NIST AI Risk Management Framework 1.0
A voluntary framework for managing risk across the AI lifecycle. There is no certification against it; organisations adopt it as a common vocabulary for identifying, measuring and treating AI risk.
- Duties mapped
- 97
- Mappings
- 97
- Jurisdictions
- 12
- Functions used
- 5
- Controls
- 26
- Evidence types
- 23
- Risk areas
- 21
- Recorded incidents
- 1,494
Duties are what the law asks; controls are what an organisation operates to meet them; evidence is how it shows it did. Incidents are the harms the AI Incident Database has recorded under the risk areas those controls address.
How it is structured
Four functions - GOVERN, MAP, MEASURE and MANAGE - each broken into categories and subcategories. GOVERN runs throughout; the other three describe a cycle.
It is the reference point for US federal AI policy and for a growing number of procurement questionnaires, so a duty that maps cleanly to a function is one you can evidence in terms a US counterparty already uses.
Legal duties by function
A duty appears under every function its mapping cites, so the totals below exceed the 97 distinct duties. References that name no single function are grouped at the end rather than dropped.
GOVERN 61 duties
-
AI business operators must notify users in advance that a product or service runs on high-impact or generative AI
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · South Korea · cites GOVERN 5.1, MANAGE 4.1
Transparency to end users.
-
Adopt the guiding principles and risk-based governance (voluntary)
India AI Governance Guidelines · India (voluntary) · cites GOVERN and MAP functions
Original editorial mapping.
-
Apply safeguards to solely automated decisions with significant effects
ICO AI guidance · United Kingdom · cites GOVERN 5.x, MANAGE 4.x
Recourse mechanisms.
-
Deployers and developers must disclose to consumers that they are interacting with an AI system
Colorado AI Act · Colorado (United States) · cites GOVERN 5.1, MANAGE 4.1
Transparency to end users.
-
Deployers must disclose deepfakes and AI-generated text published on matters of public interest
EU AI Act · European Union · cites GOVERN 5.1, MANAGE 4.1
Transparency to end users; NIST AI 600-1 content provenance.
-
Deployers must explain individual decisions taken with high-risk AI on request
EU AI Act · European Union · cites GOVERN 5.1, MANAGE 4.1
Recourse and communication for affected individuals.
-
Deployers must publish a statement about the high-risk AI systems they use
Colorado AI Act · Colorado (United States) · cites GOVERN 4.2, MAP 5.2
Transparency about deployed systems and their impacts.
-
Deployers must tell natural persons that a high-risk AI system is used in decisions about them
EU AI Act · European Union · cites GOVERN 5.1, MANAGE 4.1
Communication with affected individuals.
-
Deployers must use reasonable care to avoid algorithmic discrimination
Colorado AI Act · Colorado (United States) · cites GOVERN 1.1, MANAGE 1.3
Legal requirements and risk treatment for deployed systems.
-
Deployers of emotion recognition or biometric categorisation must inform exposed persons
EU AI Act · European Union · cites GOVERN 5.1, MEASURE 2.10
Communication and privacy risk.
-
Deployers, distributors and importers must assume provider duties when they rebrand or substantially modify high-risk AI
EU AI Act · European Union · cites GOVERN 6.1, MAP 1.1
Roles across the AI supply chain and context of use.
-
Determine the appropriate level of human involvement in AI decisions
Singapore Model AI Governance Framework · Singapore (voluntary) · cites GOVERN 3.2, MANAGE 2.x
Original editorial mapping.
-
Developers and deployers must not use AI to incite self-harm, harm to others or crime
Texas Responsible AI Governance Act (TRAIGA) · Texas (United States) · cites GOVERN 1.1, MAP 1.1, MEASURE 2.6
Legal requirements, intended purpose and safety evaluation.
-
Developers and distributors must not build AI intended to produce child sexual abuse material or unlawful sexual deepfakes
Texas Responsible AI Governance Act (TRAIGA) · Texas (United States) · cites GOVERN 1.1, MEASURE 2.6, MANAGE 2.3
Legal requirements, safety evaluation and abuse mitigation; NIST AI 600-1 addresses obscene and abusive content.
-
Developers must document high-risk systems and disclose known risks
Colorado AI Act · Colorado (United States) · cites GOVERN 1.4, MAP 3.x
Documentation and transparency.
-
Developers must notify the Attorney General and deployers of discovered algorithmic discrimination
Colorado AI Act · Colorado (United States) · cites MANAGE 4.3, GOVERN 6.2
Incident communication to authorities and downstream parties.
-
Disclose AI interaction and label synthetic content
EU AI Act · European Union · cites GOVERN 4.x; NIST AI 600-1 content provenance suggestions
Generative AI profile guidance on provenance.
-
Do not deploy or provide AI for prohibited practices
EU AI Act · European Union · cites GOVERN 1.1, MAP 1.1
Original editorial mapping to legal-requirement identification and context mapping.
-
Draw up technical documentation before placing a high-risk system on the market
EU AI Act · European Union · cites GOVERN 1.4, MAP 3.x
Documentation practices.
