Interactive playbook · NIST AI RMF 1.0 · No sign-up - The AI risk framework, in plain words, with your own profile at the end.
The NIST AI Risk Management Framework is the reference the Australian guidance, ISO 42001 and most enterprise AI policies borrow from. It has four functions and 72 outcomes. A business of 10 to 200 people needs about a dozen of them done well. Turn the engine, test the ideas, then answer eight questions and see where you stand.
GOVERN · Cross-cutting
A culture where AI risk is somebody’s job.
At your size this is a four-page policy staff have read, a register with an owner and a review date for every AI use including the features vendors switched on, a written line on how much risk you accept, and one person who signs off before anything new goes live.
Source: National Institute of Standards and Technology, January 2023
How the engine runs
This is not a waterfall. GOVERN runs the whole time; MAP, MEASURE and MANAGE repeat for the life of every AI use.
What NIST means by risk
Risk is the composite measure of an event’s probability of occurring and the magnitude or degree of the consequences. The consequences can be positive, negative, or both.
Source: National Institute of Standards and Technology, January 2023
Choose a function. GOVERN is the hub; the other three repeat for the life of every AI use.
Why AI needs its own playbook - AI does not fail the way software fails.
The framework opens by listing how AI risk differs from software risk. Flip the switch and read the same four rows from each side.
Predictability
Behaviour emerges from data. Side effects appear that no statistical test predicted.
Maintenance
Data drift, model drift and concept drift change the system while you are not looking. Maintenance is continuous.
Opacity
Large pre-trained models are hard to inspect. Predicting how they fail is hard even for the people who built them.
Testing
Testing standards are still forming. Ground truth may not exist, and the same input can give a different answer tomorrow.
Source: National Institute of Standards and Technology, January 2023
- of staff use AI in ways that breach policyKPMG and University of Melbourne, Trust in AI 2025
- 48 %
- of organisations breached through AI had no AI governance policyIBM and Ponemon Institute, July 2025
- 63 %
- of generative AI pilots show no measurable profit and loss impactFortune, August 2025
- 95 %
- of agentic AI projects will be cancelled by the end of 2027, with inadequate risk controls among the reasonsGartner, June 2025
- 40 %
Risk is a line you draw - NIST defines risk. It does not tell you how much to accept.
The framework tells you to prioritise the risks you find. Where the line sits is yours to set, and it changes which of these eight uses needs redesigning before it goes any further.
NIST defines risk and tells you to prioritise. It does not set your tolerance: that depends on the law that applies to you, what your customers expect, and what you can afford to get wrong. Trying to eliminate all risk is counterproductive; set the slider to zero and see.
Tolerance 0.30 · lower means less risk accepted
3 of 8 over the line. Redesign, restrict or stop those.
- Meeting notes summariserManageable
- Marketing copy first draftsManageable
- Invoice coding suggestionsManageable
- Website chatbot answering product questionsManageable
- Copilot over every SharePoint fileOver the line
- Client emails sent by AI without reviewOver the line
- Screening job applicationsOver the line
- Scoring credit or tenancy applicationsManageable
Eight sample AI uses. Synthetic data.
Source: National Institute of Standards and Technology, January 2023
How far a harm travels - One wrong output can reach three rings.
NIST sorts harm into three rings: the people affected, the organisation, and the wider systems both sit inside. Four incidents, all of them real and all of them sourced.
Harm to an ecosystem
ReachedInterconnected systems, markets, courts, the environment.
Harm to an organisation
ReachedOperations, security, money and reputation.
Harm to people
ReachedIndividuals and groups: rights, safety, money, a decision made about them.
Choose an incident
Reaches 3 of 3 rings
A report delivered to a federal department in 2025 contained references and a court quotation that did not exist. Part of the fee was refunded and the model used was disclosed after the fact.
Source: Fortune, October 2025
What trustworthy means - Seven characteristics, and they pull against each other.
The framework names seven. Valid and reliable is the base; accountable and transparent frames the rest. Two pairs pull in opposite directions, and deciding how far to lean is a judgement, not a setting.
Accountable and transparent
Safe
Does not endanger life, health, property or the environment.
Two that pull against each other
Privacy-enhanced
Valid and reliable
De-identifying or thinning the data that trains or feeds a system can lower its accuracy. NIST names this trade-off directly.
