Skip to content
NakodaAI
← Research & Resources

StandardNIST (U.S. Department of Commerce)2023-01-26

Artificial Intelligence Risk Management Framework (AI RMF 1.0)

By National Institute of Standards and Technology

A voluntary framework organised around four functions - Govern, Map, Measure, Manage - for identifying, assessing and treating the risks of designing, developing or deploying AI systems.

Why it matters

AI RMF is the most widely adopted vocabulary for AI risk management outside a specific legal jurisdiction, which is exactly why it travels well: a UAE company can use its four functions to structure a governance programme without importing US law along with it.

Key takeaways

  • Four core functions: Govern (accountability and policy), Map (context and risk identification), Measure (analysis and tracking), Manage (resourcing and response).
  • Treats AI risk as socio-technical - harms can come from data, deployment context and human oversight, not only from model code.
  • Explicitly sector-agnostic and voluntary: it is a vocabulary and a process, not a compliance checklist tied to one law.
  • Companion NIST AI RMF Playbook gives suggested actions for each function, useful as an implementation starting point.

UAE / MENA relevance

Referenced informally by UAE-based governance and audit practice as a structuring tool even though the UAE has no equivalent mandatory federal framework yet - it is the practical middle ground between the UAE's own strategy documents and a certifiable standard like ISO/IEC 42001.

Part of these reading paths

Related

Also worth reading

Policy documentUK Government (host); signed by 28 states + EU, later 29 + EU2023-11-01

The Bletchley Declaration by Countries Attending the AI Safety Summit

The declaration signed at the UK's AI Safety Summit at Bletchley Park committing signatory states - including the US, China, the EU and the UAE - to international cooperation on frontier-AI safety.

  • AI Governance & Policy
  • AI Safety & Alignment
  • UAE & MENA AI