-
Employers and employment agencies must let candidates request an alternative selection process or accommodation
NYC Local Law 144 (automated employment decision tools) · New York (United States) · cites GOVERN 5.1, MANAGE 4.1
Recourse route for affected individuals.
-
Employers and employment agencies must notify candidates and employees before an automated tool is used
NYC Local Law 144 (automated employment decision tools) · New York (United States) · cites GOVERN 5.1, MANAGE 4.1
Transparency to affected individuals.
-
Employers and employment agencies must publish a summary of the bias audit results
NYC Local Law 144 (automated employment decision tools) · New York (United States) · cites GOVERN 4.2, MEASURE 2.11
Public transparency of fairness results.
-
Employers must inform workers and their representatives before using high-risk AI at work
EU AI Act · European Union · cites GOVERN 5.1, MAP 1.6
Engagement with affected groups.
-
Enable and assign effective human oversight
EU AI Act · European Union · cites GOVERN 3.2, MANAGE 2.x
Roles and human-AI configuration.
-
Ensure AI literacy of staff operating AI systems
EU AI Act · European Union · cites GOVERN 2.2
Workforce training and awareness.
-
Establish accountability and governance for AI
UK AI regulation framework · United Kingdom (voluntary) · cites GOVERN 2.1
Roles and responsibilities.
-
Establish accountability processes and a risk-management process (guardrails 1 and 2)
Australian Voluntary AI Safety Standard · Australia (voluntary) · cites GOVERN and MAP
Original editorial mapping.
-
Establish internal governance structures and measures for AI
Singapore Model AI Governance Framework · Singapore (voluntary) · cites GOVERN 2.x
Original editorial mapping.
-
Foreign AI business operators above the threshold must designate a domestic representative in Korea
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · South Korea · cites GOVERN 2.1
Roles and responsibilities.
-
Frontier developers must protect employees who report catastrophic-risk concerns
California SB 53 · California (United States) · cites GOVERN 4.1, GOVERN 4.3
Culture that surfaces risks and incident-sharing practices.
-
Frontier developers must publish a transparency report before deploying a new frontier model
California SB 53 · California (United States) · cites GOVERN 4.2, MAP 5.1, MEASURE 2.6
Public documentation of intended use and safety evaluation.
-
Government agencies must disclose to consumers that they are interacting with an AI system
Texas Responsible AI Governance Act (TRAIGA) · Texas (United States) · cites GOVERN 5.1, MANAGE 4.1
Transparency to end users.
-
Governmental entities must not use AI for biometric identification from public data without consent where it infringes rights
Texas Responsible AI Governance Act (TRAIGA) · Texas (United States) · cites GOVERN 1.1, MEASURE 2.10
Legal requirements and privacy risk.
-
Governmental entities must not use AI for social scoring
Texas Responsible AI Governance Act (TRAIGA) · Texas (United States) · cites GOVERN 1.1, MAP 1.1
Legal requirements and context mapping.
-
Health-care providers must disclose the use of AI in patient services
Texas Responsible AI Governance Act (TRAIGA) · Texas (United States) · cites GOVERN 5.1, MANAGE 4.1
Transparency to affected individuals.
-
Large frontier developers must publish a frontier AI framework
California SB 53 · California (United States) · cites GOVERN 1.x; NIST AI 600-1
Original editorial mapping.
-
Large frontier developers must send periodic summaries of catastrophic-risk assessments to the state
California SB 53 · California (United States) · cites MEASURE 2.6, MANAGE 1.2, GOVERN 4.3
Safety evaluation, prioritisation and information sharing with authorities.
-
Law-enforcement deployers must obtain authorisation for post-remote biometric identification and report annually
EU AI Act · European Union · cites GOVERN 1.1, MANAGE 1.3
Legal requirements and documented use decisions.
-
Non-EU providers must appoint an EU authorised representative for high-risk AI
EU AI Act · European Union · cites GOVERN 2.1, GOVERN 6.1
Roles and third-party arrangements.
-
Non-EU providers of GPAI models must appoint an EU authorised representative
EU AI Act · European Union · cites GOVERN 2.1, GOVERN 6.1
Roles and third-party arrangements.
-
Notify consumers and explain adverse consequential decisions
Colorado AI Act · Colorado (United States) · cites GOVERN 5.x, MANAGE 4.x
Recourse and communication.
-
Notify individuals about the use of personal data in AI recommendations and decisions
PDPC AI advisory guidelines · Singapore · cites GOVERN 4.x
Original editorial mapping.
-
Operate a quality management system
EU AI Act · European Union · cites GOVERN function
Governance structures and policies.
-
Operators of high-impact AI must be able to explain outputs and the main criteria behind them
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · South Korea · cites MEASURE 2.9, GOVERN 5.1
Explainability and communication to affected parties.
-
Operators of high-impact AI must ensure human management and supervision
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · South Korea · cites GOVERN 3.2, MANAGE 2.4
Human-AI configuration and override mechanisms.
