OnwynStandards › NIST AI Risk Management Framework 1.0

Scheme / framework · 1.0

NIST AI Risk Management Framework 1.0

The NIST AI Risk Management Framework is a voluntary, non-certifiable framework for managing the risks of designing, developing, deploying, and using AI systems — organized into four functions: Govern (the standing organizational machinery), Map (understanding each system in context), Measure (testing and tracking trustworthiness), and Manage (acting on what you find). It is US-origin but globally used, maps well onto ISO/IEC 42001 and EU AI Act work, and is a common reference in enterprise due diligence. This pack translates each framework category into a concrete activity an SME deploying or building AI can actually execute — the goal is trustworthy AI in practice: valid, safe, secure, accountable, explainable, privacy-enhanced, and fair.

25
Requirements
4
Areas
12
Recommended documents
0
Mapped frameworks
Start NIST AI Risk Management Framework 1.0 free Have us do it instead

What this standard asks for

Every requirement in NIST AI Risk Management Framework 1.0, grouped the way the standard groups them. In the Compliance Engine each one carries what to do, how to evidence it, what auditors commonly reject, and a button to bring in a consultant if you would rather not work it out alone.

Govern — policies, accountability & culture

6 requirements

  • GV-1Policies, processes and legal awareness for AI risk
  • GV-2Accountability structures — who owns AI risk
  • GV-3Workforce diversity and multidisciplinary input
  • GV-4Risk culture — critical thinking and safety-first norms
  • GV-5Engagement with external stakeholders and feedback
  • GV-6Third-party AI risk policies

Map — context, categorization & risk identification

5 requirements

  • MP-1Establish the context for each AI system
  • MP-2Categorize each AI system
  • MP-3Understand capabilities, usage and benefits realistically
  • MP-4Map risks from third-party components and data
  • MP-5Characterize impacts on individuals, groups and society

Measure — testing & trustworthiness tracking

9 requirements

  • MS-1Choose metrics and methods — a working TEVV practice
  • MS-2.1Measure validity and reliability
  • MS-2.2Measure safety — outputs that could cause harm
  • MS-2.3Measure security and resilience
  • MS-2.4Measure transparency, accountability and explainability
  • MS-2.5Measure privacy protection
  • MS-2.6Measure fairness and manage harmful bias
  • MS-3Track identified risks and surface the unexpected
  • MS-4Validate that measurement itself works

Manage — treatment, monitoring & response

5 requirements

  • MG-1Prioritize and treat AI risks by documented tolerance
  • MG-2Sustain value and prepare for failure
  • MG-3Manage third-party AI risks operationally
  • MG-4Monitor, respond to incidents, and improve
  • NIST-AI-600-1Generative AI Profile — extend the framework to GenAI use

The documents you will end up with

The recommended document set for NIST AI Risk Management Framework 1.0 — 12 in total. The engine tracks which you have, which are missing, and which of your existing documents already cover a requirement.

AI Risk Management Policy

The written rules for how AI risk is handled here, and the legal and regulatory obligations the organisation has decided apply to it.

AI Accountability Map

Who owns AI risk for each system, who can pause a deployment, and where the decision sits when teams disagree.

Stakeholder Engagement and Feedback Plan

How people outside the build team — users, affected groups, domain experts — get to raise concerns, and what happens to what they say.

Third-Party AI Policy

What you require of vendors, models and datasets you did not build, and how you keep watching them after procurement.

AI System Context Record

For each system: what it is for, where it sits in the business, what it can and cannot realistically do, and how you categorised it.

Component and Data Provenance Map

Where the models, libraries and training data came from, and what risk each of those origins carries.

Impact Characterization

Who could be affected by this system and how, including groups who never chose to interact with it.

Test, Evaluation, Verification and Validation Plan

What you measure about an AI system, with which methods and thresholds, and how you check the measurement itself is telling you the truth.

AI Evaluation Report

The results: how the system performs on validity, safety, security, explainability, privacy and bias, and what the numbers do not cover.

AI Risk Register

The live list of identified AI risks with tolerance, priority, treatment and owner — plus somewhere to log the ones nobody predicted.

AI Monitoring and Incident Response Plan

How deployed systems are watched for drift and failure, what the shutdown or rollback path is, and how incidents feed back into the design.

Generative AI Profile Addendum

The extra risks that only show up with generative systems — confabulation, harmful content, prompt injection, information leakage — and what you do about each.

Start NIST AI Risk Management Framework 1.0 today

Every live framework is included in one subscription — no per-framework pricing. Your first 30 days are free, we ask for no card, and there is nothing to cancel. On any requirement you can bring in a senior consultant for a review, a call, or done-for-you implementation.