Foundations of the NIST AI Risk Management Framework
Govern, map, measure, and manage AI risk under NIST AI RMF 1.0 — turning the framework's four functions into the controls, evidence, and documented decisions an organization can defend to an auditor or a regulator.
Issued by National Center for Secure AI Education · Valid for 2 years
What it covers
- What the AI RMF is and is not: its scope, its voluntary posture, and how it relates to ISO/IEC 42001, the NIST Cybersecurity Framework, and the NIST Privacy Framework
- The characteristics of trustworthy AI, and the real trade-offs between them
- GOVERN: policies, accountable roles, escalation paths, and setting a risk tolerance before a model is chosen
- MAP: establishing an AI system's context, intended use, foreseeable misuse, and the parties it can harm
- MEASURE: selecting metrics and evaluation methods proportionate to risk — and naming what cannot be measured
- MANAGE: prioritizing and treating AI risk, monitoring deployed systems, and deciding when a system must not ship
- Third-party and supply-chain AI risk: foundation models, vendor components, and risk you inherit without evidence
- The Generative AI Profile (NIST AI 600-1): the risks unique to generative systems and the actions it prescribes
- Authoring an AI RMF Profile tailored to a sector, a use case, and an organization's risk appetite
- Documentation and audit trail: the artifacts that make an AI risk decision defensible after the fact
- Incident response, post-deployment monitoring, drift, and decommissioning an AI system
- Making the assurance case: presenting an AI risk assessment to auditors, regulators, and customers
How it is earned
Earned by completing all required modules of the Foundations of the NIST AI Risk Management Framework course and passing review of the capstone: a complete AI RMF assessment of one real or realistic AI system. For that system the holder documents its context, intended use, foreseeable misuse, and affected parties under MAP; produces a governance record under GOVERN naming the accountable roles, the applicable policies, and the organization's stated risk tolerance; delivers an evaluation plan and its results under MEASURE, including an explicit statement of what could not be measured and why; and delivers a prioritized risk register under MANAGE with treatments, residual risk, a monitoring plan, and incident-response and decommissioning triggers. The assessment must also cover the system's third-party and supply-chain exposure, apply the Generative AI Profile where the system is generative, and be defended in review — including the conditions under which the holder would recommend that the system not be deployed.
Skills it attests
- AI risk management: Govern, Map, Measure, Manage · NIST AI Risk Management Framework 1.0
- Generative AI risk management · NIST Generative AI Profile
- AI management systems · ISO/IEC 42001:2023
- Cybersecurity risk management · NIST Cybersecurity Framework 2.0
- Privacy risk management · NIST Privacy Framework 1.0
The credential you receive
Earn this certification and National Center for Secure AI Education issues you a credential: a signed Open Badges 3.0 record with its own page, and the printable sheet below. The specimen shows the layout with a sample holder — a real credential carries the holder's name, its issue date and a verification link anyone can check.
Specimen — not an issued credential. Machine-readable Open Badges achievement
