Voluntary tool
NIST AI Risk Management Framework
United States · AI RMF 1.0
What the text addressesIt organises continuous risk management through four functions: Govern, Map, Measure and Manage.
- Who and where it concerns
- Voluntary US framework that can be used internationally. It does not replace the law of the relevant jurisdiction.
- Why this reference exists
- NIST AI RMF addresses a management problem: a risk is not controlled merely because it was entered once in a register. It must be understood in context, measured with stated limits, assigned to responsible people and revisited throughout the system’s life.
- What it calls us to examine
- Connect responsibilities, use context, measurement and risk-treatment decisions to documented, reviewable evidence.
- What changes in practice
- Govern, Map, Measure and Manage give technical, business, legal and leadership teams a shared language. An audit can examine whether uses and affected people are identified, measures are relevant and residual risks lead to decisions that are followed up. This voluntary framework does not replace applicable regulation.
Official document checked in the CSAEAI collection NIST AI 100-1, AI RMF 1.0, January 2023, Section 5 (Govern, Map, Measure, Manage).
Read the official source↗Voluntary tool
NIST Generative AI Profile
United States · NIST AI 600-1 · 2024
What the text addressesIt describes risks specific to or amplified by generative AI, including confidently presented false outputs, privacy, harmful bias, security and information integrity.
- Who and where it concerns
- A voluntary profile supplementing the NIST AI RMF for generative-AI actors; it is neither a general US statute nor a certification.
- Why this reference exists
- A generative system can produce persuasive but false answers, disclose sensitive information or amplify misleading content. The NIST profile makes these risks more visible within the general risk-management framework.
- What it calls us to examine
- Connect relevant risks to the use context and AI RMF actions, without assuming that every risk or action applies equally to every system.
- What changes in practice
- Start with risks that are genuinely plausible for the model and its use, then identify observable evidence for managing them. The profile guides analysis and prioritisation; a list of risks is not automatic evidence of safety.
Official document checked in the CSAEAI collection NIST AI 600-1, Generative Artificial Intelligence Profile, July 2024, Sections 2 and 3.
Read the official source↗Standard
ISO/IEC 42001:2023
International standard · AI management system
What the text addressesIt specifies an AI management system to establish, maintain and continually improve.
- Who and where it concerns
- International standard for organisations developing, providing or using AI. Adopting it, or obtaining certification, is distinct from legal compliance.
- Why this reference exists
- ISO/IEC 42001 is primarily about the organisation developing or using AI. Responsible governance cannot depend on a few people’s good intentions alone; it requires assigned responsibilities, processes and continual improvement.
- What it calls us to examine
- Define responsibilities, policies, objectives, risk and impact assessment, controls and recurring organisational review.
- What changes in practice
- A review looks at the management system’s scope, objectives, roles, assessment of risks and impacts, controls and recurring review. Any certification has a defined scope. By itself, it does not prove that a particular product satisfies every law or has no risk.
Official document checked in the CSAEAI collection ISO/IEC 42001:2023, Clauses 4–10 and Annex A.
Read the official source↗Principles
OECD AI Principles
Adopted in 2019 · updated in 2024
What the text addressesThe Recommendation sets out five values-based principles: inclusive growth, sustainable development and well-being; human rights and democratic values, including fairness and privacy; transparency and explainability; robustness, security and safety; and accountability. It separately offers five recommendations to policymakers.
- Who and where it concerns
- International policy and responsible-conduct principles; they do not themselves create CSAEAI certification or identical duties in every country.
- Why this reference exists
- The OECD Principles offer a shared language for judging whether AI benefits people and remains trustworthy. They bring together concerns often treated separately: rights, fairness, transparency, safety and accountability.
- What it calls us to examine
- Examine benefits and risks for people, whether outputs can be understood, system resilience and actors’ ability to account for their decisions.
- What changes in practice
- They prompt concrete questions: does a person know AI is involved? Can they understand material factors, seek an explanation and challenge an outcome? Who watches the system when its use changes? These are principles and recommendations; precise legal duties come from the rules of each jurisdiction.
Official document checked in the CSAEAI collection OECD, C/MIN(2024)16/FINAL, revised Recommendation of 3 May 2024, Section 1.
Read the official source↗Principles
UNESCO Recommendation on the Ethics of AI
International recommendation · 2021
What the text addressesIt connects AI ethics to human rights, diversity, the environment, education and inequality.
- Who and where it concerns
- Guidance adopted by UNESCO member states. It informs public action and is not the same as directly applicable national law.
- Why this reference exists
- UNESCO asks us to look beyond the product or company deploying AI. A system may work technically while deepening exclusion, overlooking a language or shifting costs onto people and ecosystems that are less visible.
- What it calls us to examine
- Assess ethical and social impacts, inclusion, data governance and follow-up measures in the real use context.
- What changes in practice
- The Recommendation encourages ethical impact assessment and policies attentive to equality, data, the environment, education and social conditions. In an audit, that means identifying affected groups, hearing their needs and following effects over time. It guides states; it is not a universal legal licence imposed directly on every system.
Official document checked in the CSAEAI collection UNESCO, Recommendation on the Ethics of Artificial Intelligence, adopted 23 November 2021.
Read the official source↗