SkarpSkarp

Chapter 2 of 13

Inside the AI RMF Core: The Four Functions and Their Outcomes

Behind the buzzwords ‘Govern, Map, Measure, Manage’ lies a detailed set of outcomes that describe what good AI risk management actually looks like. This module walks through the AI RMF Core so you can see how the four functions organize concrete activities across the AI lifecycle.

15 min readen

Step 1 – From Principles to the AI RMF Core

Zooming into the AI RMF Core

The NIST AI RMF 1.0 (released 2023) turns AI principles into concrete practices. Its Core section describes in detail what good AI risk management looks like.

Core Structure

The AI RMF Core is organized as Functions → Categories → Subcategories. The four top-level Functions are: Govern, Map, Measure, Manage.

Lifecycle & Sociotechnical View

These Functions span the entire AI lifecycle and use a sociotechnical view: they care about technical performance and real-world impacts on people, organizations, and systems.

Your Learning Goal

You do not need to memorize every Subcategory. Focus on: how the structure works, what each Function aims to achieve, and how Functions overlap across the lifecycle.

Step 2 – The Core Structure: Functions, Categories, Subcategories

Three-Level Structure

The AI RMF Core is a table of desired outcomes with three levels: Functions → Categories → Subcategories.

Functions

There are four Functions: Govern, Map, Measure, Manage. They are big clusters of activities and are not strictly sequential; they overlap and repeat.

Categories

Each Function has several Categories that group related outcomes. Example: Govern may include "Policies, Processes, and Procedures" and "Workforce".

Subcategories

Each Category has Subcategories: specific, observable outcomes, often starting with verbs like "identified", "documented", or "monitored".

How Orgs Use It

As of 2026, organizations often mirror this structure in internal AI policies and control libraries, aligning their tasks with Functions, Categories, and Subcategories.

Step 3 – Quick Mapping Exercise: Where Does This Fit?

Try this thought exercise to get used to the Functions.

For each activity below, decide which Function it mainly belongs to: Govern, Map, Measure, or Manage.

  1. A company sets an AI policy that says: "High-risk models must undergo bias assessment before deployment."
  2. A team interviews end-users and domain experts to understand how an AI tool might change their workflows.
  3. Data scientists run a fairness test comparing model performance across demographic groups.
  4. An operations team rolls back a newly deployed model after monitoring shows unexpected errors.

Pause and answer before checking the suggested mapping:

Suggested mapping

  1. Govern – setting policies and rules.
  2. Map – understanding context, stakeholders, and use.
  3. Measure – testing and evaluating technical and socio-technical properties.
  4. Manage – acting on risk information during deployment and operations.

Notice that in real projects, tasks can touch more than one Function, but one is usually primary.

Step 4 – Govern: Setting the Ground Rules for AI

What is Govern?

Govern is about how an organization sets direction, assigns responsibility, and builds a culture for trustworthy AI risk management.

Key Themes

Govern covers: AI risk policies, roles and responsibilities, workforce skills and culture, and integration with existing risk, privacy, and security governance.

Across the Lifecycle

Govern is continuous: it shapes which AI projects are allowed, what checks are needed before deployment, and when systems must be updated or retired.

Sociotechnical Focus

Govern emphasizes human and societal impacts, not just model accuracy. Policies may forbid deployments that could enable discrimination or unsafe uses.

Regulatory Context

As of 2026, laws like the EU AI Act expect strong AI governance. The AI RMF Govern Function offers a widely used, non-regulatory reference model.

Step 5 – Govern in Practice: A University Chatbot

Scenario: University Chatbot

A university wants an AI chatbot to answer financial-aid questions. How does the Govern Function appear in this project?

Policies & Roles

The university labels this chatbot "high impact" and assigns a system owner, technical owner, and risk contact with clear responsibilities.

Standards & Requirements

Policies require privacy impact assessments, bias and accuracy checks, and escalation paths when the chatbot is uncertain.

Training & Culture

Staff supervising the chatbot are trained to spot harmful answers, override the system, and report incidents centrally.

Why This is Govern

These actions set the environment and expectations for the AI system. They are governance, not model-building, and belong to the Govern Function.

Step 6 – Map: Understanding Context, Use, and Stakeholders

What is Map?

Map is about deeply understanding the AI system's purpose, context, stakeholders, and potential impacts before and during development.

Key Questions

Map outcomes answer: What problem are we solving? Who are the stakeholders? In what context will AI operate? What can go wrong and who could be harmed?

Typical Map Themes

Map covers context establishment, stakeholder and impact analysis, and risk identification and prioritization.

Across the Lifecycle

Map is strongest in planning and design but should be revisited whenever use, context, or observed risks change.

Sociotechnical Focus

Map looks beyond data and models to how AI interacts with processes, laws, and human decision-making. Many real-world failures trace back to weak mapping.

Step 7 – Quick Check: Govern vs Map

Test your understanding of the difference between Govern and Map.

A hospital plans to use an AI tool to prioritize patients in the emergency room. Which activity is the **best example of the Map Function**?

  1. Approving an organization-wide policy that all high-risk AI must go through an ethics review board.
  2. Interviewing nurses and doctors to understand how triage decisions are currently made and what could go wrong if AI makes mistakes.
  3. Assigning a Chief AI Officer who is accountable for all AI systems in the hospital.
  4. Requiring that the vendor provide monthly performance reports for the AI tool after deployment.
Show Answer

Answer: B) Interviewing nurses and doctors to understand how triage decisions are currently made and what could go wrong if AI makes mistakes.

Option 2 is Map: it focuses on understanding current workflows, context, and potential harms. Options 1 and 3 are Govern (policies and roles). Option 4 is closer to Manage (ongoing oversight and action based on performance).

