Skip to main content

Evidence note

Artificial Intelligence Risk Management Framework 1.0

Government Guidance2023National Institute of Standards and Technology

What does it cover?

A voluntary risk-management framework for organisations designing, developing, deploying or using AI systems.

Key points

  1. 1The framework is organised around Govern, Map, Measure and Manage.
  2. 2It treats AI risk management as contextual and continuous rather than a universal checklist.
  3. 3It identifies multiple trustworthy-AI characteristics, including validity, reliability, safety, security, resilience, transparency and privacy.

Why it matters. Lornets interpretation.

AI assurance should begin with operating context and evidence rather than applying identical controls to every AI use case.

This is the Lornets reading of the source, not a finding of the source itself.

What it does not establish

  1. 1Using the framework does not certify an individual AI system.
  2. 2The framework is voluntary.
  3. 3NIST has announced that AI RMF 1.0 is being revised.

Source

Organisation
National Institute of Standards and Technology
Evidence type
Government Guidance
Published
2023
Status
Current. Current, revision underway.

View official guidance

Relevant Lornets framework areas

Framework domains

  • AI Assurance
  • Security & Access Control
  • Data & Privacy Engineering
  • Reliability & Recoverability

Related evidence

Last verified 2026-08-11

2024

Government Guidance

NIST AI 600-1: Generative Artificial Intelligence Profile

The profile addresses risks including confabulation, data privacy, information integrity, information security and component integration.

National Institute of Standards and Technology

  • AI Assurance
  • Security & Supply Chain

2022

Government Guidance

NIST Secure Software Development Framework v1.1

SSDF organises secure-development practices into a structured set of outcomes rather than prescribing one development methodology.

Current, revision underway

National Institute of Standards and Technology, SP 800-218, SSDF v1.1

  • Security & Supply Chain
  • Software Quality & Maintainability