Explainable and interpretable
Capability
The most capable models are the hardest to interpret. Insisting on a model you can explain can rule out the one that performs best.
Trustworthiness is a spectrum, not a checklist. The decision to commission a system rests on a contextual weighing of these trade-offs, and the organisation’s values decide the weights.
Source: National Institute of Standards and Technology, January 2023
The four functions - Govern, map, measure, manage. Here is what each one means at your size.
GOVERN runs the whole time. The other three repeat for the life of every AI use. Choose a function to see the published outcomes, what it means for a business of your size, and the one step that closes it.
Cross-cutting
6 categories · 19 subcategories
A culture where AI risk is somebody’s job.
At your size this is a four-page policy staff have read, a register with an owner and a review date for every AI use including the features vendors switched on, a written line on how much risk you accept, and one person who signs off before anything new goes live.
Key actions
- Write the policies and the risk tolerance down (GOVERN 1).
- Name who is accountable, and give them the authority (GOVERN 2).
- Build a team that notices harm, and a culture that reports it (GOVERN 3, 4, 5).
- Treat vendor tools and third-party models as your risk too (GOVERN 6).
Outputs
- A policy in plain words
- A register with owners and review dates
- A stated risk tolerance
At your size
- Step 1: Check
- Step 2: Discover
- Step 3: Guard (current)
- Step 4: Ship
- Step 5: Sustain
Or, if the inventory comes first, ADM Transparency Review.
63 %
of organisations breached through AI had no AI governance policy
Source: IBM and Ponemon Institute, July 2025
Who does what, and when - You are almost always the deployer.
The framework maps seven lifecycle stages against the actors at each one. Most of those columns belong to the vendor. Switch to the small business view to see which of them is you.
| Stage | AI design | AI development | AI deployment | Test, evaluation, verification and validation | Governance and oversight | People and planet |
|---|---|---|---|---|---|---|
| Plan and design | AI design leads at Plan and design | AI development not involved at Plan and design | AI deployment not involved at Plan and design | Test, evaluation, verification and validation involved at Plan and design | Governance and oversight involved at Plan and design | People and planet involved at Plan and design |
| Collect and process data | AI design leads at Collect and process data | AI development involved at Collect and process data | AI deployment not involved at Collect and process data | Test, evaluation, verification and validation involved at Collect and process data | Governance and oversight involved at Collect and process data | People and planet not involved at Collect and process data |
| Build and use model | AI design not involved at Build and use model | AI development leads at Build and use model | AI deployment not involved at Build and use model | Test, evaluation, verification and validation involved at Build and use model | Governance and oversight involved at Build and use model | People and planet not involved at Build and use model |
| Verify and validate | AI design not involved at Verify and validate | AI development leads at Verify and validate | AI deployment not involved at Verify and validate | Test, evaluation, verification and validation leads at Verify and validate | Governance and oversight involved at Verify and validate | People and planet not involved at Verify and validate |
| Deploy and use | AI design not involved at Deploy and use | AI development not involved at Deploy and use | AI deployment leads at Deploy and use | Test, evaluation, verification and validation involved at Deploy and use | Governance and oversight involved at Deploy and use | People and planet not involved at Deploy and use |
| Operate and monitor | AI design not involved at Operate and monitor | AI development not involved at Operate and monitor | AI deployment leads at Operate and monitor | Test, evaluation, verification and validation involved at Operate and monitor | Governance and oversight involved at Operate and monitor | People and planet not involved at Operate and monitor |
| Use or impacted by | AI design not involved at Use or impacted by | AI development not involved at Use or impacted by | AI deployment involved at Use or impacted by | Test, evaluation, verification and validation involved at Use or impacted by | Governance and oversight involved at Use or impacted by | People and planet involved at Use or impacted by |
Hover or tab to a cell to read it in words.
- Not involved
- Involved
- Leads
A business of 10 to 200 people almost never builds a model. It buys one, or a vendor switches one on. That makes MAP and MANAGE at deployment and operation your whole job, with GOVERN running underneath.
Source: National Institute of Standards and Technology, January 2023
As a best practice, the people who verify and validate a system are separated from the people who build or use it.
Source: National Institute of Standards and Technology, January 2023
The Australian overlay - One framework, four names.
