Skip to content
Article reader Listen + reading controls
LISTEN + READ YOUR WAY

Article reader

Preparing the reader…

0:00 0:00
Reading settings
Text size
100%

AI risk management begins with context

The National Institute of Standards and Technology (NIST) has released version 1.0 of its Artificial Intelligence Risk Management Framework (AI RMF). It is voluntary, sector-neutral, and deliberately flexible. That may frustrate anyone looking for a short compliance checklist. It is also the framework's most useful design choice.

Artificial intelligence (AI) risk is not a property of a model in isolation. It emerges from what the system is asked to do, the conditions under which it operates, the people who depend on it, and the organization's capacity to recognize and respond when it fails.

“Map” is not administrative preamble

The AI RMF organizes work into four functions: Govern, Map, Measure, and Manage. Teams may be tempted to rush toward Measure because metrics feel concrete. But measurement without a mapped context can create false precision.

An error rate does not tell us enough. We need to know which errors, affecting whom, in what decision, with what opportunity for correction. A system that recommends movies and a system that supports maintenance on safety-critical equipment may share an algorithm and still require radically different evidence.

This is why the framework asks organizations to document intended purposes, deployment settings, affected groups, human oversight, and foreseeable impacts. Mapping is where a technical artifact becomes a sociotechnical system.

Human-factors research has made this point for decades. Parasuraman, Sheridan, and Wickens's model of automation shows that automation can support different stages of information processing and can be applied at different levels. The right design depends on the task. “Human in the loop” is not a sufficient specification; the human may be asked to intervene too late, with too little information, or after skills have atrophied.

Trustworthiness is plural

The framework describes trustworthy AI using multiple characteristics, including validity and reliability, safety, security and resilience, accountability and transparency, explainability and interpretability, privacy enhancement, and fairness with harmful bias managed.

These qualities can reinforce one another, but they can also compete. More monitoring may improve accountability while increasing privacy exposure. A simplified explanation may improve usability while concealing uncertainty. Tighter security can slow the feedback needed to discover operational failure.

Risk management is therefore not a hunt for a single score. It is a process for making tradeoffs explicit, assigning responsibility, and preserving the evidence behind them. The framework's language of governance matters because technical teams should not be left to resolve organizational value conflicts alone.

Start with one decision, not an enterprise inventory

Leaders do not need to implement the entire framework everywhere at once. A more credible start is to choose one consequential decision supported by AI and build a system profile around it.

Ask five questions:

  1. What decision changes because this system exists?
  2. Who has the authority and information to challenge its output?
  3. What conditions define acceptable performance?
  4. Which harms or failures would require restriction, rollback, or retirement?
  5. What evidence will show that the system remains fit for purpose after deployment?

Then connect those answers to owners, tests, operating procedures, and review dates. The output should not be a report that sits beside the system. It should shape requirements, interfaces, training, monitoring, and incident response.

The AI RMF gives organizations a common language at a moment when capabilities and enthusiasm are moving quickly. Its deeper contribution is a discipline: begin with the real decision and the real environment, then decide what trustworthiness requires there.

A model can be evaluated in a laboratory. A system earns trust only in context.

Sources and research trail

READER-NEUTRAL SUBSCRIPTION

Follow Field Notes via RSS.

Copy this address into the RSS reader you already use. New notes will appear there automatically—no account, email address, or tracking required.