Skip to main content

Overview

The NIST AI Risk Management Framework (AI RMF 1.0), published by the National Institute of Standards and Technology in January 2023, provides a voluntary framework for managing risks throughout the AI lifecycle. It is designed to help organizations design, develop, deploy, and use AI systems in ways that are trustworthy and responsible. NIST AI RMF is becoming the de facto standard for AI governance in the United States, referenced by federal procurement policies and increasingly adopted by private sector organizations.

Core functions

The framework is organized around four core functions:

Govern

Establish and maintain policies, processes, and organizational structures for AI risk management.

Map

Identify and contextualize risks associated with AI systems.

Measure

Analyze and assess identified AI risks using quantitative and qualitative methods.

Manage

Prioritize, respond to, and monitor AI risks on an ongoing basis.

Trustworthy AI characteristics

NIST AI RMF defines seven characteristics of trustworthy AI:
  1. Valid & reliable — The AI system performs as intended with consistent results
  2. Safe — The system does not endanger life, health, property, or the environment
  3. Secure & resilient — Protected against adversarial attacks and graceful under failure
  4. Accountable & transparent — Decisions are explainable and responsibility is clear
  5. Explainable & interpretable — Outputs can be understood by stakeholders
  6. Privacy-enhanced — Personal data is protected throughout the AI lifecycle
  7. Fair with harmful bias managed — Bias is identified, measured, and mitigated

How Know Your AI maps to NIST AI RMF

Resources

Compliance

How Know Your AI automates regulatory compliance.

Evaluation

Run NIST-aligned evaluations on your AI systems.