How to apply the NIST AI RMF to your AI systems
NIST AI Risk Management Framework 1.0
- Status
- Voluntary
- Binding
- No
- Object analysed
- AI system
- Requirements
- 72
- Next milestone
- Dec 2026
In short
The US reference voluntary framework: 4 functions (Govern, Map, Measure, Manage), 72 subcategories. Cited as a safe harbour by Colorado and Texas.
Steps to compliance
- Qualify each AI systemAxes to decide: Internal risk tier (organisation-defined).
- Determine your roleDuties vary by role: AI actor.
- Apply the 72 requirementsThey focus on: Governance & accountability, Risk management, Accuracy & robustness and Post-deployment monitoring.
- Prove it with checks49 checks to document, 31 of which also serve ISO 42001, AI Act and US federal.
- Track the deadlinesNext milestone: Dec 2026, Expected RMF revision (potential).
Scope and penalties
- Kind
- Voluntary framework
- Scope
- Any organisation designing, deploying or using AI.
- Territorial reach
- No territorial scope; de facto reference for US public buyers.
- Penalties
- None (voluntary). Leverage: safe harbour in state laws.
- Jurisdiction
- United States (federal)
Timeline
Qualifying a system
Classification axes and possible verdicts
Internal risk tier (organisation-defined)
Requirements
72 requirements
| Code | Article | Requirement | Applies to | Checks |
|---|---|---|---|---|
| GOVERN-1.1 | GOVERN | Legal and regulatory requirements involving AI are understood, managed, and documented.DetailAI systems may be subject to specific applicable legal and regulatory requirements. Some legal requirements can mandate (e.g., nondiscrimination, data privacy and security controls) documentation, disclosure, and increased AI system transparency. These requirements are complex and may not be applicable or differ across applications and contexts. | ||
| GOVERN-1.2 | GOVERN | The characteristics of trustworthy AI are integrated into organizational policies, processes, procedures, and practices.DetailPolicies, processes, and procedures are central components of effective AI risk management and fundamental to individual and organizational accountability. All stakeholders benefit from policies, processes, and procedures which require preventing harm by design and default. | ||
| GOVERN-1.3 | GOVERN | Processes, procedures, and practices are in place to determine the needed level of risk management activities based on the organization's risk tolerance.DetailRisk management resources are finite in any organization. Adequate AI governance policies delineate the mapping, measurement, and prioritization of risks to allocate resources toward the most material issues for an AI system to ensure effective risk management. Policies may specify systematic processes for assigning mapped and measured risks to standardized risk scales. | ||
| GOVERN-1.4 | GOVERN | The risk management process and its outcomes are established through transparent policies, procedures, and other controls based on organizational risk priorities.DetailClear policies and procedures relating to documentation and transparency facilitate and enhance efforts to communicate roles and responsibilities for the Map, Measure and Manage functions across the AI lifecycle. Standardized documentation can help organizations systematically integrate AI risk management processes and enhance accountability efforts. For example, by adding their contact information to a work product document, AI actors can improve communication, increase ownership of work products, and potentially enhance consideration of product quality. Documentation may generate downstream benefits related to improved system replicability and robustness. Proper documentation storage and access procedures allow for quick retrieval of critical information during a negative incident. Explainable machine learning efforts (models and explanatory methods) may bolster technical documentation practices by introducing additional information for review and interpretation by AI Actors. | ||
| GOVERN-1.5 | GOVERN | Ongoing monitoring and periodic review of the risk management process and its outcomes are planned and organizational roles and responsibilities clearly defined, including determining the frequency of periodic review.DetailAI systems are dynamic and may perform in unexpected ways once deployed or after deployment. Continuous monitoring is a risk management process for tracking unexpected issues and performance changes, in real-time or at a specific frequency, across the AI system lifecycle. | ||
| GOVERN-1.6 | GOVERN | Mechanisms are in place to inventory AI systems and are resourced according to organizational risk priorities.DetailAn AI system inventory is an organized database of artifacts relating to an AI system or model. It may include system documentation, incident response plans, data dictionaries, links to implementation software or source code, names and contact information for relevant AI actors, or other information that may be helpful for model or system maintenance and incident response purposes. AI system inventories also enable a holistic view of organizational AI assets. A serviceable AI system inventory may allow for the quick resolution of: | ||
| GOVERN-1.7 | GOVERN | Processes and procedures are in place for decommissioning and phasing out AI systems safely and in a manner that does not increase risks or decrease the organization's trustworthiness.DetailIrregular or indiscriminate termination or deletion of models or AI systems may be inappropriate and increase organizational risk. For example, AI systems may be subject to regulatory requirements or implicated in future security or legal investigations. To maintain trust, organizations may consider establishing policies and processes for the systematic and deliberate decommissioning of AI systems. Typically, such policies consider user and community concerns, risks in dependent and linked systems, and security, legal or regulatory concerns. Decommissioned models or systems may be stored in a model inventory along with active models, for an established length of time. | ||
| GOVERN-2.1 | GOVERN | Roles and responsibilities and lines of communication related to mapping, measuring, and managing AI risks are documented and are clear to individuals and teams throughout the organization.DetailThe development of a risk-aware organizational culture starts with defining responsibilities. For example, under some risk management structures, professionals carrying out test and evaluation tasks are independent from AI system developers and report through risk management functions or directly to executives. This kind of structure may help counter implicit biases such as groupthink or sunk cost fallacy and bolster risk management functions, so efforts are not easily bypassed or ignored. | ||
| GOVERN-2.2 | GOVERN | The organization's personnel and partners receive AI risk management training to enable them to perform their duties and responsibilities consistent with related policies, procedures, and agreements.DetailTo enhance AI risk management adoption and effectiveness, organizations are encouraged to identify and integrate appropriate training curricula into enterprise learning requirements. Through regular training, AI actors can maintain awareness of: | ||
