NIST AI RMF DATA INFRASTRUCTURE MODEL

Context establishment

Part of: MP: MAP — Context & Risk Identification

Description

Legal, regulatory, and societal contexts of AI system deployment are identified and documented, including norms and expectations. You cannot manage risks you don't understand, and you cannot understand risks without understanding context.

Suggested Actions

1
Research and document all applicable AI regulations for your jurisdiction and use case: EU AI Act, state-level AI laws (Colorado, Illinois BIPA, NYC Local Law 144), sector-specific requirements (FDA for medical AI, SR 11-7 for banking), and emerging legislation
2
Document societal norms and ethical expectations for the AI system's domain — what would a reasonable person expect about AI involvement in this context?
3
Identify relevant industry standards and best practices (ISO 42001, NIST AI RMF, IEEE 7000 series, sector-specific guidance)
4
Map organizational context including existing risk tolerance, corporate values, brand reputation considerations, and competitive landscape
5
Assess the current state of public trust and awareness regarding AI in your domain — deploy into a context you understand, not one you assume
6
Document deployment constraints: geographic scope, language requirements, cultural considerations, connectivity requirements, and accessibility needs