NIST AI Risk Management Framework
The reference vocabulary for AI risk in the United States, and the one most enterprise risk teams have already adopted internally. It organises AI risk into four functions — Govern, Map, Measure, Manage — and asks whether an organisation can show it does each of them, rather than prescribing specific technology.
Govern and Map are evidenced by the registry: Policy Sets with a draft → pending → active lifecycle, Controls with segregation of duties, and AI Use Cases and Agents that record intended purpose and risk rating. Measure is where the new capabilities land — the Ethics & Bias report answers MEASURE 2.1 on trustworthy characteristics, and Project Moonshot runs answer MEASURE 2.7 on adversarial testing. Manage is the Violations pipeline and Review Queue.