NIST.AI.100 1 · Table (p.37)
From NIST.AI.100-1.pdf · page 37
| 0 | 1 |
|---|---|
| Practices related to managing AI risks are described in the NIST AI RMF Playbook. Table | |
| 4 lists the MANAGE function’s categories and subcategories. | |
| Table 4: Categories and subcategories for the MANAGE function. | |
| Categories | Subcategories |
| MANAGE 1: AI | MANAGE 1.1: A determination is made as to whether the AI |
| risks based on | system achieves its intended purposes and stated objectives and |
| assessments and | whether its development or deployment should proceed. |
| other analytical | |
| MANAGE 1.2: Treatment of documented AI risks is prioritized | |
| output from the | |
| based on impact, likelihood, and available resources or methods. | |
| MAP and MEASURE | |
| MANAGE 1.3: Responses to the AI risks deemed high priority, as | |
| functions are | |
| identified by the MAP function, are developed, planned, and doc- | |
| prioritized, | |
| umented. Risk response options can include mitigating, transfer- | |
| responded to, and | |
| ring, avoiding, or accepting. | |
| managed. | |
| MANAGE 1.4: Negative residual risks (defined as the sum of all | |
| unmitigated risks) to both downstream acquirers of AI systems | |
| and end users are documented. | |
| MANAGE 2: | MANAGE 2.1: Resources required to manage AI risks are taken |
| Strategies to | into account – along with viable non-AI alternative systems, ap- |
| maximize AI | proaches, or methods – to reduce the magnitude or likelihood of |
| benefits and | potential impacts. |
| minimize negative | |
| MANAGE 2.2: Mechanisms are in place and applied to sustain | |
| impacts are planned, | |
| the value of deployed AI systems. | |
| prepared, | |
| MANAGE 2.3: Procedures are followed to respond to and recover | |
| implemented, | |
| from a previously unknown risk when it is identified. | |
| documented, and | |
| MANAGE 2.4: Mechanisms are in place and applied, and respon- | |
| informed by input | |
| sibilities are assigned and understood, to supersede, disengage, or | |
| from relevant AI | |
| deactivate AI systems that demonstrate performance or outcomes | |
| actors. | |
| inconsistent with intended use. | |
| MANAGE 3: AI | MANAGE 3.1: AI risks and benefits from third-party resources |
| risks and benefits | are regularly monitored, and risk controls are applied and |
| from third-party | documented. |
| entities are | |
| MANAGE 3.2: Pre-trained models which are used for develop- | |
| managed. | |
| ment are monitored as part of AI system regular monitoring and | |
| maintenance. |
Source Metadata