Published by the American National Institute of Standards and Technology, and voluntary. Its value to a product team is that it is the least bureaucratic structure available for asking whether you have thought about the right things.
The four functions
Govern is the one that runs through the others. Who is accountable, what the organisation's risk tolerance is, what policies apply, how decisions are recorded and how people are trained. Without it the other three produce artefacts nobody owns.
Map establishes context. What the system is for, who it affects, what could go wrong, and what assumptions the design rests on. This is where you decide the harms worth worrying about, and doing it badly makes everything downstream measure the wrong things.
Measure analyses and tracks what Map identified. Evaluation against your own cases, performance broken down by subgroup, red teaming, and the metrics that will be watched after launch. The framework is explicit that qualitative measures count where numbers are not available, which matters because most important harms do not have a metric.
Manage acts on it. Prioritise which risks to treat, decide what to accept and record why, put the controls in, and maintain them as the system and the world change.
Why it suits a product team
It asks the questions a product decision needs rather than the ones a compliance function needs, and it is written in language a person can act on.
Map is a discovery exercise, Measure is evaluation, and Manage is a prioritisation call with a rationale written beside it. Those are all things product people already do, and the framework mostly insists they get done deliberately rather than in passing.
The Generative AI Profile
NIST published a companion covering risks specific to generative systems, including confabulation, dangerous content, data privacy, information integrity, harmful bias and the security surface. It is the more useful document if you are shipping a feature built on a foundation model, because the core framework is written for AI generally.
Where it sits beside the others
The EU AI Act is law and says what you must do. ISO/IEC 42001 is a standard you can be certified against and says how to run a management system. NIST is voluntary guidance and says how to think about the risk.
They overlap heavily in substance. A team that has genuinely done Map, Measure and Manage has most of the material the Act's technical documentation asks for, which is the practical argument for using it even where nothing obliges you to.
Using it without a programme
The small version is a page per feature. What it does and who it affects, what could go wrong and how badly, what you measured and what it showed, what you decided to accept and why, and who owns it.
That page is Map, Measure, Manage and Govern at a scale a team can sustain, and it is worth more than a framework adopted in name and abandoned in practice.
Practise this
You need one feature of your own, fifteen minutes, and the names of real people rather than the names of teams.
Put the four functions down the page and write a single human name against each, along with the artefact that person would produce if asked to show the work, and when it was last touched. A team name is not an answer and neither is a name attached to nothing, so leave a row blank rather than filling it charitably.
Feature ..........................................
Function Who, by name What they would show you Last touched
Govern ............ ......................... ..........
Map ............ ......................... ..........
Measure ............ ......................... ..........
Manage ............ ......................... ..........
Govern risk tolerance, policy, who decides, who is trained
Map what it is for, who it affects, what could go wrong
Measure evaluation, subgroup performance, red teaming, live metrics
Manage what we treat, what we accept and why, the controls
One row is usually empty, and it is usually Govern. Map tends to belong to whoever wrote the brief and Measure to whoever built the evaluation set, while the person who decides how much risk is acceptable and puts a name to that decision often turns out to be nobody in particular, or everybody, which behaves the same way on the day something goes wrong. Read the last column too, because a name attached to a document nobody has opened in a year is an owner in title only.
Naming four people for one feature teaches you which function your organisation is running on goodwill, and that is the one that gives way under pressure.