Skip to content
SCA

AI Security · Framework

NIST AI RMF

NIST's voluntary framework for managing AI risk across four functions.

Overview

The NIST AI Risk Management Framework (AI RMF 1.0) is a voluntary framework to help organizations manage the risks of AI systems and build trustworthy AI — addressing not only security but fairness, transparency, safety, and accountability.

The four functions

  • Govern — cultivate a culture of risk management (cross-cutting).
  • Map — establish context and identify risks.
  • Measure — analyze and track risks with metrics.
  • Manage — prioritize and act on risks.

Why it matters

It complements security-only frameworks by framing AI-specific risk. Use it alongside MITRE ATLAS (threats) and ISO/IEC 42001 (management system) for a complete governance picture.

References

See the primary source below.

Primary sources