Direct answer

The NIST AI Risk Management Framework is a voluntary, rights-preserving, non-sector-specific resource for organizations that design, develop, deploy, or use AI. Its core organizes outcomes around Govern, Map, Measure, and Manage.

Govern is cross-cutting. Map establishes context and identifies risks. Measure evaluates risks and trustworthiness using appropriate methods. Manage prioritizes, treats, monitors, and communicates risk. These functions are not a one-time checklist or fixed sequence; organizations apply them continuously and proportionally across the lifecycle.

Use boundary

Use the source documents and qualified legal, audit, certification, or technical advice for formal obligations. This concept is an executive orientation, not a substitute for the underlying standard or law.