NIST's Four AI Risk Management Functions Explained
Govern, Map, Measure and Manage provide an adaptable framework for organizations deploying automated systems.
The NIST AI Risk Management Framework identifies four connected functions: Govern, Map, Measure and Manage. The framework is intended to support ongoing risk practices, not provide a pass-or-fail certificate. Governance applies across the system lifecycle, while the other functions help teams describe context, collect evidence and respond to identified risks.
Mapping might identify that a voice agent takes personal information and schedules clinic visits. Measurement would test whether it records consent correctly, makes false claims or fails to transfer difficult calls to a person. Management involves setting escalation thresholds, reviewing incidents and updating controls when the model or operating environment changes.
A small company can use the same principles as a large organization without assuming every control is equally appropriate. Document the intended use, responsible personnel, tests and rollback process. NIST guidance is voluntary, and using its vocabulary should never be presented as government endorsement of a specific AI product.
Reporting sources & references
These links identify the reporting or public materials on which the article is based; they do not imply our newsroom witnessed the events.