Skip to main content
5 categories, 18 subcategories

MAP: Establish the context: what the system is for, who it touches, and what could go wrong.

The complete MAP function of the NIST AI Risk Management Framework, every category and subcategory, verified against NIST AI 100-1 on August 25, 2026.

MAP establishes the context that frames everything downstream. It asks what the AI system is for, where it will run, who it will affect, what it should never do, and what the organization can tolerate. Without that context, the framework says plainly, risk management is difficult to perform.

MAP is where the go or no-go decision gets its evidence. Its outcomes feed MEASURE and MANAGE, and it is revisited as context, capabilities and impacts change.

MAP

MAP 1: Context is established and understood

  1. MAP 1.1

    Intended purposes, beneficial uses, applicable laws and norms, and the settings where the system will run are understood and documented.

  2. MAP 1.2

    The interdisciplinary people, skills and capacities needed to establish context are identified and documented.

  3. MAP 1.3

    The organization's mission and its goals for AI technology are understood and documented.

  4. MAP 1.4

    The business value or context of business use is clearly defined, or re-evaluated for an existing system.

  5. MAP 1.5

    Organizational risk tolerances are determined and documented.

  6. MAP 1.6

    System requirements are elicited from and understood by relevant AI actors, and design decisions account for socio-technical implications.

MAP

MAP 2: The AI system is categorized

  1. MAP 2.1

    The specific tasks and methods the system will support are defined (for example classifiers, generative models, recommenders).

  2. MAP 2.2

    The system's knowledge limits, and how its output will be used and overseen by humans, are documented.

  3. MAP 2.3

    Scientific integrity and testing, evaluation, verification and validation considerations are identified and documented.

MAP

MAP 3: Capabilities, usage, goals, expected benefits and costs are understood against benchmarks

  1. MAP 3.1

    Potential benefits of the intended functionality and performance are examined and documented.

  2. MAP 3.2

    Potential costs, including non-monetary costs of errors, are examined against organizational risk tolerance and documented.

  3. MAP 3.3

    The targeted application scope is specified and documented, based on capability, context and categorization.

  4. MAP 3.4

    Processes for operator and practitioner proficiency are defined, assessed and documented.

  5. MAP 3.5

    Processes for human oversight are defined, assessed and documented, following the policies set in GOVERN.

MAP

MAP 4: Risks and benefits are mapped for all components, including third-party software and data

  1. MAP 4.1

    Approaches for mapping technology and legal risks of components, including third-party data or software, are in place, followed and documented.

  2. MAP 4.2

    Internal risk controls for components, including third-party AI technologies, are identified and documented.

MAP

MAP 5: Impacts on individuals, groups, communities, organizations and society are characterized

  1. MAP 5.1

    The likelihood and magnitude of each identified impact, beneficial or harmful, are identified and documented.

  2. MAP 5.2

    Practices and personnel support regular engagement with relevant AI actors and integrate feedback about positive, negative and unanticipated impacts.

The other functions

MAP is a skill before it is a checklist

Reading the categories tells you what good looks like. The AI Governance program drills the calls themselves, and the credential shows an employer you made them under assessment.

Category and subcategory identifiers follow NIST AI 100-1 exactly; the wording is our plain-English paraphrase. Read the authoritative text in NIST AI 100-1. Not affiliated with or endorsed by NIST. Last verified: August 25, 2026.