage AI risks in a structured way — covering governance, risk identification, measurement, and ongoing management.
The NIST AI RMF (AI 100-1, January 2023) is structured around four core functions: Govern (establishing the governance context for AI risk management), Map (contextualising AI risk by characterising the system and its risks), Measure (analysing and assessing risks using qualitative and quantitative methods), and Manage (prioritising and treating AI risks with appropriate controls). Each function contains categories and subcategories providing granular guidance. An AI RMF Playbook accompanies the framework with practical implementation guidance. The NIST AI RMF is widely adopted in US federal agencies and increasingly referenced by global organisations alongside or in lieu of EU frameworks.
Organisations operating in both US and EU markets can use the NIST AI RMF as a bridge framework — it aligns broadly with ISO/IEC 42001 and EU AI Act principles, enabling a unified governance programme.
Like the NIST Cybersecurity Framework for information security — a voluntary, adaptable framework that has become a de facto standard for structuring risk management conversations between business and technical teams.
A widely used US government framework that helps organisations manage AI risks in a structured way — covering governance, risk identification, measurement, and ongoing management.
The NIST AI RMF (AI 100-1, January 2023) is structured around four core functions: Govern (establishing the governance context for AI risk management), Map (contextualising AI risk by characterising the system and its risks), Measure (analysing and assessing risks using qualitative and quantitative methods), and Manage (prioritising and treating AI risks with appropriate controls). Each function contains categories and subcategories providing granular guidance. An AI RMF Playbook accompanies the framework with practical implementation guidance. The NIST AI RMF is widely adopted in US federal agencies and increasingly referenced by global organisations alongside or in lieu of EU frameworks.
Organisations operating in both US and EU markets can use the NIST AI RMF as a bridge framework — it aligns broadly with ISO/IEC 42001 and EU AI Act principles, enabling a unified governance programme.