| GOVERN-2.3 | GOVERN | Executive leadership of the organization takes responsibility for decisions about risks associated with AI system development and deployment.DetailSenior leadership and members of the C-Suite in organizations that maintain an AI portfolio, should maintain awareness of AI risks, affirm the organizational appetite for such risks, and be responsible for managing those risks.. | ||
| GOVERN-3.1 | GOVERN | Decision-making related to mapping, measuring, and managing AI risks throughout the lifecycle is informed by a diverse team (e.g., diversity of demographics, disciplines, experience, expertise, and backgrounds).DetailA diverse team that includes AI actors with diversity of experience, disciplines, and backgrounds to enhance organizational capacity and capability for anticipating risks is better equipped to carry out risk management. Consultation with external personnel may be necessary when internal teams lack a diverse range of lived experiences or disciplinary expertise. | ||
| GOVERN-3.2 | GOVERN | Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight of AI systems.DetailIdentifying and managing AI risks and impacts are enhanced when a broad set of perspectives and actors across the AI lifecycle, including technical, legal, compliance, social science, and human factors expertise is engaged. AI actors include those who operate, use, or interact with AI systems for downstream tasks, or monitor AI system performance. Effective risk management efforts include: | ||
| GOVERN-4.1 | GOVERN | Organizational policies and practices are in place to foster a critical thinking and safety-first mindset in the design, development, deployment, and uses of AI systems to minimize potential negative impacts.DetailA risk culture and accompanying practices can help organizations effectively triage the most critical risks. Organizations in some industries implement three (or more) “lines of defense,” where separate teams are held accountable for different aspects of the system lifecycle, such as development, risk management, and auditing. While a traditional three- lines approach may be impractical for smaller organizations, leadership can commit to cultivating a strong risk culture through other means. For example, “effective challenge,” is a culture- based practice that encourages critical thinking and questioning of important design and implementation decisions by experts with the authority and stature to make such changes. | ||
| GOVERN-4.2 | GOVERN | Organizational teams document the risks and potential impacts of the AI technology they design, develop, deploy, evaluate, and use, and they communicate about the impacts more broadly.DetailImpact assessments are one approach for driving responsible technology development practices. And, within a specific use case, these assessments can provide a high-level structure for organizations to frame risks of a given algorithm or deployment. Impact assessments can also serve as a mechanism for organizations to articulate risks and generate documentation for managing and oversight activities when harms do arise. | ||
| GOVERN-4.3 | GOVERN | Organizational practices are in place to enable AI testing, identification of incidents, and information sharing.DetailIdentifying AI system limitations, detecting and tracking negative impacts and incidents, and sharing information about these issues with appropriate AI actors will improve risk management. Issues such as concept drift, AI bias and discrimination, shortcut learning or underspecification are difficult to identify using current standard AI testing processes. Organizations can institute in-house use and testing policies and procedures to identify and manage such issues. Efforts can take the form of pre-alpha or pre-beta testing, or deploying internally developed systems or products within the organization. Testing may entail limited and controlled in-house, or publicly available, AI system testbeds, and accessibility of AI system interfaces and outputs. | ||
| GOVERN-5.1 | GOVERN | Organizational policies and practices are in place to collect, consider, prioritize, and integrate feedback from those external to the team that developed or deployed the AI system regarding the potential individual and societal impacts related to AI risks.DetailBeyond internal and laboratory-based system testing, organizational policies and practices may consider AI system fitness-for-purpose related to the intended context of use. | ||
| GOVERN-5.2 | GOVERN | Mechanisms are established to enable the team that developed or deployed AI systems to regularly incorporate adjudicated feedback from relevant AI actors into system design and implementation.DetailOrganizational policies and procedures that equip AI actors with the processes, knowledge, and expertise needed to inform collaborative decisions about system deployment improve risk management. These decisions are closely tied to AI systems and organizational risk tolerance. | ||
| GOVERN-6.1 | GOVERN | Policies and procedures are in place that address AI risks associated with third-party entities, including risks of infringement of a third-party's intellectual property or other rights.DetailRisk measurement and management can be complicated by how customers use or integrate third-party data or systems into AI products or services, particularly without sufficient internal governance structures and technical safeguards. | ||
| GOVERN-6.2 | GOVERN | Contingency processes are in place to handle failures or incidents in third-party data or AI systems deemed to be high-risk.DetailTo mitigate the potential harms of third-party system failures, organizations may implement policies and procedures that include redundancies for covering third-party functions. | ||
| MAP-1.1 | MAP | Intended purposes, potentially beneficial uses, context-specific laws, norms and expectations, and prospective settings in which the AI system will be deployed are understood and documented. Considerations include: the specific set or types of users along with their expectations; potential positive and negative impacts of system uses to individuals, communities, organizations, society, and the planet; assumptions and related limitations about AI system purposes, uses, and risks across the development or product AI lifecycle; and related TEVV and system metrics.DetailHighly accurate and optimized systems can cause harm. Relatedly, organizations should expect broadly deployed AI tools to be reused, repurposed, and potentially misused regardless of intentions. | ||
| MAP-1.2 | MAP | Interdisciplinary AI actors, competencies, skills, and capacities for establishing context reflect demographic diversity and broad domain and user experience expertise, and their participation is documented. Opportunities for interdisciplinary collaboration are prioritized.DetailSuccessfully mapping context requires a team of AI actors with a diversity of experience, expertise, abilities and backgrounds, and with the resources and independence to engage in critical inquiry. | ||
