NIST AI RMF APPLICATION GOVERNANCE INFRASTRUCTURE MODEL

Purpose evaluation

Part of: MG: MANAGE — Risk Response & Communication

Description

AI systems are evaluated to determine whether their intended purpose, use cases, and deployment context are appropriate and beneficial. The first risk management decision is whether to deploy at all.

Suggested Actions

1
Review AI system purpose against organizational values and societal benefit — not every application that CAN use AI SHOULD use AI
2
Evaluate necessity and proportionality: Is AI the right solution, or could a simpler approach achieve similar results with less risk? A lookup table that works is better than an ML model that might be biased
3
Consider alternative non-AI or lower-risk approaches to achieve the same objectives — document why AI was selected over alternatives with specific evidence of superior performance or capability
4
Obtain stakeholder input on appropriateness of AI system deployment, especially from communities that will be most affected by the system's decisions or outputs
5
Assess whether the expected benefits are distributed equitably — an AI system that benefits the organization while harming users or communities requires careful justification
6
Re-evaluate purpose and appropriateness periodically and after significant changes — a system that was appropriate at launch may become inappropriate as context changes