Glossary

NIST AI RMF

The NIST AI Risk Management Framework is a voluntary US framework that helps organizations identify, assess, and manage risks associated with AI systems.

The NIST AI Risk Management Framework (AI RMF) was published by the US National Institute of Standards and Technology to promote trustworthy and responsible AI. It is voluntary and adaptable across sectors and use cases.

The framework is organized around four core functions: GOVERN, which establishes a culture of risk management; MAP, which contextualizes risks; MEASURE, which analyzes and tracks them; and MANAGE, which prioritizes and acts on them. Together they form a continuous loop rather than a one-time assessment.

The AI RMF complements binding regulation such as the EU AI Act by providing concrete, characteristics-based guidance — for example around validity, reliability, safety, security, accountability, transparency, fairness, and privacy — that organizations can operationalize as controls.

Related terms