| MAP-1.3 | MAP | The organization's mission and relevant goals for AI technology are understood and documented.DetailDefining and documenting the specific business purpose of an AI system in a broader context of societal values helps teams to evaluate risks and increases the clarity of “go/no- go” decisions about whether to deploy. | ||
| MAP-1.4 | MAP | The business value or context of business use has been clearly defined or - in the case of assessing existing AI systems - re-evaluated.DetailSocio-technical AI risks emerge from the interplay between technical development decisions and how a system is used, who operates it, and the social context into which it is deployed. Addressing these risks is complex and requires a commitment to understanding how contextual factors may interact with AI lifecycle actions. One such contextual factor is how organizational mission and identified system purpose create incentives within AI system design, development, and deployment tasks that may result in positive and negative impacts. By establishing comprehensive and explicit enumeration of AI systems’ context of of business use and expectations, organizations can identify and manage these types of risks. | ||
| MAP-1.5 | MAP | Organizational risk tolerances are determined and documented.DetailRisk tolerance reflects the level and type of risk the organization is willing to accept while conducting its mission and carrying out its strategy. | ||
| MAP-1.6 | MAP | System requirements (e.g., 'the system shall respect the privacy of its users') are elicited from and understood by relevant AI actors. Design decisions take socio-technical implications into account to address AI risks.DetailAI system development requirements may outpace documentation processes for traditional software. When written requirements are unavailable or incomplete, AI actors may inadvertently overlook business and stakeholder needs, over-rely on implicit human biases such as confirmation bias and groupthink, and maintain exclusive focus on computational requirements. | ||
| MAP-2.1 | MAP | The specific tasks and methods used to implement the tasks that the AI system will support are defined (e.g., classifiers, generative models, recommenders).DetailAI actors define the technical learning or decision-making task(s) an AI system is designed to accomplish, or the benefits that the system will provide. The clearer and narrower the task definition, the easier it is to map its benefits and risks, leading to more fulsome risk management. | ||
| MAP-2.2 | MAP | Information about the AI system's knowledge limits and how system output may be utilized and overseen by humans is documented. Documentation provides sufficient information to assist relevant AI actors when making decisions and taking subsequent actions.DetailAn AI lifecycle consists of many interdependent activities involving a diverse set of actors that often do not have full visibility or control over other parts of the lifecycle and its associated contexts or risks. The interdependencies between these activities, and among the relevant AI actors and organizations, can make it difficult to reliably anticipate potential impacts of AI systems. For example, early decisions in identifying the purpose and objective of an AI system can alter its behavior and capabilities, and the dynamics of deployment setting (such as end users or impacted individuals) can shape the positive or negative impacts of AI system decisions. As a result, the best intentions within one dimension of the AI lifecycle can be undermined via interactions with decisions and conditions in other, later activities. This complexity and varying levels of visibility can introduce uncertainty. And, once deployed and in use, AI systems may sometimes perform poorly, manifest unanticipated negative impacts, or violate legal or ethical norms. These risks and incidents can result from a variety of factors. For example, downstream decisions can be influenced by end user over-trust or under-trust, and other complexities related to AI-supported decision-making. | ||
| MAP-2.3 | MAP | Scientific integrity and TEVV considerations are identified and documented, including those related to experimental design, data collection and selection (e.g., availability, representativeness, suitability), system trustworthiness, and construct validation.DetailStandard testing and evaluation protocols provide a basis to confirm assurance in a system that it is operating as designed and claimed. AI systems’ complexities create challenges for traditional testing and evaluation methodologies, which tend to be designed for static or isolated system performance. Opportunities for risk continue well beyond design and deployment, into system operation and application of system-enabled decisions. Testing and evaluation methodologies and metrics therefore address a continuum of activities. TEVV is enhanced when key metrics for performance, safety, and reliability are interpreted in a socio-technical context and not confined to the boundaries of the AI system pipeline. | ||
| MAP-3.1 | MAP | Potential benefits of intended AI system functionality and performance are examined and documented.DetailAI systems have enormous potential to improve quality of life, enhance economic prosperity and security costs. Organizations are encouraged to define and document system purpose and utility, and its potential positive impacts and benefits beyond current known performance benchmarks. | ||
| MAP-3.2 | MAP | Potential costs, including non-monetary costs, which result from expected or realized AI errors or system functionality and trustworthiness - as connected to organizational risk tolerance - are examined and documented.DetailAnticipating negative impacts of AI systems is a difficult task. Negative impacts can be due to many factors, such as system non-functionality or use outside of its operational limits, and may range from minor annoyance to serious injury, financial losses, or regulatory enforcement actions. AI actors can work with a broad set of stakeholders to improve their capacity for understanding systems’ potential impacts – and subsequently – systems’ risks. | ||
| MAP-3.3 | MAP | Targeted application scope is specified and documented based on the system's capability, established context, and AI system categorization.DetailSystems that function in a narrow scope tend to enable better mapping, measurement, and management of risks in the learning or decision-making tasks and the system context. A narrow application scope also helps ease TEVV functions and related resources within an organization. | ||
