AIPolicyTracker
Voluntary National Institute of Standards and Technology · 2023

NIST AI Risk Management Framework 1.0

A voluntary framework for managing risk across the AI lifecycle. There is no certification against it; organisations adopt it as a common vocabulary for identifying, measuring and treating AI risk.

Duties mapped
97
Mappings
97
Jurisdictions
12
Functions used
5
Evidence types
23
Risk areas
21
Recorded incidents
1,494

Duties are what the law asks; controls are what an organisation operates to meet them; evidence is how it shows it did. Incidents are the harms the AI Incident Database has recorded under the risk areas those controls address.

How it is structured

Four functions - GOVERN, MAP, MEASURE and MANAGE - each broken into categories and subcategories. GOVERN runs throughout; the other three describe a cycle.

It is the reference point for US federal AI policy and for a growing number of procurement questionnaires, so a duty that maps cleanly to a function is one you can evidence in terms a US counterparty already uses.

Legal duties by function

A duty appears under every function its mapping cites, so the totals below exceed the 97 distinct duties. References that name no single function are grouped at the end rather than dropped.

GOVERN 61 duties

MAP 30 duties

MEASURE 31 duties

MANAGE 42 duties

Other references 3 duties

Controls that cite this standard

Each control is an original description of what an organisation operates. The reference is the function it corresponds to, by number only.

Controls referencing NIST AI RMF
ControlFunctionDuties servedEvidence
AI governance policy and accountability structure
Policy
GOVERN 1.1, 1.2, 1.3, 2.1, 3.116AI policy, Board or executive approval of the AI policy, AI governance forum minutes
AI impact and fundamental-rights impact assessment
Process
MAP 5.1, 5.2; MEASURE 2.1111AI impact assessment, Impact assessment approval, Impact assessment procedure and template
AI incident management and regulatory reporting
Process
MANAGE 4.1, 4.3; GOVERN 4.3, 6.214AI incident response playbook, AI incident record, Incident report to an authority
AI interaction and use disclosure notices
Process
MEASURE 2.8; GOVERN 5.117AI interaction or use notice, Notice catalogue, Notice wording approval
AI literacy and role-based training programme
Training programme
GOVERN 2.2, 4.14AI training completion records, Role-to-curriculum training matrix, AI training curriculum and materials
AI risk assessment and lifecycle risk register
Process
MAP 3, MAP 4, MANAGE 1.2, 1.3, 2.112AI system risk assessment, Per-system AI risk register, Residual-risk acceptance
AI system inventory and classification
Process
MAP 1.1, 1.5; GOVERN 1.611AI system register, Risk-tier classification sign-off, AI intake and classification procedure
Accuracy, robustness, fairness and security testing
Technical measure
MEASURE 2.5, 2.6, 2.7, 2.1115Pre-release test report, Test plan and acceptance criteria, Release test sign-off
Adversarial and red-team testing for generative AI
Technical measure
MEASURE 2.6, 2.7; MANAGE 2.28Red-team exercise report, Red-team rules of engagement and scenario library, Adversarial findings tracker
Automatic event logging and record retention
Technical measure
MEASURE 2.4; MANAGE 4.18AI system event logs, Log schema and retention standard, Log integrity and retention check
Conformity assessment, declaration and registration
Process
GOVERN 1.1; MAP 4.14Declaration of conformity or certificate, Registration record in the relevant database, Conformity evidence pack
Contractual allocation of AI duties across the supply chain
Contractual term
GOVERN 6.1; MANAGE 3.18AI supplier clause set, AI customer or deployer clause set, Contract clause index against the AI register
Data governance and dataset documentation
Process
MAP 2.3; MEASURE 2.1, 2.2, 2.118Dataset documentation sheet, Data quality and bias check report, Dataset approval for use
Decision explanation, human review and appeal route
Process
MEASURE 2.9; GOVERN 5.1; MANAGE 4.110Adverse-decision explanation template, AI decision challenge and human review procedure, Challenge and reversal log
Frontier model safety and security framework
Policy
GOVERN 1.3, 1.4; MAP 5.1; MEASURE 2.6; MANAGE 1.39Published frontier safety framework, Dangerous-capability evaluation report, Threshold notification to an authority
Human oversight design and override procedure
Process
GOVERN 3.2; MAP 3.5; MANAGE 2.411Human oversight and override procedure, Human-involvement design rationale, Overseer training completion
Model release and change-management gate
Process
MANAGE 1.1, 2.3; GOVERN 1.75Release or change approval record, Release and change-classification procedure
Post-deployment monitoring and drift detection
Technical measure
MEASURE 3.1, 3.3; MANAGE 4.110Post-market monitoring plan, Monitoring dashboard or periodic monitoring report, Monitoring review decision
Privacy and data-protection controls for AI
Process
MEASURE 2.10; MAP 4.1; GOVERN 1.113Data protection impact assessment for an AI system, AI data-flow and legal-basis record, Privacy notice section on AI use
Prohibited and unacceptable-use screening gate
Process
GOVERN 1.1; MAP 1.17Prohibited-use screening record, Screening list and escalation procedure
Public-sector AI use-case register and algorithmic transparency
Process
MAP 1.1, 1.5; GOVERN 1.6, 5.16Public AI use-case inventory, Algorithmic transparency statement for one use case, Inventory review and publication sign-off
Quality management system for AI development and supply
Policy
GOVERN 1.4, 1.5, 1.73AI quality management system manual, Internal audit of the AI management system, Management review minutes
Synthetic content labelling and provenance marking
Technical measure
MEASURE 2.8; MANAGE 4.15Content labelling and provenance standard, Watermark and provenance robustness test, Visible AI-generated content label
Technical documentation, model cards and instructions for use
Process
GOVERN 1.4; MAP 2.2; MEASURE 2.813Technical documentation file, Model card or deployer information pack, Instructions for use
Training-data provenance and copyright register
Process
MAP 4.1; GOVERN 6.14Training source register, Copyright and rights-reservation policy, Public summary of training content
Vendor and third-party AI due diligence
Process
GOVERN 6.1, 6.2; MAP 4.1, 4.2; MANAGE 3.16AI supplier due-diligence assessment, AI supplier and component register, Supplier onboarding decision

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.

Frequently asked questions

What is NIST AI Risk Management Framework 1.0?
A voluntary framework for managing risk across the AI lifecycle. There is no certification against it; organisations adopt it as a common vocabulary for identifying, measuring and treating AI risk.
Does NIST AI RMF make an organisation legally compliant?
No. Adoption evidences a management practice, not compliance with any statute. A crosswalk shows where the two overlap so existing evidence can be reused; it does not transfer legal obligations.