-
Operators of high-impact AI must prepare user-protection measures and keep records of their safety and trust measures
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · South Korea · cites GOVERN 1.4, MANAGE 4.1
Documentation and post-deployment user protection.
-
Provide appropriate transparency and explainability
UK AI regulation framework · United Kingdom (voluntary) · cites GOVERN 4.x, MAP 1.x
Original editorial mapping.
-
Provide contestability, supply-chain transparency and records (guardrails 7 to 9)
Australian Voluntary AI Safety Standard · Australia (voluntary) · cites GOVERN 6.x
Third-party risk.
-
Provide deployers with clear instructions for use
EU AI Act · European Union · cites GOVERN 4.x, MAP 1.x
Transparency to downstream users.
-
Provide routes to contest AI outcomes and seek redress
UK AI regulation framework · United Kingdom (voluntary) · cites GOVERN 5.1, MANAGE 4.x
Feedback and recourse mechanisms.
-
Providers must keep high-risk AI documentation for ten years
EU AI Act · European Union · cites GOVERN 1.4
Documentation of governance and risk decisions retained.
-
Providers must meet the full set of provider duties for high-risk AI
EU AI Act · European Union · cites GOVERN 1.1, GOVERN 2.1
Legal requirements identified and roles assigned.
-
Providers must supply conformity evidence and log access to authorities on request
EU AI Act · European Union · cites GOVERN 1.4, GOVERN 4.2
Transparency and accountability records.
-
Providers of GPAI models must maintain technical documentation and inform downstream providers
EU AI Act · European Union · cites GOVERN 1.4, MAP 2.2, MEASURE 2.1
Documentation of design, testing and evaluation.
-
Providers of GPAI models must notify the Commission within two weeks of meeting the systemic-risk threshold
EU AI Act · European Union · cites GOVERN 1.1, MAP 1.1
Legal requirement tracking and system context.
-
Providers of high-risk AI must have written agreements with suppliers of components, tools and services
EU AI Act · European Union · cites GOVERN 6.1
Policies for third-party AI risks.
-
Public authorities must register their use of high-risk AI and must not use unregistered systems
EU AI Act · European Union · cites GOVERN 1.6, MAP 1.1
Inventory of deployed systems and context.
-
Publish an annual AI use-case inventory
OMB M-25-21 · United States · cites GOVERN 1.6
Inventory of AI systems.
-
Respect the right to object to automated decision-making without human intervention
UAE PDPL · United Arab Emirates · cites GOVERN 5.x, MANAGE 4.x
Original editorial mapping.
-
Use high-risk AI as instructed, monitor it and inform affected people
EU AI Act · European Union · cites MANAGE 3.x, GOVERN 5.x
Deployment management and stakeholder engagement.
-
Verify conformity before importing or distributing high-risk AI
EU AI Act · European Union · cites GOVERN 6.1, GOVERN 6.2
Third-party risk management.
MAP 30 duties
-
Adopt the guiding principles and risk-based governance (voluntary)
India AI Governance Guidelines · India (voluntary) · cites GOVERN and MAP functions
Original editorial mapping.
-
Apply data governance and quality criteria to training, validation and testing data
EU AI Act · European Union · cites MAP 2.3, MEASURE 2.1, MEASURE 2.11
Data quality and bias measurement.
-
Apply minimum risk-management practices to high-impact AI
OMB M-25-21 · United States · cites MAP, MEASURE, MANAGE
The memo is aligned with the AI RMF vocabulary.
-
Carry out a data protection impact assessment for high-risk AI processing
ICO AI guidance · United Kingdom · cites MAP 5.1
Impact assessment.
-
Carry out a fundamental rights impact assessment before deployment
EU AI Act · European Union · cites MAP 5.1, MAP 5.2
Impacts on individuals, groups and society.
-
Deployers must complete impact assessments for high-risk AI
Colorado AI Act · Colorado (United States) · cites MAP 5.x
Original editorial mapping.
-
Deployers must ensure input data they control is relevant and representative
EU AI Act · European Union · cites MAP 2.3, MEASURE 2.2
Data representativeness in context.
-
Deployers must publish a statement about the high-risk AI systems they use
Colorado AI Act · Colorado (United States) · cites GOVERN 4.2, MAP 5.2
Transparency about deployed systems and their impacts.
-
Deployers must use the provider's transparency information in their data protection impact assessment
EU AI Act · European Union · cites MAP 3.1, MEASURE 2.10
Privacy risk assessed with system information.
-
Deployers, distributors and importers must assume provider duties when they rebrand or substantially modify high-risk AI
EU AI Act · European Union · cites GOVERN 6.1, MAP 1.1
Roles across the AI supply chain and context of use.
-
Developers and deployers must not use AI to incite self-harm, harm to others or crime
Texas Responsible AI Governance Act (TRAIGA) · Texas (United States) · cites GOVERN 1.1, MAP 1.1, MEASURE 2.6
Legal requirements, intended purpose and safety evaluation.
-
Developers must document high-risk systems and disclose known risks
Colorado AI Act · Colorado (United States) · cites GOVERN 1.4, MAP 3.x
Documentation and transparency.