| MAP-3.4 | MAP | Processes for operator and practitioner proficiency with AI system performance and trustworthiness - and relevant technical standards and certifications - are defined, assessed, and documented.DetailHuman-AI configurations can span from fully autonomous to fully manual. AI systems can autonomously make decisions, defer decision-making to a human expert, or be used by a human decision-maker as an additional opinion. In some scenarios, professionals with expertise in a specific domain work in conjunction with an AI system towards a specific end goal—for example, a decision about another individual(s). Depending on the purpose of the system, the expert may interact with the AI system but is rarely part of the design or development of the system itself. These experts are not necessarily familiar with machine learning, data science, computer science, or other fields traditionally associated with AI design or development and - depending on the application - will likely not require such familiarity. For example, for AI systems that are deployed in health care delivery the experts are the physicians and bring their expertise about medicine—not data science, data modeling and engineering, or other computational factors. The challenge in these settings is not educating the end user about AI system capabilities, but rather leveraging, and not replacing, practitioner domain expertise. | ||
| MAP-3.5 | MAP | Processes for human oversight are defined, assessed, and documented in accordance with organizational policies from the govern function.DetailAs AI systems have evolved in accuracy and precision, computational systems have moved from being used purely for decision support—or for explicit use by and under the control of a human operator—to automated decision making with limited input from humans. Computational decision support systems augment another, typically human, system in making decisions.These types of configurations increase the likelihood of outputs being produced with little human involvement. | ||
| MAP-4.1 | MAP | Approaches for mapping AI technology and legal risks of its components - including the use of third-party data or software - are in place, followed, and documented, as are risks of infringement of a third party's intellectual property or other rights.DetailTechnologies and personnel from third-parties are another potential sources of risk to consider during AI risk management activities. Such risks may be difficult to map since risk priorities or tolerances may not be the same as the deployer organization. | ||
| MAP-4.2 | MAP | Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented.DetailIn the course of their work, AI actors often utilize open-source, or otherwise freely available, third-party technologies – some of which may have privacy, bias, and security risks. Organizations may consider internal risk controls for these technology sources and build up practices for evaluating third-party material prior to deployment. | ||
| MAP-5.1 | MAP | Likelihood and magnitude of each identified impact (both potentially beneficial and harmful) based on expected use, past uses of AI systems in similar contexts, public incident reports, feedback from those external to the team that developed or deployed the AI system, or other data are identified and documented.DetailAI actors can evaluate, document and triage the likelihood of AI system impacts identified in Map 5.1 Likelihood estimates may then be assessed and judged for go/no-go decisions about deploying an AI system. If an organization decides to proceed with deploying the system, the likelihood and magnitude estimates can be used to assign TEVV resources appropriate for the risk level. | ||
| MAP-5.2 | MAP | Practices and personnel for supporting regular engagement with relevant AI actors and integrating feedback about positive, negative, and unanticipated impacts are in place and documented.DetailAI systems are socio-technical in nature and can have positive, neutral, or negative implications that extend beyond their stated purpose. Negative impacts can be wide- ranging and affect individuals, groups, communities, organizations, and society, as well as the environment and national security. | ||
| MEASURE-1.1 | MEASURE | Approaches and metrics for measurement of AI risks enumerated during the map function are selected for implementation starting with the most significant AI risks. The risks or trustworthiness characteristics that will not - or cannot - be measured are properly documented.DetailThe development and utility of trustworthy AI systems depends on reliable measurements and evaluations of underlying technologies and their use. Compared with traditional software systems, AI technologies bring new failure modes, inherent dependence on training data and methods which directly tie to data quality and representativeness. Additionally, AI systems are inherently socio-technical in nature, meaning they are influenced by societal dynamics and human behavior. AI risks – and benefits – can emerge from the interplay of technical aspects combined with societal factors related to how a system is used, its interactions with other AI systems, who operates it, and the social context in which it is deployed. In other words, What should be measured depends on the purpose, audience, and needs of the evaluations. | ||
| MEASURE-1.2 | MEASURE | Appropriateness of AI metrics and effectiveness of existing controls are regularly assessed and updated, including reports of errors and potential impacts on affected communities.DetailDifferent AI tasks, such as neural networks or natural language processing, benefit from different evaluation techniques. Use-case and particular settings in which the AI system is used also affects appropriateness of the evaluation techniques. Changes in the operational settings, data drift, model drift are among factors that suggest regularly assessing and updating appropriateness of AI metrics and their effectiveness can enhance reliability of AI system measurements. | ||
| MEASURE-1.3 | MEASURE | Internal experts who did not serve as front-line developers for the system and/or independent assessors are involved in regular assessments and updates. Domain experts, users, AI actors external to the team that developed or deployed the AI system, and affected communities are consulted in support of assessments as necessary per organizational risk tolerance.DetailThe current AI systems are brittle, the failure modes are not well described, and the systems are dependent on the context in which they were developed and do not transfer well outside of the training environment. A reliance on local evaluations will be necessary along with a continuous monitoring of these systems. Measurements that extend beyond classical measures (which average across test cases) or expand to focus on pockets of failures where there are potentially significant costs can improve the reliability of risk management activities. Feedback from affected communities about how AI systems are being used can make AI evaluation purposeful. Involving internal experts who did not serve as front-line developers for the system and/or independent assessors regular assessments of AI systems helps a fulsome characterization of AI systems’ performance and trustworthiness . | ||
| MEASURE-2.1 | MEASURE | Test sets, metrics, and details about the tools used during TEVV are documented.DetailDocumenting measurement approaches, test sets, metrics, processes and materials used, and associated details builds foundation upon which to build a valid, reliable measurement process. Documentation enables repeatability and consistency, and can enhance AI risk management decisions. | ||
