Lesson 21 / 26
NIST AI RMF, ISO/IEC 42001 and OECD
Use recognised frameworks to structure governance rather than inventing everything from scratch.
Standing on shared structure
The NIST AI Risk Management Framework (voluntary, from the US standards body) organises work into four functions: Govern (culture, policies, accountability), Map (understand context, purpose and risks), Measure (test and track risks and performance) and Manage (prioritise and treat risks, respond to incidents). ISO/IEC 42001 is an international standard for an AI management system, against which organisations can be audited and certified. The OECD AI Principles set high-level values many governments reference. None of these is a law by itself, but they give a recognised structure that regulators, customers and auditors understand.
Mapping your practices to NIST functions
Use this kind of table to see gaps. Anything in the right column that is empty is work to do.
NIST function Question Our evidence
Govern Who is accountable? Is there a policy? AI policy v2; review board charter
Map What is the use, context, who is hurt? use-case canvases; impact assessments
Measure How do we test and track risk? evaluation sets; fairness slices; dashboards
Manage How do we treat risks and respond? risk register; incident runbook; change gatesAdopt, then adapt
Start by adopting a framework's vocabulary and checklist, then adapt it to your size and sector. A small team can do a lightweight version of each function; the aim is a repeatable habit.
Quick check: Which are the four functions of the NIST AI RMF?
- Buy, Sell, Hold, Trade
- Govern, Map, Measure, Manage
- Plan, Do, Skip, Stop
- Read, Write, Edit, Delete
Answer
Govern, Map, Measure, Manage — Govern, Map, Measure and Manage structure how an organisation handles AI risk.