Resource · Quick Reference

NIST AI RMF Quick Reference

Key Takeaway

The NIST AI Risk Management Framework organizes AI risk work into four functions: Govern, Map, Measure, and Manage. It is voluntary guidance, not a certification, which makes it a common starting structure for organizations building an AI governance program.

The framework is sector-agnostic and deliberately flexible. Rather than prescribing controls, it gives organizations a shared vocabulary for deciding who is accountable, where AI is used, how risk is tracked, and how issues are closed. The table below is a plain-language reference for each function.

The four functions at a glance

FunctionIn plain languageWhat it typically produces
GovernWho decides, and who is accountable.A charter, named owners, policies, and a review rhythm.
MapWhere AI is used and who it affects.A use-case inventory and a record of context and affected groups.
MeasureHow risk and performance are tracked.Defined measures, testing records, and findings that can be compared over time.
ManageHow issues are prioritized, owned, and closed.A risk register, assigned actions, and an incident response path.

Questions each function tends to raise

Govern

Accountability and structure
  • Who has authority to approve or stop an AI use?
  • Is there a written statement of how AI may and may not be used?
  • How often is the arrangement reviewed?

Map

Context and inventory
  • Is there one list of every AI use, with a named owner for each?
  • Who does each use affect, inside and outside the organization?
  • Which uses rely on third-party models or data?

Measure

Tracking and evidence
  • What is measured for each use, and by whom?
  • How are accuracy, bias, and reliability tested before and after launch?
  • Where are the results recorded?

Manage

Action and follow-through
  • How are risks ranked and assigned an owner?
  • What happens when a measure falls outside its expected range?
  • How do closed issues feed back into the inventory?

Where the other resources fit

The functions are not steps to complete once. Many organizations start with the use-case inventory (Map) and the charter (Govern), then build measurement and response around them. See the inventory template and the charter worksheet.

In Practice

A team uses the four functions as headings on a one-page plan. Under Govern it names an approver. Under Map it lists its AI uses. Under Measure it picks one measure per use. Under Manage it assigns an owner to each open issue. The framework supplies the structure, and the organization supplies the content.

Next step

Turn the four functions into a working program.

We map your current AI use to Govern, Map, Measure and Manage, show where the gaps are, and give you an action roadmap.

Related ToolBenchmark where you stand: take the AI Governance Readiness Assessment → Working With UsWant help applying this to your organization? See how we work →
This resource is a working template provided by 360° CyberSecure for informational purposes only. It does not constitute legal, regulatory, or compliance advice, and it is not a substitute for review by qualified counsel.