Book a call

Interactive playbook · NIST AI RMF 1.0 · No sign-up - The AI risk framework, in plain words, with your own profile at the end.

The NIST AI Risk Management Framework is the reference the Australian guidance, ISO 42001 and most enterprise AI policies borrow from. It has four functions and 72 outcomes. A business of 10 to 200 people needs about a dozen of them done well. Turn the engine, test the ideas, then answer eight questions and see where you stand.

GOVERN · Cross-cutting

A culture where AI risk is somebody’s job.

At your size this is a four-page policy staff have read, a register with an owner and a review date for every AI use including the features vendors switched on, a written line on how much risk you accept, and one person who signs off before anything new goes live.

Source: National Institute of Standards and Technology, January 2023

How the engine runs

This is not a waterfall. GOVERN runs the whole time; MAP, MEASURE and MANAGE repeat for the life of every AI use.

What NIST means by risk

Risk is the composite measure of an event’s probability of occurring and the magnitude or degree of the consequences. The consequences can be positive, negative, or both.

Source: National Institute of Standards and Technology, January 2023

Choose a function. GOVERN is the hub; the other three repeat for the life of every AI use.

Why AI needs its own playbook - AI does not fail the way software fails.

The framework opens by listing how AI risk differs from software risk. Flip the switch and read the same four rows from each side.

Predictability

Behaviour emerges from data. Side effects appear that no statistical test predicted.

Maintenance

Data drift, model drift and concept drift change the system while you are not looking. Maintenance is continuous.

Opacity

Large pre-trained models are hard to inspect. Predicting how they fail is hard even for the people who built them.

Testing

Testing standards are still forming. Ground truth may not exist, and the same input can give a different answer tomorrow.

Source: National Institute of Standards and Technology, January 2023

of staff use AI in ways that breach policyKPMG and University of Melbourne, Trust in AI 2025
48 %
of organisations breached through AI had no AI governance policyIBM and Ponemon Institute, July 2025
63 %
of generative AI pilots show no measurable profit and loss impactFortune, August 2025
95 %
of agentic AI projects will be cancelled by the end of 2027, with inadequate risk controls among the reasonsGartner, June 2025
40 %

Risk is a line you draw - NIST defines risk. It does not tell you how much to accept.

The framework tells you to prioritise the risks you find. Where the line sits is yours to set, and it changes which of these eight uses needs redesigning before it goes any further.

NIST defines risk and tells you to prioritise. It does not set your tolerance: that depends on the law that applies to you, what your customers expect, and what you can afford to get wrong. Trying to eliminate all risk is counterproductive; set the slider to zero and see.

LikelihoodImpact

Tolerance 0.30 · lower means less risk accepted

3 of 8 over the line. Redesign, restrict or stop those.

  • Meeting notes summariserManageable
  • Marketing copy first draftsManageable
  • Invoice coding suggestionsManageable
  • Website chatbot answering product questionsManageable
  • Copilot over every SharePoint fileOver the line
  • Client emails sent by AI without reviewOver the line
  • Screening job applicationsOver the line
  • Scoring credit or tenancy applicationsManageable

Eight sample AI uses. Synthetic data.

Source: National Institute of Standards and Technology, January 2023

How far a harm travels - One wrong output can reach three rings.

NIST sorts harm into three rings: the people affected, the organisation, and the wider systems both sit inside. Four incidents, all of them real and all of them sourced.

  • Harm to an ecosystem

    Reached

    Interconnected systems, markets, courts, the environment.

  • Harm to an organisation

    Reached

    Operations, security, money and reputation.

  • Harm to people

    Reached

    Individuals and groups: rights, safety, money, a decision made about them.

Choose an incident

Reaches 3 of 3 rings

A report delivered to a federal department in 2025 contained references and a court quotation that did not exist. Part of the fee was refunded and the model used was disclosed after the fact.

Source: Fortune, October 2025

What trustworthy means - Seven characteristics, and they pull against each other.

The framework names seven. Valid and reliable is the base; accountable and transparent frames the rest. Two pairs pull in opposite directions, and deciding how far to lean is a judgement, not a setting.

Accountable and transparent

Safe

Does not endanger life, health, property or the environment.

Two that pull against each other

Privacy-enhanced

Valid and reliable

De-identifying or thinning the data that trains or feeds a system can lower its accuracy. NIST names this trade-off directly.

Explainable and interpretable

Capability

The most capable models are the hardest to interpret. Insisting on a model you can explain can rule out the one that performs best.