-
Developers must use reasonable care to avoid algorithmic discrimination
Colorado AI Act · Colorado (United States) · cites MAP 1.1, MEASURE 2.11, MANAGE 1.3
Fairness and bias evaluated and managed.
-
Do not deploy or provide AI for prohibited practices
EU AI Act · European Union · cites GOVERN 1.1, MAP 1.1
Original editorial mapping to legal-requirement identification and context mapping.
-
Draw up technical documentation before placing a high-risk system on the market
EU AI Act · European Union · cites GOVERN 1.4, MAP 3.x
Documentation practices.
-
Employers and employment agencies must disclose the data collected and their retention policy for the tool
NYC Local Law 144 (automated employment decision tools) · New York (United States) · cites MAP 2.2, MEASURE 2.10
Data documentation and privacy transparency.
-
Employers must inform workers and their representatives before using high-risk AI at work
EU AI Act · European Union · cites GOVERN 5.1, MAP 1.6
Engagement with affected groups.
-
Establish a risk management system for high-risk AI
EU AI Act · European Union · cites MAP, MEASURE and MANAGE functions
The AI RMF's core functions map closely to Article 9's iterative process.
-
Establish accountability processes and a risk-management process (guardrails 1 and 2)
Australian Voluntary AI Safety Standard · Australia (voluntary) · cites GOVERN and MAP
Original editorial mapping.
-
Frontier developers must publish a transparency report before deploying a new frontier model
California SB 53 · California (United States) · cites GOVERN 4.2, MAP 5.1, MEASURE 2.6
Public documentation of intended use and safety evaluation.
-
Governmental entities must not use AI for social scoring
Texas Responsible AI Governance Act (TRAIGA) · Texas (United States) · cites GOVERN 1.1, MAP 1.1
Legal requirements and context mapping.
-
Operators of AI above the compute threshold must run lifecycle risk management and report safety results
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · South Korea · cites MAP 5.1, MEASURE 2.6, MANAGE 1.3, MANAGE 4.3
Safety evaluation, risk treatment and incident response.
-
Operators of high-impact AI must establish and operate a risk management plan
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · South Korea · cites MAP 1.5, MANAGE 1.3
Risk tolerance and treatment.
-
Operators of high-impact AI should assess its impact on fundamental rights before use
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · South Korea (voluntary) · cites MAP 5.1, MAP 5.2
Impact characterisation and engagement.
-
Provide appropriate transparency and explainability
UK AI regulation framework · United Kingdom (voluntary) · cites GOVERN 4.x, MAP 1.x
Original editorial mapping.
-
Provide deployers with clear instructions for use
EU AI Act · European Union · cites GOVERN 4.x, MAP 1.x
Transparency to downstream users.
-
Providers must document and register a conclusion that an Annex III system is not high-risk
EU AI Act · European Union · cites MAP 1.5, MAP 3.1
Scoping and classification of the system's impact.
-
Providers of GPAI models must maintain technical documentation and inform downstream providers
EU AI Act · European Union · cites GOVERN 1.4, MAP 2.2, MEASURE 2.1
Documentation of design, testing and evaluation.
-
Providers of GPAI models must notify the Commission within two weeks of meeting the systemic-risk threshold
EU AI Act · European Union · cites GOVERN 1.1, MAP 1.1
Legal requirement tracking and system context.
-
Public authorities must register their use of high-risk AI and must not use unregistered systems
EU AI Act · European Union · cites GOVERN 1.6, MAP 1.1
Inventory of deployed systems and context.
MEASURE 31 duties
-
AI business operators must label generative AI output and clearly flag realistic synthetic media
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · South Korea · cites MEASURE 2.7, MANAGE 4.1
Content provenance as described in NIST AI 600-1.
-
Achieve appropriate accuracy, robustness and cybersecurity
EU AI Act · European Union · cites MEASURE 2.5, 2.6, 2.7
Validity, safety, security and resilience measurement.
-
Apply data governance and quality criteria to training, validation and testing data
EU AI Act · European Union · cites MAP 2.3, MEASURE 2.1, MEASURE 2.11
Data quality and bias measurement.
-
Apply minimum risk-management practices to high-impact AI
OMB M-25-21 · United States · cites MAP, MEASURE, MANAGE
The memo is aligned with the AI RMF vocabulary.
-
Deployers must ensure input data they control is relevant and representative
EU AI Act · European Union · cites MAP 2.3, MEASURE 2.2
Data representativeness in context.
-
Deployers must use the provider's transparency information in their data protection impact assessment
EU AI Act · European Union · cites MAP 3.1, MEASURE 2.10
Privacy risk assessed with system information.
-
Deployers of emotion recognition or biometric categorisation must inform exposed persons
EU AI Act · European Union · cites GOVERN 5.1, MEASURE 2.10
Communication and privacy risk.
-
Design high-risk systems to log events automatically
EU AI Act · European Union · cites MEASURE 2.x, MANAGE 4.1
Monitoring and traceability.
