Governance practice

How to run an AI risk assessment, using the NIST framework's own structure

Standfirst: Run the assessment the way the NIST AI Risk Management Framework structures it. Put the GOVERN function in place across the organization, then apply MAP, MEASURE and MANAGE to each AI system at each stage of its lifecycle. Then test the result against Article 9 of the EU AI Act, because for high-risk systems a risk management system is a legal obligation, and the overlap between the two is close but not complete.

The Core is a method, not a checklist

The AI RMF (NIST AI 100-1, version 1.0) organizes its Core into four functions: GOVERN, MAP, MEASURE and MANAGE. Each function breaks into categories, then subcategories, then specific actions and outcomes. NIST is explicit about what those actions are not:

"Actions do not constitute a checklist, nor are they necessarily an ordered set of steps."

That single sentence is the reason a downloaded template is not a risk assessment. The Core "provides outcomes and actions that enable dialogue, understanding, and activities to manage AI risks and responsibly develop trustworthy AI systems." Outcomes, not forms. You have to reach the outcome by a route you can explain.

The framework is voluntary. NIST says users "may apply these functions as best suits their needs for managing AI risks based on their resources and capabilities," and some organizations will select among categories rather than apply them all. It also tells you where to start. Assuming a governance structure is in place, functions may be performed in any order, but "most users of the AI RMF would start with the MAP function and continue to MEASURE or MANAGE." However you sequence it, "the process should be iterative, with cross-referencing between functions as necessary."

So the method has two layers. GOVERN runs once, across the whole organization, and never stops. MAP, MEASURE and MANAGE run per system and per lifecycle stage.

Step 1: GOVERN, across the organization

NIST describes GOVERN as the function that "cultivates and implements a culture of risk management within organizations designing, developing, deploying, evaluating, or acquiring AI systems." It is not one phase among four:

"GOVERN is a cross-cutting function that is infused throughout AI risk management and enables the other functions of the process. Aspects of GOVERN, especially those related to compliance or evaluation, should be integrated into each of the other functions."

The first GOVERN category sets up everything a later auditor will ask about:

Subcategory Outcome
GOVERN 1.1 Legal and regulatory requirements involving AI are understood, managed, and documented.
GOVERN 1.2 The characteristics of trustworthy AI are integrated into organizational policies, processes, procedures, and practices.
GOVERN 1.3 Processes, procedures, and practices are in place to determine the needed level of risk management activities based on the organization's risk tolerance.
GOVERN 1.4 The risk management process and its outcomes are established through transparent policies, procedures, and other controls based on organizational risk priorities.

Read GOVERN 1.1 as the door through which Article 9 enters your program: if you build systems the EU AI Act classifies as high risk, that legal requirement gets documented here. Read GOVERN 1.3 as the reason no template can decide how deep your assessment goes. The depth follows from your organization's risk tolerance, which is a governance decision, not a download.

NIST adds that senior leadership sets the tone for risk management, and that documentation "can enhance transparency, improve human review processes, and bolster accountability in AI system teams." GOVERN also does not end. Users must "continue to execute the GOVERN function as knowledge, cultures, and needs or expectations from AI actors evolve over time."

Step 2: MAP, MEASURE and MANAGE, per system and per stage

The function names carry the method. You map a system's context and its risks. You measure the risks you mapped. You manage the risks you measured. NIST insists this happens across the whole lifecycle: "Risk management should be continuous, timely, and performed throughout the AI system lifecycle dimensions."

Work one system at a time. Take a purely hypothetical example: your company is designing a model that screens job applications. At the design stage, MAP means establishing what the system is for, who it affects and what could go wrong for them. MEASURE means assessing each identified risk against the tolerance your GOVERN 1.3 process set. MANAGE means deciding what to do about each measured risk, doing it, and recording why. When the system moves to deployment, you run the loop again, because deployment surfaces risks design did not.

Who does this matters. NIST says the "Core functions should be carried out in a way that reflects diverse and multidisciplinary perspectives, potentially including the views of AI actors outside the organization," because a diverse team creates opportunities to surface problems and identify existing and emergent risks. A risk assessment written by one engineer at one desk fails that test before it starts.

For tactical suggestions within each function, NIST publishes a companion resource, the AI RMF Playbook, which is voluntary like the framework itself and lets users tailor guidance to their own context.

Where Article 9 overlaps with the Core

Article 9 of the EU AI Act requires that "a risk management system shall be established, implemented, documented and maintained in relation to high-risk AI systems." Article 9(2) then describes something with the same shape as the Core:

"The risk management system shall be understood as a continuous iterative process planned and run throughout the entire lifecycle of a high-risk AI system, requiring regular systematic review and updating."

The steps it mandates line up with the functions you have just run:

Article 9(2) step Closest Core function
(a) Identification and analysis of known and reasonably foreseeable risks to health, safety or fundamental rights under the intended purpose MAP
(b) Estimation and evaluation of risks under the intended purpose and under reasonably foreseeable misuse MEASURE
(c) Evaluation of other risks based on data from the post-market monitoring system under Article 72 MEASURE, run again after deployment
(d) Adoption of appropriate and targeted risk management measures for the risks identified under point (a) MANAGE

The requirement in Article 9(1) that the system be established, documented and maintained is what GOVERN builds. Both texts demand a continuous, iterative, lifecycle-long process. If you have worked the Core honestly, you have already produced most of what Article 9 asks to see.

Where Article 9 does not overlap

The differences matter as much as the mapping, and they are the ones worth memorizing.

One is law, one is a choice. The framework is voluntary. Article 9 says "shall," and it binds providers of high-risk AI systems.

The scope of risk is narrower. Article

Common questions

What are the four functions of the NIST AI RMF?

GOVERN, MAP, MEASURE and MANAGE. NIST states GOVERN applies across all stages of an organization's AI risk management, while MAP, MEASURE and MANAGE are applied in system-specific contexts and at specific lifecycle stages.

Does the EU AI Act require a risk assessment?

Article 9 requires a risk management system for high-risk AI systems, established, implemented, documented and maintained across the lifecycle. That is a legal obligation, and it is separate from adopting a voluntary framework.

Sources

Every figure, date and quotation above was read from the document itself, not from a summary of it.

Credential Press is not affiliated with, endorsed by or authorized by the IAPP, ISO, the IEC, NIST or any other body. This is not legal advice.

We are writing the book on this. The AIGP Exam Guide covers all 4 domains and all 13 competencies, in proportion to the published item weights. Join the first-reader list and you get it free before it goes on sale.