Trustworthiness is a spectrum, not a checklist. The decision to commission a system rests on a contextual weighing of these trade-offs, and the organisation’s values decide the weights.

Source: National Institute of Standards and Technology, January 2023

The four functions - Govern, map, measure, manage. Here is what each one means at your size.

GOVERN runs the whole time. The other three repeat for the life of every AI use. Choose a function to see the published outcomes, what it means for a business of your size, and the one step that closes it.

Cross-cutting

6 categories · 19 subcategories

A culture where AI risk is somebody’s job.

At your size this is a four-page policy staff have read, a register with an owner and a review date for every AI use including the features vendors switched on, a written line on how much risk you accept, and one person who signs off before anything new goes live.

Key actions

  • Write the policies and the risk tolerance down (GOVERN 1).
  • Name who is accountable, and give them the authority (GOVERN 2).
  • Build a team that notices harm, and a culture that reports it (GOVERN 3, 4, 5).
  • Treat vendor tools and third-party models as your risk too (GOVERN 6).

Outputs

  • A policy in plain words
  • A register with owners and review dates
  • A stated risk tolerance

At your size

  1. Step 1: Check
  2. Step 2: Discover
  3. Step 3: Guard (current)
  4. Step 4: Ship
  5. Step 5: Sustain
Does this

Guardrails Pack

Fixed scope · 10 working days · AU $2,900 ex GST

See the scope

Or, if the inventory comes first, ADM Transparency Review.

63 %

of organisations breached through AI had no AI governance policy

Source: IBM and Ponemon Institute, July 2025

Who does what, and when - You are almost always the deployer.

The framework maps seven lifecycle stages against the actors at each one. Most of those columns belong to the vendor. Switch to the small business view to see which of them is you.

Small business view
AI actors by lifecycle stage, each cell marked not involved, involved or leads
StageAI designAI developmentAI deploymentTest, evaluation, verification and validationGovernance and oversightPeople and planet
Plan and designAI design leads at Plan and designAI development not involved at Plan and designAI deployment not involved at Plan and designTest, evaluation, verification and validation involved at Plan and designGovernance and oversight involved at Plan and designPeople and planet involved at Plan and design
Collect and process dataAI design leads at Collect and process dataAI development involved at Collect and process dataAI deployment not involved at Collect and process dataTest, evaluation, verification and validation involved at Collect and process dataGovernance and oversight involved at Collect and process dataPeople and planet not involved at Collect and process data
Build and use modelAI design not involved at Build and use modelAI development leads at Build and use modelAI deployment not involved at Build and use modelTest, evaluation, verification and validation involved at Build and use modelGovernance and oversight involved at Build and use modelPeople and planet not involved at Build and use model
Verify and validateAI design not involved at Verify and validateAI development leads at Verify and validateAI deployment not involved at Verify and validateTest, evaluation, verification and validation leads at Verify and validateGovernance and oversight involved at Verify and validatePeople and planet not involved at Verify and validate
Deploy and useAI design not involved at Deploy and useAI development not involved at Deploy and useAI deployment leads at Deploy and useTest, evaluation, verification and validation involved at Deploy and useGovernance and oversight involved at Deploy and usePeople and planet not involved at Deploy and use
Operate and monitorAI design not involved at Operate and monitorAI development not involved at Operate and monitorAI deployment leads at Operate and monitorTest, evaluation, verification and validation involved at Operate and monitorGovernance and oversight involved at Operate and monitorPeople and planet not involved at Operate and monitor
Use or impacted byAI design not involved at Use or impacted byAI development not involved at Use or impacted byAI deployment involved at Use or impacted byTest, evaluation, verification and validation involved at Use or impacted byGovernance and oversight involved at Use or impacted byPeople and planet involved at Use or impacted by

Hover or tab to a cell to read it in words.

  • Not involved
  • Involved
  • Leads
At your size

A business of 10 to 200 people almost never builds a model. It buys one, or a vendor switches one on. That makes MAP and MANAGE at deployment and operation your whole job, with GOVERN running underneath.

Source: National Institute of Standards and Technology, January 2023

Best practice

As a best practice, the people who verify and validate a system are separated from the people who build or use it.

Source: National Institute of Standards and Technology, January 2023

The Australian overlay - One framework, four names.

The Guidance for AI Adoption, the Voluntary AI Safety Standard and ISO/IEC 42001 all describe the same four moves in different words. Change the lens and the four cards relabel.