-
Developers and deployers must not use AI to incite self-harm, harm to others or crime
Texas Responsible AI Governance Act (TRAIGA) · Texas (United States) · cites GOVERN 1.1, MAP 1.1, MEASURE 2.6
Legal requirements, intended purpose and safety evaluation.
-
Developers and deployers must not use AI with the intent to unlawfully discriminate against a protected class
Texas Responsible AI Governance Act (TRAIGA) · Texas (United States) · cites MEASURE 2.11, MANAGE 1.3
Fairness and bias evaluated and managed.
-
Developers and distributors must not build AI intended to produce child sexual abuse material or unlawful sexual deepfakes
Texas Responsible AI Governance Act (TRAIGA) · Texas (United States) · cites GOVERN 1.1, MEASURE 2.6, MANAGE 2.3
Legal requirements, safety evaluation and abuse mitigation; NIST AI 600-1 addresses obscene and abusive content.
-
Developers must use reasonable care to avoid algorithmic discrimination
Colorado AI Act · Colorado (United States) · cites MAP 1.1, MEASURE 2.11, MANAGE 1.3
Fairness and bias evaluated and managed.
-
Employers and employment agencies must disclose the data collected and their retention policy for the tool
NYC Local Law 144 (automated employment decision tools) · New York (United States) · cites MAP 2.2, MEASURE 2.10
Data documentation and privacy transparency.
-
Employers and employment agencies must obtain an independent bias audit before using an automated employment decision tool
NYC Local Law 144 (automated employment decision tools) · New York (United States) · cites MEASURE 2.11, MEASURE 1.3
Fairness evaluation by independent assessors.
-
Employers and employment agencies must publish a summary of the bias audit results
NYC Local Law 144 (automated employment decision tools) · New York (United States) · cites GOVERN 4.2, MEASURE 2.11
Public transparency of fairness results.
-
Ensure AI systems are safe, secure and robust throughout their lifecycle
UK AI regulation framework · United Kingdom (voluntary) · cites MEASURE 2.5–2.7
Original editorial mapping.
-
Establish a risk management system for high-risk AI
EU AI Act · European Union · cites MAP, MEASURE and MANAGE functions
The AI RMF's core functions map closely to Article 9's iterative process.
-
Frontier developers must publish a transparency report before deploying a new frontier model
California SB 53 · California (United States) · cites GOVERN 4.2, MAP 5.1, MEASURE 2.6
Public documentation of intended use and safety evaluation.
-
Governmental entities must not use AI for biometric identification from public data without consent where it infringes rights
Texas Responsible AI Governance Act (TRAIGA) · Texas (United States) · cites GOVERN 1.1, MEASURE 2.10
Legal requirements and privacy risk.
-
Large frontier developers must send periodic summaries of catastrophic-risk assessments to the state
California SB 53 · California (United States) · cites MEASURE 2.6, MANAGE 1.2, GOVERN 4.3
Safety evaluation, prioritisation and information sharing with authorities.
-
Manage systemic risk for high-impact general-purpose models
EU AI Act · European Union · cites MEASURE 2.x; NIST AI 600-1
Evaluation and red-teaming practices.
-
Operate a post-market monitoring system
EU AI Act · European Union · cites MANAGE 4.1, MEASURE 3.x
Post-deployment monitoring.
-
Operators of AI above the compute threshold must run lifecycle risk management and report safety results
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · South Korea · cites MAP 5.1, MEASURE 2.6, MANAGE 1.3, MANAGE 4.3
Safety evaluation, risk treatment and incident response.
-
Operators of high-impact AI must be able to explain outputs and the main criteria behind them
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · South Korea · cites MEASURE 2.9, GOVERN 5.1
Explainability and communication to affected parties.
-
Providers must retain automatically generated logs under their control
EU AI Act · European Union · cites MEASURE 2.4, MANAGE 4.1
Traceability data for monitoring.
-
Providers of GPAI models must maintain technical documentation and inform downstream providers
EU AI Act · European Union · cites GOVERN 1.4, MAP 2.2, MEASURE 2.1
Documentation of design, testing and evaluation.
-
Providers of generative AI must mark synthetic output as artificially generated in a machine-readable way
EU AI Act · European Union · cites MEASURE 2.7, MANAGE 4.1
Provenance mechanisms as recommended in NIST AI 600-1.
-
Providers of systemic-risk GPAI models must secure the model and its infrastructure
EU AI Act · European Union · cites MEASURE 2.7, MANAGE 2.2
Security and resilience of the system.
-
Providers of systemic-risk GPAI models must track and report serious incidents to the AI Office
EU AI Act · European Union · cites MANAGE 4.3, MEASURE 3.1
Incident response and tracking of emergent risks.
-
Test and monitor systems, enable human control, and be transparent with users (guardrails 4 to 6)
Australian Voluntary AI Safety Standard · Australia (voluntary) · cites MEASURE and MANAGE functions
Original editorial mapping.
-
Use AI in ways that are fair and do not discriminate unlawfully
UK AI regulation framework · United Kingdom (voluntary) · cites MEASURE 2.11
Fairness and bias evaluation.
