Prioritise, respond to and monitor AI risks (Manage)
Under NIST AI RMF, MANAGE function
Source-linked
Open official source
What does it require?
Manage allocates resources to mapped and measured risks, plans responses including decommissioning, manages third-party risks, and documents post-deployment monitoring, incident response and communication.
Practical action
Maintain a risk-treatment plan and an incident and monitoring log per system.
Who does it apply to?
Voluntary; any organisation adopting the framework.
- Sectors
- Cross-sector / all sectors
Evidence examples
- Risk treatment and monitoring plan (document)
Framework mappings
Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| ISO/IEC 42001:2023 | Clauses 8 and 10 | Operation and improvement. | medium |
Similar obligations in other instruments
- Apply minimum risk-management practices to high-impact AI — OMB M-25-21, United States
- Establish a risk management system for high-risk AI — EU AI Act, European Union
- Deployers must implement a risk management policy and programme — Colorado AI Act, Colorado (United States)
- Ensure AI systems are safe, secure and robust throughout their lifecycle — UK AI regulation framework, United Kingdom (voluntary)
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.