The S Curve
Sat, 3 OctMelbourne · Singapore · New York
Book a call
Insight

What is the NIST AI Risk Management Framework for if you are not a model-risk team?

A voluntary framework released on 26 January 2023, plus the later generative profile. Useful as questions. Useless as a talisman.

The S-Curve·6 min read
What is the NIST AI Risk Management Framework for if you are not a model-risk team? cover

Most people who hear the name assume it is a manual for banks and model validators. It is a public framework from the US National Institute of Standards and Technology, written so that organisations can manage risks to people, to the organisation and to society from artificial intelligence. NIST released version 1.0 on 26 January 2023. The institute is clear that use is voluntary. The point is to make trustworthiness part of how AI is designed, built, used and evaluated, not to hand you a licence that means you are finished.

If you do not run a model-risk team, you can still use it as a set of questions. You cannot use it as a substitute for knowing your own workflow. The page that introduces the framework also says it was built in the open: a request for information, public drafts, workshops, and room for comment. That history matters because the document is a consensus artefact, not a product brochure and not a statute.

What NIST has actually published

The overview page lists more than the original booklet. There is a companion playbook, a roadmap, a crosswalk to other efforts, and a set of perspectives. On 30 March 2023 NIST launched the Trustworthy and Responsible AI Resource Center to help people implement the framework and line it up with work in other countries. Use cases from other organisations sit on that center's site.

On 26 July 2024 NIST released NIST-AI-600-1, the Generative Artificial Intelligence Profile. The institute's description is specific. The profile helps organisations identify risks that are particular to generative AI, and it proposes actions that can be lined up with the organisation's own goals. It is not a claim that every chatbot project needs the same control. It is a menu you have to choose from.

On 7 April 2026 NIST released a concept note for another profile, this one on trustworthy AI in critical infrastructure. The note is aimed at operators of critical infrastructure who need practices to consider when they take on AI-enabled capability. And the same page says AI RMF 1.0 is being revised as part of the White House AI Action Plan. If you downloaded a PDF in 2023 and filed it, you are reading a document the author is already updating. Check the date before you treat a slide as current.

What it is not

It is not a law. Voluntary is the word NIST uses. A regulator in your own country may still expect you to manage the risk, but the framework itself does not fine you. Treating it as a law produces two bad habits. Teams either ignore it because "it does not apply here", or they perform it, with a binder and no decision.

It is not a tool review. Nothing on the overview page will tell you whether a particular vendor is safe for your customer data. That judgment needs your data, your users and your downside. A framework can suggest the categories of harm to look for. It cannot see your tenancy.

It is not only for data scientists. The audience NIST describes is anyone designing, developing, using or evaluating AI products, services and systems. A product manager deciding whether an assistant may draft a customer email is using AI. An operations lead letting a model triage tickets is using AI. A learning lead buying a course is not, by itself, governing a system, but the course will fail if the system has no owner. The framework is a way to talk about that ownership in a language other firms will recognise. It is a poor way to avoid the conversation.

A way to read it if you run a normal team

Start with the system you already have, not with the PDF. Write one paragraph: what the system does, who it affects, what data it sees, and whether it advises a person or acts. If you cannot write the paragraph, you are not ready for a profile. You are ready for an inventory.

Then use the generative profile's spirit, without pretending you have completed it. Generative systems fail in ways a classic prediction model does not. They produce fluent text that is not in the source. They can be talked into ignoring an instruction. They get pasted into places the designer did not intend, because staff bring their own accounts. Your controls should match those failures: a source check, a limit on what the system may do unsupervised, and a rule for unsanctioned tools. The profile proposes actions. You still pick the ones that match the harm you actually face.

Critical infrastructure operators have a tighter version coming, signalled by the April 2026 concept note. If you are not in that sector, do not wait for it, and do not pretend you are. Borrow the habit, which is to name the practices you will consider before the capability is live, and ignore the costume.

How this sits next to a workshop

A framework does not train a team. It gives the leaders a shelf to put decisions on. Staff still need a plain line: what they may paste, what they must check, who they call. Leaders still need an intake for new uses, so the tenth chatbot does not appear by surprise. Collective Campus teaches that split in the AI governance workshop, mapped to the documents auditors already ask about, including this framework. The workshop is not the document. The document will not run the session for you.

If you read only one page before a steering meeting, read NIST's own overview and note three dates: 26 January 2023 for the original release, 26 July 2024 for the generative profile, and 7 April 2026 for the critical-infrastructure concept note. Then ask which of those documents anyone in the room has opened. A policy that cites the framework and a room that has not read it is a citation, not a control.

What to do on Monday

Keep the ambition small enough to finish.

  1. List the AI systems that can reach a customer, a worker or a record. Include the unsanctioned ones you already know about. A list of approved tools that ignores the real ones is a story.
  2. For each system, name a human owner and say whether it drafts or acts.
  3. Pick one generative use and write the failure you have already seen, not the failure in a generic risk poster.
  4. Choose two actions from the spirit of the generative profile that would have caught that failure. Do those. Do not boil the ocean of the playbook in the first month.
  5. Put a review date on the calendar, because NIST is revising 1.0 and your own use will drift.

The framework is useful because it is shared, voluntary and explicit about trustworthiness. It is useless as a talisman. The work is still local: your system, your harm, your owner, your check. If those four are missing, another download will not supply them.

A last caution on language. Trustworthiness, in NIST's framing, is something you build into design, development, use and evaluation. It is not a slogan you add to a launch note. If the only place the word appears is the front of a board pack, you have not used the framework. You have decorated a decision you were going to make anyway.

Source: NIST, "AI Risk Management Framework". https://www.nist.gov/itl/ai-risk-management-framework

From The S Curve

News and insights for innovation, digital transformation, future of work and L&D leaders.

Stay ahead of learning and development, corporate innovation and digital transformation news. Plus the future of work. For leaders in AU, NZ, HK, SG, the US, the UK and Canada.