NIST AI RMF MEASURE 4
You check whether your measurements are working and improve them.
What NIST says
Feedback about efficacy of measurement is gathered and assessed.
Category statement quoted from NIST AI 100-1 (AI RMF 1.0). Function: MEASURE, identified risks are assessed, analyzed, or tracked.
Evidence that shows you're doing it
- Review of metric usefulness
- Feedback from users and experts on measurement gaps
Rate yourself
- Not done
- Ad hoc
- Defined
- Operating
- Measured and improving
The AI Governance Toolkit (Professional, $599) has the NIST AI RMF mapping workbook: maturity scoring, evidence, owners and next steps for every category, plus the ISO/IEC 42001 crosswalk.
Other MEASURE categories
- MEASURE 1: You picked sensible ways to measure the risks you mapped, and you use them.
- MEASURE 2: Systems are tested for the qualities that make AI trustworthy: validity, safety, security, privacy, fairness, transparency and explainability.
- MEASURE 3: Risks are tracked over time, including new ones that appear after launch.