Skip to content

VIII.3VIII · Govern itgovern

NIST AI RMF - the risk process

Where SAIF tells you which safeguards to build, NIST AI RMF tells you how to reason about and act on risk - the process that decides which safeguards you need, whether a gap blocks a launch, and how you prove you are managing it over time. This is the full working map of the framework and its Generative AI Profile.

Document identity

The Artificial Intelligence Risk Management Framework (AI RMF 1.0) is NIST AI 100-1 (DOI 10.6028/NIST.AI.100-1), released 26 January 2023 under the National AI Initiative Act of 2020. It is voluntary, non-sector-specific, and use-case-agnostic, with the stated purpose “to better manage risks to individuals, organizations, and society associated with AI” (NIST AI RMF landing; AI 100-1 PDF; AIRC Knowledge Base).

The framework defines risk as “a composite measure of an event’s probability of occurring and the magnitude … of the consequences,” and insists that harm be considered across three dimensions: people, organizations, and the ecosystem. It comes in two parts: Part 1 - Foundational Information (framing, trustworthiness, AI actors and lifecycle, including TEVV - test, evaluation, verification, and validation) and Part 2 - Core and Profiles (the four functions plus how to build Profiles).

The seven characteristics of trustworthy AI

Every function ultimately serves these seven characteristics (AIRC - Characteristics). They are not co-equal: Valid and Reliable is foundational (the others build on it), and Accountable and Transparent cuts across all the rest.

#CharacteristicWhat it demands
1Valid and Reliable (foundational)The system does what it claims, repeatably, under real conditions
2SafeIt does not, under defined conditions, endanger life, health, property, or environment
3Secure and ResilientIt withstands adversarial attack and recovers - the security characteristic this book targets
4Accountable and Transparent (cross-cutting)Someone is answerable; the system’s behavior is disclosed and traceable
5Explainable and InterpretableIts mechanisms and outputs can be understood and reasoned about
6Privacy-EnhancedIt safeguards autonomy, identity, and dignity in how it handles data
7Fair - with Harmful Bias ManagedIt manages the three bias types in SP 1270: systemic, computational/statistical, and human-cognitive

The Core - four functions

The Core is where the work happens. Below is the full structure with every category and subcategory ID, verified against the AIRC Core (Section 5). Read GOVERN as the always-on culture layer, and MAP -> MEASURE -> MANAGE as the per-system loop that runs inside it.

GOVERN (6 categories / 19 subcategories) - cross-cutting

Cultivate a risk-management culture: policies, accountability, workforce, and third-party discipline. This is the operating system the other three functions run on.

CategorySubcategories (abbreviated)
GV-1 Policies & processes1.1 legal/regulatory understood · 1.2 trustworthiness in policy · 1.3 risk-management level matched to risk tolerance · 1.4 transparent process · 1.5 monitoring & periodic review + roles · 1.6 AI system inventory · 1.7 safe decommissioning
GV-2 Accountability structures2.1 roles/responsibilities documented · 2.2 AI risk training · 2.3 executive responsibility
GV-3 Workforce diversity & oversight3.1 diverse team · 3.2 human-AI oversight roles defined
GV-4 Risk-aware culture4.1 safety-first mindset · 4.2 document risks & impacts · 4.3 testing/incident/info-sharing
GV-5 Engagement with AI actors5.1 collect external feedback · 5.2 integrate adjudicated feedback
GV-6 Third-party / supply-chain6.1 third-party risk incl. IP · 6.2 high-risk contingency

MAP (5 categories / 18 subcategories)

Establish context and decide whether to proceed at all. The output of MAP is a documented, evidence-based decision to build (or not).

CategorySubcategories (abbreviated)
MP-1 Context established1.1 intended purpose/laws/settings · 1.2 interdisciplinary actors · 1.3 mission/goals · 1.4 business value · 1.5 risk tolerances · 1.6 socio-technical requirements
MP-2 Categorization2.1 tasks/methods (classifier/generative/recommender) · 2.2 knowledge limits & human oversight · 2.3 scientific integrity & TEVV
MP-3 Benefits & costs3.1 benefits · 3.2 costs incl. non-monetary · 3.3 targeted scope · 3.4 operator proficiency · 3.5 human oversight
MP-4 Risks incl. third-party4.1 legal/IP mapping · 4.2 internal risk controls
MP-5 Impacts characterized5.1 likelihood x magnitude · 5.2 regular AI-actor engagement

MEASURE (4 categories / 22 subcategories)

Analyze, benchmark, and monitor - the TEVV function. This is the largest function by subcategory count, because “you cannot manage what you do not measure.”

CategorySubcategories (abbreviated)
MS-1 Methods & metrics1.1 select for top risks + document what can’t be measured · 1.2 assess metric appropriateness · 1.3 independent assessors
MS-2 Evaluate trustworthy characteristics2.1 TEVV test sets · 2.2 human-subject protection · 2.3 deployment-like conditions · 2.4 monitor in production · 2.5 valid & reliable · 2.6 safe incl. fail-safe · 2.7 security/resilience · 2.8 transparency/accountability · 2.9 explainability · 2.10 privacy · 2.11 fairness/bias · 2.12 environmental · 2.13 TEVV effectiveness
MS-3 Track risks over time3.1 emergent risks · 3.2 hard-to-measure risks · 3.3 user/community feedback & appeal
MS-4 Feedback on measurement4.1 connect to deployment context · 4.2 validate via domain experts · 4.3 measurable improvements/declines

MANAGE (4 categories / 13 subcategories)

Prioritize, respond, and monitor - act on what MEASURE found.

