
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.
Govern, Map, Measure, Manage — the four functions behind the voluntary US AI risk framework, and why organizations outside the US use it too.
Most organizations building an AI governance program start by asking "which regulation applies to us" — a reasonable question, but the wrong first one. Regulations tell you what you're legally required to do; they don't tell you how to actually run a risk-management process day to day. That's what NIST's AI Risk Management Framework is for — and it's why organizations well outside the US, including plenty operating solely under the EU AI Act or UK guidance, use it as the operational engine underneath whatever law actually binds them.
NIST released AI RMF 1.0 in January 2023 as voluntary guidance — not a law, not a certification, and not tied to any single jurisdiction. It's a process framework for managing risk across an AI system's full lifecycle, from initial design through deployment and eventual retirement. Unlike a control checklist you can simply tick through, it's meant to be applied iteratively: revisited as a system changes, not completed once and filed away.
The framework's structure is genuinely useful independent of any specific law, which is exactly why it travels well across jurisdictions:
NIST's own AI RMF Playbook breaks each function down into concrete, suggested actions — useful as a starting checklist, though it's explicitly non-prescriptive about exactly how an organization implements them.
The AI RMF was never going to be the only relevant AI governance document for an EU or Gulf-based organization — the EU AI Act, the UK's sectoral approach, and the UAE and Saudi Arabia's own emerging frameworks each carry their own binding or non-binding obligations. What the RMF offers instead is a jurisdiction-agnostic risk process that sits underneath whichever specific law or standard actually applies — the same reason ISO/IEC 42001, a certifiable management-system standard built on similar risk-management logic, has seen international adoption despite ISO 27001 already being the more commonly cited baseline in most of these organizations' existing security programs.
The Measure function is where a lot of AI governance programs quietly fall short — treating "risk measurement" as a documentation exercise rather than genuinely testing what a deployed system can be made to do. Our own breakdown of what actually happens when someone tries to break an LLM-powered feature and how to secure AI models and LLM deployments in practice cover the technical side of that measurement — least privilege for agents, treating external input as untrusted, and real adversarial testing against the system you've actually deployed, not the vendor's underlying foundation model.
If you're building an AI governance program from scratch, the AI RMF is a genuinely reasonable place to start the risk-management process itself, independent of which specific regulation ultimately governs your deployment. Our AI Services engagements test what a deployed AI system can actually be made to do — the real-world input the RMF's Measure function calls for — and our Cybersecurity Consulting team can help build the governance structure the Govern function describes around your actual environment.
Tell us about your environment and goals — we'll help you scope the right engagement.