NIST AI RMF 1.0
Voluntary framework for managing AI risks and incorporating trustworthiness considerations across design, development, deployment and use.
Voluntary framework for managing AI risks and incorporating trustworthiness considerations across design, development, deployment and use.
Cross-sectoral voluntary framework that can be adapted to organisational context and risk tolerance.
Not a standalone law; often used as a risk-management reference and assurance basis.
Voluntary framework for managing AI risks and incorporating trustworthiness considerations across design, development, deployment and use.
Establish accountable governance, policies, roles and risk culture for AI.
Actor: all · Domain: governance
Evidence: Governance charter, roles, policy set and review records.
Prioritise, treat, monitor and communicate AI risks over the lifecycle.
Actor: all · Domain: risk management
Evidence: Risk register, treatment plan, residual-risk acceptance and monitoring.
Document intended purpose, context, affected parties, dependencies and foreseeable risks.
Actor: all · Domain: risk classification
Evidence: Use-case dossier, stakeholder analysis and risk map.
Use fit-for-purpose measurements and evaluations to understand system performance and risk.
Actor: all · Domain: evaluation
Evidence: Evaluation plan, test evidence, thresholds and limitations.
Cybatar's mapping is designed for AI governance and assurance work. Legal interpretation remains anchored to the current primary text and competent authority guidance.
Open NIST source