NIST AI Risk Management Framework
A voluntary framework organised around four functions — Govern, Map, Measure, Manage — for identifying and managing risk across an AI system's lifecycle. Published January 2023, with a generative AI profile added subsequently.
Why it matters for autonomous finance
The reference document US financial institutions will be measured against, whether or not it is ever mandated, because it is what examiners already know. Its real contribution is the Govern function: it puts organisational accountability ahead of technical controls, which is the correct ordering and the one most firms invert.
What it does not cover
It is a process framework, not a conformance standard. There is no certification, no pass mark, and no defined threshold — two firms can both claim alignment while operating at completely different risk levels. It also predates autonomous agents acting with capital, and reads throughout as though a human decides and the model advises.
No treatment of delegated authority, agent identity, or systemic correlation. Every entry in this register carries this section. A standard read past its scope is worse than no standard, because it produces confidence without coverage.