Chapter 2 of 13
Inside the AI RMF Core: The Four Functions and Their Outcomes
Behind the buzzwords ‘Govern, Map, Measure, Manage’ lies a detailed set of outcomes that describe what good AI risk management actually looks like. This module walks through the AI RMF Core so you can see how the four functions organize concrete activities across the AI lifecycle.
Step 1 – From Principles to the AI RMF Core
Zooming into the AI RMF Core
The NIST AI RMF 1.0 (released 2023) turns AI principles into concrete practices. Its Core section describes in detail what good AI risk management looks like.
Core Structure
The AI RMF Core is organized as Functions → Categories → Subcategories. The four top-level Functions are: Govern, Map, Measure, Manage.
Lifecycle & Sociotechnical View
These Functions span the entire AI lifecycle and use a sociotechnical view: they care about technical performance and real-world impacts on people, organizations, and systems.
Your Learning Goal
You do not need to memorize every Subcategory. Focus on: how the structure works, what each Function aims to achieve, and how Functions overlap across the lifecycle.
Step 2 – The Core Structure: Functions, Categories, Subcategories
Three-Level Structure
The AI RMF Core is a table of desired outcomes with three levels: Functions → Categories → Subcategories.
Functions
There are four Functions: Govern, Map, Measure, Manage. They are big clusters of activities and are not strictly sequential; they overlap and repeat.
Categories
Each Function has several Categories that group related outcomes. Example: Govern may include "Policies, Processes, and Procedures" and "Workforce".
Subcategories
Each Category has Subcategories: specific, observable outcomes, often starting with verbs like "identified", "documented", or "monitored".
How Orgs Use It
As of 2026, organizations often mirror this structure in internal AI policies and control libraries, aligning their tasks with Functions, Categories, and Subcategories.
Step 3 – Quick Mapping Exercise: Where Does This Fit?
Try this thought exercise to get used to the Functions.
For each activity below, decide which Function it mainly belongs to: Govern, Map, Measure, or Manage.
- A company sets an AI policy that says: "High-risk models must undergo bias assessment before deployment."
- A team interviews end-users and domain experts to understand how an AI tool might change their workflows.
- Data scientists run a fairness test comparing model performance across demographic groups.
- An operations team rolls back a newly deployed model after monitoring shows unexpected errors.
Pause and answer before checking the suggested mapping:
Suggested mapping
- Govern – setting policies and rules.
- Map – understanding context, stakeholders, and use.
- Measure – testing and evaluating technical and socio-technical properties.
- Manage – acting on risk information during deployment and operations.
Notice that in real projects, tasks can touch more than one Function, but one is usually primary.
Step 4 – Govern: Setting the Ground Rules for AI
What is Govern?
Govern is about how an organization sets direction, assigns responsibility, and builds a culture for trustworthy AI risk management.
Key Themes
Govern covers: AI risk policies, roles and responsibilities, workforce skills and culture, and integration with existing risk, privacy, and security governance.
Across the Lifecycle
Govern is continuous: it shapes which AI projects are allowed, what checks are needed before deployment, and when systems must be updated or retired.
Sociotechnical Focus
Govern emphasizes human and societal impacts, not just model accuracy. Policies may forbid deployments that could enable discrimination or unsafe uses.
Regulatory Context
As of 2026, laws like the EU AI Act expect strong AI governance. The AI RMF Govern Function offers a widely used, non-regulatory reference model.
Step 5 – Govern in Practice: A University Chatbot
Scenario: University Chatbot
A university wants an AI chatbot to answer financial-aid questions. How does the Govern Function appear in this project?
Policies & Roles
The university labels this chatbot "high impact" and assigns a system owner, technical owner, and risk contact with clear responsibilities.
Standards & Requirements
Policies require privacy impact assessments, bias and accuracy checks, and escalation paths when the chatbot is uncertain.
Training & Culture
Staff supervising the chatbot are trained to spot harmful answers, override the system, and report incidents centrally.
Why This is Govern
These actions set the environment and expectations for the AI system. They are governance, not model-building, and belong to the Govern Function.
Step 6 – Map: Understanding Context, Use, and Stakeholders
What is Map?
Map is about deeply understanding the AI system's purpose, context, stakeholders, and potential impacts before and during development.
Key Questions
Map outcomes answer: What problem are we solving? Who are the stakeholders? In what context will AI operate? What can go wrong and who could be harmed?
Typical Map Themes
Map covers context establishment, stakeholder and impact analysis, and risk identification and prioritization.
Across the Lifecycle
Map is strongest in planning and design but should be revisited whenever use, context, or observed risks change.
Sociotechnical Focus
Map looks beyond data and models to how AI interacts with processes, laws, and human decision-making. Many real-world failures trace back to weak mapping.
Step 7 – Quick Check: Govern vs Map
Test your understanding of the difference between Govern and Map.
A hospital plans to use an AI tool to prioritize patients in the emergency room. Which activity is the **best example of the Map Function**?
- Approving an organization-wide policy that all high-risk AI must go through an ethics review board.
- Interviewing nurses and doctors to understand how triage decisions are currently made and what could go wrong if AI makes mistakes.
- Assigning a Chief AI Officer who is accountable for all AI systems in the hospital.
- Requiring that the vendor provide monthly performance reports for the AI tool after deployment.
Show Answer
Answer: B) Interviewing nurses and doctors to understand how triage decisions are currently made and what could go wrong if AI makes mistakes.
Option 2 is Map: it focuses on understanding current workflows, context, and potential harms. Options 1 and 3 are Govern (policies and roles). Option 4 is closer to Manage (ongoing oversight and action based on performance).
