foundations

Foundations of the NIST AI Risk Management Framework

This credential recognizes the holder's ability to apply the NIST AI Risk Management Framework (AI RMF 1.0, NIST AI 100-1) to AI systems an organization builds, buys, or operates. The holder can establish the governance structures the framework's GOVERN function calls for — policies, roles, accountability, escalation paths, and a documented risk tolerance — and connect them to the decisions an organization actually makes about an AI system; execute the MAP function to establish an AI system's context, intended and foreseeable uses, affected parties, and the harms it can cause in operation, including harms to people, to organizations, and to the wider ecosystem; apply the MEASURE function by selecting metrics and evaluation methods proportionate to the system's risks, testing against the characteristics of trustworthy AI — validity and reliability, safety, security and resilience, accountability and transparency, explainability and interpretability, privacy, and fairness with harmful bias managed — and stating plainly where a risk resists measurement; and carry out the MANAGE function by prioritizing risks against documented tolerance, selecting treatments, monitoring deployed systems, responding to incidents, and recommending that a system not be deployed, or be decommissioned, when its residual risk cannot be justified. The holder can assess third-party and supply-chain AI risk, including foundation models and vendor components whose training data and evaluation evidence are not disclosed; apply the framework's Generative AI Profile (NIST AI 600-1) to the risks specific to generative systems; tailor the framework into a profile fit for a sector, a use case, and an organization's risk appetite; and produce the documentation and audit trail — decision records, evaluation evidence, and monitoring results — that makes an AI risk decision defensible to an auditor, a regulator, or a customer after the fact. The holder can further situate the AI RMF alongside adjacent frameworks, including ISO/IEC 42001, the NIST Cybersecurity Framework, and the NIST Privacy Framework, and explain what each does and does not cover.

Criteria

Earned by completing all required modules of the Foundations of the NIST AI Risk Management Framework course and passing review of the capstone: a complete AI RMF assessment of one real or realistic AI system. For that system the holder documents its context, intended use, foreseeable misuse, and affected parties under MAP; produces a governance record under GOVERN naming the accountable roles, the applicable policies, and the organization's stated risk tolerance; delivers an evaluation plan and its results under MEASURE, including an explicit statement of what could not be measured and why; and delivers a prioritized risk register under MANAGE with treatments, residual risk, a monitoring plan, and incident-response and decommissioning triggers. The assessment must also cover the system's third-party and supply-chain exposure, apply the Generative AI Profile where the system is generative, and be defended in review — including the conditions under which the holder would recommend that the system not be deployed.

Open Badges 3.0 Achievement · request with Accept: application/ld+json for the JSON-LD representation.