
Explore the NIST AI RMF to assess, manage, and mitigate AI risks, including fairness, security, privacy, and explainability, for responsible deployment. Review how regulation and incidents drive ethical oversight.
Explore the NIST AI RMF, a community-driven, adaptable framework guiding risk management across the AI life cycle. It reduces risk, builds trust, and supports compliant, ethical AI.
Demonstrates the NIST AI risk management framework in health care by detailing governance, system architecture, risk metrics, and mitigation through encryption, audits, and real-time monitoring for Health AI.
Examine why AI risk is hard to measure, undefined risks, third‑party components, and emergent risks, and see how the AI RMF prioritizes risk within organizational contexts.
Prioritize AI risks by context, triaging failures, and documenting residual risk to ensure trustworthy health AI and alignment with enterprise risk management.
Balance trustworthiness traits: validity, reliability, safety, security, resilience, accountability, transparency, explainability, and fairness, guiding AI risk management through stakeholder input and context-driven trade-offs.
Enhance accountability through transparency across design choices, data provenance, and decision processes. Enable explainability, interpretability, privacy, and fairness to reinforce trust and allow redress for adverse outputs.
Navigate the four core functions of the NIST AI RMF—governance, map, measure, and manage—to identify, assess, and mitigate AI risks, with a flexible playbook for actionable guidance across AI lifecycle.
The governance function establishes policies, processes, and practices to map, measure, and manage AI risks with transparency and accountability, aligning with ethical standards and regulatory requirements.
Establish a transparent risk management process with clear policies, procedures, and controls aligned to organizational risk priorities, supported by standardized documentation across the AI lifecycle.
Document roles and responsibilities, lines of communication for mapping, measuring, and managing ai risks, ensure independent testing from development, and emphasize executive leadership oversight and risk management training.
Governance 3 focuses on mapping, measuring, and managing AI risks across the life cycle, supported by diverse, senior-led teams with clear roles, training protocols, and transparent human oversight.
Governance 4.1–4.3 cultivate a safety-first, risk-aware culture across the AI lifecycle by employing three lines of defense, red teaming, impact assessments, transparent documentation, and incident sharing.
Establish policies to collect, consider, and integrate external stakeholder feedback on AI risks, using participatory engagement across the life cycle to inform design, risk tolerance, and accountability.
Governance 6.1 and 6.2 establish policies to vet, integrate, and audit third-party data, software, and hardware for AI risk management. Emphasize transparency, explainability, and contingency planning in health AI diagnostics.
Map 1.1–1.3 document the intended purpose, beneficial uses, laws, expectations, and user contexts, while emphasizing interdisciplinary teams and transparency in health AI risk management.
Map 1.4–1.6 guide aligning AI systems with organizational values and sociotechnical context, define business value, set risk tolerances for go/no-go decisions, and elicit stakeholder-driven requirements with transparency.
Map 2 under the nist ai risk management framework emphasizes clearly defining ai tasks and methods, such as classifiers or diagnostic imaging, to map benefits and risks for health ai.
Document benefits, costs, and targeted scope through stakeholder engagement and participatory design in Health AI systems, as outlined in map 3.1–3.3 of the NIST AI RMF.
Map 3.4 frames operator proficiency, training, documentation, and certified integration of ai into domain expertise, while Map 3.5 codes human oversight and governance-driven practices for health ai.
Map 4 guides mapping AI technology and legal risks from third party data or software, documenting methods to address IP, privacy, and biases in Health AI.
Map 5 documents the likelihood and magnitude of AI impacts, both beneficial and harmful, from expected use, past contexts, and external feedback, guiding independent third-party testing and risk-based resource allocation.
Explore the measure function for assessing AI risk using quantitative, qualitative, or mixed methods. Learn to test, benchmark, document results, and use metrics to inform management decisions and risk monitoring.
Measure 1 prioritizes selecting metrics to quantify AI risks identified during mapping, focusing on the most significant risks and ensuring transparent documentation for trustworthy health AI systems.
Document test sets, metrics, and tools for repeatable AI risk management. Evaluate with human subject protection and deployment-like conditions.
Continuously monitor deployed AI systems in production for drift and safety, validating performance before deployment and documenting limitations through real-time statistics, clinical feedback, transparency, and human oversight.
Evaluate measures 2.7 to 2.9 to secure AI systems, ensure resilience, promote transparency and accountability, and document explainability, validation, and model cards for healthcare decisions.
Health AI uses measure 2.10 to protect patient privacy with differential privacy, data de-identification, data governance, and audits, while measure 2.11 evaluates fairness with transparent documentation.
Assess environmental impact across the artificial intelligence lifecycle in healthcare diagnostics, document emissions, apply carbon calculators, monitor energy and water; evaluate metrics with end-user input to ensure transparency and equity.
Health AI implements measure 3 of the NIST AI risk management framework by identifying and tracking existing and emergent AI risks through real-time monitoring and comprehensive documentation.
Measure 4.1–4.3 outline integrating deployment contexts, domain expert and end-user feedback, documenting measurement approaches, and sustaining a transparent, participatory loop to improve trustworthiness, safety, and performance in health AI diagnostics.
Manage function allocates risk resources to mapped and measured risks, implements risk treatment plans to respond, recover, and communicate incidents, using governance, expert input, documentation, and improvement to reduce failures.
Assess whether a health ai system meets its intended purpose and objectives and decide whether to proceed, balancing risks and benefits with trustworthiness factors like performance, transparency, and ethical compliance.
Develop responses to high priority AI risks identified by the map function, document mitigating, transferring, avoiding, or accepting actions, and residual risks under manage 1.4 health AI with NIST RMF.
Evaluate resources and viable non-ai alternatives to manage health AI risks, plan with risk tolerances and stakeholder engagement, and sustain AI value through monitoring, data management, privacy controls, and transparency.
Manage 2.3 outlines procedures to respond to unknown risks in health AI, with continuous monitoring and rapid incident response, while 2.4 assigns clear responsibilities and disengagement protocols.
Manage 3 outlines governing risks and benefits of third party resources in health AI diagnostics, with risk controls, documentation, pre-trained models, transfer learning, and decommissioning when risk tolerance is exceeded.
Explore post-deployment monitoring that captures user and AI-actor input, supports incident response and change management, and drives continual improvement with bias, privacy, and security considerations.
Aligns the governance, map, measure, and manage functions of the NIST AI RMF to identify, assess, and mitigate AI risks, building trust, safety, and ethical systems.
The "NIST AI Risk Management Framework (AI RMF)" course is designed to equip professionals with the knowledge and tools needed to navigate the complexities of AI risk management effectively. This course delves into the NIST AI RMF, providing a thorough understanding of its principles, functions, and practical applications. Students will explore the MAP, MEASURE, and MANAGE functions, learning how to identify, assess, and mitigate AI risks throughout the AI lifecycle.
Participants will gain insights into the importance of trustworthiness in AI systems, covering key characteristics such as validity, reliability, safety, security, resilience, accountability, transparency, explainability, interpretability, privacy enhancement, and fairness. The course emphasizes the need for a holistic approach to AI risk management, integrating these characteristics to develop robust and trustworthy AI solutions.
Through real-world examples and case studies, including HealthAI, students will see the practical application of the AI RMF in various contexts. The course also covers the importance of continual monitoring and improvement, ensuring that AI systems remain aligned with organizational goals and societal values as they evolve.
This course is ideal for AI practitioners, risk managers, data scientists, and organizational leaders who are involved in the development, deployment, or oversight of AI systems. No prior experience with the NIST AI RMF is required, making it accessible to beginners and valuable to seasoned professionals alike. Join us to master the art of AI risk management and ensure the development of safe, reliable, and ethical AI systems.