What matters in AI.

Subscribe

Learn / AI governance

Definition · AI governance

AI risk management

AI risk management is the practice of identifying, assessing and treating the risks that AI systems create, formalised for the US by NIST's AI Risk Management Framework (AI RMF 1.0, published 26 January 2023). The framework is voluntary, rights-preserving and non-sector-specific, and organises the work around four functions: GOVERN, MAP, MEASURE and MANAGE.

Last reviewed

Key points

  • NIST's AI RMF 1.0 (published 26 January 2023) is voluntary, rights-preserving, non-sector-specific and use-case agnostic.
  • It organises AI risk management into four functions — GOVERN, MAP, MEASURE and MANAGE — where GOVERN is cross-cutting and enables the other three.
  • It names seven characteristics of trustworthy AI, from valid and reliable to fair with harmful bias managed, and says trade-offs among them are "usually involved".
  • As of 2026 the framework is being revised under the White House AI Action Plan, and a critical-infrastructure profile is in development.

NIST’s AI Risk Management Framework (AI RMF 1.0, NIST AI 100-1) is the governance document the AI security topics in this corpus plug into. It does not secure a system itself: it names the risks, the functions that manage them, and the characteristics a trustworthy system should have.

Why it matters

AI security protects the model; the AI RMF governs the whole lifecycle — design, development, deployment and use. Its seven trustworthiness characteristics are where the trade-off framing that AI security trade-offs builds on comes from, and NIST’s Generative AI Profile (AI 600-1), which AI red teaming draws on, is a profile built on the RMF.

How it works

The AI RMF 1.0, published 26 January 2023, organises risk management around four functions, each broken into categories and subcategories in the Part 2 Core:

  • GOVERN is cross-cutting. NIST says it is “infused throughout AI risk management and enables the other functions of the process”, and it covers policies, accountability, inventory and third-party supply chain.
  • MAP establishes the context: what the system is for, who it affects, and what could go wrong.
  • MEASURE analyses, assesses, benchmarks and monitors AI risk and related impacts, including the trustworthiness characteristics over time.
  • MANAGE allocates resources to mapped and measured risks: prioritising, treating, responding and monitoring.

Seven characteristics define trustworthy: valid and reliable; safe; secure and resilient; accountable and transparent; explainable and interpretable; privacy-enhanced; and fair with harmful bias managed. NIST says creating trustworthy AI “requires balancing each of these characteristics based on the AI system’s context of use”, and that trade-offs among them are “usually involved”.

Where it stands now

AI RMF 1.0 is a living document. As of this review (September 2026) it is being revised under the White House AI Action Plan; on 7 April 2026 NIST released a concept note for an AI RMF Profile on Trustworthy AI in Critical Infrastructure; and the AI RMF Playbook, which turns each Core sub-category into suggested actions, is being updated after the revision. The framework itself is intended for voluntary use.

Where definitions disagree

“AI risk management” carries different legal force in different places. NIST’s AI RMF is explicitly voluntary — the framework says it is “intended to be voluntary, rights-preserving, non-sector-specific, and use-case agnostic”. The EU AI Act turns the same concern into law: Article 9 requires high-risk systems to maintain a risk-management system, and EU AI Act Article 15 makes accuracy, robustness and cybersecurity binding. One says “should”, the other “shall”.

The RMF is a framework, not a certifiable standard: NIST does not certify organisations or systems against it. Its “risk” is also narrow by design — the composite of an event’s probability and the magnitude of its consequences — which is not every harm the word “risk” is used for in the field.

Questions and answers

What is the NIST AI Risk Management Framework?

The NIST AI Risk Management Framework (AI RMF 1.0, NIST AI 100-1), published on 26 January 2023, is a voluntary, rights-preserving, non-sector-specific framework for managing the risks of AI systems across their lifecycle. It organises risk management around four functions — GOVERN, MAP, MEASURE and MANAGE — and names seven characteristics of trustworthy AI, from valid and reliable to fair with harmful bias managed.

What are the four functions of the AI RMF?

GOVERN, MAP, MEASURE and MANAGE. GOVERN is the cross-cutting function: NIST says it is "infused throughout AI risk management and enables the other functions of the process", covering policies, accountability, inventory and supply chain. MAP establishes the context of a system's risks, MEASURE analyses, assesses and monitors them, and MANAGE allocates resources to treat and respond to them.

What are the seven characteristics of trustworthy AI in the AI RMF?

NIST's AI RMF lists seven: valid and reliable; safe; secure and resilient; accountable and transparent; explainable and interpretable; privacy-enhanced; and fair with harmful bias managed. NIST says creating trustworthy AI "requires balancing each of these characteristics based on the AI system's context of use", and that trade-offs among them are "usually involved".

Is the NIST AI RMF mandatory?

No. NIST states the framework is "intended to be voluntary, rights-preserving, non-sector-specific, and use-case agnostic". It is guidance, not law, and NIST does not certify organisations or systems against it. The contrast is the EU: the EU AI Act makes risk management and cybersecurity obligations binding for high-risk systems, so the same concern is voluntary in the US and mandatory in the EU.

What is the status of the NIST AI RMF?

AI RMF 1.0 is a living document and is being revised as part of the White House AI Action Plan. On 7 April 2026 NIST released a concept note for an AI RMF Profile on Trustworthy AI in Critical Infrastructure. The companion AI RMF Playbook, which turns each Core sub-category into suggested actions, will be updated after the revision.

Sources

  1. Artificial Intelligence Risk Management Framework (NIST AI 100-1, AI RMF 1.0)NIST, 26 Jan 2023
  2. NIST, AI Risk Management Framework (nist.gov/itl/ai-risk-management-framework)NIST, 13 Aug 2026
  3. NIST AI RMF Playbook (airc.nist.gov/airmf-resources/playbook)NIST

Guides that use this term