Step 8 – Measure: Evaluating AI Risks and Performance
What is Measure?
Measure is about assessing the AI system: collecting evidence on risks and performance so decisions are based on data, not guesses.
Key Questions
Measure asks: How accurate, robust, fair, secure, and reliable is the system? How do we know? How uncertain are we about those answers?
Typical Measure Themes
It covers metric selection, testing and validation (including red-teaming), and documenting uncertainty and limitations.
Across the Lifecycle
Measure is central in development and pre-deployment, but continues in production via monitoring, drift detection, and re-evaluation.
Beyond Technical Metrics
Measure also includes sociotechnical evaluations: user studies, human feedback, and impact assessments, not just numerical scores.
Step 9 – Measure & Manage: A Generative AI Content Tool
Scenario: Generative AI for Marketing
A company uses a generative AI model to draft marketing content. How do Measure and Manage appear in this case?
Measure: What to Test
They define tests for hallucinations, toxicity and bias, and brand safety, and run red-team exercises to probe the model's behavior.
Manage: Acting on Results
Based on test results, they limit use to internal drafts, require human review, add filters, and define incident response steps.
Ongoing Management
They schedule re-testing after model or prompt changes, closing the loop between measurement and management.
Measure → Manage Loop
This shows the pattern: Measure provides evidence; Manage uses that evidence to adjust deployment, controls, and responses.
Step 10 – Linking the Four Functions Across the Lifecycle
Check how well you can see the Functions as a connected loop across the AI lifecycle.
Which sequence best describes how the four Functions interact **over time** for a single AI system?
- Govern happens once at the start; then Map, then Measure, then Manage, and the process ends.
- Map, Measure, and Manage are technical tasks; Govern is only for executives and does not need to connect to them.
- Govern sets policies and roles that shape Map, Measure, and Manage; results from Measure and Manage feed back into updating Govern and future Map activities.
- Measure and Manage replace the need for Govern and Map once the system is deployed.
Show Answer
Answer: C) Govern sets policies and roles that shape Map, Measure, and Manage; results from Measure and Manage feed back into updating Govern and future Map activities.
Option 3 is correct: Govern is ongoing and shapes the other Functions, while evidence from Measure and actions in Manage feed back into governance and future mapping. The Functions form a loop, not a one-time sequence.
Step 11 – Flashcard Review: Key Terms and Functions
Use these flashcards to quickly review the core ideas from this module.
- AI RMF Core
- The part of the NIST AI Risk Management Framework that lists desired outcomes for trustworthy AI, organized into Functions, Categories, and Subcategories.
- Function (in AI RMF)
- A high-level group of related AI risk management activities. The AI RMF has four: Govern, Map, Measure, Manage.
- Category (in AI RMF)
- A mid-level grouping of related outcomes within a Function, such as policies, stakeholder analysis, or testing.
- Subcategory (in AI RMF)
- A specific, observable outcome that describes what successful risk management looks like for a given Category.
- Govern Function
- Establishes organizational policies, roles, processes, and culture for AI risk management, influencing all lifecycle stages.
- Map Function
- Understands the AI system's purpose, context, stakeholders, and potential impacts, identifying and prioritizing risks.
- Measure Function
- Assesses AI system risks and performance using metrics, tests, evaluations, and human feedback.
- Manage Function
- Uses risk and performance information to make decisions, implement controls, respond to incidents, and adapt the AI system over time.
- Sociotechnical Risk Perspective
- An approach that considers both technical properties and social, organizational, and human impacts of AI systems.
Step 12 – Apply It: Map Your Own AI Use Case
To consolidate your understanding, apply the four Functions to a simple AI use case.
- Pick a use case (real or hypothetical)
- Example: AI system for grading short-answer quizzes; AI tool for flagging fraudulent transactions; AI assistant for customer support.
- Write 1–2 sentences per Function for your use case:
- Govern: What policies, roles, or training should exist around this system?
- Map: Who are the stakeholders and what could go wrong in context?
- Measure: What tests and metrics would you use to evaluate risks and performance?
- Manage: What decisions or controls would you put in place based on these measurements?
- Optional reflection questions
- Which Function felt easiest to describe? Why?
- Which Function did you overlook at first? What does that tell you about how AI projects are usually run?
If you are working in a group, compare answers. Notice how different backgrounds (technical, legal, social science) highlight different risks and Functions.
Key Terms
- Map
- The AI RMF Function focused on understanding the AI system's context, intended use, stakeholders, and potential impacts.
- AI RMF
- The NIST AI Risk Management Framework, a voluntary framework released in 2023 that helps organizations manage risks of AI systems.
- Govern
- The AI RMF Function focused on organizational governance for AI: policies, roles, processes, and culture.
- Manage
- The AI RMF Function focused on making decisions and taking actions to address AI risks over time, including controls and incident response.
- Measure
- The AI RMF Function focused on assessing and evaluating AI system risks and performance using metrics, tests, and feedback.
- Category
- A mid-level grouping of related outcomes within a Function, such as policies, stakeholder analysis, or testing.
- Function
- A top-level grouping of related AI risk management activities in the AI RMF Core: Govern, Map, Measure, Manage.
- AI RMF Core
- The central part of the AI RMF that lists desired outcomes for trustworthy AI, organized into Functions, Categories, and Subcategories.
- Subcategory
- A specific, observable outcome that describes what successful risk management looks like for a given Category.
- Sociotechnical
- Relating to the interaction between social systems (people, organizations, institutions) and technical systems (software, hardware, data).