A governance lead is mapping responsibilities for an AI programme onto the four core functions of the NIST AI Risk Management Framework so that each activity sits under the function it genuinely belongs to. Which TWO statements correctly match a NIST AI RMF core function to the work it is meant to cover? Select TWO.
- AThe Govern function establishes the culture, policies, accountability lines and oversight that cut across and sustain the other three functions throughout the AI lifecycle. Correct
- BThe Map function defines the context, intended use and categorisation of a system so its potential risks can be framed before they are measured or treated. Correct
- CThe Measure function selects the policies and assigns the accountable executive for AI risk across the whole organisation before any system is analysed.
- DThe Manage function uses quantitative and qualitative tools to assess and benchmark a system's risks against the agreed trustworthiness metrics.
- EThe four core functions are Identify, Protect, Detect and Respond, applied in that order to each AI system the organisation builds.
Why A is correct: Correct: Govern is the cross-cutting function that sets policy, accountability and oversight enabling Map, Measure and Manage to operate.
Why B is correct: Correct: Map gathers context and frames risks, giving the later analysis and response functions something concrete to act on.
Why C is wrong: Tempting because Measure sounds organisation-wide, but setting policy and accountability is the Govern function, not Measure, which analyses and tracks risk.
Why D is wrong: Tempting because Manage handles risk, but assessing and benchmarking against metrics is the Measure function; Manage prioritises and acts on those findings.
Why E is wrong: Tempting because these are real NIST functions, but they belong to the Cybersecurity Framework; the AI RMF functions are Govern, Map, Measure and Manage.