A CISO asks the data science team how they ensure their AI model governance program satisfies the NIST AI RMF MANAGE function. Which activity is specifically part of MANAGE?
- A.A. Creating the initial AI risk register listing all identified risks
- B.B. Deploying mitigating controls for high-priority risks, monitoring effectiveness, and adjusting responses as new risks emerge
- C.C. Calculating confusion matrix metrics on the validation dataset
- D.D. Documenting the stakeholder groups affected by the AI system
Why B is correct
NIST AI RMF MANAGE function covers implementing risk treatments: deploying controls, monitoring their effectiveness, adjusting response plans, and managing residual risks over the AI system lifecycle. Creating the risk register is a MAP/MEASURE activity. Calculating confusion matrix metrics is MEASURE. Documenting affected stakeholders is MAP. MANAGE is the execution layer - it takes identified and measured risks and implements, monitors, and continuously improves risk responses.
Know someone studying for AI Security Fundamentals? Send them this one.