Skip to main content
Lornets

Evidence note

Artificial Intelligence Risk Management Framework 1.0

Government Guidance2023National Institute of Standards and Technology

What does it cover?

A voluntary risk-management framework for organisations designing, developing, deploying or using AI systems.

Key points

  1. 01The framework is organised around Govern, Map, Measure and Manage.
  2. 02It treats AI risk management as contextual and continuous rather than a universal checklist.
  3. 03It identifies multiple trustworthy-AI characteristics, including validity, reliability, safety, security, resilience, transparency and privacy.

Why it matters. Lornets interpretation.

AI assurance should begin with operating context and evidence rather than applying identical controls to every AI use case.

This is the Lornets reading of the source, not a finding of the source itself.

What it does not establish

  1. 01Using the framework does not certify an individual AI system.
  2. 02The framework is voluntary.
  3. 03NIST has announced that AI RMF 1.0 is being revised.

Source

Organisation
National Institute of Standards and Technology
Evidence type
Government Guidance
Published
2023
Status
Current. Current, revision underway.

View official guidance

Relevant Lornets framework areas

Framework domains

  • AI Assurance
  • Security & Access Control
  • Data & Privacy Engineering
  • Reliability & Recoverability

Related evidence

Government Guidance

2022

NIST Secure Software Development Framework v1.1

National Institute of Standards and Technology, SP 800-218, SSDF v1.1

SSDF organises secure-development practices into a structured set of outcomes rather than prescribing one development methodology.

  • Security & Supply Chain
  • Software Quality & Maintainability

Current, revision underway

Read Evidence Note

Source record

Published
2023
Last verified
2026-08-11
Source status
Current. Current, revision underway.