The Guidance for AI Adoption, the Voluntary AI Safety Standard and ISO/IEC 42001 all describe the same four moves in different words. Change the lens and the four cards relabel.
GOVERN
- Cross-cutting
MAP
- Context
MEASURE
- Evaluation
MANAGE
- Execution
The mapping between the four functions and the Australian practices is our analysis, not an official crosswalk. NIST publishes crosswalks, including to ISO/IEC 42001, and the Australian guidance was written to sit alongside both.
Source: NIST Trustworthy and Responsible AI Resource Center, Current
Source: National AI Centre, Department of Industry, Science and Resources, October 2025
Currently reading the four functions as NIST AI RMF.
26 Jan 2023
NIST AI RMF 1.0 published
Four functions, 19 categories, 72 subcategories. Voluntary.
Source: National Institute of Standards and Technology, January 2023
1 Feb 2024
AS ISO/IEC 42001:2023 adopted in Australia
The AI management system standard, adopted identically.
Source: Standards Australia, February 2024
5 Sept 2024
Voluntary AI Safety Standard
Ten guardrails for Australian organisations.
Source: Department of Industry, Science and Resources, September 2024
29 Oct 2024
ASIC reports on AI governance gaps
Of 23 licensees reviewed, nearly half had no policy on fairness or bias in AI.
Source: Australian Securities and Investments Commission, October 2024
21 Oct 2025
Guidance for AI Adoption
Six essential practices replace the ten guardrails for industry, with a register template and a screening tool.
Source: National AI Centre, Department of Industry, Science and Resources, October 2025
2 Dec 2025
National AI Plan
No mandatory guardrails for now. Existing law applies, and an AI Safety Institute is created.
Source: ABC News, 2 December 2025
15 Dec 2025
Government AI policy version 2.0
Accountable officials, transparency statements and use-case registers for Commonwealth entities.
Source: Digital Transformation Agency, December 2025
26 Aug 2026
National Cabinet agrees to legislate AI standards
Legislation intended in early 2027. What it will require of ordinary business users is not yet defined.
Source: Prime Minister of Australia, August 2026
10 Dec 2026
Privacy Act automated decision-making transparency
Privacy policies must name the decisions a computer program makes or substantially shapes about people.
Source: Office of the Australian Information Commissioner, Commences 10 December 2026
Where the framework stands
Version 1.0, January 2023. NIST has announced a revision and has not published it. The Generative AI Profile (July 2024), a draft Cyber AI Profile (December 2025) and an AI Agent Standards Initiative (February 2026) sit alongside it.
Source: National Institute of Standards and Technology, 2026
Source: National Institute of Standards and Technology, July 2024
Source: National Institute of Standards and Technology, December 2025
Source: NIST Center for AI Standards and Innovation, February 2026
This is general information, not legal advice.
Your profile · Eight questions · Three minutes - Where is the widest gap between your Current Profile and the target?
Two questions per function. The profile draws as you answer and names the gap to close first, with the fixed-price step that closes it. Nothing you enter leaves your browser.
What closes every gap - One ladder covers all four functions.
The same five steps we scope every engagement with. Each one carries a named set of framework outcomes, so nothing depends on knowing which function a gap belongs to.
- Step 1: Check
- Step 2: Discover
- Step 3: Guard (current)
- Step 4: Ship
- Step 5: Sustain
01
Check
The MAP inventory: every AI use found, including the ones on personal cards and the features that switched themselves on.
02
Discover
MAP 3 and MANAGE 1: opportunities ranked on value, effort and risk, so the first build is the one that earns its guardrails.
03
Guard
GOVERN in full: policy, register, owners, risk tolerance, the Privacy Act wording.
04
Ship
MEASURE by doing: baseline in week one, hostile test before launch, a measured result in week four.
05
Sustain
MANAGE 4: monthly register review, vendor default watch, incident plan, decommission when a use stops earning its place.
Questions people ask - Four short answers.
The framework is voluntary. The Australian law that applies to how you use AI is not.
- Is the NIST AI RMF mandatory in Australia?
- No. It is a voluntary United States framework. Australian law that applies to AI use is technology-neutral: the Privacy Act, consumer law, anti-discrimination law and sector rules. The Guidance for AI Adoption and ISO/IEC 42001 both borrow the framework’s structure, so following it puts you ahead of all three.
- What are the four functions of the NIST AI RMF?
