NIST AI Risk Management Framework
A voluntary structure for governing, mapping, measuring and managing AI risk across the lifecycle.
Voluntary global baselineFrom a question to a researched briefing, practical controls,
and the evidence your team needs.
Optional manual screening. Research can suggest a starting context for you.
Add a legal review of the jurisdictions your use case affects.
Screening prompts, not legal classifications. Confirm the facts with your legal and risk teams.
A voluntary structure for governing, mapping, measuring and managing AI risk across the lifecycle.
Voluntary global baselineA companion to the AI RMF addressing risks specific to generative AI, including unreliable outputs and information integrity.
Generative AI systemsAn AI management system standard for organizations that provide or use AI. A certificate concerns its defined scope, not every legal obligation.
Voluntary unless contractually requiredA security reference for applications using large language models, including prompt injection, sensitive information exposure and excessive agency.
LLM applications