| MEASURE-2.2 | MEASURE | Evaluations involving human subjects meet applicable requirements (including human subject protection) and are representative of the relevant population.DetailMeasurement and evaluation of AI systems often involves testing with human subjects or using data captured from human subjects. Protection of human subjects is required by law when carrying out federally funded research, and is a domain specific requirement for some disciplines. Standard human subjects protection procedures include protecting the welfare and interests of human subjects, designing evaluations to minimize risks to subjects, and completion of mandatory training regarding legal requirements and expectations. | ||
| MEASURE-2.3 | MEASURE | AI system performance or assurance criteria are measured qualitatively or quantitatively and demonstrated for conditions similar to deployment setting(s). Measures are documented.DetailThe current risk and impact environment suggests AI system performance estimates are insufficient and require a deeper understanding of deployment context of use. Computationally focused performance testing and evaluation schemes are restricted to test data sets and in silico techniques. These approaches do not directly evaluate risks and impacts in real world environments and can only predict what might create impact based on an approximation of expected AI use. To properly manage risks, more direct information is necessary to understand how and under what conditions deployed AI creates impacts, who is most likely to be impacted, and what that experience is like. | ||
| MEASURE-2.4 | MEASURE | The functionality and behavior of the AI system and its components - as identified in the map function - are monitored when in production.DetailAI systems may encounter new issues and risks while in production as the environment evolves over time. This effect, often referred to as “drift”, means AI systems no longer meet the assumptions and limitations of the original design. Regular monitoring allows AI Actors to monitor the functionality and behavior of the AI system and its components – as identified in the MAP function - and enhance the speed and efficacy of necessary system interventions. | ||
| MEASURE-2.5 | MEASURE | The AI system to be deployed is demonstrated to be valid and reliable. Limitations of the generalizability beyond the conditions under which the technology was developed are documented.DetailAn AI system that is not validated or that fails validation may be inaccurate or unreliable or may generalize poorly to data and settings beyond its training, creating and increasing AI risks and reducing trustworthiness. AI Actors can improve system validity by creating processes for exploring and documenting system limitations. This includes broad consideration of purposes and uses for which the system was not designed. | ||
| MEASURE-2.6 | MEASURE | The AI system is evaluated regularly for safety risks - as identified in the map function. The AI system to be deployed is demonstrated to be safe, its residual negative risk does not exceed the risk tolerance, and it can fail safely, particularly if made to operate beyond its knowledge limits. Safety metrics reflect system reliability and robustness, real-time monitoring, and response times for AI system failures.DetailMany AI systems are being introduced into settings such as transportation, manufacturing or security, where failures may give rise to various physical or environmental harms. AI systems that may endanger human life, health, property or the environment are tested thoroughly prior to deployment, and are regularly evaluated to confirm the system is safe during normal operations, and in settings beyond its proposed use and knowledge limits. | ||
| MEASURE-2.7 | MEASURE | AI system security and resilience - as identified in the map function - are evaluated and documented.DetailAI systems, as well as the ecosystems in which they are deployed, may be said to be resilient if they can withstand unexpected adverse events or unexpected changes in their environment or use – or if they can maintain their functions and structure in the face of internal and external change and degrade safely and gracefully when this is necessary. Common security concerns relate to adversarial examples, data poisoning, and the exfiltration of models, training data, or other intellectual property through AI system endpoints. AI systems that can maintain confidentiality, integrity, and availability through protection mechanisms that prevent unauthorized access and use may be said to be secure. | ||
| MEASURE-2.8 | MEASURE | Risks associated with transparency and accountability - as identified in the map function - are examined and documented.DetailTransparency enables meaningful visibility into entire AI pipelines, workflows, processes or organizations and decreases information asymmetry between AI developers and operators and other AI Actors and impacted communities. Transparency is a central element of effective AI risk management that enables insight into how an AI system is working, and the ability to address risks if and when they emerge. The ability for system users, individuals, or impacted communities to seek redress for incorrect or problematic AI system outcomes is one control for transparency and accountability. Higher level recourse processes are typically enabled by lower level implementation efforts directed at explainability and interpretability functionality. See Measure 2.9. | ||
| MEASURE-2.9 | MEASURE | The AI model is explained, validated, and documented, and AI system output is interpreted within its context - as identified in the map function - to inform responsible use and governance.DetailExplainability and interpretability assist those operating or overseeing an AI system, as well as users of an AI system, to gain deeper insights into the functionality and trustworthiness of the system, including its outputs. | ||
| MEASURE-2.10 | MEASURE | Privacy risk of the AI system - as identified in the map function - is examined and documented.DetailPrivacy refers generally to the norms and practices that help to safeguard human autonomy, identity, and dignity. These norms and practices typically address freedom from intrusion, limiting observation, or individuals’ agency to consent to disclosure or control of facets of their identities (e.g., body, data, reputation). | ||
| MEASURE-2.11 | MEASURE | Fairness and bias - as identified in the map function - are evaluated and results are documented.DetailFairness in AI includes concerns for equality and equity by addressing issues such as harmful bias and discrimination. Standards of fairness can be complex and difficult to define because perceptions of fairness differ among cultures and may shift depending on application. Organizations’ risk management efforts will be enhanced by recognizing and considering these differences. Systems in which harmful biases are mitigated are not necessarily fair. For example, systems in which predictions are somewhat balanced across demographic groups may still be inaccessible to individuals with disabilities or affected by the digital divide or may exacerbate existing disparities or systemic biases. | ||