- GOVERN sets the culture, policies and accountability and runs the whole time. MAP establishes the context and the risks of each AI use. MEASURE tests, evaluates and monitors. MANAGE prioritises the risks and acts on them, including after deployment.
- How does the framework map to the Australian Guidance for AI Adoption?
- Our reading: practice 1 (accountability) and 4 (sharing information) sit in GOVERN; practice 2 (impacts) in MAP; practice 5 (test and monitor) in MEASURE; practices 3 (manage risks) and 6 (human control) in MANAGE. It is an analysis, not an official crosswalk.
- Does a business of 20 people need all 72 subcategories?
- No. Most apply to organisations that build models. A deployer needs a policy, a register with owners, an inventory with a go or no-go per use, a baseline and a test before go-live, a human review step, a rollback and a plan for when a vendor changes a default. That is about a dozen outcomes, and the profile check on this page covers them.
Sources - Every claim on this page has one.
The framework is theirs. The translation, the Australian mapping and the profile check are ours.
- 01Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1National Institute of Standards and Technology · January 2023
- 02NIST AI RMF PlaybookNational Institute of Standards and Technology · March 2023, maintained
- 03AI RMF: Generative Artificial Intelligence Profile, NIST AI 600-1National Institute of Standards and Technology · July 2024
- 04AI Risk Management Framework programme page, revision noticeNational Institute of Standards and Technology · 2026
- 05Crosswalks to the AI RMF, including ISO/IEC 42001NIST Trustworthy and Responsible AI Resource Center · Current
- 06Cyber AI Profile, NIST IR 8596, initial preliminary draftNational Institute of Standards and Technology · December 2025
- 07AI Agent Standards InitiativeNIST Center for AI Standards and Innovation · February 2026
- 08Guidance for AI Adoption: six essential practices (Foundations)National AI Centre, Department of Industry, Science and Resources · October 2025
- 09Guidance for AI Adoption: implementation practicesNational AI Centre, Department of Industry, Science and Resources · May 2026
- 10Voluntary AI Safety StandardDepartment of Industry, Science and Resources · September 2024
- 11National AI Plan: growth and existing laws over new AI-specific regulationABC News · 2 December 2025
- 12Meeting of National Cabinet, 26 August 2026Prime Minister of Australia · August 2026
- 13Policy for the responsible use of AI in government, version 2.0Digital Transformation Agency · December 2025
- 14Privacy and Other Legislation Amendment Act 2024, automated decision-making transparencyOffice of the Australian Information Commissioner · Commences 10 December 2026
- 15Guidance on privacy and the use of commercially available AI productsOffice of the Australian Information Commissioner · October 2024
- 16REP 798 Beware the gap: governance arrangements in the face of AI innovationAustralian Securities and Investments Commission · October 2024
- 17Standards Australia adopts AS ISO/IEC 42001:2023Standards Australia · February 2024
- 18Cost of a Data Breach Report 2025IBM and Ponemon Institute · July 2025
- 19The GenAI Divide, MIT NANDA, as reportedFortune · August 2025
- 20Gartner predicts over 40 % of agentic AI projects will be cancelled by the end of 2027Gartner · June 2025
- 21SME AI Pulse: adoption insights December 2025 to February 2026National AI Centre · March 2026
- 22Trust, attitudes and use of artificial intelligence: a global study 2025KPMG and the University of Melbourne · April 2025
- 23Deloitte to partially refund the Australian government over a report with AI-fabricated citationsFortune · October 2025
- 24CVE-2025-32711, Microsoft 365 Copilot information disclosure (EchoLeak)Microsoft Security Response Center · June 2025
- 25New guidelines and practice directions to combat generative AI hallucinations in Queensland courts and tribunalsMcCullough Robertson · October 2025
This page is general information, not legal advice or a risk assessment. The framework is NIST’s; the translation, the Australian mapping and the profile check are ours. The eight AI uses in the tolerance field are synthetic. Nothing entered in the profile check is collected.
Want the whole picture, not just the framework?
Nine questions, three minutes, nothing leaves your browser. The scorecard shows which of the five steps you are on and which service fits.
Want your profile drawn properly? Book a call.
Twenty minutes. We tell you which function to close first, what it costs, and whether you need us at all.
+61 490 083 850 · Wollongong, NSW