NIST AI RMF
A voluntary structure for governing, mapping, measuring, and managing AI risk across the lifecycle.
Put it to work Build a shared risk language and a use-case risk record.
AI RMF 1.0 is under revision; check NIST for updates.
FreeFIELD GUIDE / AI SECURITY MANAGEMENT
A practical route through governance, risk, and security. Pick where your company is today. Take the tools you need for what comes next.
Choose by use case. Different teams can be at different stages.
For teams exploring AI, choosing tools, or experimenting with a few use cases. Start with the benefit, the people affected, and the capacity to operate it safely.
Define the task, who benefits, and what a successful pilot would improve. Compare it with a workable non-AI baseline.
Agree who approves the use case, which tools and data are permitted, and which decisions require human review.
Inventory approved and unofficial AI tools, their owners, data exposure, suppliers, and intended uses.
Assess foreseeable harms, privacy and security needs, and whether the team has the skills, oversight, and evidence to run the pilot.
Set evaluation criteria, escalation routes, a fallback, and a review date before expanding the pilot.
Original guidance informed by these notebook topics, with official resources linked below. The three paths are an editorial guide, not a formal maturity standard.
For teams with AI in day-to-day work. Connect security, evaluation, suppliers, and human oversight to the way each system is actually used.
Record model and application versions, data sources, retrieval stores, integrations, owners, and provider/customer responsibilities.
Evaluate quality, privacy, relevant bias, robustness, and misuse using representative examples. Retest when models, prompts, data, or workflows change.
Limit access and tool permissions, isolate untrusted inputs, validate outputs, and protect sensitive data. A system prompt is not an access control.
Assign owners and response thresholds for quality, data changes, safety events, costs, and incidents. Exercise rollback and human escalation.
Check retention, training use, sub-processors, change notices, and incident support. Tie each release to evaluation evidence and explicit risk acceptance.
Original guidance informed by these notebook topics, with official resources linked below. The three paths are an editorial guide, not a formal maturity standard.
For organizations running AI across products or business units. Make assurance repeatable, challenge your controls, and use the results to improve them.
Map applicable framework requirements to owners, system scope, test results, and review dates. Automate evidence collection where it remains reliable.
Use risk-led red teaming, control testing, and independent reviews. Validate relevant failure scenarios and track fixes through retesting.
Track concentration in vendors and models, common data dependencies, and incident trends alongside business outcomes. Set escalation and exception expiry rules.
Use scoped identities, least-privilege tools, external policy enforcement, approval gates, execution limits, and safe interruption. Agent adoption is a design choice.
Review the management system, lessons from incidents, and corrective actions. Pursue external certification when it serves a defined organizational need.
Original guidance informed by these notebook topics, with official resources linked below. The three paths are an editorial guide, not a formal maturity standard.
THE RESOURCE SHELF
Explore the official resources.
A voluntary structure for governing, mapping, measuring, and managing AI risk across the lifecycle.
Put it to work Build a shared risk language and a use-case risk record.
AI RMF 1.0 is under revision; check NIST for updates.
FreePractical suggestions to help translate AI RMF outcomes into organizational actions.
Put it to work Select actions for your context and assign their owners.
Use alongside the AI RMF; tailor the actions to your system.
FreePrinciples for human rights, fairness, transparency, robustness, safety, and accountability.
Put it to work Translate your organization's AI values into policies and decision criteria.
High-level principles need supporting controls and evidence.
FreeRequirements for establishing, maintaining, and improving an AI management system.
Put it to work Structure policies, responsibilities, operations, reviews, and continual improvement.
Start applying the management approach at any stage; certification is a separate assessment.
Free overview · paid standardAI RMF companion guidance focused on risks and suggested actions for generative AI.
Put it to work Extend evaluations and risk treatment for your GenAI use cases.
NIST AI 600-1; use with the core AI RMF.
FreeCommon LLM application risks including prompt injection, data disclosure, unsafe output handling, and excessive agency.
Put it to work Choose abuse cases and security tests for your application.
A useful risk catalogue; it does not cover every threat.
FreeAI control objectives, framework mappings, implementation guidance, and the AI-CAIQ questionnaire.
Put it to work Assign shared control responsibilities and collect supplier or internal evidence.
Select guidance for your role: customer, application, model, platform, or cloud provider.
Free resource · account may be neededA living knowledge base of adversary tactics, techniques, mitigations, and case studies involving AI.
Put it to work Threat-model your systems and plan adversarial control tests.
Useful earlier too, whenever an AI system needs threat modelling.
FreeOfficial policy information and links to the law, guidance, and AI Act Service Desk.
Put it to work Investigate applicability by jurisdiction, system use, and provider/deployer role.
Check current guidance and sector obligations; these stages do not determine legal risk categories.
FreeThese paths are an original way to navigate resources, informed by my AISM study notebook and checked against official publisher pages. Frameworks can be useful at several stages; the recommendations indicate a starting point, not an eligibility rule.
Adapt actions to each use case, organization, and applicable obligations. Completing a checklist does not establish certification, legal compliance, or system safety. The PDF handouts are original planning templates; source PDFs and paid study materials are not redistributed.
Resource pages reviewed October 3, 2026. Frameworks and regulations evolve; follow the official links for current material.