GOVERN

  • Cross-cutting

MAP

  • Context

MEASURE

  • Evaluation

MANAGE

  • Execution

The mapping between the four functions and the Australian practices is our analysis, not an official crosswalk. NIST publishes crosswalks, including to ISO/IEC 42001, and the Australian guidance was written to sit alongside both.

Currently reading the four functions as NIST AI RMF.

  1. 26 Jan 2023

    NIST AI RMF 1.0 published

    Four functions, 19 categories, 72 subcategories. Voluntary.

    Source: National Institute of Standards and Technology, January 2023

  2. 1 Feb 2024

    AS ISO/IEC 42001:2023 adopted in Australia

    The AI management system standard, adopted identically.

    Source: Standards Australia, February 2024

  3. 5 Sept 2024

    Voluntary AI Safety Standard

    Ten guardrails for Australian organisations.

    Source: Department of Industry, Science and Resources, September 2024

  4. 29 Oct 2024

    ASIC reports on AI governance gaps

    Of 23 licensees reviewed, nearly half had no policy on fairness or bias in AI.

    Source: Australian Securities and Investments Commission, October 2024

  5. 21 Oct 2025

    Guidance for AI Adoption

    Six essential practices replace the ten guardrails for industry, with a register template and a screening tool.

    Source: National AI Centre, Department of Industry, Science and Resources, October 2025

  6. 2 Dec 2025

    National AI Plan

    No mandatory guardrails for now. Existing law applies, and an AI Safety Institute is created.

    Source: ABC News, 2 December 2025

  7. 15 Dec 2025

    Government AI policy version 2.0

    Accountable officials, transparency statements and use-case registers for Commonwealth entities.

    Source: Digital Transformation Agency, December 2025

  8. 26 Aug 2026

    National Cabinet agrees to legislate AI standards

    Legislation intended in early 2027. What it will require of ordinary business users is not yet defined.

    Source: Prime Minister of Australia, August 2026

  9. 10 Dec 2026

    Privacy Act automated decision-making transparency

    Privacy policies must name the decisions a computer program makes or substantially shapes about people.

    Source: Office of the Australian Information Commissioner, Commences 10 December 2026

Where the framework stands

Version 1.0, January 2023. NIST has announced a revision and has not published it. The Generative AI Profile (July 2024), a draft Cyber AI Profile (December 2025) and an AI Agent Standards Initiative (February 2026) sit alongside it.

This is general information, not legal advice.

Your profile · Eight questions · Three minutes - Where is the widest gap between your Current Profile and the target?

Two questions per function. The profile draws as you answer and names the gap to close first, with the fixed-price step that closes it. Nothing you enter leaves your browser.

1 · GOVERN

Is there a written AI policy staff have seen, and a named person accountable for AI use?
Is there a register of every AI use with an owner and a review date, including AI features a vendor switched on?

2 · MAP

Can you list every AI tool in use, what it is for and what data goes into it?
For each AI use, has someone written down who it affects and whether it makes or shapes decisions about people?

3 · MEASURE

Before an AI tool went live, did anyone measure the process it changes and test it with wrong or hostile inputs?
Is there a number that shows what each AI use changed, checked in the last quarter?

4 · MANAGE

Does every live AI use have a human review step before its output is acted on, and a way to switch it off?
If an AI tool gave a wrong or harmful output, or a vendor changed a default overnight, is there a written plan for who does what?

What closes every gap - One ladder covers all four functions.

The same five steps we scope every engagement with. Each one carries a named set of framework outcomes, so nothing depends on knowing which function a gap belongs to.

  1. Step 1: Check
  2. Step 2: Discover
  3. Step 3: Guard (current)
  4. Step 4: Ship
  5. Step 5: Sustain

01

Check

The MAP inventory: every AI use found, including the ones on personal cards and the features that switched themselves on.

02

Discover

MAP 3 and MANAGE 1: opportunities ranked on value, effort and risk, so the first build is the one that earns its guardrails.

03

Guard

GOVERN in full: policy, register, owners, risk tolerance, the Privacy Act wording.

04

Ship

MEASURE by doing: baseline in week one, hostile test before launch, a measured result in week four.

05

Sustain

MANAGE 4: monthly register review, vendor default watch, incident plan, decommission when a use stops earning its place.

Questions people ask - Four short answers.

The framework is voluntary. The Australian law that applies to how you use AI is not.

