The quick read
- A shared structure can help teams connect technical findings to accountable decisions.
- Describe the intended use, identify important failure modes and decide how they will be measured.
The framework in context
NIST released AI Risk Management Framework 1.0 in January 2023 and a generative AI profile in July 2024. The framework is intended for voluntary use in the design, development, use and evaluation of AI systems. Its core functions—Govern, Map, Measure and Manage—organise work that continues throughout deployment.
What a framework can do
A shared structure can help teams connect technical findings to accountable decisions. It does not certify a product or eliminate uncertainty. The usefulness comes from applying it to a real system, with named owners and evidence about the people and processes affected.
How to begin
Describe the intended use, identify important failure modes and decide how they will be measured. Record which risks are accepted, mitigated or escalated, then revisit the assessment when the system changes. Use NIST’s official resources to select practices appropriate to the context.
Sources & notes
AI-assisted editorial content checked against the linked sources.
Sources reviewed for the September 2026 launch edition.