NIST AI RMF
The NIST AI Risk Management Framework is a voluntary US framework that helps organizations identify, assess, and manage risks associated with AI systems.
The NIST AI Risk Management Framework (AI RMF) was published by the US National Institute of Standards and Technology to promote trustworthy and responsible AI. It is voluntary and adaptable across sectors and use cases.
The framework is organized around four core functions: GOVERN, which establishes a culture of risk management; MAP, which contextualizes risks; MEASURE, which analyzes and tracks them; and MANAGE, which prioritizes and acts on them. Together they form a continuous loop rather than a one-time assessment.
The AI RMF complements binding regulation such as the EU AI Act by providing concrete, characteristics-based guidance — for example around validity, reliability, safety, security, accountability, transparency, fairness, and privacy — that organizations can operationalize as controls.
Related terms
- AI ComplianceAI compliance is the practice of ensuring artificial-intelligence systems meet applicable legal, regulatory, and ethical requirements throughout their lifecycle.
- EU AI ActThe EU AI Act is the European Union's regulation for artificial intelligence, applying tiered obligations to AI systems according to the level of risk they pose.
- Risk RegisterA risk register is a centralized record of an organization's identified risks, capturing their likelihood, impact, ownership, and treatment status.
- GRCGRC stands for Governance, Risk, and Compliance — an integrated approach to aligning an organization's strategy, risk management, and adherence to regulations and standards.