NIST AI Risk Management Framework: what it asks of a training dataset list
The NIST AI Risk Management Framework. Its MAP, MEASURE, MANAGE and GOVERN subcategories name the legal risk of third-party data (MP-4.1), privacy risk (MS-2.10), bias (MS-2.11), test sets (MS-2.1) and third-party resources (MN-3.1).
Cited for every list.
Findings that cite it
| Finding | Clause |
|---|---|
| Origin not recorded | NIST AI RMF GV-1.6 |
| Terms not recorded | NIST AI RMF MP-4.1 NIST AI RMF GV-6.1 |
| Terms that need review for this use | NIST AI RMF MP-4.1 NIST AI RMF GV-6.1 |
| Personal data with no lawful basis recorded, or reused from another purpose | NIST AI RMF MS-2.10 |
| Labelled by a vendor, a crowd or a model with no quality check recorded | NIST AI RMF MP-4.2 |
| No version or snapshot date | NIST AI RMF MS-2.1 |
| Declared potential overlap between train and test | NIST AI RMF MS-2.1 NIST AI RMF MP-2.3 |
| High-risk use with no bias examination recorded | NIST AI RMF MS-2.11 |
| Older than your N-year policy threshold (a threshold you set, not a legal deadline) | NIST AI RMF MP-2.3 |
| Content where a label belongs | NIST AI RMF MS-2.10 |
| Vendor data with no provider named | NIST AI RMF MN-3.1 NIST AI RMF GV-6.1 |
Source classes anchored here
42NIST AI Risk Management Framework: every clause cited
10 of the 72 heldThe requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim.
NIST AI RMF GV-1.6Inventory of AI systemsMechanisms are in place to inventory AI systems and are resourced according to organizational risk priorities. A maintained inventory identifies the AI systems and models in use, and the resource given to maintaining it is proportionate to the risk the inventoried systems carry.
NIST AI RMF GV-6.1Third-party and intellectual property risk policyPolicies and procedures are in place that address AI risks associated with third-party entities, including risks of infringement of a third party’s intellectual property or other rights. Third-party AI risk is addressed by policy covering data, models, software and services obtained externally, including the rights position on training data and model outputs.
NIST AI RMF MN-3.1Third-party resources monitoredAI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented. Third-party data, model, software and hardware dependencies are monitored on an ongoing basis, not assessed once at procurement, and the controls applied are recorded.
NIST AI RMF MN-3.2Pre-trained models monitoredPre-trained models which are used for development are monitored as part of AI system regular monitoring and maintenance. Pre-trained and transfer-learned models are treated as a monitored component in their own right, since their provenance and behaviour are not controlled by the deploying organisation.
NIST AI RMF MP-2.3Data collection, selection and TEVVScientific integrity and TEVV considerations are identified and documented, including those related to experimental design, data collection and selection (e.g., availability, representativeness, suitability), system trustworthiness, and construct validation. The evaluation design is documented as a scientific claim: what was measured, on what data, and whether the measure validly stands for the property claimed.
NIST AI RMF MP-4.1Legal risks of components and third-party dataApproaches for mapping AI technology and legal risks of its components – including the use of third-party data or software – are in place, followed, and documented, as are risks of infringement of a third-party’s intellectual property or other rights. There is a followed approach for mapping the technology and legal risk carried by each component, including data and software obtained from third parties and the rights position attached to them.
NIST AI RMF MP-4.2Internal controls for third-party componentsInternal risk controls for components of the AI system including third-party AI technologies are identified and documented. For each component carrying risk, the internal control applied to it is identified and written down, so the risk mapping produces controls rather than a list.
NIST AI RMF MS-2.1Test sets documentedTest sets, metrics, and details about the tools used during test, evaluation, validation, and verification (TEVV) are documented. The TEVV record is complete enough for the evaluation to be repeated: which test sets, which metrics, which tools and which versions.
NIST AI RMF MS-2.10Privacy risk examinedPrivacy risk of the AI system – as identified in the MAP function – is examined and documented. Privacy examination covers what the AI system makes possible, inference and re-identification from training data and outputs, not only the lawfulness of the input data.
NIST AI RMF MS-2.11Fairness and bias evaluatedFairness and bias – as identified in the MAP function – is evaluated and results are documented. Fairness evaluation states which fairness definition was applied and why, evaluates against it, and records the results including where the definition itself is contested.