| MEASURE-2.12 | MEASURE | Environmental impact and sustainability of AI model training and management activities - as identified in the map function - are assessed and documented.DetailLarge-scale, high-performance computational resources used by AI systems for training and operation can contribute to environmental impacts. Direct negative impacts to the environment from these processes are related to energy consumption, water consumption, and greenhouse gas (GHG) emissions. The OECD has identified metrics for each type of negative direct impact. | ||
| MEASURE-2.13 | MEASURE | Effectiveness of the employed TEVV metrics and processes in the measure function are evaluated and documented.DetailThe development of metrics is a process often considered to be objective but, as a human and organization driven endeavor, can reflect implicit and systemic biases, and may inadvertently reflect factors unrelated to the target function. Measurement approaches can be oversimplified, gamed, lack critical nuance, become used and relied upon in unexpected ways, fail to account for differences in affected groups and contexts. | ||
| MEASURE-3.1 | MEASURE | Approaches, personnel, and documentation are in place to regularly identify and track existing, unanticipated, and emergent AI risks based on factors such as intended and actual performance in deployed contexts.DetailFor trustworthy AI systems, regular system monitoring is carried out in accordance with organizational governance policies, AI actor roles and responsibilities, and within a culture of continual improvement. If and when emergent or complex risks arise, it may be necessary to adapt internal risk management procedures, such as regular monitoring, to stay on course. Documentation, resources, and training are part of an overall strategy to support AI actors as they investigate and respond to AI system errors, incidents or negative impacts. | ||
| MEASURE-3.2 | MEASURE | Risk tracking approaches are considered for settings where AI risks are difficult to assess using currently available measurement techniques or where metrics are not yet available.DetailRisks identified in the Map function may be complex, emerge over time, or difficult to measure. Systematic methods for risk tracking, including novel measurement approaches, can be established as part of regular monitoring and improvement processes. | ||
| MEASURE-3.3 | MEASURE | Feedback processes for end users and impacted communities to report problems and appeal system outcomes are established and integrated into AI system evaluation metrics.DetailAssessing impact is a two-way effort. Many AI system outcomes and impacts may not be visible or recognizable to AI actors across the development and deployment dimensions of the AI lifecycle, and may require direct feedback about system outcomes from the perspective of end users and impacted groups. | ||
| MEASURE-4.1 | MEASURE | Measurement approaches for identifying AI risks are connected to deployment context(s) and informed through consultation with domain experts and other end users. Approaches are documented.DetailAI Actors carrying out TEVV tasks may have difficulty evaluating impacts within the system context of use. AI system risks and impacts are often best described by end users and others who may be affected by output and subsequent decisions. AI Actors can elicit feedback from impacted individuals and communities via participatory engagement processes established in Govern 5.1 and 5.2, and carried out in Map 1.6, 5.1, and 5.2. | ||
| MEASURE-4.2 | MEASURE | Measurement results regarding AI system trustworthiness in deployment context(s) and across the AI lifecycle are informed by input from domain experts and relevant AI actors to validate whether the system is performing consistently as intended. Results are documented.DetailFeedback captured from relevant AI Actors can be evaluated in combination with output from Measure 2.5 to 2.11 to determine if the AI system is performing within pre-defined operational limits for validity and reliability, safety, security and resilience, privacy, bias and fairness, explainability and interpretability, and transparency and accountability. This feedback provides an additional layer of insight about AI system performance, including potential misuse or reuse outside of intended settings. | ||
| MEASURE-4.3 | MEASURE | Measurable performance improvements or declines based on consultations with relevant AI actors, including affected communities, and field data about context-relevant risks and trustworthiness characteristics are identified and documented.DetailTEVV activities conducted throughout the AI system lifecycle can provide baseline quantitative measures for trustworthy characteristics. When combined with results from Measure 2.5 to 2.11 and Measure 4.1 and 4.2, TEVV actors can maintain a comprehensive view of system performance. These measures can be augmented through participatory engagement with potentially impacted communities or other forms of stakeholder elicitation about AI systems’ impacts. These sources of information can allow AI actors to explore potential adjustments to system components, adapt operating conditions, or institute performance improvements. | ||
| MANAGE-1.1 | MANAGE | A determination is made as to whether the AI system achieves its intended purposes and stated objectives and whether its development or deployment should proceed.DetailAI systems may not necessarily be the right solution for a given business task or problem. A standard risk management practice is to formally weigh an AI system’s negative risks against its benefits, and to determine if the AI system is an appropriate solution. Tradeoffs among trustworthiness characteristics —such as deciding to deploy a system based on system performance vs system transparency–may require regular assessment throughout the AI lifecycle. | ||
| MANAGE-1.2 | MANAGE | Treatment of documented AI risks is prioritized based on impact, likelihood, and available resources or methods.DetailRisk refers to the composite measure of an event’s probability of occurring and the magnitude (or degree) of the consequences of the corresponding events. The impacts, or consequences, of AI systems can be positive, negative, or both and can result in opportunities or risks. | ||
| MANAGE-1.3 | MANAGE | Responses to the AI risks deemed high priority, as identified by the map function, are developed, planned, and documented. Risk response options can include mitigating, transferring, avoiding, or accepting.DetailOutcomes from GOVERN-1, MAP-5 and MEASURE-2, can be used to address and document identified risks based on established risk tolerances. Organizations can follow existing regulations and guidelines for risk criteria, tolerances and responses established by organizational, domain, discipline, sector, or professional requirements. In lieu of such guidance, organizations can develop risk response plans based on strategies such as accepted model risk management, enterprise risk management, and information sharing and disclosure practices. | ||
