# NIST AI RMF, ISO/IEC 42001 and OECD — AI Strategy, Ethics and Governance

Source: https://www.geekswithgeeks.com/en/ai-strategy-governance/reg-frameworks

> Use recognised frameworks to structure governance rather than inventing everything from scratch.

## Standing on shared structure

The **NIST AI Risk Management Framework** (voluntary, from the US standards body) organises work into four functions: **Govern** (culture, policies, accountability), **Map** (understand context, purpose and risks), **Measure** (test and track risks and performance) and **Manage** (prioritise and treat risks, respond to incidents). **ISO/IEC 42001** is an international standard for an **AI management system**, against which organisations can be audited and certified. The **OECD AI Principles** set high-level values many governments reference. None of these is a law by itself, but they give a recognised structure that regulators, customers and auditors understand.

## Mapping your practices to NIST functions

Use this kind of table to see gaps. Anything in the right column that is empty is work to do.

```text
NIST function   Question                              Our evidence
Govern          Who is accountable? Is there a policy?  AI policy v2; review board charter
Map             What is the use, context, who is hurt?  use-case canvases; impact assessments
Measure         How do we test and track risk?          evaluation sets; fairness slices; dashboards
Manage          How do we treat risks and respond?      risk register; incident runbook; change gates
```

## Adopt, then adapt

Start by adopting a framework's vocabulary and checklist, then adapt it to your size and sector. A small team can do a lightweight version of each function; the aim is a repeatable habit.

**Quiz:** Which are the four functions of the NIST AI RMF?

- [ ] Buy, Sell, Hold, Trade
- [x] Govern, Map, Measure, Manage
- [ ] Plan, Do, Skip, Stop
- [ ] Read, Write, Edit, Delete

*Answer:* Govern, Map, Measure, Manage. Govern, Map, Measure and Manage structure how an organisation handles AI risk.
