NIST AI RMF · 72 Plays
AI Risk Management
Playbook
Navigate the NIST AI Risk Management Framework with actionable plays organized across four core functions.
Govern: Cultivate a culture of AI risk management through policies and procedures.
GOVERN-1
7 playsGOVERN-2
3 playsGOVERN-3
2 playsGOVERN-4
3 playsGOVERN-5
2 playsGOVERN-6
2 playsMap: Contextualize risks and establish AI risk profiles.
MAP-1
6 playsMAP-2
3 playsMAP-3
5 playsMAP-4
2 playsMAP-5
2 playsMeasure: Analyze, assess, benchmark, and monitor AI risk and related impacts.
MEASURE-1
3 playsMEASURE-2
13 playsMEASURE-3
3 playsMEASURE-4
3 playsManage: Allocate risk resources to mapped and measured risks on a regular basis.
MANAGE-1
4 playsMANAGE-2
4 playsMANAGE-3
2 playsMANAGE-4
3 playsWhere to go next
- IT audit of AI systems — how an audit function tests against this framework rather than implements it.
- AI security and assurance — the controls and the evidence they have to produce.
- Public sector AI governance — governing procured AI where the framework is applied.
- AI governance playbook — the delivery process, with tiering and approval gates.