A Chief Risk Officer at a mid-sized investment bank is building an AI governance program and decides to adopt the NIST AI Risk Management Framework (AI RMF 1.0). The CRO wants to prioritize the function that helps the organization understand the context and risk profile of AI systems before committing to deployment. Which NIST AI RMF Core Function should be the CRO's starting point?
Select an answer to reveal the explanation.
Short Explanation and Infographic
NIST AI RMF is structured like a building project: you have to survey the land before you design or build anything. The MAP function is that survey — it says 'what are we actually deploying, who does it affect, and what could go wrong in context?' You can't MEASURE risk you haven't MAPped, and you can't MANAGE risk you haven't MEASURED. GOVERN is always-on, but MAP is where context-setting begins.
Full explanation below image
Full Explanation
The NIST AI Risk Management Framework (AI RMF 1.0), published in January 2023, organizes AI risk management activities into four Core Functions: GOVERN, MAP, MEASURE, and MANAGE. These functions are not strictly sequential—GOVERN is a cross-cutting function that operates continuously—but MAP represents the foundational context-setting step before risk quantification or treatment can occur.
MAP is the function through which organizations categorize AI systems by their intended use case, operational context, potential negative consequences (harms to individuals, organizations, or society), and the populations of people who may be impacted. In a financial services context, this means identifying whether a given AI system is used for credit decisions, fraud detection, trading, or client communications—and characterizing who bears risk if the system fails or produces biased outputs.
Option C is correct because the CRO's stated priority—understanding context and risk profile before deployment—directly aligns with MAP's purpose. Without MAP outputs, the other functions operate without adequate context.
Option A (MANAGE) is incorrect as the starting point. MANAGE involves implementing risk treatment actions, monitoring, and incident response. These activities presuppose that risks have already been identified and assessed through MAP and MEASURE.
Option B (GOVERN) is a plausible starting point for a governance program broadly, because GOVERN establishes the policies, roles, and culture that enable all other functions. However, GOVERN does not provide the context-specific risk profile of individual AI systems—that is MAP's role. The question asks about understanding a system's context and risk profile, which points to MAP.
Option D (MEASURE) applies quantitative and qualitative techniques (including testing, evaluation, and red-teaming) to assess trustworthiness properties like accuracy, fairness, and robustness. MEASURE builds on the context established in MAP and is therefore downstream of the CRO's stated priority.
Financial institutions should treat MAP outputs as living documents that are revisited whenever the AI system, its use case, or the regulatory environment changes materially.