AIPolicyTracker

AI governance glossary

NIST AI Risk Management Framework (AI RMF)

Definition

A voluntary framework from the US National Institute of Standards and Technology for managing the risks of AI systems, organised in four functions: Govern (culture and accountability), Map (context and risks), Measure (analysis and tracking) and Manage (prioritising and acting on risks).

Source: NIST AI 100-1. A plain-language explanation for orientation, not the legal text; follow the source for the binding wording.

NIST AI RMF record →NIST, EU and ISO crosswalk →

Laws and policies on record that use it

Duties that mention it

  • AI systemA machine-based system that operates with some autonomy, may adapt after it is deployed, and infers from the i...
  • Red teaming (AI)Structured adversarial testing in which testers try to make an AI system fail: produce harmful output, leak da...

All glossary terms · Think a definition is off? Tell us; corrections are logged on the corrections page.

Frequently asked questions

What does "NIST AI Risk Management Framework" mean?

A voluntary framework from the US National Institute of Standards and Technology for managing the risks of AI systems, organised in four functions: Govern (culture and accountability), Map (context and risks), Measure (analysis and tracking) and Manage (prioritising and acting on risks).

Where does the term NIST AI Risk Management Framework come from?

This explanation follows NIST AI 100-1. It is a plain-language paraphrase for orientation; the source has the binding wording.

Which laws and policies use the term NIST AI Risk Management Framework?

Among the records on this site: Texas Responsible AI Governance Act (TRAIGA) (Texas); Colorado AI Act (Colorado) and NIST AI RMF (US).