MANAGE 42 duties
-
AI business operators must label generative AI output and clearly flag realistic synthetic media
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · South Korea · cites MEASURE 2.7, MANAGE 4.1
Content provenance as described in NIST AI 600-1.
-
AI business operators must notify users in advance that a product or service runs on high-impact or generative AI
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · South Korea · cites GOVERN 5.1, MANAGE 4.1
Transparency to end users.
-
Apply minimum risk-management practices to high-impact AI
OMB M-25-21 · United States · cites MAP, MEASURE, MANAGE
The memo is aligned with the AI RMF vocabulary.
-
Apply safeguards to solely automated decisions with significant effects
ICO AI guidance · United Kingdom · cites GOVERN 5.x, MANAGE 4.x
Recourse mechanisms.
-
Deployers and developers must disclose to consumers that they are interacting with an AI system
Colorado AI Act · Colorado (United States) · cites GOVERN 5.1, MANAGE 4.1
Transparency to end users.
-
Deployers must disclose deepfakes and AI-generated text published on matters of public interest
EU AI Act · European Union · cites GOVERN 5.1, MANAGE 4.1
Transparency to end users; NIST AI 600-1 content provenance.
-
Deployers must explain individual decisions taken with high-risk AI on request
EU AI Act · European Union · cites GOVERN 5.1, MANAGE 4.1
Recourse and communication for affected individuals.
-
Deployers must monitor high-risk AI, suspend use on risk and report serious incidents
EU AI Act · European Union · cites MANAGE 2.4, MANAGE 4.1, MANAGE 4.3
Deactivation mechanisms, post-deployment monitoring and incident response.
-
Deployers must notify the Attorney General of discovered algorithmic discrimination
Colorado AI Act · Colorado (United States) · cites MANAGE 4.3
Incident response and reporting.
-
Deployers must tell natural persons that a high-risk AI system is used in decisions about them
EU AI Act · European Union · cites GOVERN 5.1, MANAGE 4.1
Communication with affected individuals.
-
Deployers must use reasonable care to avoid algorithmic discrimination
Colorado AI Act · Colorado (United States) · cites GOVERN 1.1, MANAGE 1.3
Legal requirements and risk treatment for deployed systems.
-
Design high-risk systems to log events automatically
EU AI Act · European Union · cites MEASURE 2.x, MANAGE 4.1
Monitoring and traceability.
-
Determine the appropriate level of human involvement in AI decisions
Singapore Model AI Governance Framework · Singapore (voluntary) · cites GOVERN 3.2, MANAGE 2.x
Original editorial mapping.
-
Developers and deployers must not use AI with the intent to unlawfully discriminate against a protected class
Texas Responsible AI Governance Act (TRAIGA) · Texas (United States) · cites MEASURE 2.11, MANAGE 1.3
Fairness and bias evaluated and managed.
-
Developers and distributors must not build AI intended to produce child sexual abuse material or unlawful sexual deepfakes
Texas Responsible AI Governance Act (TRAIGA) · Texas (United States) · cites GOVERN 1.1, MEASURE 2.6, MANAGE 2.3
Legal requirements, safety evaluation and abuse mitigation; NIST AI 600-1 addresses obscene and abusive content.
-
Developers must notify the Attorney General and deployers of discovered algorithmic discrimination
Colorado AI Act · Colorado (United States) · cites MANAGE 4.3, GOVERN 6.2
Incident communication to authorities and downstream parties.
-
Developers must use reasonable care to avoid algorithmic discrimination
Colorado AI Act · Colorado (United States) · cites MAP 1.1, MEASURE 2.11, MANAGE 1.3
Fairness and bias evaluated and managed.
-
Employers and employment agencies must let candidates request an alternative selection process or accommodation
NYC Local Law 144 (automated employment decision tools) · New York (United States) · cites GOVERN 5.1, MANAGE 4.1
Recourse route for affected individuals.
-
Employers and employment agencies must notify candidates and employees before an automated tool is used
NYC Local Law 144 (automated employment decision tools) · New York (United States) · cites GOVERN 5.1, MANAGE 4.1
Transparency to affected individuals.
-
Enable and assign effective human oversight
EU AI Act · European Union · cites GOVERN 3.2, MANAGE 2.x
Roles and human-AI configuration.
-
Establish a risk management system for high-risk AI
EU AI Act · European Union · cites MAP, MEASURE and MANAGE functions
The AI RMF's core functions map closely to Article 9's iterative process.
-
Government agencies must disclose to consumers that they are interacting with an AI system
Texas Responsible AI Governance Act (TRAIGA) · Texas (United States) · cites GOVERN 5.1, MANAGE 4.1
Transparency to end users.
-
Health-care providers must disclose the use of AI in patient services
Texas Responsible AI Governance Act (TRAIGA) · Texas (United States) · cites GOVERN 5.1, MANAGE 4.1
Transparency to affected individuals.
