MEASURE: Test the system against the risks MAP found, with methods you can defend.
The complete MEASURE function of the NIST AI Risk Management Framework, every category and subcategory, verified against NIST AI 100-1 on August 25, 2026.
MEASURE turns the risks MAP identified into numbers, assessments and tracked evidence. It covers how metrics are chosen, how the system is evaluated against each characteristic of trustworthiness, how risks are tracked over time, and whether the measurement itself is working.
This is the function with the most subcategories, and the reason is honest: trustworthy AI is not one property but seven, and each one has to be evaluated on its own.
MEASURE 1: Appropriate methods and metrics are identified and applied
- MEASURE 1.1
Metrics for the risks enumerated in MAP are selected, starting with the most significant; what cannot be measured is documented rather than ignored.
- MEASURE 1.2
The appropriateness of AI metrics and the effectiveness of existing controls are regularly assessed and updated.
- MEASURE 1.3
Experts who did not build the system, or independent assessors, are involved in regular assessments and updates.
MEASURE 2: AI systems are evaluated for trustworthy characteristics
- MEASURE 2.1
Test sets, metrics and the tools used during testing, evaluation, verification and validation are documented.
- MEASURE 2.2
Evaluations involving human subjects meet applicable requirements and represent the relevant population.
- MEASURE 2.3
Performance or assurance criteria are measured under conditions similar to the deployment setting.
- MEASURE 2.4
The functionality and behavior of the system and its components are monitored in production.
- MEASURE 2.5
The system is demonstrated to be valid and reliable, and the limits of its generalizability are documented.
- MEASURE 2.6
The system is evaluated regularly for safety risks; residual risk stays within tolerance and the system can fail safely.
- MEASURE 2.7
Security and resilience are evaluated and documented.
- MEASURE 2.8
Risks tied to transparency and accountability are examined and documented.
- MEASURE 2.9
The model is explained, validated and documented, and its output is interpreted within its context.
- MEASURE 2.10
Privacy risk is examined and documented.
- MEASURE 2.11
Fairness and bias are evaluated and the results documented.
- MEASURE 2.12
The environmental impact and sustainability of training and management activities are assessed and documented.
- MEASURE 2.13
The effectiveness of the measurement metrics and processes themselves is evaluated and documented.
MEASURE 3: Mechanisms for tracking identified AI risks over time are in place
- MEASURE 3.1
Approaches, personnel and documentation regularly identify and track existing, unanticipated and emergent risks in deployed contexts.
- MEASURE 3.2
Risk tracking considers settings where risks are hard to assess with currently available measurement techniques.
- MEASURE 3.3
End users and impacted communities can report problems and appeal outcomes, and that feedback enters evaluation metrics.
MEASURE 4: Feedback about the efficacy of measurement is gathered and assessed
- MEASURE 4.1
Measurement approaches are connected to deployment contexts and informed by domain experts and end users.
- MEASURE 4.2
Measurement results are validated with domain experts and relevant actors to confirm the system performs as intended.
- MEASURE 4.3
Measurable improvements or declines, drawn from consultations and field data, are identified and documented.
MEASURE is a skill before it is a checklist
Reading the categories tells you what good looks like. The AI Governance program drills the calls themselves, and the credential shows an employer you made them under assessment.
Category and subcategory identifiers follow NIST AI 100-1 exactly; the wording is our plain-English paraphrase. Read the authoritative text in NIST AI 100-1. Not affiliated with or endorsed by NIST. Last verified: August 25, 2026.