MAP (NIST AI RMF)
The NIST AI RMF function focused on establishing context, identifying risks, and understanding an AI system's purpose, stakeholders, and potential impacts. MAP activities include defining the use case, identifying affected populations, assessing benefits and costs, and cataloguing risks before development begins.
Why It Matters
You can't measure or manage what you haven't mapped. The MAP function ensures organizations understand their AI system's context deeply enough to identify the right risks — not just the obvious ones.
Example
When mapping a new AI-powered insurance pricing model, the team identifies affected stakeholders (policyholders, agents, regulators), maps potential risks (pricing discrimination, data quality issues, model opacity), and documents the system's intended benefits versus potential harms.
Think of it like...
MAP is like a site survey before construction — you need to understand the terrain, the soil conditions, and the neighborhood before you can design a building that's safe and appropriate for the location.
Related Terms
NIST AI Risk Management Framework (AI RMF)
A voluntary framework published by the U.S. National Institute of Standards and Technology that provides structured guidance for managing AI risks through four core functions: Govern, Map, Measure, and Manage. It's designed to be flexible, sector-agnostic, and compatible with other risk management frameworks.
GOVERN (NIST AI RMF)
The cross-cutting function of the NIST AI RMF focused on establishing and maintaining the organizational policies, processes, procedures, and practices needed for AI risk management. Unlike Map, Measure, and Manage — which apply to individual AI systems — GOVERN applies across the entire organization.
MEASURE (NIST AI RMF)
The NIST AI RMF function focused on quantifying, assessing, and tracking identified AI risks using metrics, tests, and evaluation methods. MEASURE activities include bias testing, performance benchmarking, explainability assessment, and security evaluation across the AI lifecycle.
MANAGE (NIST AI RMF)
The NIST AI RMF function focused on allocating resources, prioritizing actions, and responding to AI risks based on insights from the Map and Measure functions. MANAGE activities include risk prioritization, mitigation implementation, incident response, continuous monitoring, and decommissioning decisions.