| MANAGE-1.4 | MANAGE | Negative residual risks (defined as the sum of all unmitigated risks) to both downstream acquirers of AI systems and end users are documented.DetailOrganizations may choose to accept or transfer some of the documented risks from MAP and MANAGE 1.3 and 2.1. Such risks, known as residual risk, may affect downstream AI actors such as those engaged in system procurement or use. Transparent monitoring and managing residual risks enables cost benefit analysis and the examination of potential values of AI systems versus its potential negative impacts. | ||
| MANAGE-2.1 | MANAGE | Resources required to manage AI risks are taken into account - along with viable non-AI alternative systems, approaches, or methods - to reduce the magnitude or likelihood of potential impacts.DetailOrganizational risk response may entail identifying and analyzing alternative approaches, methods, processes or systems, and balancing tradeoffs between trustworthiness characteristics and how they relate to organizational principles and societal values. Analysis of these tradeoffs is informed by consulting with interdisciplinary organizational teams, independent domain experts, and engaging with individuals or community groups. These processes require sufficient resource allocation. | ||
| MANAGE-2.2 | MANAGE | Mechanisms are in place and applied to sustain the value of deployed AI systems.DetailSystem performance and trustworthiness may evolve and shift over time, once an AI system is deployed and put into operation. This phenomenon, generally known as drift, can degrade the value of the AI system to the organization and increase the likelihood of negative impacts. Regular monitoring of AI systems’ performance and trustworthiness enhances organizations’ ability to detect and respond to drift, and thus sustain an AI system’s value once deployed. Processes and mechanisms for regular monitoring address system functionality and behavior - as well as impacts and alignment with the values and norms within the specific context of use. For example, considerations regarding impacts on personal or public safety or privacy may include limiting high speeds when operating autonomous vehicles or restricting illicit content recommendations for minors. | ||
| MANAGE-2.3 | MANAGE | Procedures are followed to respond to and recover from a previously unknown risk when it is identified.DetailAI systems – like any technology – can demonstrate non-functionality or failure or unexpected and unusual behavior. They also can be subject to attacks, incidents, or other misuse or abuse – which their sources are not always known apriori. Organizations can establish, document, communicate and maintain treatment procedures to recognize and counter, mitigate and manage risks that were not previously identified. | ||
| MANAGE-2.4 | MANAGE | Mechanisms are in place and applied, and responsibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use.DetailPerformance inconsistent with intended use does not always increase risk or lead to negative impacts. Rigorous TEVV practices are useful for protecting against negative impacts regardless of intended use. When negative impacts do arise, superseding (bypassing), disengaging, or deactivating/decommissioning a model, AI system component(s), or the entire AI system may be necessary, such as when: | ||
| MANAGE-3.1 | MANAGE | AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented.DetailAI systems may depend on external resources and associated processes, including third- party data, software or hardware systems. Third parties’ supplying organizations with components and services, including tools, software, and expertise for AI system design, development, deployment or use can improve efficiency and scalability. It can also increase complexity and opacity, and, in-turn, risk. Documenting third-party technologies, personnel, and resources that were employed can help manage risks. Focusing first and foremost on risks involving physical safety, legal liabilities, regulatory compliance, and negative impacts on individuals, groups, or society is recommended. | ||
| MANAGE-3.2 | MANAGE | Pre-trained models which are used for development are monitored as part of AI system regular monitoring and maintenance.DetailA common approach in AI development is transfer learning, whereby an existing pre- trained model is adapted for use in a different, but related application. AI actors in development tasks often use pre-trained models from third-party entities for tasks such as image classification, language prediction, and entity recognition, because the resources to build such models may not be readily available to most organizations. Pre-trained models are typically trained to address various classification or prediction problems, using exceedingly large datasets and computationally intensive resources. The use of pre-trained models can make it difficult to anticipate negative system outcomes or impacts. Lack of documentation or transparency tools increases the difficulty and general complexity when deploying pre-trained models and hinders root cause analyses. | ||
| MANAGE-4.1 | MANAGE | Post-deployment AI system monitoring plans are implemented, including mechanisms for capturing and evaluating input from users and other relevant AI actors, appeal and override, decommissioning, incident response, recovery, and change management.DetailAI system performance and trustworthiness can change due to a variety of factors. Regular AI system monitoring can help deployers identify performance degradations, adversarial attacks, unexpected and unusual behavior, near-misses, and impacts. Including pre- and post-deployment external feedback about AI system performance can enhance organizational awareness about positive and negative impacts, and reduce the time to respond to risks and harms. | ||
| MANAGE-4.2 | MANAGE | Measurable activities for continual improvements are integrated into AI system updates and include regular engagement with interested parties, including relevant AI actors.DetailRegular monitoring processes enable system updates to enhance performance and functionality in accordance with regulatory and legal frameworks, and organizational and contextual values and norms. These processes also facilitate analyses of root causes, system degradation, drift, near-misses, and failures, and incident response and documentation. | ||
| MANAGE-4.3 | MANAGE | Incidents and errors are communicated to relevant AI actors, including affected communities. Processes for tracking, responding to, and recovering from incidents and errors are followed and documented.DetailRegularly documenting an accurate and transparent account of identified and reported errors can enhance AI risk management activities., Examples include: |
Checks to document
Evidence collected for a check counts for every regulation that uses it.
