Reference and glossary
Quick reference
Section titled “Quick reference”| Item | Value |
|---|---|
| Framework | NIST Artificial Intelligence Risk Management Framework |
| Published baseline | AI RMF 1.0, NIST AI 100-1 |
| Published | 26 January 2023 |
| Nature | Voluntary |
| Functions | GOVERN, MAP, MEASURE, MANAGE |
| Categories | 19 |
| Core outcomes | 72 |
| Companion implementation resource | NIST AI RMF Playbook |
| Generative AI companion | NIST AI 600-1 |
| Gamut assessment scope | One selected AI system |
| Assessment structure | Current Profile and Target Profile |
AI RMF Core
Section titled “AI RMF Core”The set of functions, categories and subcategories that provides outcomes for managing AI risk.
Function
Section titled “Function”A high-level group of AI risk-management activity:
- GOVERN.
- MAP.
- MEASURE.
- MANAGE.
Category
Section titled “Category”A group of related outcomes within a function.
Subcategory
Section titled “Subcategory”A more specific Core outcome. Gamut uses stable short IDs such as GV-1.1, MP-2.2, ME-2.7
and MG-4.1 for navigation.
Profile
Section titled “Profile”A tailoring of the AI RMF Core to a use case, sector, technology, organisation or system.
Current Profile
Section titled “Current Profile”The assessed present position for the selected system.
Target Profile
Section titled “Target Profile”The intended future risk-management position.
Profile gap
Section titled “Profile gap”The difference between Current and Target Profiles. It should drive treatment, evidence, testing, ownership and monitoring.
Playbook
Section titled “Playbook”NIST’s voluntary companion resource containing suggested actions related to Core outcomes. It is not a mandatory checklist.
Trustworthiness characteristics
Section titled “Trustworthiness characteristics”- Valid and reliable.
- Safe.
- Secure and resilient.
- Accountable and transparent.
- Explainable and interpretable.
- Privacy-enhanced.
- Fair, with harmful bias managed.
Testing, evaluation, verification and validation.
AI actor
Section titled “AI actor”A person or organisation performing a role in the AI lifecycle, such as developer, deployer, operator, evaluator, affected individual or supplier.
Socio-technical
Section titled “Socio-technical”The combined interaction of technology, people, organisations, processes and context.
Risk tolerance
Section titled “Risk tolerance”The level and type of risk an organisation is prepared to accept in pursuit of objectives.
Current outcome labels
Section titled “Current outcome labels”Not assessed
Section titled “Not assessed”No defensible determination has been made.
Not achieved
Section titled “Not achieved”The outcome is absent or materially ineffective.
Partially achieved
Section titled “Partially achieved”Some elements operate, but material gaps remain.
Achieved
Section titled “Achieved”The outcome operates for the selected system and is sufficiently supported.
These are Gamut assessment labels, not NIST maturity levels.
Assurance depth
Section titled “Assurance depth”Unverified / 0
Section titled “Unverified / 0”Assertion only.
Documented / 1
Section titled “Documented / 1”Design documentation and ownership reviewed.
Implemented / 2
Section titled “Implemented / 2”System-specific operating evidence supports implementation.
Assured / 3
Section titled “Assured / 3”Operating evidence, effective testing and adverse-finding review support the conclusion.
Priority labels
Section titled “Priority labels”Baseline
Section titled “Baseline”Foundational assessment depth retained in the Profile.
Priority
Section titled “Priority”System facts make the outcome particularly relevant.
Enhanced
Section titled “Enhanced”The context calls for deeper system-specific evidence, testing or review.
These are Gamut planning labels, not NIST severity ratings.
Accepted evidence
Section titled “Accepted evidence”Evidence that is relevant, scoped, current, authentic, sufficiently complete and reviewed.
Evidence request
Section titled “Evidence request”A request for a specific artefact or operating record needed to support an outcome.
Control test
Section titled “Control test”A bounded procedure with objective, expected result, pass criteria, safety limits and actual result.
Finding
Section titled “Finding”A documented gap, failed test, unsupported assumption, exception or adverse condition requiring action or risk decision.
Adverse evidence
Section titled “Adverse evidence”Information that contradicts or weakens a positive conclusion, such as a failed test, open finding, incident or rejected evidence.
Residual risk
Section titled “Residual risk”Risk remaining after current practices, evidence, limitations and treatment are considered.
Reassessment trigger
Section titled “Reassessment trigger”A change or event requiring review before the normal review date.
Generative AI Profile
Section titled “Generative AI Profile”NIST AI 600-1, a cross-sectoral companion Profile for generative AI.
The 12 GAI risk families
Section titled “The 12 GAI risk families”- CBRN information or capabilities.
- Confabulation.
- Dangerous, violent or hateful content.
- Data privacy.
- Environmental impacts.
- Harmful bias and homogenisation.
- Human-AI configuration.
- Information integrity.
- Information security.
- Intellectual property.
- Obscene, degrading or abusive content.
- Value-chain and component integration.
Crosswalk
Section titled “Crosswalk”A traceability reference between related framework concepts. It is not automatic equivalence.
Confirmation
Section titled “Confirmation”An accountable human sign-off on the recorded Profile at a point in time. It is not NIST certification.
Frequently asked questions
Section titled “Frequently asked questions”Is the NIST AI RMF mandatory?
Section titled “Is the NIST AI RMF mandatory?”The framework itself is voluntary. Other law, regulation, contract or policy may independently require risk-management activity.
Does NIST certify AI systems against the AI RMF?
Section titled “Does NIST certify AI systems against the AI RMF?”The Gamut assessment must not be represented as NIST certification or endorsement.
Is the AI RMF a checklist?
Section titled “Is the AI RMF a checklist?”No. The Core is outcome-oriented, and the Playbook is a voluntary set of suggestions.
Does every outcome need the same effort?
Section titled “Does every outcome need the same effort?”No. Tailor effort to context and risk, while explicitly considering the Core and documenting the reason for priority.
Is Achieved the same as Assured?
Section titled “Is Achieved the same as Assured?”No. Achieved describes the outcome. Assured describes the strength of support.
Can an outcome be Not achieved at Assured depth?
Section titled “Can an outcome be Not achieved at Assured depth?”Yes. Strong evidence and testing can confirm a real gap.
Can a documented policy justify Achieved?
Section titled “Can a documented policy justify Achieved?”Not by itself. System-specific implementation and effectiveness matter.
Does a mapped GTSAF or ISO control prove a NIST outcome?
Section titled “Does a mapped GTSAF or ISO control prove a NIST outcome?”No. It may provide relevant evidence or implementation support, but the NIST outcome still needs direct assessment.
Does AI assistance complete the Profile?
Section titled “Does AI assistance complete the Profile?”No. It provides advisory analysis for human review.
Does an API key grant access?
Section titled “Does an API key grant access?”No. Access remains subject to the user’s authorised workspace, role, plan and feature availability.
What happens when the system changes?
Section titled “What happens when the system changes?”Review the Profile, evidence, tests, findings, priorities and conclusion. Material change may require a new assessment basis.
Is AI RMF 1.0 still current?
Section titled “Is AI RMF 1.0 still current?”It is the published baseline described here. NIST states that a revision is in progress. Check the official AI RMF page for current status.
Safe one-sentence explanation
Section titled “Safe one-sentence explanation”Gamut applies the voluntary NIST AI RMF 1.0 Core to a named AI system through Current and Target Profiles, separates outcome from assurance strength, links evidence, testing and findings, adds the NIST Generative AI Profile when relevant, and keeps final risk decisions with accountable humans.