MAKE ME RICH

ENTITY / Technology

AI risk management: from impressive output to responsible use

A practical introduction to assessing an AI system in context using the NIST Govern, Map, Measure and Manage functions.

9 MIN READUPDATED 20 AUGUST 20262 PRIMARY / OFFICIAL SOURCES

QUICK ANSWER

The useful idea.

AI risk management is a continuous process for understanding a system's context, possible impacts, evidence and controls. NIST organises this work around four connected functions: Govern, Map, Measure and Manage.

FrameworkVoluntary

The AI RMF is a general risk-management resource, not a product certification.

CoreGovern · Map · Measure · Manage

The functions are connected and intended for continuous use.

Unit of analysisSystem in context

Performance alone does not describe human, organisational and societal impacts.

01

Start with the use, not the label

Two products may use similar models while creating different risks because their users, stakes, data and deployment settings differ. Mapping the context clarifies who may benefit, who may be harmed and which failures matter.

A low-stakes drafting assistant and a system influencing access to employment should not be evaluated with the same evidence threshold.

02

Measures need decisions attached

Accuracy, robustness, privacy, explainability and fairness can involve several measures. A number becomes useful when it is connected to a threshold, comparison or action and when the evaluation data resemble the real setting.

Human review is not a magic safeguard. Reviewers need time, authority, relevant information and a clear escalation path. Evaluation should include foreseeable misuse and the experience of people affected by errors, not only the operator's preferred scenario.

03

Treat management as a loop

Governance defines responsibility and risk tolerance. Mapping describes context. Measurement gathers evidence. Management prioritises and responds. Deployment then creates new evidence, which should return to the earlier functions.

The framework does not certify that a system is trustworthy. It helps organisations make assumptions, evidence and trade-offs visible enough to challenge and improve. Documentation should therefore record owners, thresholds, incidents, changes and unresolved risks throughout the system lifecycle.

CONNECTED KNOWLEDGE

Entities on this page

Technology fieldArtificial intelligenceAlso: AIOPEN ENTITY →Standards instituteNISTAlso: National Institute of Standards and TechnologyOPEN ENTITY →

SOURCE DESK

Open the evidence

Important facts and definitions are traced to these primary, governmental or institutional sources. The explanation above is original; links let you inspect the underlying context and updates.

  1. Official voluntary framework and its Govern, Map, Measure and Manage functions.

    Accessed 20 August 2026
  2. Public terminology resource for AI risk and trustworthiness.

    Accessed 20 August 2026

CONNECTED DISCOVERY

One answer should open another.

These destinations share a subject, entity or editorial relationship with this page. They are recommendations, never paid placements.

Keep reading

Related entities

Compare the ideas

Current context

Test what you learned