Skip to content

Governance, Law & Compliance

NIST AI Risk Management Framework

A voluntary guide from the US National Institute of Standards and Technology for managing AI risks.

Example

A team uses its Govern, Map, Measure and Manage functions to structure oversight.

Why people use it

It gives organizations a shared way to organize AI risk work.

What you'll hear

“Let's use the framework to organize the review.”

What this means for you

Use it to organize concrete responsibilities and evidence about risks.

Can you control it?

Yes

Yes. An organization can choose to use the guide and decide who carries out its recommended risk-management work.

Common questions

Is using the framework itself a legal following the rules certificate?
No. It is guidance, not a guarantee of following the rules or safety.
Is it a law?
No. It is a voluntary framework, although an organization may choose to require its use internally.
Does using it certify an AI product?
No. Following a framework does not by itself certify a product or guarantee safe performance.

Related terms

Still have questions?

Up to 500 characters.

Ask LATHIC about AI. Relevant glossary entries may be included.

Your question, the glossary entries it matches, and a rotating pseudonymous identifier go to Microsoft Azure’s OpenAI service through Vercel AI Gateway to generate an answer. Zero retention and no training are required of the provider, and LATHIC does not save your question or answer. Privacy Notice