What the framework is for
NIST’s AI Risk Management Framework helps organizations identify and manage AI risks while promoting trustworthy and responsible use. It is voluntary, flexible, and intended to work across sectors and system types rather than prescribe one technical architecture.
The companion Generative AI Profile adapts the framework to risks that are especially relevant to generative systems. NIST released the profile as NIST AI 600-1 in July 2024. NIST is also revising AI RMF 1.0, so teams should track the current official material.
Govern: make accountability real
- Name accountable owners for the business outcome, model behavior, data, security, and human oversight.
- Define acceptable use, prohibited use, risk appetite, escalation paths, and exception handling.
- Set procurement requirements for third-party models, datasets, tools, and monitoring support.
- Train staff to recognize system limits, unsafe outputs, privacy risks, and social impacts.
Map: understand the context before testing
- Document the intended purpose, users, affected people, decision stakes, and operating environment.
- Map data provenance, external dependencies, deployment boundaries, and human handoffs.
- Identify reasonably foreseeable misuse and how failures could propagate through the workflow.
- Decide which risks matter most for this use case instead of relying on a generic checklist alone.
Measure: test claims with evidence
- Create representative evaluation sets, including edge cases and adversarial inputs.
- Measure task quality alongside harmful content, privacy leakage, security, bias, robustness, and uncertainty.
- Test the whole system, not only the base model, including retrieval, tools, prompts, interfaces, and human review.
- Record methods, limitations, thresholds, failed tests, and the decisions made from results.
Manage: prioritize, respond, and monitor
- Prioritize risks based on likelihood, severity, affected groups, and the organization’s ability to intervene.
- Choose controls such as constrained tool access, retrieval boundaries, filters, confirmations, and human review.
- Monitor production signals, user reports, model or vendor changes, and drift in the surrounding workflow.
- Maintain incident response, rollback, notification, and learning processes. Exercise them before an emergency.
A useful first deliverable
For one live use case, create a compact risk record: purpose, owner, users, data, dependencies, top risks, evaluation evidence, controls, residual risks, monitoring signals, and review date. That single artifact creates a shared reference for product, engineering, security, legal, and operations.
Repeat the process for higher-priority systems, then standardize what proves useful. The goal is not maximum paperwork; it is enough reliable evidence to make and revisit risk decisions.
Primary sources
We used the following official materials to verify this guide: