πŸ”’
Access Restricted
Please enter your credentials to access the audit module.
Invalid username or password.
NIST AI 100-1 Β· RMF 1.0 Β· Audit Learning Module

AI Risk Management
Audit Framework

An interactive learning module aligned with NIST AI 100-1. Master the four core functions β€” GOVERN, MAP, MEASURE, MANAGE β€” through structured checklists, evidence guides, and assessments.

4
Core Functions
21
Categories
72
Subcategories
25
Quiz Questions
πŸ“Š Audit Completion Dashboard
GOVERN 0%
MAP 0%
MEASURE 0%
MANAGE 0%
Overall Audit Progress
0%
πŸ“‹ AI System Lifecycle
πŸ”¬
Plan & Design
Phase 1
πŸ› οΈ
Develop & Train
Phase 2
πŸ§ͺ
Evaluate & Verify
Phase 3
πŸš€
Deploy & Use
Phase 4
πŸ“Š
Monitor & Maintain
Phase 5
πŸ”„
Retire & Decommission
Phase 6
πŸ”· The Four Core Functions
πŸ›οΈ GOVERN

Cultivates organizational culture and policies for AI risk management. Establishes accountability, roles, processes, and transparency across all other functions. It is the foundation β€” all other functions are informed by GOVERN.

GOVERN 1 Β· Policies GOVERN 2 Β· Accountability GOVERN 3 Β· DEIA GOVERN 4 Β· Culture GOVERN 5 Β· Stakeholders GOVERN 6 Β· Supply Chain
πŸ—ΊοΈ MAP

Establishes context for AI system risks. Identifies intended uses, stakeholders, potential harms, and environmental factors. Contextual discovery enables meaningful risk identification and framing before assessment begins.

MAP 1 Β· Context MAP 2 Β· Stakeholders MAP 3 Β· Harms MAP 4 Β· Benefits MAP 5 Β· Impacts
πŸ“ MEASURE

Quantifies and qualifies identified AI risks using metrics, benchmarks, and testing methods. Evaluates performance, fairness, safety, and security through structured TEVV (Test, Evaluate, Verify, Validate) activities.

MEASURE 1 Β· Methods MEASURE 2 Β· Testing MEASURE 3 Β· Tracking MEASURE 4 Β· Feedback
βš™οΈ MANAGE

Implements controls and mitigation strategies for prioritized AI risks. Plans responses, monitors outcomes, and drives continuous improvement. Includes incident response, decommissioning, and ongoing operational risk oversight.

MANAGE 1 Β· Prioritize MANAGE 2 Β· Strategies MANAGE 3 Β· Responses MANAGE 4 Β· Monitoring
βœ… Trustworthy AI Characteristics (NIST AI 100-1, Part 1)
βœ”οΈ
Valid & Reliable
The AI system performs accurately for its intended purpose and functions consistently under expected operating conditions. This is the foundation for all other trustworthy characteristics.
πŸ›‘οΈ
Safe
The system does not, under defined conditions, cause physical, digital, psychological, financial, or societal harm to people or the environment. Safety is the primary risk consideration.
πŸ”’
Secure & Resilient
Protected against malicious manipulation and unauthorized access (security) and capable of withstanding or recovering from adverse events, disruptions, or attacks (resilience).
πŸ“’
Accountable & Transparent
Responsibility for system outcomes is clearly assigned to appropriate actors (accountability). Adequate information about the system is disclosed to relevant stakeholders (transparency).
πŸ’‘
Explainable & Interpretable
System outputs and the underlying reasoning are understandable to humans. Explainability supports informed decision-making and meaningful human oversight of AI systems.
πŸ”
Privacy-Enhanced
Protections for personal and sensitive data are embedded throughout the AI system lifecycle, from design through decommissioning, consistent with applicable privacy laws and regulations.
βš–οΈ
Fair with Bias Managed
Outputs are equitable and efforts are made to identify, assess, and mitigate unjustified disparate impacts, discrimination, or harmful bias across groups and individuals.
πŸ›οΈ
Core Function

GOVERN

Cultivates a culture of risk management. Establishes organizational policies, processes, accountability structures, and transparency practices. GOVERN is a cross-cutting function that underpins and informs all other RMF functions throughout the AI lifecycle.

πŸ—ΊοΈ
Core Function

MAP

Identifies and contextualizes AI risks. Involves understanding the system's intended purpose, stakeholders, deployment environment, and potential failure modes or harms. MAP enables meaningful risk framing and prioritization for downstream assessment.

πŸ“
Core Function

MEASURE

Evaluates and analyzes AI risks using quantitative and qualitative methods. Focuses on Test, Evaluate, Verify, and Validate (TEVV) activities covering performance, fairness, safety, and security metrics, enabling evidence-based risk decisions.

βš™οΈ
Core Function

MANAGE

Prioritizes and acts on AI risks identified during MAP and MEASURE phases. Implements controls, mitigation strategies, and incident response plans. Drives continuous improvement through monitoring, feedback loops, and decommissioning processes.

🧠
Knowledge Assessment
Test your understanding of NIST AI RMF concepts and audit procedures
πŸ“ 25 Questions ⏱️ ~15 min 🎯 All 4 Functions πŸ“š NIST AI 100-1
--
of 25

--
GOVERN
--
MAP
--
MEASURE
Score: 0 / 0

Based on NIST AI 100-1: AI Risk Management Framework (AI RMF 1.0) Β· National Institute of Standards and Technology

This module is for educational purposes. All content is derived from publicly available NIST publications.