A voluntary American framework organizing AI system risk management into four functions, now the common vocabulary of audits.
The American framework for managing artificial intelligence risk is voluntary and carries no binding force, which explains both its rapid spread and its limits. It organizes the work into four functions, govern, map, measure and manage, the first cutting across the other three, and it defines seven characteristics of a trustworthy system, among them validity, safety, security, accountability, explainability and fairness. Its real contribution is lexical rather than methodological, since those functions resemble any risk management arrangement, but it supplies shared vocabulary letting an insurer, an auditor and an operator name the same thing, which a field where every actor used its own words badly lacked. For underwriting it has become the standard line of questioning in policies covering liability attached to an AI system, the insurer asking which functions are documented rather than whether the model is good.
The United States National Institute of Standards and Technology published the first version of its AI Risk Management Framework on 26 January 2023, supplemented in July 2024 by a profile devoted to generative artificial intelligence.
AI RMF, NIST AI RMF, cadre NIST IA