Governance framework · 1.0 · 2023-01-26; revision underway

NIST AI Risk Management Framework

Maintained by NIST

What it helps you do

NIST AI RMF supports govern, Map, Measure, and Manage functions for addressing AI risks across organizations and system lifecycles.

  • AI / ML
  • Cross-cutting
PlanAcquireHarmonizeExchangeLearn + reuse

01

Where it fits and where it does not

Use these four checks before committing implementation time.

Use it when
Governance overlay for intended use, accountability, risk measurement, release decisions, and ongoing monitoring.
Limits
Voluntary and use-case agnostic; it does not prescribe life-science schemas, legal compliance, or quantitative acceptance thresholds.
Best for
AI / ML and Cross-cutting teams working across Plan → Harmonize → Learn + reuse.
Maturity
EstablishedSuitable for production assessment. Pin the exact release and any implementation profile.

02

See it in the workflow

This view shows the input, the change the standard introduces, and the resulting output.

  1. InputWhat starts

    AI / ML and Cross-cutting source data, metadata, and local mappings

  2. NIST AI RMFWhat changes

    Use NIST AI RMF as a pinned governance framework across Plan → Harmonize → Learn + reuse

  3. OutputWhat becomes possible

    A handoff the next system or team can validate against the same release

Readiness gateVoluntary and use-case agnostic; it does not prescribe life-science schemas, legal compliance, or quantitative acceptance thresholds.

03

A concrete example

A data owner maps intended use and affected populations, defines quality and harm metrics, records approvals, and manages release and monitoring actions.

Why it matters: Provides the governance structure for deciding readiness, not a machine-readable certificate that a dataset is ready.

04

What it fits with

Sits above technical data standards; DQV, Croissant, provenance, policy vocabularies, and domain tests can supply evidence to its processes.

05

Implementation starter

Start with one bounded handoff. Pin, test, and review it before scaling.

  1. Define one handoff, its accountable owner, and the decision NIST AI RMF must support.

  2. Pin the exact version and companion artifacts: 1.0 · 2023-01-26; revision underway.

  3. Map one representative input to the required governance framework artifacts.

  4. Test the result against the canonical source and record every exception.

  5. Preserve the source data, mappings, and review evidence before scaling.

06

Test the main limitation

Risk

Voluntary and use-case agnostic; it does not prescribe life-science schemas, legal compliance, or quantitative acceptance thresholds.

Test

Run one representative end-to-end pilot and record exactly where NIST AI RMF loses context, needs an extension, or depends on another standard.

Risk

Machine-readable output may still be unfit for analysis or ML.

Test

Test the output for missing context, provenance, terminology alignment, time leakage, and the intended downstream decision. Provides the governance structure for deciding readiness, not a machine-readable certificate that a dataset is ready.

07

Official resources

Specifications, diagrams, examples, and guides from the organizations that maintain them.

  • Primary source1.0 · 2023-01-26; revision underway

    NIST AI RMF 1.0

    Official publisher or steward guidance for this governance framework profile.

    Publisher
    NIST
    Open official source

Next action

Put this profile in context

Compare its role with adjacent standards or place it inside an end-to-end data pathway before choosing an implementation.