Berk Bayri

NIST AI RMF

The NIST AI Risk Management Framework: a voluntary, use-case-agnostic US framework for managing AI risks. NIST's related work also stresses monitoring deployed AI systems after launch.

The NIST AI Risk Management Framework is guidance published by the US National Institute of Standards and Technology to help organizations identify, assess and manage risks from AI systems. It is voluntary and intentionally use-case agnostic: it describes outcomes and practices rather than prescribing controls for one industry.

Monitoring after deployment

NIST's work on monitoring deployed AI makes a point that is directly relevant to operations: post-deployment monitoring is crucial because AI systems can show variability and unpredictable behavior in real-world settings, and the monitoring problem is still fragmented. That makes preserving field evidence more important, not less.

How it relates

A framework like this tells an organization what to govern. It does not replace operational practice such as AI incident reporting, where first reports keep an observation record before the root cause is known, or concrete guardrails. Company-specific disclosure processes from AI vendors are not enterprise standards; a broad framework such as this one is a better reference for an enterprise program.

Read more in The first AI incident report should be incomplete.