CategorySubcategories (abbreviated)
MG-1 Prioritize & respond1.1 proceed/deploy decision · 1.2 prioritize treatments · 1.3 response = mitigate/transfer/avoid/accept · 1.4 document residual risk
MG-2 Maximize benefit / minimize harm2.1 resources + non-AI alternatives · 2.2 sustain value · 2.3 recover from unknown risk · 2.4 supersede/deactivate (kill switch)
MG-3 Third-party management3.1 monitor third-party resources · 3.2 monitor pre-trained models
MG-4 Risk treatment & communication4.1 post-deployment monitoring / IR / change mgmt · 4.2 continual improvement · 4.3 communicate incidents to affected communities

The AI RMF Playbook

The Playbook is the companion that turns the Core’s outcomes into action. It offers “suggested actions for achieving the outcomes laid out in the AI RMF Core,” keyed to each subcategory with three things: Suggested Actions, Transparency & Documentation questions, and References.

Crucially, NIST states the Playbook is “neither a checklist nor set of steps to be followed in its entirety” - you select the actions that fit your context and risk tolerance. It ships in PDF, CSV, Excel, and JSON and is updated roughly twice a year. Related companions include the Roadmap, Crosswalks (to ISO 42001, SP 800-53, EU AI Act, and more), and Profiles.

The Generative AI Profile (AI 600-1)

For any generative-AI system, layer the AI RMF: Generative Artificial Intelligence Profile - NIST AI 600-1 (DOI 10.6028/NIST.AI.600-1), published 26 July 2024 as a deliverable under Executive Order 14110 (AI 600-1 PDF). It is a cross-sectoral use-case profile: it does not replace the Core, it specializes it for GenAI.

Its suggested actions each carry an Action ID keyed to a function+subcategory (for example GV-1.3-004, MS-2.7-009), an AI-Actor-Task tag, and the specific GenAI risk(s) addressed - so every recommendation traces back to a Core subcategory. The Profile is organized around four primary considerations: Governance, Content Provenance, Pre-deployment Testing, and Incident Disclosure.

The twelve GenAI risk categories (verbatim from the final July 2024 publication):

#Risk#Risk
1CBRN Information or Capabilities7Human-AI Configuration
2Confabulation (hallucination)8Information Integrity
3Dangerous, Violent, or Hateful Content9Information Security
4Data Privacy10Intellectual Property
5Environmental Impacts11Obscene, Degrading, and/or Abusive Content
6Harmful Bias or Homogenization12Value Chain and Component Integration

Now run the screen. This is the artifact the gate block calls “run the 12-risk screen” - one row per risk. Mark each Y/N, then name the control or eval that owns every Y. An N is not free: log a one-line reason under MAP (MP-4.1). Route the security-flavored rows through the same garak + PyRIT run that files as MS-2.7 evidence.

#GenAI riskApplies to us? (Y/N)Core-function hook (which control/eval owns it)
1CBRN Information or Capabilitiesgarak dangerous-capability probes -> MS-2.6 (safe / fail-safe)
2Confabulation (hallucination)grounded-output eval set -> MS-2.5 (valid & reliable)
3Dangerous, Violent, or Hateful ContentPyRIT content probes -> MS-2.6 (safe)
4Data Privacygarak leakreplay (PII leak) -> MS-2.10 (privacy)
5Environmental Impactscompute / energy accounting -> MS-2.12 (environmental)
6Harmful Bias or Homogenizationbias eval (SP 1270 three types) -> MS-2.11 (fairness / bias)
7Human-AI Configurationoversight-role design -> GV-3.2 + MP-2.2 (human oversight)
8Information Integritycontent-provenance / watermark controls -> MS-2.8 (transparency)
9Information Securitygarak + PyRIT -> MS-2.7 (security / resilience)
10Intellectual PropertyIP / license mapping -> MP-4.1 + GV-6.1 (third-party incl. IP)
11Obscene, Degrading, and/or Abusive ContentPyRIT abuse probes -> MS-2.6 (safe)
12Value Chain and Component Integrationmodel / SBOM provenance -> GV-6.1 + MG-3.2 (monitor pre-trained models)

Any Y with an empty hook is an open gap that MG-1.1 cannot clear - it holds the deploy decision until a control is attached or a signed MG-1.4 residual-risk acceptance names who owns it.

How to operationalize each function

The framework is only useful if it changes what you do. Here is the working translation of each function into concrete practice.

The Core tables above are the full map. What you actually operate is a much shorter list of gates and one tooling hook - the decision-critical subcategories, not all 72:

NIST AI RMF - the gates you actually operate
# GOVERN gates (always on)
build risk-tiered AI inventory # GV-1.6 <- can't govern what you can't see
set risk-tolerance go/no-go gates # GV-1.3 <- the gate that blocks a launch
# MEASURE hook - where the red-team earns its keep
run garak + PyRIT against the target, then
file the results as MS-2.7 evidence # MS-2.7 security/resilience evaluated & documented
# MANAGE gates - turn test results into a defensible decision
evidence-based deploy decision # MG-1.1 <- proceed / hold
document residual risk (signed off) # MG-1.4 <- what you accepted and who owns it
kill switch / deactivation path # MG-2.4 <- can you pull it in production?
# FOR GENERATIVE AI: layer AI 600-1
run the 12-risk screen; apply actions under
Governance / Content Provenance / Pre-deployment Testing / Incident Disclosure
tracing every Action ID back to its Core subcategory