What it is, and what it is not
The NIST AI Risk Management Framework is published by the United States National Institute of Standards and Technology. It is voluntary, not certifiable and not prescriptive: it does not tell you which controls to implement, but how to structure the conversation about AI risk inside an organisation.
Those three characteristics tend to be read as weakness and are the opposite. A company that does not yet know which AI it uses is in no position to take on a certification. The NIST framework lets you start on Monday, with no auditor, no formal scope and no committed timeline.
It also includes a specific profile for generative AI, which is the part most organisations care about: it addresses risks such as information leaking through prompts, model confabulation, intellectual property and provider dependency.
The four functions
| Function | What it resolves |
|---|---|
| Govern | Cuts across the other three. Defines who is accountable, what policy exists, how decisions are taken and how they are documented. Without it, the others produce information nobody uses |
| Map | Identify the context: which AI systems exist, what they are used for, who is affected and what can go wrong. This is where almost every organisation discovers its mental map does not match reality |
| Measure | Analyse and track the identified risks with concrete metrics. Here the framework separates from a theoretical exercise: it demands numbers and movement over time |
| Manage | Prioritise and act: mitigate, transfer, accept or avoid each risk, and record the decision and its reason |
Why it is useful even for a European company
It is a US framework, but it has become an international reference through three routes:
- Supply chain. It arrives as a requirement from a parent company or a US customer.
- Crosswalks to other frameworks. Published mappings exist between the NIST framework and ISO 42001. Work done for one carries over to the other.
- Preparation for the EU AI Act. The inventory, the risk assessment and the documented decisions the European regulation requires are the same things this framework produces.
Put another way: it is the draft. ISO 42001 is the certifiable version and the EU AI Act is the legal obligation. Starting with the draft is not wasting time, it is doing it in the right order.