AI Risk Management
AI risk management identifies, evaluates and controls possible adverse outcomes across an AI system's lifecycle. The competency is relating model and workflow failures to affected people and operations, assigning accountable owners and deciding which controls, monitoring or changes are needed before and after the system is used.
What it is
Risk depends on context: a plausible incorrect sentence has different consequences in a creative draft, a maintenance instruction or an automated action. AI risk management considers the model, data, tools, deployment and human response as one system. NIST's AI Risk Management Framework organizes work through Govern, Map, Measure and Manage functions. This is distinct from a single safety filter or model evaluation. Evaluations provide evidence about selected behavior; risk management determines its significance, responsibilities and response. It also separates a known control from an untested assumption that the control will work.
What the work involves
The practitioner maps intended use and affected parties, identifies plausible failure pathways and records impact and uncertainty. They assign owners, select preventive or detective controls and test whether those controls interrupt the relevant pathway. They define escalation, monitoring and review conditions, preserving a record of decisions and residual risk. Useful work produces a living risk register and response plan connected to actual system behavior, including clear authority to restrict or stop a capability when evidence changes.
Illustrative example
A team evaluates an assistant that drafts equipment operating instructions. Domain reviewers identify a failure where retrieved advice applies to a different device variant. The risk owner requires variant confirmation, source visibility and human approval before instructions are used. A test intentionally supplies conflicting variants and checks the fallback. An incident plan defines who investigates if an inappropriate instruction reaches a user and how affected versions are withdrawn.
Limits and common mistakes
A register can become paperwork if controls are not implemented or reviewed. Likelihood estimates may be uncertain, and rare failures can escape routine evaluation. Content filtering addresses only part of the system's risk. Check control effectiveness, owner authority and escalation behavior. Risk management cannot promise the absence of harm; it supports explicit, revisable decisions about a defined use and the evidence available to its accountable operators.
Prerequisites
Related skills
- ← is part of: AI Auditability
- ← is subcategory of: AI Data Security
- ← is part of: AI Output Verification
- ← is subcategory of: AI Red Teaming
- → is subcategory of: AI
- ← is subcategory of: AI Supply Chain Security
- ← is part of: Adversarial AI Testing
- ← is part of: Human-in-the-Loop AI
- ← is an instance of: NeMo Guardrails
- ← is an instance of: SAIF
- ← is subcategory of: AI Ethics
- ← is subcategory of: AI Rate Limiting
- ← is subcategory of: AI Toxicity Analysis
- ← is subcategory of: AI Watermarking
- ← is subcategory of: Explainable AI
Sources and further reading
- NIST AI Risk Management Framework
Provides the contextual, lifecycle-based Govern, Map, Measure and Manage framework.
- NIST AI RMF Playbook
Supports operational actions, roles, documentation and review of AI risk controls.
Last updated: 2026-10-10