The NIST AI Risk Management Framework
What the four functions of the AI RMF actually ask an organisation to do, why Govern is the one that determines whether the rest happens, and what a voluntary framework can and cannot deliver.
The AI Risk Management Framework, published by the US National Institute of Standards and Technology in January 2023, is voluntary, sector-agnostic and non-prescriptive. Those three properties are usually read as weaknesses. They are the reason it has been adopted as the common vocabulary across organisations that share no regulator, and they are also why an organisation can claim to follow it while doing very little.
The four functions
Govern establishes the structures: policies, accountability, roles, risk tolerance, and how AI risk connects to enterprise risk management. It is described as cross-cutting rather than sequential, and it is the function that determines whether the other three produce anything. An organisation with excellent measurement and no governance produces reports nobody acts on.
Map establishes context. What is the system for, who does it affect, what are the intended and foreseeable uses, what could go wrong, and what are the interdependencies. This is where most of the value sits, because a risk not identified here is not managed later, and it is the function that most benefits from involving people outside the building team.
Measure analyses and tracks the identified risks with quantitative and qualitative methods: evaluation, testing, monitoring, and assessment of the trustworthiness characteristics the framework enumerates, which include validity and reliability, safety, security and resilience, accountability and transparency, explainability and interpretability, privacy enhancement, and fairness with harmful bias managed.
Manage allocates resources to the risks, decides what is treated, transferred, avoided or accepted, and covers response and recovery. The acceptance decision is the substantive one and needs to name who accepted the risk.
Why the structure works
The framework's contribution is not any single control. It is that it forces the questions in an order where the answers compound: identify context before measuring, measure before deciding, and hold the whole thing inside a governance structure that assigns accountability.
The Generative AI Profile, published in 2024 as a companion, maps the same functions onto risks specific to generative systems, including confabulation, harmful content, information security, and data provenance. Using the profile rather than the base framework alone is what makes it concrete for an LLM application.
When it breaks
Voluntary means unenforced. There is no certification, no audit regime and no consequence for a superficial application. An organisation can produce documents corresponding to each function and change no behaviour, and nothing in the framework prevents that.
Non-prescriptive means the hard questions stay open. The framework says to establish risk tolerance; it does not say what tolerance is appropriate. That is correct for a cross-sector document and it leaves the substantive judgement exactly where it was.
Map is skipped because it requires the widest input. Identifying who a system affects and how it could fail requires people outside the engineering team, which is organisationally expensive. Teams that skip to Measure end up rigorously measuring the risks they already knew about.
It is a management framework, not a technical standard. It tells you to measure fairness and does not tell you which metric, which is the question that actually decides the outcome. Pairing it with technical guidance is necessary, and treating adoption as a technical achievement misreads what it is.
10 flashcards for this concept
Click a card to reveal the answer.