-
Large frontier developers must send periodic summaries of catastrophic-risk assessments to the state
California SB 53 · California (United States) · cites MEASURE 2.6, MANAGE 1.2, GOVERN 4.3
Safety evaluation, prioritisation and information sharing with authorities.
-
Law-enforcement deployers must obtain authorisation for post-remote biometric identification and report annually
EU AI Act · European Union · cites GOVERN 1.1, MANAGE 1.3
Legal requirements and documented use decisions.
-
Notify consumers and explain adverse consequential decisions
Colorado AI Act · Colorado (United States) · cites GOVERN 5.x, MANAGE 4.x
Recourse and communication.
-
Operate a post-market monitoring system
EU AI Act · European Union · cites MANAGE 4.1, MEASURE 3.x
Post-deployment monitoring.
-
Operators of AI above the compute threshold must run lifecycle risk management and report safety results
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · South Korea · cites MAP 5.1, MEASURE 2.6, MANAGE 1.3, MANAGE 4.3
Safety evaluation, risk treatment and incident response.
-
Operators of high-impact AI must ensure human management and supervision
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · South Korea · cites GOVERN 3.2, MANAGE 2.4
Human-AI configuration and override mechanisms.
-
Operators of high-impact AI must establish and operate a risk management plan
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · South Korea · cites MAP 1.5, MANAGE 1.3
Risk tolerance and treatment.
-
Operators of high-impact AI must prepare user-protection measures and keep records of their safety and trust measures
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · South Korea · cites GOVERN 1.4, MANAGE 4.1
Documentation and post-deployment user protection.
-
Provide routes to contest AI outcomes and seek redress
UK AI regulation framework · United Kingdom (voluntary) · cites GOVERN 5.1, MANAGE 4.x
Feedback and recourse mechanisms.
-
Providers must retain automatically generated logs under their control
EU AI Act · European Union · cites MEASURE 2.4, MANAGE 4.1
Traceability data for monitoring.
-
Providers must take corrective action and inform the supply chain about non-conforming high-risk AI
EU AI Act · European Union · cites MANAGE 2.4, MANAGE 4.3
Mechanisms to deactivate or supersede systems and respond to incidents.
-
Providers of generative AI must mark synthetic output as artificially generated in a machine-readable way
EU AI Act · European Union · cites MEASURE 2.7, MANAGE 4.1
Provenance mechanisms as recommended in NIST AI 600-1.
-
Providers of systemic-risk GPAI models must secure the model and its infrastructure
EU AI Act · European Union · cites MEASURE 2.7, MANAGE 2.2
Security and resilience of the system.
-
Providers of systemic-risk GPAI models must track and report serious incidents to the AI Office
EU AI Act · European Union · cites MANAGE 4.3, MEASURE 3.1
Incident response and tracking of emergent risks.
-
Report critical safety incidents to the Office of Emergency Services
California SB 53 · California (United States) · cites MANAGE 4.3
Incident response.
-
Report serious incidents to market surveillance authorities
EU AI Act · European Union · cites MANAGE 4.3
Incident response and communication.
-
Respect the right to object to automated decision-making without human intervention
UAE PDPL · United Arab Emirates · cites GOVERN 5.x, MANAGE 4.x
Original editorial mapping.
-
Test and monitor systems, enable human control, and be transparent with users (guardrails 4 to 6)
Australian Voluntary AI Safety Standard · Australia (voluntary) · cites MEASURE and MANAGE functions
Original editorial mapping.
-
Use high-risk AI as instructed, monitor it and inform affected people
EU AI Act · European Union · cites MANAGE 3.x, GOVERN 5.x
Deployment management and stakeholder engagement.
Other references 3 duties
-
Deployers must implement a risk management policy and programme
Colorado AI Act · Colorado (United States) · cites Whole framework (named in the statute)
The statute names the AI RMF as a recognised framework.
-
Meet general-purpose AI model provider obligations
EU AI Act · European Union · cites NIST AI 600-1 (Generative AI profile) — intellectual property and data privacy risks
Original editorial mapping.
-
Report incidents and mark AI-generated content (generative AI framework)
Singapore Model AI Governance Framework · Singapore (voluntary) · cites NIST AI 600-1 content provenance and incident disclosure
Original editorial mapping.
Controls that cite this standard
Each control is an original description of what an organisation operates. The reference is the function it corresponds to, by number only.
