National Institute of Standards and Technology mark.

NIST AI 100-1 presents the voluntary AI Risk Management Framework. Its Core uses Govern, Map, Measure and Manage to organise work on AI-related risks, with governance operating across the other functions. See the AI RMF 1.0 publication.

Use in a programme

Define the AI system, intended use, affected people and organisational responsibilities. Identify relevant risks and evaluate them in context, then decide how to respond and monitor the result.

The functions support ongoing risk management; they are not a guarantee that an AI system is trustworthy in every situation or a fixed sequence that must be completed only once.

Use in CSFaaS

The reviewed library lists NIST AI 100-1 - EN. Check the source edition, assign responsibility for the relevant outcomes and connect policies and evidence to the assessment.

Document AI-system risks and treatment decisions in the wider risk workflow. Prompt instructions and integration settings may support particular activities, but their existence does not demonstrate completion of an AI risk-management programme.

Keep source outcomes, workspace adaptations and assurance evidence distinct so reviewers can understand what has actually been evaluated.