Framework
NIST AI Risk Management Framework 1.0
The U.S. National Institute of Standards and Technology framework for managing risks in the design, development, use, and evaluation of AI products and services.
The NIST AI RMF 1.0 provides a structured, flexible, and measurable approach to AI risk management suitable for organisations of any size and sector. It is not a compliance checklist: it is a framework for integrating AI risk governance into existing enterprise risk and software lifecycle practices.
Core functions
| Function | Purpose | Key outputs |
|---|---|---|
| Govern | Establish organisational culture, policies, accountability structures, and risk appetite for AI systems | Risk ownership, policies, workforce training, third-party oversight |
| Map | Understand the AI system’s context: purpose, data sources, model architecture, users, deployment environment | System inventory, data flows, boundary definitions, stakeholder identification |
| Measure | Apply quantitative and qualitative methods to assess AI risks, trustworthiness characteristics, and control effectiveness | Metrics, testing results, bias audits, security assessments, red-teaming reports |
| Manage | Prioritise, respond to, and monitor AI risks through controls, mitigations, and continuous improvement | Risk treatment plans, control implementations, incident response, benefit-risk tradeoffs |
ATLAS connection
The four NIST functions align with the ATLAS operating model: Govern maps to ownership and accountability; Map connects to inventory and classification; Measure corresponds to evidence collection and control validation; Manage links to response, remediation, and control improvement. The Shadow AI risk entry explicitly references NIST AI RMF governance requirements.
Official source: NIST