RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026Start here · 100 retrospective records ↗
AI Use Field Guide

Start here / Privacy & safety

Privacy & safety / From the archive · 26 January 2023 event · prepared 16 September 2026

A US standards agency split AI risk into four working parts

NIST's voluntary framework organizes AI risk management into four functions and was built with input from over 240 organizations, NIST states.

Visual for this record: nist-ai-risk-management-framework-2023
Visual published by nist.gov, shown for identification of the record. Credit: nist.gov · source page ↗ Rights: owner-review-pending.

Start here

'Manage AI risk' is not a task a person or team can act on directly; it needs breaking into steps a workplace can do. On 26 January 2023 the US National Institute of Standards and Technology released the AI Risk Management Framework, a voluntary document built, NIST states, over eighteen months with input from more than 240 organisations. For a reader who is not a developer, the framework matters less as a technical manual and more as a vocabulary: it gives four named functions that any organisation using AI can be asked whether it performs.

What the documents say

The framework's overview page, current as retrieved on 16 September 2026, describes it as intended 'to improve the ability to incorporate trustworthiness considerations into the design, development, use, and evaluation of AI products, services, and systems,' organised around four functions: govern, map, measure, and manage. NIST's announcement quotes then-Director Laurie Locascio saying the framework 'can help companies and other organisations in any sector and any size to jump-start or enhance their AI risk management approaches,' and then-Deputy Commerce Secretary Don Graves framing the goal as advancing 'civil rights, civil liberties and equity for all' alongside innovation. The announcement names the problem AI risk poses compared with older software: models are trained on data that keeps changing and are shaped by social context, making effects on people, from chatbots to hiring, harder to predict than with conventional programs.

Check this

A reader cannot run NIST's framework, but can use its four functions as questions for any organisation deploying AI that affects them: does it govern, meaning clear ownership of AI risk; does it map, meaning it has identified where AI is used; does it measure, meaning it tests for and tracks problems; and does it manage, meaning it acts on what measurement finds. Asking which of the four an organisation cannot answer is more useful than asking whether their AI is 'responsible,' a term the framework does not certify.

What holds and what fails

The framework holds as shared vocabulary: voluntary and sector-neutral, it can be referenced by a hospital, school district, or vendor without new legislation, and its four functions appear, renamed, across other guidance including the CISA-NCSC secure AI guidelines. It fails as an enforcement mechanism: NIST does not audit compliance, and citing the framework's name is not the same as an organisation having implemented any of its four functions. Treat a company's reference to it as a claim worth following up, not evidence on its own.

  • Ask an organisation which of govern, map, measure, or manage it can describe concretely for its AI use.
  • Do not accept a reference to 'the NIST framework' alone as proof of any specific safeguard.
  • Compare a vendor's stated AI risk practices against the framework's four functions, not just its own language.

The framework's real contribution is a shared way of talking about a diffuse problem; whether an organisation using AI actually does the governing, mapping, measuring, and managing it names is a separate question this document cannot answer.

Sources & reading trail

NIST Risk Management Framework Aims to Improve Trustworthiness of Artificial Intelligence ↗

Announces the framework's release, its four functions, development process, and quotes from NIST and Commerce officials.

Source published: 26 January 2023 · Retrieved: 16 September 2026

AI Risk Management Framework ↗

Living overview page describing the framework's purpose, voluntary status, and intended broad organisational use.

Source published: Not established · Retrieved: 16 September 2026

Documentation, regulator guidance and studies establish the record; the checks and the boundary are AI Use Field Guide editorial analysis. This retrospective draft does not imply the site published on the event date.