Lesson 21 / 26

NIST AI RMF, ISO/IEC 42001 and OECD

Use recognised frameworks to structure governance rather than inventing everything from scratch.

Standing on shared structure

The NIST AI Risk Management Framework (voluntary, from the US standards body) organises work into four functions: Govern (culture, policies, accountability), Map (understand context, purpose and risks), Measure (test and track risks and performance) and Manage (prioritise and treat risks, respond to incidents). ISO/IEC 42001 is an international standard for an AI management system, against which organisations can be audited and certified. The OECD AI Principles set high-level values many governments reference. None of these is a law by itself, but they give a recognised structure that regulators, customers and auditors understand.

Mapping your practices to NIST functions

Use this kind of table to see gaps. Anything in the right column that is empty is work to do.

NIST function   Question                              Our evidence
Govern          Who is accountable? Is there a policy?  AI policy v2; review board charter
Map             What is the use, context, who is hurt?  use-case canvases; impact assessments
Measure         How do we test and track risk?          evaluation sets; fairness slices; dashboards
Manage          How do we treat risks and respond?      risk register; incident runbook; change gates

Adopt, then adapt

Start by adopting a framework's vocabulary and checklist, then adapt it to your size and sector. A small team can do a lightweight version of each function; the aim is a repeatable habit.

Quick check: Which are the four functions of the NIST AI RMF?

  • Buy, Sell, Hold, Trade
  • Govern, Map, Measure, Manage
  • Plan, Do, Skip, Stop
  • Read, Write, Edit, Delete
Answer

Govern, Map, Measure, Manage — Govern, Map, Measure and Manage structure how an organisation handles AI risk.