HomeResourcesNIST AI RMF
NIST AI RMF 1.0

NIST AI RMF: Turning Govern-Map-Measure-Manage Into a Working Program

The NIST AI Risk Management Framework is the leading voluntary framework for trustworthy AI governance. Published in January 2023 and actively maintained, it organises AI risk management into four functions that together move AI governance from policy aspiration to operational reality.

VOLUNTARYSECTOR-AGNOSTICSCALABLECOMPANION TO ISO 42001 & EU AI ACT
The four functions

Govern. Map. Measure. Manage.

The four functions are interconnected, not sequential. NIST recommends starting with Govern and an AI inventory before moving to risk mapping and measurement. Each function maps directly to Wahid AI modules.

GOVERNEstablish the culture, accountability, and policies for responsible AI

Govern is the foundation. It establishes the organisational practices, culture, and accountability structures that enable responsible AI risk management. Without Govern, Map, Measure, and Manage operate without direction.

Establish AI risk governance policies and procedures
Assign roles and responsibilities for AI risk management
Define risk tolerance and appetite for AI systems
Implement mechanisms to track AI risk across the organisation
Establish human oversight and intervention protocols
Create processes for workforce AI risk awareness and training
Wahid AI: Board Reporting module — six live executive lenses; Risk Register with appetite thresholds and named owners
MAPIdentify and categorise AI risks in context

Map establishes the context for AI risk decisions. It identifies the intended purpose, potential impacts, and stakeholders for each AI system, enabling risk identification proportionate to the system's role and environment.

Classify AI systems by intended use and impact tier
Identify internal and external stakeholders affected by each AI system
Assess the business context and deployment environment
Document AI system limitations and known failure modes
Map third-party and supply chain AI dependencies
Identify legal, regulatory, and ethical obligations per system
Wahid AI: Use-Case Intake & Impact module — dual-framework classification against DTA Policy v2.0 and EU AI Act at intake
MEASUREAnalyse and assess AI risks with quantitative and qualitative methods

Measure translates identified risks into rated exposures with evidence. It requires both quantitative and qualitative assessment methods, covering accuracy, fairness, robustness, explainability, and resilience.

Assess AI risk likelihood and impact using defined rating scales
Test for bias, fairness, and explainability across use populations
Evaluate model robustness and adversarial resilience
Assess control design and operating effectiveness
Measure third-party AI vendor risk using structured due diligence
Track performance metrics against defined AI quality targets
Wahid AI: Risk, Controls & Incidents module — 5x5 appetite map, named risk owners, residual ratings with documented rationale
MANAGEPrioritise, respond to, and monitor AI risks through their lifecycle

Manage closes the loop. It operationalises treatment decisions — accept, mitigate, transfer, or avoid — and instruments ongoing monitoring through KRIs, incident tracking, and continuous re-validation as AI systems and environments evolve.

Prioritise risks for treatment based on appetite and residual exposure
Implement and validate treatment plans with named owners and milestones
Monitor AI system performance for drift, decay, and emergent risks
Respond to incidents and near misses with root-cause analysis
Maintain audit trail of risk decisions, acceptances, and treatments
Conduct periodic re-assessment as systems and environments change
Wahid AI: Compliance Mapping module — obligations move Open > In Progress > Evidenced > Met; blocking obligations gate go-live
Trustworthy AI characteristics

The eight properties of trustworthy AI

NIST AI RMF is built around eight characteristics that AI systems should exhibit to be considered trustworthy. Each is addressed through the Govern-Map-Measure-Manage functions.

01

Accountable and transparent

AI actors are responsible for outcomes. Decisions are explainable to appropriate stakeholders.

02

Explainable and interpretable

AI outputs can be understood and traced by those who need to act on or audit them.

03

Fair with harmful bias managed

AI systems do not produce unjustified differential outcomes across demographic groups.

04

Privacy-enhanced

Privacy values are embedded throughout the AI lifecycle — not bolted on after deployment.

05

Reliable and robust

AI systems perform within defined parameters across expected and unexpected inputs.

06

Safe

AI system risks are identified and managed to an acceptable level before and during deployment.

07

Secure and resilient

AI systems resist adversarial attack and recover from disruption.

08

Valid and validated

AI systems are tested for fitness for purpose before deployment and re-validated as conditions change.

FAQ

NIST AI RMF — common questions

01

What is the NIST AI RMF?

The NIST AI Risk Management Framework (AI RMF 1.0) is a voluntary framework published by the US National Institute of Standards and Technology in January 2023. It helps organisations identify, assess, and manage risks associated with AI systems through four core functions: Govern, Map, Measure, and Manage.

02

Is NIST AI RMF mandatory?

No — it is voluntary and sector-agnostic. However, it is widely adopted as a baseline for trustworthy AI governance and is referenced by APRA and ASIC in Australia, and increasingly embedded in US federal procurement and regulatory guidance.

03

How does NIST AI RMF relate to ISO 42001?

The two frameworks are complementary. ISO 42001 provides certification and management system structure. NIST AI RMF provides function-level risk management depth. Wahid AI maps to both simultaneously, so evidence generated under one framework satisfies requirements for the other where they overlap.

04

Where do I start with NIST AI RMF implementation?

NIST recommends starting with Govern — establishing governance structures, policies, and accountability before mapping individual AI system risks. Paired with an AI inventory, this gives organisations a foundation before moving to detailed risk measurement and management activities.

Move from NIST AI RMF policy to a working risk register.

Wahid AI operationalises all four NIST AI RMF functions in one workflow. Govern structures the program. Map runs at intake. Measure lives in the risk register. Manage closes obligations with evidence.