O Oluma Cyber Security Framework Files · No. 17 Framework · AI Risk Management NIST AI RMF The voluntary playbook for trustworthy AI — the same calm, structured thinking NIST brought to cybersecurity, now aimed at the unique risks of artificial intelligence. v1.0 · 20234 Functions7 Trust TraitsGen-AI Profile 2024 RMF GOVMAPMEASMNG How we’ll read this 01 The Problem02 Why It Exists03 The Story04 How It Works05 Example06 Who Uses It07 Career08 Strengths & Challenges09 Takeaway 01 The Problem How do you manage a risk you can’t fully see? AI risk is genuinely strange. A model can be biased in ways no one intended, confidently wrong, impossible to fully explain, or vulnerable to attacks that don’t exist for ordinary software. Traditional risk frameworks weren’t built for systems that learn, drift, and surprise you. Organizations rushing to deploy AI had no shared way to reason about these risks — or even a common vocabulary for what “trustworthy AI” actually means. 02 Why It Was Created A common language for trustworthy AI NIST built the AI Risk Management Framework to do for AI what its Cybersecurity Framework did for security: provide a voluntary, flexible structure and a shared vocabulary for managing risk — without dictating specific technology. The core ideaFirst define what “trustworthy” means, then give organizations functions to manage toward it — governing, understanding context, measuring, and responding — so AI risk becomes a discipline, not a guess. It’s deliberately not a law and not certifiable — it’s the thinking tool underneath compliance, usable by anyone building or buying AI. 03 The Story Behind It Built for AI, updated for the generative wave 2023AI RMF 1.0Released in January 2023, modeled on the Cybersecurity Framework so the two could be used together, and defining what trustworthy AI means. 2024The Generative AI ProfileAs foundation models exploded, NIST added a companion profile identifying risks unique to generative AI — and suggested actions to manage them. 2026Still the referenceVersion 1.0 remains the finalized core (a revision is underway), while new profiles — for critical infrastructure and beyond — keep extending it to fresh contexts. 04 How It Works Four functions, seven traits of trust The framework runs on four functions that work together, not in a strict line — the same intuitive shape as the Cybersecurity Framework, so teams already fluent in CSF feel at home. GovernMapMeasureManage Govern sets the culture and accountability; Map establishes context and identifies risks; Measure analyzes and tracks them; Manage acts on them. Underneath sits a definition of what trustworthy AI should be: 01 Valid & reliable 02 Safe 03 Secure & resilient 04 Accountable & transparent 05 Explainable & interpretable 06 Privacy-enhanced 07 Fair — bias managed + Profiles: current → target AI RMF vs. the EU AI Act vs. ISO 42001The AI RMF is the voluntary method; the EU AI Act is a binding law; ISO/IEC 42001 is the certifiable management system. Many organizations use the RMF to operationalize what the law requires and the ISO standard certifies. 05 Real-World Example A company brings order to its AI adoption A company is deploying AI across several teams and wants to do it responsibly — without a heavy legal mandate forcing its hand. It adopts the AI RMF to build a current-to-target roadmap, exactly like a CSF profile. Their AI RMF rolloutGovern first, then map, measure, manage Govern — set AI policies, roles, and accountability Map — catalog AI use cases and their context and risks Measure — test for bias, robustness, and reliability Manage — prioritize and act on the biggest risks Layer the Generative AI Profile onto its LLM tools The result is a shared vocabulary for AI risk across every team — and a defensible story to show regulators and customers. 06 Who Uses It The common backbone of AI governance 🧠AI builders & deployersOrganizations developing or adopting AI who want a structured way to manage its risks. 🌍Global enterprisesThough US-origin and voluntary, it’s become a common worldwide backbone for AI risk programs. ⚖️Regulated & public sectorBodies that reference it as a benchmark for responsible AI, often alongside binding rules. It’s the connective tissue between AI law and AI certification. pairs with EU AI Actcertifiable via ISO 42001mirrors NIST CSFoverlaps Privacy Framework 07 Career Relevance Get fluent before everyone else does AI governance roles are being created faster than people can fill them, and the AI RMF is the shared language of the field. Because it mirrors the Cybersecurity Framework, anyone who knows CSF has a real head start. AI risk analystRun the functionsOperate Govern/Map/Measure/Manage across an organization’s AI portfolio. Responsible-AI leadBuild the programTurn the trustworthy-AI traits into policies, testing, and oversight that actually hold. GRC professionalBridge to the restConnect the AI RMF to the EU AI Act, ISO 42001, and your existing CSF program so one effort serves many. If CSF was the credential of the last decade, AI RMF fluency is shaping up to be the credential of the next. 08 Strengths & Challenges Honest trade-offs ✦ Strengths A shared vocabulary for trustworthy AI Flexible, voluntary, and scalable to any size Mirrors the Cybersecurity Framework — easy to adopt Profiles turn it into a real roadmap Helps operationalize binding AI laws ⚠ Challenges Voluntary — rigor depends on your discipline Not certifiable on its own (pair with ISO 42001) Measuring AI risk is genuinely hard Guidance is still maturing as AI evolves 09 Final Takeaway The AI RMF brings calm structure to the messiest new risk in technology.It won’t hand you the answers, but it gives an organization one shared way to ask the right questions about AI — govern, map, measure, manage — built on the same instincts as the Cybersecurity Framework. Learn it now, and you’re fluent in the language AI governance is being built on.