← Legislation library

United States

NIST AI RMF

The NIST AI Risk Management Framework is a voluntary US framework for managing risks from AI systems. It is organised around four functions, Govern, Map, Measure, and Manage, to help organisations build trustworthy and responsible AI.

13 subcategorys

Subcategory 1

Legal and regulatory requirements

Legal and regulatory requirements related to AI risk management are understood, managed, and adhered to.

Subcategory 1

Intended purpose and context

Intended purposes, context of use, and potential impacts of AI systems are identified and documented.

Subcategory 1

Risk measurement approaches

AI risks are measured using approaches that are appropriate to the context and aligned with organisational risk tolerance.

Subcategory 1

Risk response planning

Plans and processes are established to respond to and recover from identified AI risks.

Subcategory 1

AI system documentation

AI systems and their risks are documented for transparency and accountability.

Subcategory 2

AI risk management integration

AI risk management processes are integrated with broader enterprise risk management.

Subcategory 2

AI system impact on individuals and groups

Potential impacts of the AI system on individuals and groups are identified, with emphasis on historically marginalised communities.

Subcategory 2

AI system performance and reliability

AI system performance and reliability are measured in context, including for known failure modes.

Subcategory 2

AI risk management practices implementation

AI risk management practices are implemented and managed, with monitoring of effectiveness and ongoing risk management.

Subcategory 2

AI risk management transparency

Information about AI risk management practices is shared with appropriate stakeholders.

Subcategory 3

Roles, responsibilities, and accountability

Roles, responsibilities, accountability, and procedures for managing AI risk are defined and communicated.

Subcategory 3

AI risk prioritisation

Identified AI risks are prioritised based on severity, likelihood, and organisational risk tolerance.

Subcategory 3

Post-deployment monitoring and response

AI systems are monitored post-deployment for risks, with processes to respond to emerging risks.

Turn NIST AI RMF into tracked tasks

eurocompliant maps these obligations to checklists and evidence, so you can prove compliance instead of re-reading the text.

Start free trial