NIST AI RMF: Turning Govern-Map-Measure-Manage Into a Working Program
The NIST AI Risk Management Framework is the leading voluntary framework for trustworthy AI governance. Published in January 2023 and actively maintained, it organises AI risk management into four functions that together move AI governance from policy aspiration to operational reality.
Govern. Map. Measure. Manage.
The four functions are interconnected, not sequential. NIST recommends starting with Govern and an AI inventory before moving to risk mapping and measurement. Each function maps directly to Wahid AI modules.
Govern is the foundation. It establishes the organisational practices, culture, and accountability structures that enable responsible AI risk management. Without Govern, Map, Measure, and Manage operate without direction.
Map establishes the context for AI risk decisions. It identifies the intended purpose, potential impacts, and stakeholders for each AI system, enabling risk identification proportionate to the system's role and environment.
Measure translates identified risks into rated exposures with evidence. It requires both quantitative and qualitative assessment methods, covering accuracy, fairness, robustness, explainability, and resilience.
Manage closes the loop. It operationalises treatment decisions — accept, mitigate, transfer, or avoid — and instruments ongoing monitoring through KRIs, incident tracking, and continuous re-validation as AI systems and environments evolve.
The eight properties of trustworthy AI
NIST AI RMF is built around eight characteristics that AI systems should exhibit to be considered trustworthy. Each is addressed through the Govern-Map-Measure-Manage functions.
Accountable and transparent
AI actors are responsible for outcomes. Decisions are explainable to appropriate stakeholders.
Explainable and interpretable
AI outputs can be understood and traced by those who need to act on or audit them.
Fair with harmful bias managed
AI systems do not produce unjustified differential outcomes across demographic groups.
Privacy-enhanced
Privacy values are embedded throughout the AI lifecycle — not bolted on after deployment.
Reliable and robust
AI systems perform within defined parameters across expected and unexpected inputs.
Safe
AI system risks are identified and managed to an acceptable level before and during deployment.
Secure and resilient
AI systems resist adversarial attack and recover from disruption.
Valid and validated
AI systems are tested for fitness for purpose before deployment and re-validated as conditions change.
NIST AI RMF — common questions
What is the NIST AI RMF?
The NIST AI Risk Management Framework (AI RMF 1.0) is a voluntary framework published by the US National Institute of Standards and Technology in January 2023. It helps organisations identify, assess, and manage risks associated with AI systems through four core functions: Govern, Map, Measure, and Manage.
Is NIST AI RMF mandatory?
No — it is voluntary and sector-agnostic. However, it is widely adopted as a baseline for trustworthy AI governance and is referenced by APRA and ASIC in Australia, and increasingly embedded in US federal procurement and regulatory guidance.
How does NIST AI RMF relate to ISO 42001?
The two frameworks are complementary. ISO 42001 provides certification and management system structure. NIST AI RMF provides function-level risk management depth. Wahid AI maps to both simultaneously, so evidence generated under one framework satisfies requirements for the other where they overlap.
Where do I start with NIST AI RMF implementation?
NIST recommends starting with Govern — establishing governance structures, policies, and accountability before mapping individual AI system risks. Paired with an AI inventory, this gives organisations a foundation before moving to detailed risk measurement and management activities.
Move from NIST AI RMF policy to a working risk register.
Wahid AI operationalises all four NIST AI RMF functions in one workflow. Govern structures the program. Map runs at intake. Measure lives in the risk register. Manage closes obligations with evidence.
RELATED FRAMEWORKS