Article reader Listen + reading controls
Article reader
Preparing the reader…
Reading settings
AI risk management begins with context¶
The National Institute of Standards and Technology (NIST) has released version 1.0 of its Artificial Intelligence Risk Management Framework (AI RMF). It is voluntary, sector-neutral, and deliberately flexible. That may frustrate anyone looking for a short compliance checklist. It is also the framework's most useful design choice.
Artificial intelligence (AI) risk is not a property of a model in isolation. It emerges from what the system is asked to do, the conditions under which it operates, the people who depend on it, and the organization's capacity to recognize and respond when it fails.
“Map” is not administrative preamble¶
The AI RMF organizes work into four functions: Govern, Map, Measure, and Manage. Teams may be tempted to rush toward Measure because metrics feel concrete. But measurement without a mapped context can create false precision.
An error rate does not tell us enough. We need to know which errors, affecting whom, in what decision, with what opportunity for correction. A system that recommends movies and a system that supports maintenance on safety-critical equipment may share an algorithm and still require radically different evidence.
This is why the framework asks organizations to document intended purposes, deployment settings, affected groups, human oversight, and foreseeable impacts. Mapping is where a technical artifact becomes a sociotechnical system.
Human-factors research has made this point for decades. Parasuraman, Sheridan, and Wickens's model of automation shows that automation can support different stages of information processing and can be applied at different levels. The right design depends on the task. “Human in the loop” is not a sufficient specification; the human may be asked to intervene too late, with too little information, or after skills have atrophied.
Trustworthiness is plural¶
The framework describes trustworthy AI using multiple characteristics, including validity and reliability, safety, security and resilience, accountability and transparency, explainability and interpretability, privacy enhancement, and fairness with harmful bias managed.
These qualities can reinforce one another, but they can also compete. More monitoring may improve accountability while increasing privacy exposure. A simplified explanation may improve usability while concealing uncertainty. Tighter security can slow the feedback needed to discover operational failure.
Risk management is therefore not a hunt for a single score. It is a process for making tradeoffs explicit, assigning responsibility, and preserving the evidence behind them. The framework's language of governance matters because technical teams should not be left to resolve organizational value conflicts alone.
Start with one decision, not an enterprise inventory¶
Leaders do not need to implement the entire framework everywhere at once. A more credible start is to choose one consequential decision supported by AI and build a system profile around it.
Ask five questions:
- What decision changes because this system exists?
- Who has the authority and information to challenge its output?
- What conditions define acceptable performance?
- Which harms or failures would require restriction, rollback, or retirement?
- What evidence will show that the system remains fit for purpose after deployment?
Then connect those answers to owners, tests, operating procedures, and review dates. The output should not be a report that sits beside the system. It should shape requirements, interfaces, training, monitoring, and incident response.
The AI RMF gives organizations a common language at a moment when capabilities and enthusiasm are moving quickly. Its deeper contribution is a discipline: begin with the real decision and the real environment, then decide what trustworthiness requires there.
A model can be evaluated in a laboratory. A system earns trust only in context.
Sources and research trail¶
- National Institute of Standards and Technology, “NIST Risk Management Framework Aims to Improve Trustworthiness of Artificial Intelligence” (January 26, 2023).
- National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework (AI RMF 1.0) (2023).
- National Institute of Standards and Technology, AI RMF Playbook (2023).
- Parasuraman, Sheridan, and Wickens, “A Model for Types and Levels of Human Interaction with Automation” (2000).
- Lee and See, “Trust in Automation: Designing for Appropriate Reliance” (2004).