| Control | Function | Duties served | Evidence |
|---|---|---|---|
| AI governance policy and accountability structure Policy | GOVERN 1.1, 1.2, 1.3, 2.1, 3.1 | 16 | AI policy, Board or executive approval of the AI policy, AI governance forum minutes |
| AI impact and fundamental-rights impact assessment Process | MAP 5.1, 5.2; MEASURE 2.11 | 11 | AI impact assessment, Impact assessment approval, Impact assessment procedure and template |
| AI incident management and regulatory reporting Process | MANAGE 4.1, 4.3; GOVERN 4.3, 6.2 | 14 | AI incident response playbook, AI incident record, Incident report to an authority |
| AI interaction and use disclosure notices Process | MEASURE 2.8; GOVERN 5.1 | 17 | AI interaction or use notice, Notice catalogue, Notice wording approval |
| AI literacy and role-based training programme Training programme | GOVERN 2.2, 4.1 | 4 | AI training completion records, Role-to-curriculum training matrix, AI training curriculum and materials |
| AI risk assessment and lifecycle risk register Process | MAP 3, MAP 4, MANAGE 1.2, 1.3, 2.1 | 12 | AI system risk assessment, Per-system AI risk register, Residual-risk acceptance |
| AI system inventory and classification Process | MAP 1.1, 1.5; GOVERN 1.6 | 11 | AI system register, Risk-tier classification sign-off, AI intake and classification procedure |
| Accuracy, robustness, fairness and security testing Technical measure | MEASURE 2.5, 2.6, 2.7, 2.11 | 15 | Pre-release test report, Test plan and acceptance criteria, Release test sign-off |
| Adversarial and red-team testing for generative AI Technical measure | MEASURE 2.6, 2.7; MANAGE 2.2 | 8 | Red-team exercise report, Red-team rules of engagement and scenario library, Adversarial findings tracker |
| Automatic event logging and record retention Technical measure | MEASURE 2.4; MANAGE 4.1 | 8 | AI system event logs, Log schema and retention standard, Log integrity and retention check |
| Conformity assessment, declaration and registration Process | GOVERN 1.1; MAP 4.1 | 4 | Declaration of conformity or certificate, Registration record in the relevant database, Conformity evidence pack |
| Contractual allocation of AI duties across the supply chain Contractual term | GOVERN 6.1; MANAGE 3.1 | 8 | AI supplier clause set, AI customer or deployer clause set, Contract clause index against the AI register |
| Data governance and dataset documentation Process | MAP 2.3; MEASURE 2.1, 2.2, 2.11 | 8 | Dataset documentation sheet, Data quality and bias check report, Dataset approval for use |
| Decision explanation, human review and appeal route Process | MEASURE 2.9; GOVERN 5.1; MANAGE 4.1 | 10 | Adverse-decision explanation template, AI decision challenge and human review procedure, Challenge and reversal log |
| Frontier model safety and security framework Policy | GOVERN 1.3, 1.4; MAP 5.1; MEASURE 2.6; MANAGE 1.3 | 9 | Published frontier safety framework, Dangerous-capability evaluation report, Threshold notification to an authority |
| Human oversight design and override procedure Process | GOVERN 3.2; MAP 3.5; MANAGE 2.4 | 11 | Human oversight and override procedure, Human-involvement design rationale, Overseer training completion |
| Model release and change-management gate Process | MANAGE 1.1, 2.3; GOVERN 1.7 | 5 | Release or change approval record, Release and change-classification procedure |
| Post-deployment monitoring and drift detection Technical measure | MEASURE 3.1, 3.3; MANAGE 4.1 | 10 | Post-market monitoring plan, Monitoring dashboard or periodic monitoring report, Monitoring review decision |
| Privacy and data-protection controls for AI Process | MEASURE 2.10; MAP 4.1; GOVERN 1.1 | 13 | Data protection impact assessment for an AI system, AI data-flow and legal-basis record, Privacy notice section on AI use |
| Prohibited and unacceptable-use screening gate Process | GOVERN 1.1; MAP 1.1 | 7 | Prohibited-use screening record, Screening list and escalation procedure |
| Public-sector AI use-case register and algorithmic transparency Process | MAP 1.1, 1.5; GOVERN 1.6, 5.1 | 6 | Public AI use-case inventory, Algorithmic transparency statement for one use case, Inventory review and publication sign-off |
| Quality management system for AI development and supply Policy | GOVERN 1.4, 1.5, 1.7 | 3 | AI quality management system manual, Internal audit of the AI management system, Management review minutes |
| Synthetic content labelling and provenance marking Technical measure | MEASURE 2.8; MANAGE 4.1 | 5 | Content labelling and provenance standard, Watermark and provenance robustness test, Visible AI-generated content label |
| Technical documentation, model cards and instructions for use Process | GOVERN 1.4; MAP 2.2; MEASURE 2.8 | 13 | Technical documentation file, Model card or deployer information pack, Instructions for use |
| Training-data provenance and copyright register Process | MAP 4.1; GOVERN 6.1 | 4 | Training source register, Copyright and rights-reservation policy, Public summary of training content |
| Vendor and third-party AI due diligence Process | GOVERN 6.1, 6.2; MAP 4.1, 4.2; MANAGE 3.1 | 6 | AI supplier due-diligence assessment, AI supplier and component register, Supplier onboarding decision |
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.
Frequently asked questions
- What is NIST AI Risk Management Framework 1.0?
- A voluntary framework for managing risk across the AI lifecycle. There is no certification against it; organisations adopt it as a common vocabulary for identifying, measuring and treating AI risk.
- Does NIST AI RMF make an organisation legally compliant?
- No. Adoption evidences a management practice, not compliance with any statute. A crosswalk shows where the two overlap so existing evidence can be reused; it does not transfer legal obligations.