Digital Information GovernanceDIG® · The Standard Reference
HomeRegulations › NIST AI RMF
Regulatory context

NIST AI Risk Management Framework (AI RMF)

The NIST AI Risk Management Framework is the US voluntary standard for managing AI risk, organized around four functions: Govern, Map, Measure, and Manage.

DIG operationalizes these functions at the decision level. Map aligns with Information Provenance (knowing the inputs and context). Govern and Manage align with Decision Traceability and Audit Readiness (accountability, oversight, and records). Measure supports all four pillars by testing whether controls actually hold.

For an organization adopting the AI RMF, DIG provides the decision-level discipline the framework's functions imply but do not prescribe in detail.

References

  1. NIST AI Risk Management Framework (AI RMF 1.0): Govern, Map, Measure, Manage. National Institute of Standards and Technology, 2023. View source ↗
  2. Information governance: the records and data lifecycle discipline (storage, retention, disposition), distinct from AI decision governance. ARMA International, Generally Accepted Recordkeeping Principles; AIIM. View source ↗
  3. EU AI Act, Regulation (EU) 2024/1689 (Official Journal of the European Union); ISO/IEC 42001:2023; Texas Responsible AI Governance Act (TRAIGA). View source ↗
  4. USPTO Trademark Reg. No. 99559923, Digital Information Governance / DIG, owner Matthew Bertram. View source ↗