NIST AI Framework Guides Risk

The NIST Artificial Intelligence Risk Management Framework (AI RMF) 1.0 provides organisations with a structured, voluntary approach to identifying, assessing and managing risks associated with artificial intelligence throughout its lifecycle. The framework is designed to help organisations incorporate trustworthiness considerations into the design, development, deployment and use of AI systems.

The framework is built around four core functions: Govern, Map, Measure and Manage. NIST describes these functions as an interconnected approach rather than a rigid sequence or checklist. Governance operates across the other three functions, while risk management is expected to continue throughout the AI system lifecycle.

1. Govern

The Govern function establishes the organisational foundation for AI risk management.

It covers policies, processes, responsibilities, risk tolerance and organisational practices needed to identify and manage AI risks. It also connects technical AI development with organisational values, legal and regulatory requirements and strategic priorities.

NIST emphasises that governance should address the full AI product lifecycle, including risks associated with third-party software, hardware and data.

2. Map

The Map function focuses on understanding the context in which an AI system operates and identifying the risks associated with that context.

Organisations should understand the system’s intended purpose, users, operating environment, applicable laws and potential positive and negative impacts.

This stage is important because the same AI technology can present very different risks depending on how and where it is deployed. NIST also encourages organisations to incorporate multidisciplinary and external perspectives where appropriate.

3. Measure

The Measure function involves assessing and monitoring identified AI risks using quantitative, qualitative or mixed methods.

AI systems should be tested before deployment and regularly during operation. Measurement can cover system performance, reliability, security, fairness, transparency and other characteristics of trustworthy AI.

NIST also stresses the importance of documenting uncertainty, testing results and potential impacts. Independent review can strengthen evaluation by reducing internal bias and conflicts of interest.

4. Manage

The Manage function converts risk assessments into action.

Organisations prioritise risks according to factors such as impact, likelihood and available resources, then determine appropriate responses. These can include mitigation, transfer, avoidance or acceptance.

The framework also calls for documented response and recovery arrangements, incident management, monitoring and mechanisms for continual improvement.

Trustworthy AI Characteristics

The framework also identifies characteristics associated with trustworthy AI, including:

  • Validity and reliability
  • Safety
  • Security and resilience
  • Accountability and transparency
  • Explainability and interpretability
  • Privacy enhancement
  • Fairness with harmful bias managed

These characteristics provide a basis for evaluating whether an AI system is appropriate for its intended purpose.

Why the Framework Matters for BFSI

The NIST approach has particular relevance to banks, insurers and other financial institutions because AI is increasingly being applied to fraud detection, credit assessment, underwriting, customer service, compliance and risk management.

For example, an AI credit system cannot be evaluated solely on predictive accuracy. Banks may also need to examine data quality, fairness, explainability, cybersecurity and the ability to monitor changes in performance after deployment.

Similarly, an AI-based insurance underwriting system needs ongoing monitoring because changes in data, models, customer behaviour or operating conditions can alter its risk profile.

The framework’s emphasis on continuous lifecycle management is therefore particularly relevant. NIST states that the four functions should continue as knowledge, methodologies, risks, system capabilities and expectations change.

The framework is currently being revised by NIST, with a revised version in progress. NIST also released a concept note in April 2026 for a Critical Infrastructure Profile addressing trustworthy AI practices for critical infrastructure operators.

The broader message is that AI governance should not be treated as a one-time approval exercise. Effective AI risk management requires governance, contextual risk identification, measurable controls, ongoing monitoring and documented responses throughout the AI lifecycle.

Want to deepen your expertise beyond today’s news?

Explore practical certification courses designed for banking, risk, insurance, compliance, ESG, AI, and emerging technologies professionals.

Learn from industry experts and earn certifications from RMAI and BFSI Sector Skill Council of India.

#Riskmanagementnews

author avatar
RMA INDIA

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.