xmodoxmodo

Frameworks · Global standards

NIST AI RMF 1.0

The NIST AI Risk Management Framework 1.0, released on 26 January 2023, is a voluntary framework for identifying, assessing and managing the risks of AI systems. It has four functions. Govern sets culture, accountability and policy across the organisation. Map, Measure and Manage frame, assess and treat the risks of each system.

Who it applies to

It suits organisations that develop, buy or deploy AI systems and want a recognised structure for AI risk. It also helps organisations whose customers or regulators cite the framework.

Main requirements

Govern

The organisation sets policies, roles, accountability and oversight for AI risk.

Map

For each AI system, the organisation records its context, intended use, stakeholders and risks.

Measure

Risks are assessed and tracked against defined metrics, including trustworthiness characteristics.

Manage

Risks are prioritised, treated and monitored, with response plans for incidents.

How xmodo supports it

  • 1

    AI systems, including models and AI-enabled vendors, are recorded in the asset register with an owner and a risk profile.

  • 2

    The four functions are set up as controls with evidence, so the AI risk register uses the same data as enterprise risk.

  • 3

    Requirements map to ISO/IEC 42001 and the EU AI Act, so one AI governance programme covers the voluntary framework, the certifiable standard and the regulation.

Related frameworks

NIST AI RMF 1.0 shares requirements with the frameworks below. Controls you already run for any of them count towards NIST AI RMF 1.0 as well.

Frequently asked questions

Can we get certified against the AI RMF?

No. It is a voluntary framework. ISO/IEC 42001 is the certifiable AI management system standard, and the EU AI Act is the regulation. xmodo runs all three in one programme.

See how xmodo works for your organisation

Get a demo on the frameworks that apply to you.

Get a demo