January 23, 2024 By Kim Walsh AI and Emerging Tech, Governance and Compliance

NIST published the AI Risk Management Framework in January 2023 and for about six months after that it existed primarily as a document that risk professionals knew about, referenced in conversations, and had not yet been asked to operationalize in any serious way. That period is over.

In 2024, the AI RMF is showing up in procurement requirements, regulatory guidance documents, and board-level questions about organizational AI governance in ways that have moved it from background reading to active practice. Organizations that have deployed AI systems, or that are planning to, are being asked to demonstrate that they have a structured approach to managing the risks those systems introduce. The NIST AI RMF is the most widely recognized framework for doing that, and not having a clear answer to “how does your AI risk management map to the framework” is an increasingly uncomfortable position.

The framework itself is organized around four core functions: Govern, Map, Measure, and Manage. These functions are designed to work together to create a structured approach to identifying AI-related risks, assessing those risks against the context of the organization’s risk tolerance, and implementing appropriate controls and oversight mechanisms. The document is available directly from NIST and reading it directly is worth the time for any governance professional who is going to be asked to apply it.

The Govern function is where most organizations are going to find the most immediate work. It addresses the policies, processes, roles, and responsibilities that need to exist for AI risk management to be sustainable rather than ad hoc. Who is accountable for AI risk in the organization? What approval process exists before a new AI system is deployed? How are ongoing AI systems monitored for performance and risk? These are governance questions that existing frameworks like COBIT and ISO 27001 provide some scaffolding for but do not address with the AI-specific context that the NIST framework provides.

The Map function addresses the context-setting work of understanding where AI is being used in the organization, what the intended purposes of those systems are, and what categories of risk are relevant given those purposes and the contexts in which they operate. This is essentially a risk identification process specific to AI, and it draws on the same risk assessment methodology that CRISC and CISA practitioners already apply in other domains. The transfer of skills is real and meaningful.

Measure addresses the development and use of metrics and methods for assessing AI risks identified in the mapping phase. This is an area where the field is still developing, and the NIST framework acknowledges that honest. Quantitative risk metrics for AI systems, particularly for risks like bias, fairness, and explainability, are harder to develop than metrics for more traditional IT security controls. The framework points toward the direction without prescribing a single methodology, which is appropriate given the current state of the field.

Manage covers the selection and implementation of risk response actions, the monitoring of those responses, and the continuous improvement processes that should keep the risk management approach current as AI systems and the risk landscape evolve. This maps most directly to existing risk management practice and is where governance professionals with GRC backgrounds will find the most familiar footing.

For compliance and GRC professionals who have not yet engaged seriously with the AI RMF, now is the time. The window for treating AI governance as someone else’s problem is closing. Organizations are asking who can lead this work, and the answer should be governance professionals with the framework literacy and risk methodology skills to do it rigorously. ISACA has developed AI governance guidance that supplements the NIST framework and their resources at ISACA’s AI governance resources are worth adding to your reading list alongside the NIST document.

Building familiarity with the AI RMF now, before your organization is under pressure to demonstrate compliance with it, puts you in a position to lead that work rather than scramble to catch up. The demand for people who can do this competently is going to outpace the supply for a while. That is a career opportunity worth taking seriously.

Kim Walsh

Kim Walsh is a CISSP and seasoned cybersecurity practitioner with deep, hands-on experience in enterprise security architecture, risk management, and compliance. She is passionate about bringing the next generation into the IT and AI space, actively mentoring young people who are just finding their footing in the field. As the mother of five kids, she has both the patience and the battle-tested communication skills to explain just about anything to just about anyone.