Skip to content

Glossary

NIST AI Risk Management Framework

A voluntary United States framework for handling the risks of AI systems, organised around four functions that give an organisation ready-made headings.

In plain terms

A structure for thinking about what could go wrong with an AI system and who is responsible for it. Nobody has to use it. Its usefulness is that somebody has already worked out the headings, so you are not inventing a way to organise the question from scratch.

01

Why it matters

Because most organisations trying to be careful about AI face a blank page, and a blank page is where the effort dies. Having four agreed headings and a common vocabulary turns an open-ended worry into something that can be assigned, worked through and reported on.

02

How it works

It is voluntary by design and says so. Nothing compels its use, which changes how it should be read: not as a compliance floor to clear, but as a structure to borrow from as far as it helps and no further.

Four functions carry it: Govern, Map, Measure and Manage. That is the whole spine, and its usefulness is in how little it is, because four headings can be held in mind by people who will never read the underlying document.

Govern comes first, and that ordering is the argument. Deciding who owns the question, what the organisation's position is and who can say no comes before any assessment, and an organisation that starts by measuring has skipped the part that makes measurement mean anything.

Its stated purpose is bringing trustworthiness into design, development, use and evaluation. Use sits in that list alongside building, which is what makes it applicable to organisations that buy AI rather than make it.

It was built through an open, consensus-driven process, which is why it reads as neutral. Nothing in it advocates a technology or a supplier, so it can be adopted without importing anybody's commercial position along with it.

It is a structure rather than a set of answers, which is easy to resent and is the correct design. What counts as acceptable differs by organisation and by use, so a framework that specified thresholds would be wrong nearly everywhere; what it can usefully fix is the order of the questions and who is expected to answer each one.

The common failure is adopting the vocabulary and not the practice. An organisation that produces a document with four headings and no named owners has borrowed the shape of the thing, and the part that would have changed a decision is the part it left behind.

The order the four functions are meant to run in

The order the four functions are meant to run inOrganisations reliably enter this sequence at the third step. Measuring is concrete, it produces numbers, and it feels like the technical heart of the exercise, whereas governing looks like deciding who attends a meeting. The consequence shows up later and is always the same: an assessment lands with findings, nobody has been given the authority to act on them, and the document becomes a record of a concern rather than a cause of a change. Starting at Govern costs a conversation and answers three questions that make everything downstream binding, which are who owns this, what position has the organisation taken, and who is able to stop a deployment. Map matters more than it looks too, because most of what goes wrong with a bought tool comes from what it reaches rather than from how the model behaves. By the time an organisation reaches Measure with those two settled, it is measuring something specific for somebody who can act on the answer, which is the difference between an exercise and a control.so findings willhave an ownerso you measurethe right thingso somebody canact on itGovernWHO OWNS IT, WHO CAN SAY NOMapWHAT IT IS FOR, WHAT ITTOUCHESMeasureHOW IT BEHAVES, TESTEDManageWHAT WE DO ABOUT IT
Organisations reliably enter this sequence at the third step. Measuring is concrete, it produces numbers, and it feels like the technical heart of the exercise, whereas governing looks like deciding who attends a meeting. The consequence shows up later and is always the same: an assessment lands with findings, nobody has been given the authority to act on them, and the document becomes a record of a concern rather than a cause of a change. Starting at Govern costs a conversation and answers three questions that make everything downstream binding, which are who owns this, what position has the organisation taken, and who is able to stop a deployment. Map matters more than it looks too, because most of what goes wrong with a bought tool comes from what it reaches rather than from how the model behaves. By the time an organisation reaches Measure with those two settled, it is measuring something specific for somebody who can act on the answer, which is the difference between an exercise and a control.
03

Seen in the wild

  • Deciding who owns the call on deploying an assistant before assessing anything about it.

    ChatGPT
  • Extending an existing governance habit to cover AI-specific questions.

    Vanta
  • Reusing evidence collection already in place rather than starting a separate exercise.

    Drata
04

Common misconceptions

People assume

Voluntary means it can be ignored.

In fact

Voluntary means nothing compels its use, and its value was never compulsion. It is a set of headings that already exist, which matters most to organisations whose alternative is inventing their own structure on a blank page.

People assume

It is for organisations building AI.

In fact

Its stated purpose covers use and evaluation alongside design and development. Most of what an organisation buying AI needs to work through fits the same four functions as what a builder needs.

05

Questions

Does anything require us to use it?
No. It is intended for voluntary use and nothing in it operates as a legal obligation. Organisations adopt it anyway, because having agreed headings and a shared vocabulary is worth more than the effort of inventing an equivalent structure themselves, and because a borrowed structure is easier to defend than a bespoke one.
Where do organisations go wrong with it?
They start at measurement, because measuring feels like progress and governing feels like meetings. Deciding who owns the question and who can stop a deployment comes first for a reason: without that, an assessment produces findings nobody is obliged to act on.
Is it useful if we only buy AI tools?
Yes, and that is the more common case. The framework covers use and evaluation as well as building, and the questions a buyer faces about who decided, what could go wrong and who is watching map onto the same four functions.
06

Key takeaways

  • Voluntary: its value is ready-made headings, not compulsion.
  • Four functions carry it: Govern, Map, Measure, Manage.
  • Govern comes first; starting at measurement is the usual mistake.
  • It covers use and evaluation, so buyers are inside its scope.
08

Tools that use this

  • ChatGPT

    Deciding who owns the deployment call before assessing anything.

  • Vanta

    Extending an existing governance habit to AI questions.

  • Drata

    Reusing evidence collection rather than starting fresh.

Last checked August 2026

All glossary terms