AI governance glossary
NIST AI Risk Management Framework (AI RMF)
Definition
A voluntary framework from the US National Institute of Standards and Technology for managing the risks of AI systems, organised in four functions: Govern (culture and accountability), Map (context and risks), Measure (analysis and tracking) and Manage (prioritising and acting on risks).
Source: NIST AI 100-1. A plain-language explanation for orientation, not the legal text; follow the source for the binding wording.
NIST AI RMF record →NIST, EU and ISO crosswalk →
Laws and policies on record that use it
- Texas Responsible AI Governance Act (TRAIGA)Texas (United States) · In force
- Colorado AI ActColorado (United States) · Repealed
- NIST AI RMFUnited States · Voluntary standard
Duties that mention it
- Deployers must implement a risk management policy and programmeColorado AI Act · Colorado (United States)
Related terms
- AI systemA machine-based system that operates with some autonomy, may adapt after it is deployed, and infers from the i...
- Red teaming (AI)Structured adversarial testing in which testers try to make an AI system fail: produce harmful output, leak da...
All glossary terms · Think a definition is off? Tell us; corrections are logged on the corrections page.
Frequently asked questions
What does "NIST AI Risk Management Framework" mean?
A voluntary framework from the US National Institute of Standards and Technology for managing the risks of AI systems, organised in four functions: Govern (culture and accountability), Map (context and risks), Measure (analysis and tracking) and Manage (prioritising and acting on risks).
Where does the term NIST AI Risk Management Framework come from?
This explanation follows NIST AI 100-1. It is a plain-language paraphrase for orientation; the source has the binding wording.
Which laws and policies use the term NIST AI Risk Management Framework?
Among the records on this site: Texas Responsible AI Governance Act (TRAIGA) (Texas); Colorado AI Act (Colorado) and NIST AI RMF (US).