NIST AI RMF
The US National Institute of Standards and Technology AI Risk Management Framework (v1.0 2023, Generative AI Profile 2024). Voluntary, organized around four functions — Govern, Map, Measure, Manage. Widely adopted as a common taxonomy even outside the US.
Related terms
- EU AI Act
European Union regulation (effective 2024, phased through 2027) that classifies AI systems into risk tiers — unacceptable (banned), high-risk (conformity assessment required), limited-risk (transparency obligations), and minimal — and imposes proportionate obligations. Applies extraterritorially to any provider placing AI on the EU market.
- ISO 42001
ISO/IEC 42001:2023 — an international standard specifying requirements for an AI Management System (AIMS). Certifiable by third parties (like ISO 27001), it demonstrates structured governance of AI development and use across the org.
- AI Governance
The framework of policies, procedures, and controls that guide the development, deployment, and use of AI systems within an organization. Ensures AI aligns with organizational values and regulations.
Related on this site
Where this fits
NIST AI RMF is part of the Evaluation & Governance vocabulary used in the Generative AI Maturity Framework. See the full glossary for the complete set of 149 defined terms, or take the free maturity assessment to see where your organisation stands.