Your staff are already using AI tools, whether or not you approved them. The NIST AI Risk Management Framework gives you a practical way to decide which uses are safe, which need guardrails, and which should stop. This guide translates it into plain language for organizations without a compliance department.
What the AI Risk Management Framework is
NIST released version 1.0 of the AI Risk Management Framework on January 26, 2023. It is voluntary, so no regulator will fine you for ignoring it.
So why pay attention? Because it gives you a shared vocabulary for AI risk. Also, auditors, insurers, and larger customers increasingly use NIST language when they ask how you govern technology.
Also, the framework is not a checklist of approved products. Instead, it describes a way of thinking about AI across its whole life, from choosing a tool to retiring it.
What “trustworthy AI” means, translated
NIST lists seven characteristics of trustworthy AI. However, the official wording is dense, so here is a working translation for a business owner.
- Valid and reliable: it produces correct results, consistently.
- Safe: it does not put people or property in danger.
- Secure and resilient: attackers cannot easily misuse it, and it recovers from problems.
- Accountable and transparent: someone owns it, and people know when AI is involved.
- Explainable and interpretable: you can understand why it produced an answer.
- Privacy-enhanced: it protects personal and confidential data.
- Fair, with harmful bias managed: it does not treat groups of people unfairly.
You will not score perfectly on all seven. That is fine, because knowing which ones matter most for a given use is the whole point.
The four functions in plain language
The core of the framework is four functions. Think of them as four jobs that someone in your organization needs to do.
Govern: decide who is responsible
Govern sits across everything else. It means setting policy, assigning ownership, and deciding how much AI risk you will accept. For a smaller organization, that could be one page and one accountable executive.
Map: know where AI is used
Next, Map means understanding each AI use in context. What is the tool, who uses it, what data goes in, and who is affected by the output?
Measure: check whether it works
Measure means testing and monitoring. For example, spot-check AI-drafted client letters for accuracy, or review whether an AI tool keeps sharing data it should not.
Manage: act on what you find
Finally, Manage means prioritizing risks and doing something about them. That could mean adding a human review step, restricting a tool, or shutting it off.
The generative AI companion
The original framework predates the explosion of chat assistants. So on July 26, 2024, NIST published a Generative AI Profile, NIST AI 600-1, to address it directly.
The profile names 12 risks that are unique to or made worse by generative AI. Also, several apply to almost every office, including confabulation (confident but false answers), data privacy, information security, and intellectual property.
If your staff use chat assistants to draft email or summarize documents, this profile is the most relevant part of the NIST material for you.
What changed this year
Two developments are worth knowing. First, the White House released America’s AI Action Plan on July 23, 2025. Among other items, it recommended that NIST revise the AI Risk Management Framework.
Second, on December 16, 2025, NIST released a preliminary draft of a Cybersecurity Framework Profile for Artificial Intelligence. It focuses on securing AI systems, using AI for cyber defense, and defending against AI-enabled attacks. NIST is taking public comments through January 30, 2026.
Neither change makes the current framework obsolete. The four functions remain a sound structure, and version 1.0 is still the current release.
So if you are waiting for a revised AI Risk Management Framework before you start, do not. Any future edition will still reward organizations that already know where AI runs and who owns it.
A starter program for a 50-person organization
You do not need a committee. Instead, you need a few decisions made on purpose. Here is a sequence that works for most organizations with 20 to 200 employees.
- Name an owner. Pick one executive who is accountable for AI decisions. That is your Govern function.
- Inventory current use. Ask each department which AI tools they use, including free ones and browser extensions.
- Classify your data. Decide what can never go into a public AI tool, such as client records, financials, and personnel files.
- Approve a short list of tools. Prefer business versions with contractual data protections over consumer accounts.
- Require human review for anything external. AI drafts are fine, but a person signs off before a client sees it.
- Write a one-page acceptable use policy. Then walk staff through it in a short meeting.
- Revisit twice a year. Tools, contracts, and risks change quickly.
Where smaller organizations overreach
First, the most common mistake is trying to implement the whole framework at once. NIST wrote it for organizations of every size, including very large ones. As a result, a literal reading can feel overwhelming.
The second mistake is banning AI outright. In my experience, bans rarely stop use. Instead, they push it onto personal accounts, where you have no visibility or control.
A better approach is proportional. Spend your effort on the uses that touch sensitive data or reach clients. Then keep lighter rules for low-risk tasks like brainstorming or rewriting internal notes.
How WEBIT approaches this
We start with visibility, because you cannot govern tools you do not know about. From there, we help clients choose approved tools, set data rules, and build review steps into daily work through our AI and automation services.
We also fold AI decisions into broader technology planning. That keeps AI governance tied to budgets and priorities through our strategic IT services, rather than living in a forgotten policy document.
Key takeaways
- The NIST framework is voluntary but gives you a credible, shared vocabulary.
- Govern, Map, Measure, and Manage translate into four clear jobs.
- The Generative AI Profile covers the chat tools most offices use today.
- Start small: an owner, an inventory, data rules, and human review.
- Bans push AI use into the shadows; proportional rules work better.
Related from WEBIT: cybersecurity services.
Not sure where your organization stands with AI? Talk to an owner.





