Concept 2 of 4

The NIST AI Risk Management Framework

2 questions test this

Published by the American National Institute of Standards and Technology, and voluntary. Its value to a product team is that it is the least bureaucratic structure available for asking whether you have thought about the right things.

The four functions

Govern is the one that runs through the others. Who is accountable, what the organisation's risk tolerance is, what policies apply, how decisions are recorded and how people are trained. Without it the other three produce artefacts nobody owns.

Map establishes context. What the system is for, who it affects, what could go wrong, and what assumptions the design rests on. This is where you decide the harms worth worrying about, and doing it badly makes everything downstream measure the wrong things.

Measure analyses and tracks what Map identified. Evaluation against your own cases, performance broken down by subgroup, red teaming, and the metrics that will be watched after launch. The framework is explicit that qualitative measures count where numbers are not available, which matters because most important harms do not have a metric.

Manage acts on it. Prioritise which risks to treat, decide what to accept and record why, put the controls in, and maintain them as the system and the world change.

Why it suits a product team

It asks the questions a product decision needs rather than the ones a compliance function needs, and it is written in language a person can act on.

Map is a discovery exercise, Measure is evaluation, and Manage is a prioritisation call with a rationale written beside it. Those are all things product people already do, and the framework mostly insists they get done deliberately rather than in passing.

The Generative AI Profile

NIST published a companion covering risks specific to generative systems, including confabulation, dangerous content, data privacy, information integrity, harmful bias and the security surface. It is the more useful document if you are shipping a feature built on a foundation model, because the core framework is written for AI generally.

Where it sits beside the others

The EU AI Act is law and says what you must do. ISO/IEC 42001 is a standard you can be certified against and says how to run a management system. NIST is voluntary guidance and says how to think about the risk.

They overlap heavily in substance. A team that has genuinely done Map, Measure and Manage has most of the material the Act's technical documentation asks for, which is the practical argument for using it even where nothing obliges you to.

Using it without a programme

The small version is a page per feature. What it does and who it affects, what could go wrong and how badly, what you measured and what it showed, what you decided to accept and why, and who owns it.

That page is Map, Measure, Manage and Govern at a scale a team can sustain, and it is worth more than a framework adopted in name and abandoned in practice.

Common misconceptions

It is a standard you get certified against.

It is voluntary guidance with no certification behind it. ISO/IEC 42001 is the standard an organisation is audited against, and the two are complementary rather than alternatives.

Govern, map, measure and manage happen in that order, once.

Govern runs throughout and the other three are continuous. Treating them as a sequence produces a document written before launch and never opened again, which is the failure the framework is built to prevent.

It only matters to organisations selling to the American government.

That is where the pressure to adopt it comes from, and its value is that it gives a small team a structure for questions they would otherwise answer ad hoc. It is the most usable thing in this area for people who are not lawyers.

2 questions test this concept

Which of the NIST AI Risk Management Framework's four functions establishes who is accountable and what the organisation's risk tolerance is?

  • AGovern.
  • BMap.
  • CMeasure.
  • DManage.
Check whether it stuck.

One per page, with a worked explanation.

Start the set
Related material
Template
Launch checklist, Everything that has to happen from two weeks out to one week after release, grouped by when it falls due, each line with a named owner and a go or no go decision on the day.
Template
Stakeholder map, One row per stakeholder with what they need from the product, their influence and interest scored one to five, where they stand today, where you need them to be, and who owns the next conversation.