Published by the American National Institute of Standards and Technology, and voluntary. Its value to a product team is that it is the least bureaucratic structure available for asking whether you have thought about the right things.
The four functions
Govern is the one that runs through the others. Who is accountable, what the organisation's risk tolerance is, what policies apply, how decisions are recorded and how people are trained. Without it the other three produce artefacts nobody owns.
Map establishes context. What the system is for, who it affects, what could go wrong, and what assumptions the design rests on. This is where you decide the harms worth worrying about, and doing it badly makes everything downstream measure the wrong things.
Measure analyses and tracks what Map identified. Evaluation against your own cases, performance broken down by subgroup, red teaming, and the metrics that will be watched after launch. The framework is explicit that qualitative measures count where numbers are not available, which matters because most important harms do not have a metric.
Manage acts on it. Prioritise which risks to treat, decide what to accept and record why, put the controls in, and maintain them as the system and the world change.
Why it suits a product team
It asks the questions a product decision needs rather than the ones a compliance function needs, and it is written in language a person can act on.
Map is a discovery exercise, Measure is evaluation, and Manage is a prioritisation call with a rationale written beside it. Those are all things product people already do, and the framework mostly insists they get done deliberately rather than in passing.
The Generative AI Profile
NIST published a companion covering risks specific to generative systems, including confabulation, dangerous content, data privacy, information integrity, harmful bias and the security surface. It is the more useful document if you are shipping a feature built on a foundation model, because the core framework is written for AI generally.
Where it sits beside the others
The EU AI Act is law and says what you must do. ISO/IEC 42001 is a standard you can be certified against and says how to run a management system. NIST is voluntary guidance and says how to think about the risk.
They overlap heavily in substance. A team that has genuinely done Map, Measure and Manage has most of the material the Act's technical documentation asks for, which is the practical argument for using it even where nothing obliges you to.
Using it without a programme
The small version is a page per feature. What it does and who it affects, what could go wrong and how badly, what you measured and what it showed, what you decided to accept and why, and who owns it.
That page is Map, Measure, Manage and Govern at a scale a team can sustain, and it is worth more than a framework adopted in name and abandoned in practice.