Secure AI Atlas mark Secure AI Atlas SECURITY & GOVERNANCE

Framework

NIST AI Risk Management Framework 1.0

The U.S. National Institute of Standards and Technology framework for managing risks in the design, development, use, and evaluation of AI products and services.

Risk ManagementGovernanceRegulationStandard

The NIST AI RMF 1.0 provides a structured, flexible, and measurable approach to AI risk management suitable for organisations of any size and sector. It is not a compliance checklist: it is a framework for integrating AI risk governance into existing enterprise risk and software lifecycle practices.

Core functions

FunctionPurposeKey outputs
GovernEstablish organisational culture, policies, accountability structures, and risk appetite for AI systemsRisk ownership, policies, workforce training, third-party oversight
MapUnderstand the AI system’s context: purpose, data sources, model architecture, users, deployment environmentSystem inventory, data flows, boundary definitions, stakeholder identification
MeasureApply quantitative and qualitative methods to assess AI risks, trustworthiness characteristics, and control effectivenessMetrics, testing results, bias audits, security assessments, red-teaming reports
ManagePrioritise, respond to, and monitor AI risks through controls, mitigations, and continuous improvementRisk treatment plans, control implementations, incident response, benefit-risk tradeoffs

ATLAS connection

The four NIST functions align with the ATLAS operating model: Govern maps to ownership and accountability; Map connects to inventory and classification; Measure corresponds to evidence collection and control validation; Manage links to response, remediation, and control improvement. The Shadow AI risk entry explicitly references NIST AI RMF governance requirements.

Official website →

Official source: NIST