Step 8 – Measure: Evaluating AI Risks and Performance

What is Measure?

Measure is about assessing the AI system: collecting evidence on risks and performance so decisions are based on data, not guesses.

Key Questions

Measure asks: How accurate, robust, fair, secure, and reliable is the system? How do we know? How uncertain are we about those answers?

Typical Measure Themes

It covers metric selection, testing and validation (including red-teaming), and documenting uncertainty and limitations.

Across the Lifecycle

Measure is central in development and pre-deployment, but continues in production via monitoring, drift detection, and re-evaluation.

Beyond Technical Metrics

Measure also includes sociotechnical evaluations: user studies, human feedback, and impact assessments, not just numerical scores.

Step 9 – Measure & Manage: A Generative AI Content Tool

Scenario: Generative AI for Marketing

A company uses a generative AI model to draft marketing content. How do Measure and Manage appear in this case?

Measure: What to Test

They define tests for hallucinations, toxicity and bias, and brand safety, and run red-team exercises to probe the model's behavior.

Manage: Acting on Results

Based on test results, they limit use to internal drafts, require human review, add filters, and define incident response steps.

Ongoing Management

They schedule re-testing after model or prompt changes, closing the loop between measurement and management.

Measure → Manage Loop

This shows the pattern: Measure provides evidence; Manage uses that evidence to adjust deployment, controls, and responses.

Step 10 – Linking the Four Functions Across the Lifecycle

Check how well you can see the Functions as a connected loop across the AI lifecycle.

Which sequence best describes how the four Functions interact **over time** for a single AI system?

  1. Govern happens once at the start; then Map, then Measure, then Manage, and the process ends.
  2. Map, Measure, and Manage are technical tasks; Govern is only for executives and does not need to connect to them.
  3. Govern sets policies and roles that shape Map, Measure, and Manage; results from Measure and Manage feed back into updating Govern and future Map activities.
  4. Measure and Manage replace the need for Govern and Map once the system is deployed.
Show Answer

Answer: C) Govern sets policies and roles that shape Map, Measure, and Manage; results from Measure and Manage feed back into updating Govern and future Map activities.

Option 3 is correct: Govern is ongoing and shapes the other Functions, while evidence from Measure and actions in Manage feed back into governance and future mapping. The Functions form a loop, not a one-time sequence.

Step 11 – Flashcard Review: Key Terms and Functions

Use these flashcards to quickly review the core ideas from this module.

AI RMF Core
The part of the NIST AI Risk Management Framework that lists desired outcomes for trustworthy AI, organized into Functions, Categories, and Subcategories.
Function (in AI RMF)
A high-level group of related AI risk management activities. The AI RMF has four: Govern, Map, Measure, Manage.
Category (in AI RMF)
A mid-level grouping of related outcomes within a Function, such as policies, stakeholder analysis, or testing.
Subcategory (in AI RMF)
A specific, observable outcome that describes what successful risk management looks like for a given Category.
Govern Function
Establishes organizational policies, roles, processes, and culture for AI risk management, influencing all lifecycle stages.
Map Function
Understands the AI system's purpose, context, stakeholders, and potential impacts, identifying and prioritizing risks.
Measure Function
Assesses AI system risks and performance using metrics, tests, evaluations, and human feedback.
Manage Function
Uses risk and performance information to make decisions, implement controls, respond to incidents, and adapt the AI system over time.
Sociotechnical Risk Perspective
An approach that considers both technical properties and social, organizational, and human impacts of AI systems.

Step 12 – Apply It: Map Your Own AI Use Case

To consolidate your understanding, apply the four Functions to a simple AI use case.

  1. Pick a use case (real or hypothetical)
  • Example: AI system for grading short-answer quizzes; AI tool for flagging fraudulent transactions; AI assistant for customer support.
  1. Write 1–2 sentences per Function for your use case:
  • Govern: What policies, roles, or training should exist around this system?
  • Map: Who are the stakeholders and what could go wrong in context?
  • Measure: What tests and metrics would you use to evaluate risks and performance?
  • Manage: What decisions or controls would you put in place based on these measurements?
  1. Optional reflection questions
  • Which Function felt easiest to describe? Why?
  • Which Function did you overlook at first? What does that tell you about how AI projects are usually run?

If you are working in a group, compare answers. Notice how different backgrounds (technical, legal, social science) highlight different risks and Functions.

Key Terms

Map
The AI RMF Function focused on understanding the AI system's context, intended use, stakeholders, and potential impacts.
AI RMF
The NIST AI Risk Management Framework, a voluntary framework released in 2023 that helps organizations manage risks of AI systems.
Govern
The AI RMF Function focused on organizational governance for AI: policies, roles, processes, and culture.
Manage
The AI RMF Function focused on making decisions and taking actions to address AI risks over time, including controls and incident response.
Measure
The AI RMF Function focused on assessing and evaluating AI system risks and performance using metrics, tests, and feedback.
Category
A mid-level grouping of related outcomes within a Function, such as policies, stakeholder analysis, or testing.
Function
A top-level grouping of related AI risk management activities in the AI RMF Core: Govern, Map, Measure, Manage.
AI RMF Core
The central part of the AI RMF that lists desired outcomes for trustworthy AI, organized into Functions, Categories, and Subcategories.
Subcategory
A specific, observable outcome that describes what successful risk management looks like for a given Category.
Sociotechnical
Relating to the interaction between social systems (people, organizations, institutions) and technical systems (software, hardware, data).

Finished reading?

Test your understanding with a custom practice exam on this chapter.

Test yourself