Is the NIST AI RMF mandatory in Australia?
No. It is a voluntary United States framework. Australian law that applies to AI use is technology-neutral: the Privacy Act, consumer law, anti-discrimination law and sector rules. The Guidance for AI Adoption and ISO/IEC 42001 both borrow the framework’s structure, so following it puts you ahead of all three.
What are the four functions of the NIST AI RMF?
GOVERN sets the culture, policies and accountability and runs the whole time. MAP establishes the context and the risks of each AI use. MEASURE tests, evaluates and monitors. MANAGE prioritises the risks and acts on them, including after deployment.
How does the framework map to the Australian Guidance for AI Adoption?
Our reading: practice 1 (accountability) and 4 (sharing information) sit in GOVERN; practice 2 (impacts) in MAP; practice 5 (test and monitor) in MEASURE; practices 3 (manage risks) and 6 (human control) in MANAGE. It is an analysis, not an official crosswalk.
Does a business of 20 people need all 72 subcategories?
No. Most apply to organisations that build models. A deployer needs a policy, a register with owners, an inventory with a go or no-go per use, a baseline and a test before go-live, a human review step, a rollback and a plan for when a vendor changes a default. That is about a dozen outcomes, and the profile check on this page covers them.

Sources - Every claim on this page has one.

The framework is theirs. The translation, the Australian mapping and the profile check are ours.

  1. 01Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1National Institute of Standards and Technology · January 2023
  2. 02NIST AI RMF PlaybookNational Institute of Standards and Technology · March 2023, maintained
  3. 03AI RMF: Generative Artificial Intelligence Profile, NIST AI 600-1National Institute of Standards and Technology · July 2024
  4. 04AI Risk Management Framework programme page, revision noticeNational Institute of Standards and Technology · 2026
  5. 05Crosswalks to the AI RMF, including ISO/IEC 42001NIST Trustworthy and Responsible AI Resource Center · Current
  6. 06Cyber AI Profile, NIST IR 8596, initial preliminary draftNational Institute of Standards and Technology · December 2025
  7. 07AI Agent Standards InitiativeNIST Center for AI Standards and Innovation · February 2026
  8. 08Guidance for AI Adoption: six essential practices (Foundations)National AI Centre, Department of Industry, Science and Resources · October 2025
  9. 09Guidance for AI Adoption: implementation practicesNational AI Centre, Department of Industry, Science and Resources · May 2026
  10. 10Voluntary AI Safety StandardDepartment of Industry, Science and Resources · September 2024
  11. 11National AI Plan: growth and existing laws over new AI-specific regulationABC News · 2 December 2025
  12. 12Meeting of National Cabinet, 26 August 2026Prime Minister of Australia · August 2026
  13. 13Policy for the responsible use of AI in government, version 2.0Digital Transformation Agency · December 2025
  14. 14Privacy and Other Legislation Amendment Act 2024, automated decision-making transparencyOffice of the Australian Information Commissioner · Commences 10 December 2026
  15. 15Guidance on privacy and the use of commercially available AI productsOffice of the Australian Information Commissioner · October 2024
  16. 16REP 798 Beware the gap: governance arrangements in the face of AI innovationAustralian Securities and Investments Commission · October 2024
  17. 17Standards Australia adopts AS ISO/IEC 42001:2023Standards Australia · February 2024
  18. 18Cost of a Data Breach Report 2025IBM and Ponemon Institute · July 2025
  19. 19The GenAI Divide, MIT NANDA, as reportedFortune · August 2025
  20. 20Gartner predicts over 40 % of agentic AI projects will be cancelled by the end of 2027Gartner · June 2025
  21. 21SME AI Pulse: adoption insights December 2025 to February 2026National AI Centre · March 2026
  22. 22Trust, attitudes and use of artificial intelligence: a global study 2025KPMG and the University of Melbourne · April 2025
  23. 23Deloitte to partially refund the Australian government over a report with AI-fabricated citationsFortune · October 2025
  24. 24CVE-2025-32711, Microsoft 365 Copilot information disclosure (EchoLeak)Microsoft Security Response Center · June 2025
  25. 25New guidelines and practice directions to combat generative AI hallucinations in Queensland courts and tribunalsMcCullough Robertson · October 2025

This page is general information, not legal advice or a risk assessment. The framework is NIST’s; the translation, the Australian mapping and the profile check are ours. The eight AI uses in the tolerance field are synthetic. Nothing entered in the profile check is collected.

Want the whole picture, not just the framework?

Nine questions, three minutes, nothing leaves your browser. The scorecard shows which of the five steps you are on and which service fits.

Take the AI scorecard

Want your profile drawn properly? Book a call.

Twenty minutes. We tell you which function to close first, what it costs, and whether you need us at all.

Book a call

+61 490 083 850 · Wollongong, NSW