| Code | Check | Scope | Themes | Also used by |
|---|---|---|---|---|
| CHK-LEGAL-MAP | Applicable legal and regulatory requirements for AI are identified, mapped and monitored | Organisation | ||
| CHK-POL-TRUST | Trustworthy-AI characteristics are embedded in organizational policies and a safety-first culture | Organisation | ||
| CHK-POL-RISK | An AI risk-management policy and process are established through transparent, documented controls | Organisation | ||
| CHK-RISK-TOLERANCE | Risk tolerances are defined and AI systems are assigned to risk levels | Organisation | ||
| CHK-ROLES-CLARIFIED | Roles, responsibilities and delegated authorities are documented and clear to relevant stakeholders | Organisation | ||
| CHK-REVIEW-PLAN | Ongoing monitoring and periodic review of the risk-management process are planned, with defined roles and review frequency | Organisation | ||
| VER-022-F-01 | Risk and incident response procedure | Organisation | ||
| VER-022-D-01 | Serious incident reporting procedure | Organisation | ||
| CHK-INVENTORY | A mechanism to inventory AI systems is in place and resourced | Organisation | ||
| CHK-DECOMM | A documented process exists for safe decommissioning and phase-out of AI systems | Organisation | ||
| CHK-TRAINING | Personnel and partners receive AI risk-management training | Organisation | ||
| CHK-EXEC-ACCOUNT | Executive leadership is accountable for AI risk decisions (board committee, risk appetite) | Organisation | ||
| CHK-TEAM-DIVERSE | A diverse, interdisciplinary team is involved and its participation documented | Organisation | ||
| VER-008-03 | Competent overseers assigned to the system | System | ||
| VER-008-01 | Documented escalation and emergency stop procedure | Organisation | ||
| CHK-EFFECTIVE-CHALLENGE | Effective-challenge, red-team or three-lines-of-defense practices are in place | Organisation | ||
| CHK-IMPACT-ASSESS | An impact assessment is performed, documented and used in go/no-go and risk decisions | System | ||
| CHK-TESTING-ENABLE | Organizational practices enable AI testing and identification of limitations | Organisation | ||
| CHK-STAKEHOLDER-FEEDBACK | Mechanisms collect, adjudicate and integrate external stakeholder / user feedback | Organisation | ||
| CHK-THIRDPARTY-POL | Policies address third-party AI/data risks, incl. IP, transparency and testing | Organisation | ||
| CHK-THIRDPARTY-CONTINGENCY | Contingency/redundancy for high-risk third-party failures and ongoing third-party monitoring | Model | ||
| CHK-USECASE-SCOPING | Intended purpose, context, applicable laws, business value and application scope are documented | System | ||
| CHK-REQ-SPEC | System requirements are elicited with socio-technical implications addressed | System | ||
| CHK-CATEGORIZATION | AI system tasks and methods are categorized (classifier, generative, recommender) | System | ||
| CHK-DOC-TECH | Technical documentation incl. knowledge limits, human oversight and usage instructions is maintained | System | ||
| CHK-TEVV | TEVV plan, test sets, metrics and data considerations are documented | System | ||
| CHK-COMPETENCE | Operator/practitioner proficiency processes and relevant standards are defined | System | ||
| CHK-COMPONENTS | Legal risks and internal controls for AI components, incl. third-party, are identified | System | ||
| CHK-MEASURE-PLAN | Measurement approaches and metrics are selected and connected to context; unmeasured risks documented | System | ||
| CHK-METRIC-REVIEW | Metric appropriateness and control effectiveness are regularly assessed and updated | System | ||
| CHK-INDEP-ASSESS | Independent or internal-expert assessment involves domain experts and affected communities | System | ||
| CHK-HUMAN-SUBJECTS | Human-subject evaluations meet protection requirements and are representative | System | ||
| VER-009-02 | Accuracy and robustness verified and documented | System | ||
| VER-021-F-01 | Operational monitoring plan | System | ||
| CHK-SAFETY | Safety risks are evaluated and safe-failure demonstrated | System | ||
| CHK-SECURITY | Security and resilience are evaluated and documented | System | ||
| CHK-TRANSPARENCY | Transparency and accountability risks are examined and documented | System | ||
| CHK-MODEL-CARD | The model is explained, validated and documented (model card) | Model | ||
| VER-019-D-01 | Need for a DPIA assessed | System | ||
| CHK-BIAS | Fairness and bias are evaluated and results documented | System | ||
| CHK-ENV | Environmental impact and sustainability of model training are assessed | Model | ||
| VER-003-01 | Documented and up-to-date risk register | System | ||
| VER-AUTO-05 | Accuracy monitoring in operation | System | ||
| CHK-GO-NOGO | A go/no-go determination on system deployment is made and documented | System | ||
| CHK-RISK-RESPONSE | Risk treatment is prioritized and high-priority responses are planned and documented | System | ||
| CHK-ALT | Required resources and viable non-AI alternatives are considered | System | ||
| VER-008-02 | System designed to allow human oversight (stop button, override) | System | ||
| CHK-MODEL-MONITORING | Pre-trained models used in development are monitored and maintained | Model | ||
| CHK-CONTINUAL-IMPROVE | Continual-improvement activities are integrated with stakeholder engagement | System |
Themes covered
Frequently asked questions
Who is in scope of NIST AI RMF?
Any organisation designing, deploying or using AI. No territorial scope; de facto reference for US public buyers.
What penalties does NIST AI RMF carry?
None (voluntary). Leverage: safe harbour in state laws.
When do the NIST AI RMF obligations apply?
Jul 26, 2024: Generative AI Profile (NIST AI 600-1); Jul 23, 2025: AI Action Plan asks for a revision of the framework; Dec 2026: Expected RMF revision.
Is NIST AI RMF binding?
No. Kind: voluntary framework. Status: voluntary.
How does NIST AI RMF relate to other regulations?
The same checks serve several texts. Shared checks: ISO 42001 (16), AI Act (9) and US federal (8).
Related regulations
Official sources
Data checked on Sep 25, 2026. General information, not legal advice. Check the official texts and get advice for your situation.
Run these requirements across all your AI systems
TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.