Siam Thanat Hack Co., Ltd.

What NIST AI Risk Management Framework 1.0 is and how to turn GenAI risk into a test plan

NIST AI RMF helps answer the questions leaders ask before adopting AI: what can go wrong, how will it be measured, and who decides? This page connects AI RMF 1.0, NIST AI 600-1, and evidence from AI red teaming.

Executive Summary and Mandate Overview
Target Audience Enterprises developing, procuring, or deploying AI and Generative AI systems across industries
Mandatory Frequency Continuous empirical evaluation and risk management across all lifecycle phases
Required Scope Govern, Map, Measure, Manage, seven trustworthy-AI characteristics, and the 12 NIST AI 600-1 risk categories
Non-Compliance Risk Confabulation, data disclosure, prompt injection, agent abuse, supply-chain risk, and evidence-free release decisions

Four functions that move teams from policy to decisions

AI RMF 1.0 is voluntary and sector agnostic. Version 1.0 remains the current published framework while NIST develops a revision that has not yet replaced it.

Infographic explaining: Four functions that move teams from policy to decisions
Visual guide: Four functions that move teams from policy to decisions
  • GOVERN establishes risk culture, policy, accountability, risk tolerance, and third-party processes so teams use consistent criteria.
  • MAP identifies intended use, users, context, boundaries, dependencies, and impacts so teams do not evaluate a model outside its deployment reality.
  • MEASURE selects metrics and TEVV methods for performance, trustworthiness, limitations, and control effectiveness before and after deployment.
  • MANAGE prioritizes risk, informs go-live decisions, selects treatment, tracks residual risk, and returns incident evidence to governance.

Seven trustworthy-AI characteristics that must be measured together

High accuracy does not make a system deployment-ready. NIST identifies seven characteristics that can reinforce or conflict with one another, requiring context-specific trade-offs.

  • Valid and Reliable and Safe address intended performance, known limitations, and harm within the deployment context.
  • Secure and Resilient and Privacy-Enhanced address attacks, failures, disruption, and inappropriate data disclosure.
  • Accountable and Transparent and Explainable and Interpretable address responsibility, traceability, and explanations suitable for affected users.
  • Fair with Harmful Bias Managed addresses uneven impact and the processes used to discover, document, and reduce harmful bias.

NIST AI 600-1 adds risks amplified by generative AI

NIST AI 600-1 is a 2024 cross-sectoral profile of AI RMF 1.0. It defines 12 risk categories and suggested actions that organizations select based on context, resources, and risk tolerance.

  • Accuracy and safety risks include Confabulation, Information Integrity, Dangerous Content, CBRN Information, and Obscene or Abusive Content.
  • People and societal risks include Data Privacy, Harmful Bias and Homogenization, and Human-AI Configuration.
  • Technology and business risks include Information Security, Intellectual Property, Environmental Impact, and Value Chain and Component Integration.
  • The profile emphasizes test plans, deployment thresholds, provenance, independent evaluation, monitoring, incident response, and shutdown plans for unacceptable risk.

Where penetration testing and AI red teaming fit in Measure

AI RMF does not impose a fixed pentest requirement. It establishes TEVV and independent-assessment outcomes. NIST AI 600-1 then names AI red teaming as a suggested action for information security.

  • MEASURE 1.3 involves internal experts who were not front-line developers or independent assessors according to organizational risk tolerance.
  • MEASURE 2.3 evaluates performance or assurance criteria under deployment-like conditions. MEASURE 2.4 monitors system functionality and behavior in production.
  • NIST AI 600-1 action MS-2.7-007 recommends red teaming for prompt injection, data poisoning, membership inference, model extraction, and abuse against other systems.
  • Feed test results into MANAGE for treatment, go-live decisions, remediation priority, and residual-risk acceptance rather than ending with a vulnerability report.

Turn AI RMF into a test plan tied to business risk

A strong test plan begins with use cases and harms, not a payload list. It then selects metrics, attack scenarios, and evidence that answer the risk owner's questions.

NIST AI RMF diagram showing Govern, Map, Measure, and Manage with a customer-service AI example and MS-2.7-007 red teaming
An example connecting risk owners, system boundaries, testing, and treatment through AI RMF
  • GOVERN defines risk owners, approval authority, risk tolerance, escalation, and testing constraints.
  • MAP creates the AI inventory, data flows, trust boundaries, dependencies, user journeys, agent permissions, and misuse cases.
  • MEASURE runs benchmarks, abuse cases, prompt injection, data leakage, agent-tool abuse, load tests, and detection validation in controlled environments.
  • MANAGE prioritizes findings from impact and likelihood, then assigns remediation, retesting, risk acceptance, and production-monitoring triggers.

Requirements and Testing Scope Matrix

Summary of the referenced clauses, the testing scope they cover, and the expected evaluation cycle.

Reference Mandate Title Scope Required Testing Cycle
MEASURE 1.3, 2.3, and 2.4 Independent assessment, assurance criteria, and production monitoring Use risk-appropriate assessors, measure deployment-like conditions, and monitor behavior in production Before go-live, after significant change, and according to risk tolerance
MAP 1.1 and MAP 1.5 Context, boundary mapping, and impact assessment Map AI attack surfaces, functional boundaries, and stakeholder safety/privacy impacts Project inception and major architectural revisions
NIST AI 600-1 MS-2.7-007 AI red teaming for information security Test prompt injection, data poisoning, membership inference, model extraction, and GenAI-assisted attacks Before release and after changes to models, data, prompts, tools, or risk profiles
MANAGE 2.4 and 4.1 Risk treatment, remediation, and feedback Execute remediation plans for identified vulnerabilities and feed results into governance Continuous remediation and retest tracking

Compliance Readiness Self-Assessment

Select items your organization has completed to evaluate your readiness score.

0%

Official source documents

Verify AI RMF 1.0, NIST AI 600-1, and framework revision status on the NIST website.

Go to the official source